You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the issue
Check CKV_AWS_304 generates a false positive within the aws_secretsmanager_secret_rotation resource when using the scheduled_expression configuration option. The AWS terraform module allows either the schedule_expression or the automatically_after_days configuration option for the rotation_rules block, they are mutually exclusive to one another.
As far as I can tell, the check only looks for the automatically_after_days configuration option based on an initial code search:
Please share an example code sample (in the IaC of your choice) + the expected outcomes.
Version (please complete the following information):
v3.2.65
Additional context
I am unable to provide the ZIP file to handle the rotation (due to internal policies), but the example logic above should build everything else, and is simply a mix of most of the example logic provided by the terraform reference documentation itself.
The text was updated successfully, but these errors were encountered:
cbowlby-bt
changed the title
Check CKV_AWS_304 reports a false positive finding when using a scheduled expression vs specifying days
False positive on CKV_AWS_304: When using scheduled expressions for secrets rotation
Apr 22, 2024
Describe the issue
Check CKV_AWS_304 generates a false positive within the
aws_secretsmanager_secret_rotation
resource when using thescheduled_expression
configuration option. The AWS terraform module allows either theschedule_expression
or theautomatically_after_days
configuration option for therotation_rules
block, they are mutually exclusive to one another.As far as I can tell, the check only looks for the
automatically_after_days
configuration option based on an initial code search:Examples
Please share an example code sample (in the IaC of your choice) + the expected outcomes.
Version (please complete the following information):
Additional context
I am unable to provide the ZIP file to handle the rotation (due to internal policies), but the example logic above should build everything else, and is simply a mix of most of the example logic provided by the terraform reference documentation itself.
The text was updated successfully, but these errors were encountered: