Releases: trussworks/terraform-aws-config
Releases · trussworks/terraform-aws-config
v5.0.0
Added the following Rules:
- backup-plan-min-frequency-and-min-retention-check
- cloud-trail-cloud-watch-logs-enabled
- cw_loggroup_retention_period_check
- dynamodb-table-encryption-enabled
- ecr-private-image-scanning-enabled
- ecr-private-lifecycle-policy-configured
- ecs-awsvpc-networking-enabled
- ecs-containers-nonprivileged
- ecs-containers-readonly-access
- ecs-no-environment-secrets
- efs-encrypted-check
- elb-logging-enabled
- elb-deletion-protection-enabled
- vpc-sg-open-only-to-authorized-ports
- mfa_enabled_for_iam_console_access
- iam-policy-no-statements-with-admin-access
- iam-policy-no-statements-with-full-access
- restricted-ssh
- access_keys_rotated
- cmk_backing_key_rotation_enabled
- nacl-no-unrestricted-ssh-rdp
- internet-gateway-authorized-vpc-only
- rds-snapshot-encrypted
- rds-cluster-deletion-protection-enabled
- db-instance-backup-enabled
- s3-bucket-level-public-access-prohibited
- s3-bucket-acl-prohibited
- s3-bucket-server-side-encryption-enabled
v4.7.0
Adds two new inputs:
enable_multi_account_logs
: Enable sending of logs and snapshots from different Config accounts / regions into a single bucketresource_types
: A list that specifies the types of AWS resources for which AWS Config records configuration changes (for example, AWS::EC2::Instance or AWS::CloudTrail::Trail). See relevant part of AWS Docs for available types.
Remove deprecated template terraform provider
- remove obsolete template_file - The template Terraform provider was deprecated a while back and is now causing issues for folks trying to use this module on arm64/M1 Macs.
Add ec2 imdsv2 check
Support attaching rules to an existing AWS Config recorder
Relax version constraints for Terraform 0.14 and deprecate Terraform 0.11 support
Add mfa-enabled-for-iam-console-access and restricted-ssh
Fix deprecated interpolation-only expression
Merge pull request #91 from dod-iac/cg_fix_tf11_deprecation Fix deprecated interpolation-only expression
Allows for an empty config_logs_prefix
Merge pull request #86 from alan-eu/master Add support for empty config_logs_prefix
Updates the config role to use the new managed AWS policy
Merge pull request #87 from trussworks/ee-update-config-policy updating the config service policy