cdk-nag
Version:
Check CDK v2 applications for best practices using a combination on available rule packs.
228 lines • 34.4 kB
JavaScript
"use strict";
var _a;
Object.defineProperty(exports, "__esModule", { value: true });
exports.ServerlessChecks = void 0;
const JSII_RTTI_SYMBOL_1 = Symbol.for("jsii.rtti");
/*
Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
SPDX-License-Identifier: Apache-2.0
*/
const aws_cdk_lib_1 = require("aws-cdk-lib");
const nag_pack_1 = require("../nag-pack");
const nag_rules_1 = require("../nag-rules");
const apigw_1 = require("../rules/apigw");
const appsync_1 = require("../rules/appsync");
const cloudwatch_1 = require("../rules/cloudwatch");
const eventbridge_1 = require("../rules/eventbridge");
const lambda_1 = require("../rules/lambda");
const sns_1 = require("../rules/sns");
const sqs_1 = require("../rules/sqs");
const stepfunctions_1 = require("../rules/stepfunctions");
/**
* Serverless Checks are a compilation of rules to validate infrastructure-as-code template against recommended practices.
*
*/
class ServerlessChecks extends nag_pack_1.NagPack {
constructor(props) {
super(props);
this.packName = 'Serverless';
}
visit(node) {
if (node instanceof aws_cdk_lib_1.CfnResource) {
this.checkLambda(node);
this.checkCloudwatch(node);
this.checkApiGw(node);
this.checkAppSync(node);
this.checkEventBridge(node);
this.checkSNS(node);
this.checkSQS(node);
this.checkStepFunctions(node);
}
}
/**
* Check Lambda Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkLambda(node) {
this.applyRule({
info: 'The Lambda function does not have a configured failure destination for asynchronous invocations.',
explanation: "When a Lambda function is invoked asynchronously (e.g., by S3, SNS, or EventBridge), it's important to configure a failure destination. This allows you to capture and handle events that fail processing, improving the reliability and observability of your serverless applications.",
level: nag_rules_1.NagMessageLevel.ERROR,
rule: lambda_1.LambdaAsyncFailureDestination,
node: node,
});
this.applyRule({
info: 'The Lambda function does not have an explicit memory value configured.',
explanation: "Lambda allocates CPU power in proportion to the amount of memory configured. By default, your functions have 128 MB of memory allocated. You can increase that value up to 10 GB. With more CPU resources, your Lambda function's duration might decrease. You can use tools such as AWS Lambda Power Tuning to test your function at different memory settings to find the one that matches your cost and performance requirements the best.",
level: nag_rules_1.NagMessageLevel.ERROR,
rule: lambda_1.LambdaDefaultMemorySize,
node: node,
});
this.applyRule({
info: 'The Lambda function does not have an explicitly defined timeout value.',
explanation: 'Lambda functions have a default timeout of 3 seconds. If your timeout value is too short, Lambda might terminate invocations prematurely. On the other side, setting the timeout much higher than the average execution may cause functions to execute for longer upon code malfunction, resulting in higher costs and possibly reaching concurrency limits depending on how such functions are invoked. You can also use AWS Lambda Power Tuning to test your function at different timeout settings to find the one that matches your cost and performance requirements the best.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: lambda_1.LambdaDefaultTimeout,
node: node,
});
this.applyRule({
info: 'The Lambda function does not have a dead letter target configured.',
explanation: 'When a Lambda function has the DeadLetterConfig property set, failed messages can be temporarily stored for review in an SQS queue or an SNS topic.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: lambda_1.LambdaDLQ,
node: node,
});
this.applyRule({
info: 'The Lambda Event Source Mapping does not have a destination configured for failed invocations.',
explanation: 'Configuring a destination for failed invocations in Lambda Event Source Mappings allows you to capture and process events that fail to be processed by your Lambda function. This helps in monitoring, debugging, and implementing retry mechanisms for failed events, improving the reliability and observability of your serverless applications.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: lambda_1.LambdaEventSourceMappingDestination,
node: node,
});
this.applyRule({
info: 'The Lambda function does not use the latest runtime version.',
explanation: 'Using the latest runtime version ensures that your Lambda function has access to the most recent features, performance improvements, and security updates. It is important to regularly update your Lambda functions to use the latest runtime versions to maintain optimal performance and security.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: lambda_1.LambdaLatestVersion,
node: node,
});
this.applyRule({
info: 'The Lambda IAM role uses wildcard permissions.',
explanation: 'You should follow least-privileged access and only allow the access needed to perform a given operation. If your Lambda function needs a broad range of permissions, you should know ahead of time which permissions you will need, have evaluated the risks of using broad permissions and can suppress this rule.',
level: nag_rules_1.NagMessageLevel.WARN,
rule: lambda_1.LambdaStarPermissions,
node: node,
});
this.applyRule({
info: 'The Lambda function does not have tracing set to Tracing.ACTIVE.',
explanation: 'When a Lambda function has ACTIVE tracing, Lambda automatically samples invocation requests, based on the sampling algorithm specified by X-Ray.',
level: nag_rules_1.NagMessageLevel.WARN,
rule: lambda_1.LambdaTracing,
node: node,
});
}
/**
* Check Cloudwatch Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkCloudwatch(node) {
this.applyRule({
info: 'The CloudWatch Log Group does not have an explicit retention policy defined.',
explanation: 'By default, logs are kept indefinitely and never expire. You can adjust the retention policy for each log group, keeping the indefinite retention, or choosing a retention period between one day and 10 years. For Lambda functions, this applies to their automatically created CloudWatch Log Groups.',
level: nag_rules_1.NagMessageLevel.WARN,
rule: cloudwatch_1.CloudWatchLogGroupRetentionPeriod,
node: node,
});
}
/**
* Check API Gateway Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkApiGw(node) {
this.applyRule({
info: 'The API Gateway Stage does not have access logging enabled.',
explanation: 'API Gateway provides access logging for API stages. Enable access logging on your API stages to monitor API requests and responses.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: apigw_1.APIGWAccessLogging,
node: node,
});
this.applyRule({
info: 'The API Gateway Stage is using default throttling setting.',
explanation: 'API Gateway default throttling settings may not be suitable for all applications. Custom throttling limits help protect your backend systems from being overwhelmed with requests, ensure consistent performance, and can be tailored to your specific use case.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: apigw_1.APIGWDefaultThrottling,
node: node,
});
this.applyRule({
info: 'The API Gateway logs are not configured for the JSON format.',
explanation: 'You can customize the log format that Amazon API Gateway uses to send logs. JSON Structured logging makes it easier to derive queries to answer arbitrary questions about the health of your application.',
level: nag_rules_1.NagMessageLevel.WARN,
rule: apigw_1.APIGWStructuredLogging,
node: node,
});
this.applyRule({
info: 'The API Gateway does not have Tracing enabled.',
explanation: 'Amazon API Gateway provides active tracing support for AWS X-Ray. Enable active tracing on your API stages to sample incoming requests and send traces to X-Ray.',
level: nag_rules_1.NagMessageLevel.WARN,
rule: apigw_1.APIGWXrayEnabled,
node: node,
});
}
/**
* Check AppSync Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkAppSync(node) {
this.applyRule({
info: 'The AppSync API does not have tracing enabled',
explanation: 'AWS AppSync can emit traces to AWS X-Ray, which enables visualizing service maps for faster troubleshooting.',
level: nag_rules_1.NagMessageLevel.WARN,
rule: appsync_1.AppSyncTracing,
node: node,
});
}
/**
* Check EventBridge Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkEventBridge(node) {
this.applyRule({
info: 'The EventBridge Target does not have a DLQ configured.',
explanation: "Configuring a Dead-Letter Queue (DLQ) for EventBridge rules helps manage failed event deliveries. When a rule's target fails to process an event, the DLQ captures these failed events, allowing for analysis, troubleshooting, and potential reprocessing. This improves the reliability and observability of your event-driven architectures by providing a safety net for handling delivery failures.",
level: nag_rules_1.NagMessageLevel.ERROR,
rule: eventbridge_1.EventBusDLQ,
node: node,
});
}
/**
* Check SNS Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkSNS(node) {
this.applyRule({
info: 'The SNS subscription does not have a redrive policy configured.',
explanation: 'Configuring a redrive policy helps manage message delivery failures by sending undeliverable messages to a dead-letter queue.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: sns_1.SNSRedrivePolicy,
node: node,
});
}
/**
* Check SQS Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkSQS(node) {
this.applyRule({
info: 'The SQS queue does not have a redrive policy configured.',
explanation: 'Configuring a redrive policy on an SQS queue allows you to define how many times SQS will make messages available for consumers before sending them to a dead-letter queue. This helps in managing message processing failures and provides a mechanism for handling problematic messages.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: sqs_1.SQSRedrivePolicy,
node: node,
});
}
/**
* Check StepFunctions Resources
* @param node the CfnResource to check
* @param ignores list of ignores for the resource
*/
checkStepFunctions(node) {
this.applyRule({
info: 'The StepFunction state machine does not have X-Ray tracing configured.',
explanation: 'AWS StepFunctions provides active tracing support for AWS X-Ray. Enable active tracing on your API stages to sample incoming requests and send traces to X-Ray.',
level: nag_rules_1.NagMessageLevel.ERROR,
rule: stepfunctions_1.StepFunctionStateMachineXray,
node: node,
});
}
}
exports.ServerlessChecks = ServerlessChecks;
_a = JSII_RTTI_SYMBOL_1;
ServerlessChecks[_a] = { fqn: "cdk-nag.ServerlessChecks", version: "2.36.41" };
//# sourceMappingURL=data:application/json;base64,