mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
feat(ecs): add new check ecs_service_fargate_latest_platform_version (#5258)
Co-authored-by: Sergio <sergio@prowler.com>
This commit is contained in:
co-authored by
Sergio
parent
158263a8bf
commit
2ffe7f3ef7
@@ -93,6 +93,8 @@ config_aws = {
|
||||
8080,
|
||||
8088,
|
||||
],
|
||||
"fargate_linux_latest_version": "1.4.0",
|
||||
"fargate_windows_latest_version": "1.0.0",
|
||||
"trusted_account_ids": [],
|
||||
"log_group_retention_days": 365,
|
||||
"max_idle_disconnect_timeout_in_seconds": 600,
|
||||
|
||||
@@ -57,6 +57,11 @@ aws:
|
||||
8088,
|
||||
]
|
||||
|
||||
# AWS ECS Configuration
|
||||
# aws.ecs_service_fargate_latest_platform_version
|
||||
fargate_linux_latest_version: "1.4.0"
|
||||
fargate_windows_latest_version: "1.0.0"
|
||||
|
||||
# AWS VPC Configuration (vpc_endpoint_connections_trust_boundaries, vpc_endpoint_services_allowed_principals_trust_boundaries)
|
||||
# AWS SSM Configuration (aws.ssm_documents_set_as_public)
|
||||
# Single account environment: No action required. The AWS account number will be automatically added by the checks.
|
||||
|
||||
+195
@@ -0,0 +1,195 @@
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.ecs.ecs_service import Service
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
SERVICE_ARN = (
|
||||
f"arn:aws:ecs:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:service/sample-service"
|
||||
)
|
||||
SERVICE_NAME = "sample-service"
|
||||
|
||||
|
||||
class Test_ecs_service_fargate_latest_platform_version:
|
||||
def test_no_services(self):
|
||||
ecs_client = mock.MagicMock
|
||||
ecs_client.services = {}
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.ecs.ecs_service.ECS",
|
||||
ecs_client,
|
||||
):
|
||||
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
|
||||
ecs_service_fargate_latest_platform_version,
|
||||
)
|
||||
|
||||
check = ecs_service_fargate_latest_platform_version()
|
||||
result = check.execute()
|
||||
assert len(result) == 0
|
||||
|
||||
def test_service_ec2_type(self):
|
||||
ecs_client = mock.MagicMock
|
||||
ecs_client.services = {}
|
||||
ecs_client.services[SERVICE_ARN] = Service(
|
||||
name=SERVICE_NAME,
|
||||
arn=SERVICE_ARN,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
launch_type="EC2",
|
||||
assign_public_ip=False,
|
||||
tags=[],
|
||||
)
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.ecs.ecs_service.ECS",
|
||||
ecs_client,
|
||||
):
|
||||
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
|
||||
ecs_service_fargate_latest_platform_version,
|
||||
)
|
||||
|
||||
check = ecs_service_fargate_latest_platform_version()
|
||||
result = check.execute()
|
||||
assert len(result) == 0
|
||||
|
||||
def test_service_linux_latest_version(self):
|
||||
ecs_client = mock.MagicMock
|
||||
ecs_client.services = {}
|
||||
ecs_client.services[SERVICE_ARN] = Service(
|
||||
name=SERVICE_NAME,
|
||||
arn=SERVICE_ARN,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
launch_type="FARGATE",
|
||||
platform_family="Linux",
|
||||
platform_version="1.4.0",
|
||||
assign_public_ip=False,
|
||||
tags=[],
|
||||
)
|
||||
|
||||
ecs_client.audit_config = {
|
||||
"fargate_linux_latest_version": "1.4.0",
|
||||
}
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.ecs.ecs_service.ECS",
|
||||
ecs_client,
|
||||
):
|
||||
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
|
||||
ecs_service_fargate_latest_platform_version,
|
||||
)
|
||||
|
||||
check = ecs_service_fargate_latest_platform_version()
|
||||
result = check.execute()
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"ECS Service {SERVICE_NAME} is using latest FARGATE Linux version 1.4.0."
|
||||
)
|
||||
assert result[0].resource_id == SERVICE_NAME
|
||||
assert result[0].resource_arn == SERVICE_ARN
|
||||
|
||||
def test_service_windows_latest_version(self):
|
||||
ecs_client = mock.MagicMock
|
||||
ecs_client.services = {}
|
||||
ecs_client.services[SERVICE_ARN] = Service(
|
||||
name=SERVICE_NAME,
|
||||
arn=SERVICE_ARN,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
launch_type="FARGATE",
|
||||
platform_family="Windows",
|
||||
platform_version="1.0.0",
|
||||
assign_public_ip=False,
|
||||
tags=[],
|
||||
)
|
||||
|
||||
ecs_client.audit_config = {
|
||||
"fargate_windows_latest_version": "1.0.0",
|
||||
}
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.ecs.ecs_service.ECS",
|
||||
ecs_client,
|
||||
):
|
||||
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
|
||||
ecs_service_fargate_latest_platform_version,
|
||||
)
|
||||
|
||||
check = ecs_service_fargate_latest_platform_version()
|
||||
result = check.execute()
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"ECS Service {SERVICE_NAME} is using latest FARGATE Windows version 1.0.0."
|
||||
)
|
||||
assert result[0].resource_id == SERVICE_NAME
|
||||
assert result[0].resource_arn == SERVICE_ARN
|
||||
|
||||
def test_service_linux_no_latest_version(self):
|
||||
ecs_client = mock.MagicMock
|
||||
ecs_client.services = {}
|
||||
ecs_client.services[SERVICE_ARN] = Service(
|
||||
name=SERVICE_NAME,
|
||||
arn=SERVICE_ARN,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
launch_type="FARGATE",
|
||||
platform_family="Linux",
|
||||
platform_version="1.2.0",
|
||||
assign_public_ip=False,
|
||||
tags=[],
|
||||
)
|
||||
|
||||
ecs_client.audit_config = {
|
||||
"fargate_linux_latest_version": "1.4.0",
|
||||
}
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.ecs.ecs_service.ECS",
|
||||
ecs_client,
|
||||
):
|
||||
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
|
||||
ecs_service_fargate_latest_platform_version,
|
||||
)
|
||||
|
||||
check = ecs_service_fargate_latest_platform_version()
|
||||
result = check.execute()
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"ECS Service {SERVICE_NAME} is not using latest FARGATE Linux version 1.4.0, currently using 1.2.0."
|
||||
)
|
||||
assert result[0].resource_id == SERVICE_NAME
|
||||
assert result[0].resource_arn == SERVICE_ARN
|
||||
|
||||
def test_service_windows_no_latest_version(self):
|
||||
ecs_client = mock.MagicMock
|
||||
ecs_client.services = {}
|
||||
ecs_client.services[SERVICE_ARN] = Service(
|
||||
name=SERVICE_NAME,
|
||||
arn=SERVICE_ARN,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
launch_type="FARGATE",
|
||||
platform_family="Windows",
|
||||
platform_version="0.9.0",
|
||||
assign_public_ip=False,
|
||||
tags=[],
|
||||
)
|
||||
|
||||
ecs_client.audit_config = {
|
||||
"fargate_windows_latest_version": "1.0.0",
|
||||
}
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.ecs.ecs_service.ECS",
|
||||
ecs_client,
|
||||
):
|
||||
from prowler.providers.aws.services.ecs.ecs_service_fargate_latest_platform_version.ecs_service_fargate_latest_platform_version import (
|
||||
ecs_service_fargate_latest_platform_version,
|
||||
)
|
||||
|
||||
check = ecs_service_fargate_latest_platform_version()
|
||||
result = check.execute()
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"ECS Service {SERVICE_NAME} is not using latest FARGATE Windows version 1.0.0, currently using 0.9.0."
|
||||
)
|
||||
assert result[0].resource_id == SERVICE_NAME
|
||||
assert result[0].resource_arn == SERVICE_ARN
|
||||
@@ -44,7 +44,6 @@ def mock_make_api_call(self, operation_name, kwarg):
|
||||
{
|
||||
"serviceArn": "arn:aws:ecs:eu-west-1:123456789012:service/test_cluster_1/test_ecs_service",
|
||||
"serviceName": "test_ecs_service",
|
||||
"launchType": "EC2",
|
||||
"networkConfiguration": {
|
||||
"awsvpcConfiguration": {
|
||||
"subnets": ["subnet-12345678"],
|
||||
@@ -52,6 +51,9 @@ def mock_make_api_call(self, operation_name, kwarg):
|
||||
"assignPublicIp": "ENABLED",
|
||||
}
|
||||
},
|
||||
"launchType": "FARGATE",
|
||||
"platformVersion": "1.4.0",
|
||||
"platformFamily": "Linux",
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -218,3 +220,6 @@ class Test_ECS_Service:
|
||||
assert ecs.services[service_arn].region == AWS_REGION_EU_WEST_1
|
||||
assert ecs.services[service_arn].assign_public_ip
|
||||
assert ecs.services[service_arn].tags == []
|
||||
assert ecs.services[service_arn].launch_type == "FARGATE"
|
||||
assert ecs.services[service_arn].platform_version == "1.4.0"
|
||||
assert ecs.services[service_arn].platform_family == "Linux"
|
||||
|
||||
Reference in New Issue
Block a user