2019-06-11 22:24:35 +00:00
|
|
|
require "resource_support/aws/aws_singular_resource_mixin"
|
|
|
|
require "resource_support/aws/aws_backend_base"
|
|
|
|
require "aws-sdk-ec2"
|
2019-05-25 08:33:26 +00:00
|
|
|
|
2018-06-07 18:41:46 +00:00
|
|
|
class AwsFlowLog < Inspec.resource(1)
|
2019-06-11 22:24:35 +00:00
|
|
|
name "aws_flow_log"
|
|
|
|
supports platform: "aws"
|
|
|
|
desc "This resource is used to test the attributes of a Flow Log."
|
2019-03-19 14:17:32 +00:00
|
|
|
example <<~EXAMPLE
|
2018-06-07 18:41:46 +00:00
|
|
|
describe aws_flow_log('fl-9c718cf5') do
|
|
|
|
it { should exist }
|
|
|
|
end
|
2019-03-19 14:17:32 +00:00
|
|
|
EXAMPLE
|
2018-06-07 18:41:46 +00:00
|
|
|
|
|
|
|
include AwsSingularResourceMixin
|
|
|
|
|
|
|
|
def to_s
|
|
|
|
"AWS Flow Log #{id}"
|
|
|
|
end
|
|
|
|
|
|
|
|
def resource_type
|
|
|
|
case @resource_id
|
|
|
|
when /^eni/
|
2019-06-11 22:24:35 +00:00
|
|
|
@resource_type = "eni"
|
2018-06-07 18:41:46 +00:00
|
|
|
when /^subnet/
|
2019-06-11 22:24:35 +00:00
|
|
|
@resource_type = "subnet"
|
2018-06-07 18:41:46 +00:00
|
|
|
when /^vpc/
|
2019-06-11 22:24:35 +00:00
|
|
|
@resource_type = "vpc"
|
2018-06-07 18:41:46 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def attached_to_eni?
|
2019-06-11 22:24:35 +00:00
|
|
|
resource_type.eql?("eni") ? true : false
|
2018-06-07 18:41:46 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
def attached_to_subnet?
|
2019-06-11 22:24:35 +00:00
|
|
|
resource_type.eql?("subnet") ? true : false
|
2018-06-07 18:41:46 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
def attached_to_vpc?
|
2019-06-11 22:24:35 +00:00
|
|
|
resource_type.eql?("vpc") ? true : false
|
2018-06-07 18:41:46 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
attr_reader :log_group_name, :resource_id, :flow_log_id
|
|
|
|
|
|
|
|
private
|
|
|
|
|
|
|
|
def validate_params(raw_params)
|
|
|
|
validated_params = check_resource_param_names(
|
|
|
|
raw_params: raw_params,
|
2019-07-09 00:20:30 +00:00
|
|
|
allowed_params: %i{flow_log_id subnet_id vpc_id},
|
2018-06-07 18:41:46 +00:00
|
|
|
allowed_scalar_name: :flow_log_id,
|
2019-06-11 22:24:35 +00:00
|
|
|
allowed_scalar_type: String
|
2018-06-07 18:41:46 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
if validated_params.empty?
|
|
|
|
raise ArgumentError,
|
2019-07-09 00:20:30 +00:00
|
|
|
"aws_flow_log requires a parameter: flow_log_id, subnet_id, or vpc_id"
|
2018-06-07 18:41:46 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
validated_params
|
|
|
|
end
|
|
|
|
|
|
|
|
def fetch_from_api
|
|
|
|
backend = BackendFactory.create(inspec_runner)
|
|
|
|
|
|
|
|
resp = backend.describe_flow_logs(filter_args)
|
|
|
|
flow_log = resp.to_h[:flow_logs].first
|
|
|
|
@exists = !flow_log.nil?
|
|
|
|
unless flow_log.nil?
|
|
|
|
@log_group_name = flow_log[:log_group_name]
|
|
|
|
@resource_id = flow_log[:resource_id]
|
|
|
|
@flow_log_id = flow_log[:flow_log_id]
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def filter_args
|
|
|
|
if @flow_log_id
|
2019-06-11 22:24:35 +00:00
|
|
|
{ filter: [{ name: "flow-log-id", values: [@flow_log_id] }] }
|
2018-06-07 18:41:46 +00:00
|
|
|
elsif @subnet_id || @vpc_id
|
|
|
|
filter = @subnet_id || @vpc_id
|
2019-06-11 22:24:35 +00:00
|
|
|
{ filter: [{ name: "resource-id", values: [filter] }] }
|
2018-06-07 18:41:46 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def id
|
|
|
|
return @flow_log_id if @flow_log_id
|
|
|
|
return @subnet_id if @subnet_id
|
|
|
|
return @vpc_id if @vpc_id
|
|
|
|
end
|
|
|
|
|
|
|
|
def backend
|
|
|
|
BackendFactory.create(inspec_runner)
|
|
|
|
end
|
|
|
|
|
|
|
|
class Backend
|
|
|
|
class AwsClientApi < AwsBackendBase
|
|
|
|
AwsFlowLog::BackendFactory.set_default_backend(self)
|
|
|
|
self.aws_client_class = Aws::EC2::Client
|
|
|
|
|
|
|
|
def describe_flow_logs(query)
|
|
|
|
aws_service_client.describe_flow_logs(query)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|