Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pulumi Policy Pack should consider _both_ RDS clusters and instances in rules #519

Open
psirenny opened this issue Aug 8, 2024 · 0 comments
Labels
🎉 enhancement Enhances the product

Comments

@psirenny
Copy link
Contributor

psirenny commented Aug 8, 2024

AWS native (and perhaps classic?) doesn’t allow setting the same properties on an instance and a cluster. For example, enabling encryption on the cluster and its instance results in an error. This makes sense; otherwise, instance settings could conflict with their owning cluster. In some cases, settings must be applied only to the cluster or the instance based on the type of RDS deployment.

However… The default RDS cluster and RDS instance policy pack rules don’t consider this. They dictate that specific settings — such as enabling encryption — must be applied to both resources. A rule that’s impossible to comply with. An ideal rule would look at both the RDS cluster and its instances to see if they're passing/failing compliance.

@psirenny psirenny added the 🎉 enhancement Enhances the product label Aug 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🎉 enhancement Enhances the product
Projects
None yet
Development

No branches or pull requests

1 participant