bp-check/services/eks.py

69 lines
2.1 KiB
Python
Raw Normal View History

2024-08-05 02:30:34 +00:00
from models import RuleCheckResult
import boto3
2024-08-06 06:36:50 +00:00
client = boto3.client("eks")
2024-08-05 02:30:34 +00:00
def eks_cluster_logging_enabled():
2024-08-06 06:36:50 +00:00
clusters = client.list_clusters()["clusters"]
compliant_resource = []
non_compliant_resources = []
for cluster in clusters:
response = client.describe_cluster(name=cluster)["cluster"]
if (
len(response["logging"]["clusterLogging"][0]["types"]) == 5
and response["logging"]["clusterLogging"][0]["enabled"] == True
):
compliant_resource.append(response["arn"])
else:
non_compliant_resources.append(response["arn"])
2024-08-05 02:30:34 +00:00
return RuleCheckResult(
2024-08-06 06:36:50 +00:00
passed=not non_compliant_resources,
compliant_resources=compliant_resource,
non_compliant_resources=non_compliant_resources,
2024-08-05 02:30:34 +00:00
)
def eks_cluster_secrets_encrypted():
2024-08-06 06:36:50 +00:00
clusters = client.list_clusters()["clusters"]
compliant_resource = []
non_compliant_resources = []
for cluster in clusters:
response = client.describe_cluster(name=cluster)["cluster"]
if (
"encryptionConfig" in response
and "secrets" in response["encryptionConfig"][0]["resources"]
):
compliant_resource.append(response["arn"])
else:
non_compliant_resources.append(response["arn"])
2024-08-05 02:30:34 +00:00
return RuleCheckResult(
2024-08-06 06:36:50 +00:00
passed=not non_compliant_resources,
compliant_resources=compliant_resource,
non_compliant_resources=non_compliant_resources,
2024-08-05 02:30:34 +00:00
)
def eks_endpoint_no_public_access():
2024-08-06 06:36:50 +00:00
clusters = client.list_clusters()["clusters"]
compliant_resource = []
non_compliant_resources = []
2024-08-05 02:30:34 +00:00
2024-08-06 06:36:50 +00:00
for cluster in clusters:
response = client.describe_cluster(name=cluster)["cluster"]
if response["resourcesVpcConfig"]["endpointPublicAccess"] == False:
compliant_resource.append(response["arn"])
else:
non_compliant_resources.append(response["arn"])
2024-08-05 02:30:34 +00:00
return RuleCheckResult(
2024-08-06 06:36:50 +00:00
passed=not non_compliant_resources,
compliant_resources=compliant_resource,
non_compliant_resources=non_compliant_resources,
2024-08-05 02:30:34 +00:00
)