Second-pass review: event coverage gap, IAM scoping, and baseline hardening - #15
Merged
Merged
Conversation
… hardening Correctness - auto-remediate-open-ssh-rdp (event-driven): also match ModifySecurityGroupRules, so editing an existing rule to 0.0.0.0/0 is remediated in seconds instead of waiting for the Config scan. The modify event has no resulting CIDR, so the Lambda re-checks the whole group. Lambda copies and both event patterns/READMEs updated. - claude-apps-gateway (Terraform): always take a final RDS snapshot on destroy. It was tied to deletion protection, which must be disabled before a destroy is possible, so the snapshot was skipped in exactly the case it was meant to protect. Now matches the CFN DeletionPolicy. - claude-apps-gateway: allow the GovCloud inference-profile prefix (us-gov.anthropic.*) in the task role, since the module claims GovCloud support. Least-privilege / hardening - member-baseline: Config bucket now has versioning, a noncurrent-version lifecycle rule and a TLS-only bucket policy (both the StackSet inline template and the Terraform copy); documented the one-Config-recorder conflict for accounts with Config already enabled (e.g. Control Tower). - ec2-isolation-runbook: scope ModifyInstanceAttribute to the security group being attached as well as the instance (AWS lists both). - bedrock-logging-enforcement: add the docs-recommended aws:SourceArn condition to the CloudWatch role trust policy, and a narrowly scoped iam:PassRole (that role, Bedrock only) for the Lambda. The PassRole is precautionary - AWS's docs don't state whether it's required. CI - Run Checkov on the Terraform-side member-baseline StackSet template, which neither existing Checkov step covered. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Second pass over the files not read in full during the first review (stale-account detector, member baseline, Config/SSM remediation, gateway Terraform and CloudFormation, Bedrock logging). Verified locally: cfn-lint,
terraform fmt/validate(all modules), Checkov (CFN 400/0, Terraform 644/0, baseline template 15/0), and the copy-consistency check all pass. Nothing was deployed to AWS.Correctness
AuthorizeSecurityGroupIngress, so editing an existing rule to0.0.0.0/0waited for the Config scan. It now also matchesModifySecurityGroupRules; because that event carries rule IDs rather than the resulting CIDR, the Lambda re-checks the whole group. Unit-tested: only the open SSH rule is revoked, other entries untouched. Both Lambda copies, both event patterns and the READMEs updated.skip_final_snapshotwas tied to deletion protection, which must be disabled before a destroy is possible, so the snapshot was skipped in exactly the case it was meant to protect. Now always snapshots, matching the CloudFormation flavour'sDeletionPolicy: Snapshot.us.anthropic.*inference-profile prefix; addedus-gov.anthropic.*since the module claims GovCloud support.Least-privilege / hardening
ModifyInstanceAttributeis now also scoped to the security group being attached, which AWS lists as a resource for that action.aws:SourceArncondition AWS's docs show on the CloudWatch role trust policy, and a narrowly scopediam:PassRole(that one role, Bedrock only) for the Lambda. The PassRole is precautionary - AWS's docs don't say whether it's required.CI
Test plan
0.0.0.0/0on port 22 with the event-driven stack deployed and confirm it is revoked within secondsNot verified / not changed
16.13(pinned in the gateway template) exists as an engine version - needs AWS credentials to check.