Skip to content

Overlapping rules in Operational-Best-Practices-for-FedRAMP-High Part 1 and Part 2 Break StackSet Deployment #439

@msntx

Description

@msntx

It is not possible to deploy either Operational-Best-Practices-for-FedRAMP-HighPart1.yaml or Operational-Best-Practices-for-FedRAMP-HighPart2.yaml as StackSets due to at least these following rules which are found in Part2 and Part1:
AcmCertificateExpirationCheck
ApiGwCacheEnabledAndEncrypted
ApiGwExecutionLoggingEnabled
ApiGwSslEnabled
AuroraResourcesProtectedByBackupPlan
AutoscalingLaunchConfigPublicIpDisabled
BackupPlanMinFrequencyAndMinRetentionCheck
CloudTrailCloudWatchLogsEnabled
CloudTrailEnabled
CloudTrailEncryptionEnabled
CloudTrailLogFileValidationEnabled
CloudtrailS3DataeventsEnabled
CloudwatchAlarmActionCheck
CloudwatchLogGroupEncrypted
DbInstanceBackupEnabled
DynamodbAutoscalingEnabled
DynamodbInBackupPlan
DynamodbPitrEnabled
DynamodbResourcesProtectedByBackupPlan

It is not clear why these rules need to be present in both packs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions