fix(gcp): Updated iam_audit_logs_enabled to check for default configuration #8633
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Context
The current check
iam_audit_logs_enabled
will pass if any audit log is enabled.The recommended configuration is to enable audit logging for every service in GCP.
The proposed changes ensure that all audit logging is enabled for every service.
Description
cloudresourcemanager_service
to store the audit log configuration instead of a booleaniam_audit_logs_enabled
to fail by defaultallServices
Steps to review
To test this change, we need to create a fresh GCP project and modify the audit log settings under IAM - Audit Logs.
Original
First, to test if the check passes when all audit logging is enabled
To test if the check fails when partial audit logging is disabled
To test if the check fails when all audit logging is disabled
To test if the check fails when only a service's audit logging is enabled
Proposed Changes
Now we will test the proposed changes
First, to test if the check passes when all audit logging is enabled
To test if the check fails when partial audit logging is disabled
To test if the check fails when all audit logging is disabled
Make sure to disable the single service audit logs
To test if the check fails when only a service's audit logging is enabled
Checklist
License
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.