feat(ecs): add new check ecs_service_fargate_latest_platform_version (#5258)

Co-authored-by: Sergio <sergio@prowler.com>
This commit is contained in:
Mario Rodriguez Lopez
2024-10-02 16:50:20 -04:00
committed by GitHub
co-authored by Sergio
parent 158263a8bf
commit 2ffe7f3ef7
9 changed files with 291 additions and 1 deletions
+2
View File
@@ -93,6 +93,8 @@ config_aws = {
8080,
8088,
],
"fargate_linux_latest_version": "1.4.0",
"fargate_windows_latest_version": "1.0.0",
"trusted_account_ids": [],
"log_group_retention_days": 365,
"max_idle_disconnect_timeout_in_seconds": 600,
+5
View File
@@ -57,6 +57,11 @@ aws:
8088,
]
# AWS ECS Configuration
# aws.ecs_service_fargate_latest_platform_version
fargate_linux_latest_version: "1.4.0"
fargate_windows_latest_version: "1.0.0"
# AWS VPC Configuration (vpc_endpoint_connections_trust_boundaries, vpc_endpoint_services_allowed_principals_trust_boundaries)
# AWS SSM Configuration (aws.ssm_documents_set_as_public)
# Single account environment: No action required. The AWS account number will be automatically added by the checks.
@@ -0,0 +1,195 @@
from unittest import mock
from prowler.providers.aws.services.ecs.ecs_service import Service
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
SERVICE_ARN = (
f"arn:aws:ecs:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:service/sample-service"
)
SERVICE_NAME = "sample-service"
class Test_ecs_service_fargate_latest_platform_version:
def test_no_services(self):
ecs_client = mock.MagicMock
ecs_client.services = {}
with mock.patch(
"prowler.providers.aws.services.ecs.ecs_service.ECS",
ecs_client,
):
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
ecs_service_fargate_latest_platform_version,
)
check = ecs_service_fargate_latest_platform_version()
result = check.execute()
assert len(result) == 0
def test_service_ec2_type(self):
ecs_client = mock.MagicMock
ecs_client.services = {}
ecs_client.services[SERVICE_ARN] = Service(
name=SERVICE_NAME,
arn=SERVICE_ARN,
region=AWS_REGION_US_EAST_1,
launch_type="EC2",
assign_public_ip=False,
tags=[],
)
with mock.patch(
"prowler.providers.aws.services.ecs.ecs_service.ECS",
ecs_client,
):
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
ecs_service_fargate_latest_platform_version,
)
check = ecs_service_fargate_latest_platform_version()
result = check.execute()
assert len(result) == 0
def test_service_linux_latest_version(self):
ecs_client = mock.MagicMock
ecs_client.services = {}
ecs_client.services[SERVICE_ARN] = Service(
name=SERVICE_NAME,
arn=SERVICE_ARN,
region=AWS_REGION_US_EAST_1,
launch_type="FARGATE",
platform_family="Linux",
platform_version="1.4.0",
assign_public_ip=False,
tags=[],
)
ecs_client.audit_config = {
"fargate_linux_latest_version": "1.4.0",
}
with mock.patch(
"prowler.providers.aws.services.ecs.ecs_service.ECS",
ecs_client,
):
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
ecs_service_fargate_latest_platform_version,
)
check = ecs_service_fargate_latest_platform_version()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"ECS Service {SERVICE_NAME} is using latest FARGATE Linux version 1.4.0."
)
assert result[0].resource_id == SERVICE_NAME
assert result[0].resource_arn == SERVICE_ARN
def test_service_windows_latest_version(self):
ecs_client = mock.MagicMock
ecs_client.services = {}
ecs_client.services[SERVICE_ARN] = Service(
name=SERVICE_NAME,
arn=SERVICE_ARN,
region=AWS_REGION_US_EAST_1,
launch_type="FARGATE",
platform_family="Windows",
platform_version="1.0.0",
assign_public_ip=False,
tags=[],
)
ecs_client.audit_config = {
"fargate_windows_latest_version": "1.0.0",
}
with mock.patch(
"prowler.providers.aws.services.ecs.ecs_service.ECS",
ecs_client,
):
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
ecs_service_fargate_latest_platform_version,
)
check = ecs_service_fargate_latest_platform_version()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"ECS Service {SERVICE_NAME} is using latest FARGATE Windows version 1.0.0."
)
assert result[0].resource_id == SERVICE_NAME
assert result[0].resource_arn == SERVICE_ARN
def test_service_linux_no_latest_version(self):
ecs_client = mock.MagicMock
ecs_client.services = {}
ecs_client.services[SERVICE_ARN] = Service(
name=SERVICE_NAME,
arn=SERVICE_ARN,
region=AWS_REGION_US_EAST_1,
launch_type="FARGATE",
platform_family="Linux",
platform_version="1.2.0",
assign_public_ip=False,
tags=[],
)
ecs_client.audit_config = {
"fargate_linux_latest_version": "1.4.0",
}
with mock.patch(
"prowler.providers.aws.services.ecs.ecs_service.ECS",
ecs_client,
):
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
ecs_service_fargate_latest_platform_version,
)
check = ecs_service_fargate_latest_platform_version()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"ECS Service {SERVICE_NAME} is not using latest FARGATE Linux version 1.4.0, currently using 1.2.0."
)
assert result[0].resource_id == SERVICE_NAME
assert result[0].resource_arn == SERVICE_ARN
def test_service_windows_no_latest_version(self):
ecs_client = mock.MagicMock
ecs_client.services = {}
ecs_client.services[SERVICE_ARN] = Service(
name=SERVICE_NAME,
arn=SERVICE_ARN,
region=AWS_REGION_US_EAST_1,
launch_type="FARGATE",
platform_family="Windows",
platform_version="0.9.0",
assign_public_ip=False,
tags=[],
)
ecs_client.audit_config = {
"fargate_windows_latest_version": "1.0.0",
}
with mock.patch(
"prowler.providers.aws.services.ecs.ecs_service.ECS",
ecs_client,
):
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
ecs_service_fargate_latest_platform_version,
)
check = ecs_service_fargate_latest_platform_version()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"ECS Service {SERVICE_NAME} is not using latest FARGATE Windows version 1.0.0, currently using 0.9.0."
)
assert result[0].resource_id == SERVICE_NAME
assert result[0].resource_arn == SERVICE_ARN
@@ -44,7 +44,6 @@ def mock_make_api_call(self, operation_name, kwarg):
{
"serviceArn": "arn:aws:ecs:eu-west-1:123456789012:service/test_cluster_1/test_ecs_service",
"serviceName": "test_ecs_service",
"launchType": "EC2",
"networkConfiguration": {
"awsvpcConfiguration": {
"subnets": ["subnet-12345678"],
@@ -52,6 +51,9 @@ def mock_make_api_call(self, operation_name, kwarg):
"assignPublicIp": "ENABLED",
}
},
"launchType": "FARGATE",
"platformVersion": "1.4.0",
"platformFamily": "Linux",
}
]
}
@@ -218,3 +220,6 @@ class Test_ECS_Service:
assert ecs.services[service_arn].region == AWS_REGION_EU_WEST_1
assert ecs.services[service_arn].assign_public_ip
assert ecs.services[service_arn].tags == []
assert ecs.services[service_arn].launch_type == "FARGATE"
assert ecs.services[service_arn].platform_version == "1.4.0"
assert ecs.services[service_arn].platform_family == "Linux"