mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
The ISO section still stated that Prowler has no built-in way to scan those partitions and told the reader to hand-edit aws_regions_by_service.json. That workaround never survived a week: prowler-bot regenerates the file every Monday. The example also listed aws-iso-global and aws-iso-b-global as if they were regions, when they are botocore pseudo endpoints that the provider no longer returns. The section now follows the same shape as the China, GovCloud and European Sovereign Cloud ones, with the regions of the four ISO partitions, and carries a warning that scanning inside them is still pending validation against a live account. The list of values accepted by PROWLER_AWS_PARTITION is completed with the four ISO partitions, which the code has always accepted and which now have region data behind them.
208 lines
7.1 KiB
Plaintext
208 lines
7.1 KiB
Plaintext
---
|
|
title: 'AWS Regions and Partitions'
|
|
---
|
|
|
|
By default Prowler is able to scan the following AWS partitions:
|
|
|
|
- Commercial: `aws`
|
|
- China: `aws-cn`
|
|
- European Sovereign Cloud: `aws-eusc`
|
|
- GovCloud (US): `aws-us-gov`
|
|
|
|
<Note>
|
|
To check the available regions for each partition and service, refer to: [aws\_regions\_by\_service.json](https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/aws/aws_regions_by_service.json)
|
|
|
|
</Note>
|
|
## Scanning AWS China, European Sovereign Cloud and GovCloud Partitions in Prowler
|
|
|
|
When scanning the China (`aws-cn`), European Sovereign Cloud (`aws-eusc`) or GovCloud (`aws-us-gov`) partitions, ensure one of the following:
|
|
|
|
- Your AWS credentials include a valid region within the desired partition.
|
|
|
|
- Specify the regions to audit within that partition using the `-f/--region` flag.
|
|
|
|
- Declare the partition with the `PROWLER_AWS_PARTITION` environment variable, set to `aws`, `aws-cn`, `aws-eusc`, `aws-us-gov`, `aws-iso`, `aws-iso-b`, `aws-iso-e` or `aws-iso-f`.
|
|
|
|
<Note>
|
|
Refer to: https://boto3.amazonaws.com/v1/documentation/api/latest/guide/credentials.html#configuring-credentials for more information about the AWS credential configuration.
|
|
|
|
</Note>
|
|
### Declaring the Partition
|
|
|
|
`PROWLER_AWS_PARTITION` tells Prowler which partition the scan runs against, without relying on a region being configured:
|
|
|
|
```bash
|
|
export PROWLER_AWS_PARTITION="aws-us-gov"
|
|
```
|
|
|
|
It matters most where nothing else says. Resolving an identity means calling STS before anything is known about the credentials, and with no region configured Prowler would otherwise start from the commercial endpoints. Declaring the partition makes that first call go to the right place, which is the difference between a scan that starts and one that fails on an endpoint the credentials cannot use.
|
|
|
|
A region configured for the session still wins when it belongs to the declared partition, so a deployment in `us-gov-west-1` is not sent to `us-gov-east-1`. A region belonging to a different partition is ignored, since a partition that has been declared explicitly is the more deliberate statement of the two.
|
|
|
|
<Note>
|
|
Set it wherever the scan runs. For deployments that scan from containers, that means the environment of the containers doing the scanning, not only the one accepting the request.
|
|
</Note>
|
|
|
|
### Scanning Specific Regions
|
|
|
|
To scan a particular AWS region with Prowler, use:
|
|
|
|
```console
|
|
prowler aws -f/--region eu-west-1 us-east-1
|
|
```
|
|
|
|
### Excluding Specific Regions
|
|
|
|
To scan all supported AWS regions except a specific subset, use the `--excluded-region` flag:
|
|
|
|
```console
|
|
prowler aws --excluded-region eu-west-1 me-south-1
|
|
```
|
|
|
|
You can also configure the exclusion list with the `PROWLER_AWS_DISALLOWED_REGIONS` environment variable as a comma-separated list:
|
|
|
|
```console
|
|
export PROWLER_AWS_DISALLOWED_REGIONS="eu-west-1,me-south-1"
|
|
prowler aws
|
|
```
|
|
|
|
Or with the AWS provider configuration in `config.yaml`:
|
|
|
|
```yaml
|
|
aws:
|
|
disallowed_regions:
|
|
- eu-west-1
|
|
- me-south-1
|
|
```
|
|
|
|
When more than one source is set, precedence is:
|
|
|
|
1. `--excluded-region`
|
|
2. `PROWLER_AWS_DISALLOWED_REGIONS`
|
|
3. `aws.disallowed_regions` in `config.yaml`
|
|
|
|
<Note>
|
|
For Prowler Local Server or API-triggered scans, set `PROWLER_AWS_DISALLOWED_REGIONS` in the runtime environment of the backend scan containers such as `api` and `worker`. The `ui` container does not enforce AWS region selection.
|
|
|
|
</Note>
|
|
|
|
### AWS Credentials Configuration
|
|
|
|
For details on configuring AWS credentials, refer to the following [Botocore](https://github.com/boto/botocore) [file](https://github.com/boto/botocore/blob/22a19ea7c4c2c4dd7df4ab8c32733cba0c7597a4/botocore/data/partitions.json).
|
|
|
|
## Scanning AWS Partitions in Prowler
|
|
|
|
### AWS China
|
|
|
|
To scan an account in the AWS China partition (`aws-cn`):
|
|
|
|
- By using the `-f/--region` flag:
|
|
|
|
```
|
|
prowler aws --region cn-north-1 cn-northwest-1
|
|
```
|
|
|
|
- By using the region configured in your AWS profile at `~/.aws/credentials` or `~/.aws/config`:
|
|
|
|
```
|
|
[default]
|
|
aws_access_key_id = XXXXXXXXXXXXXXXXXXX
|
|
aws_secret_access_key = XXXXXXXXXXXXXXXXXXX
|
|
region = cn-north-1
|
|
```
|
|
|
|
<Note>
|
|
With this configuration, all partition regions will be scanned without needing the `-f/--region` flag
|
|
|
|
</Note>
|
|
### AWS GovCloud (US)
|
|
|
|
To scan an account in the AWS GovCloud (US) partition (`aws-us-gov`):
|
|
|
|
- By using the `-f/--region` flag:
|
|
|
|
```
|
|
prowler aws --region us-gov-east-1 us-gov-west-1
|
|
```
|
|
|
|
- By using the region configured in your AWS profile at `~/.aws/credentials` or `~/.aws/config`:
|
|
|
|
```
|
|
[default]
|
|
aws_access_key_id = XXXXXXXXXXXXXXXXXXX
|
|
aws_secret_access_key = XXXXXXXXXXXXXXXXXXX
|
|
region = us-gov-east-1
|
|
```
|
|
|
|
<Note>
|
|
With this configuration, all partition regions will be scanned without needing the `-f/--region` flag
|
|
|
|
</Note>
|
|
### AWS European Sovereign Cloud
|
|
|
|
To scan an account in the AWS European Sovereign Cloud partition (`aws-eusc`):
|
|
|
|
- By using the `-f/--region` flag:
|
|
|
|
```
|
|
prowler aws --region eusc-de-east-1
|
|
```
|
|
|
|
- By using the region configured in your AWS profile at `~/.aws/credentials` or `~/.aws/config`:
|
|
|
|
```
|
|
[default]
|
|
aws_access_key_id = XXXXXXXXXXXXXXXXXXX
|
|
aws_secret_access_key = XXXXXXXXXXXXXXXXXXX
|
|
region = eusc-de-east-1
|
|
```
|
|
|
|
<Note>
|
|
With this configuration, all partition regions will be scanned without needing the `-f/--region` flag
|
|
|
|
</Note>
|
|
### AWS ISO (US \& Europe)
|
|
|
|
The AWS ISO partitions, commonly referred to as "secret partitions", are air-gapped from the Internet. Their regions, and the services available in each of them, ship with the AWS SDK, so Prowler resolves them like any other partition and no manual edit of [aws\_regions\_by\_service.json](https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/aws/aws_regions_by_service.json) is required.
|
|
|
|
<Warning>
|
|
Support for the ISO partitions has not been exercised against a live ISO account. The regions and per-service availability come from the endpoint metadata bundled with the AWS SDK, and the behaviour is covered by tests, but scanning inside these partitions is still pending validation in a real environment. Report anything that does not work as described here.
|
|
|
|
</Warning>
|
|
|
|
To scan an account in an AWS ISO partition (`aws-iso`, `aws-iso-b`, `aws-iso-e` or `aws-iso-f`):
|
|
|
|
- By using the `-f/--region` flag:
|
|
|
|
```
|
|
prowler aws --region us-isob-east-1
|
|
```
|
|
|
|
- By using the region configured in your AWS profile at `~/.aws/credentials` or `~/.aws/config`:
|
|
|
|
```
|
|
[default]
|
|
aws_access_key_id = XXXXXXXXXXXXXXXXXXX
|
|
aws_secret_access_key = XXXXXXXXXXXXXXXXXXX
|
|
region = us-isob-east-1
|
|
```
|
|
|
|
<Note>
|
|
With this configuration, all partition regions will be scanned without needing the `-f/--region` flag
|
|
|
|
</Note>
|
|
|
|
The regions of each ISO partition are:
|
|
|
|
| Partition | Regions |
|
|
| --- | --- |
|
|
| `aws-iso` | `us-iso-east-1`, `us-iso-west-1` |
|
|
| `aws-iso-b` | `us-isob-east-1`, `us-isob-west-1` |
|
|
| `aws-iso-e` | `eu-isoe-west-1` |
|
|
| `aws-iso-f` | `us-isof-east-1`, `us-isof-south-1` |
|
|
|
|
<Note>
|
|
These partitions offer far fewer services than the commercial one. A service that is not available in the audited partition is skipped rather than reported as failing.
|
|
|
|
</Note>
|