Skip to content

Second-pass review: event coverage gap, IAM scoping, and baseline hardening - #15

Merged
DustyStudy merged 1 commit into
mainfrom
fix/second-pass-review
Sep 18, 2026
Merged

DustyStudy merged 1 commit into
mainfrom
fix/second-pass-review

Conversation

@DustyStudy

@DustyStudy DustyStudy commented Sep 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

Second pass over the files not read in full during the first review (stale-account detector, member baseline, Config/SSM remediation, gateway Terraform and CloudFormation, Bedrock logging). Verified locally: cfn-lint, terraform fmt/validate (all modules), Checkov (CFN 400/0, Terraform 644/0, baseline template 15/0), and the copy-consistency check all pass. Nothing was deployed to AWS.

Correctness

  • SSH/RDP event-driven path missed edited rules. It only matched AuthorizeSecurityGroupIngress, so editing an existing rule to 0.0.0.0/0 waited for the Config scan. It now also matches ModifySecurityGroupRules; because that event carries rule IDs rather than the resulting CIDR, the Lambda re-checks the whole group. Unit-tested: only the open SSH rule is revoked, other entries untouched. Both Lambda copies, both event patterns and the READMEs updated.
  • Terraform gateway never took a final RDS snapshot. skip_final_snapshot was tied to deletion protection, which must be disabled before a destroy is possible, so the snapshot was skipped in exactly the case it was meant to protect. Now always snapshots, matching the CloudFormation flavour's DeletionPolicy: Snapshot.
  • Gateway on GovCloud: the task role only allowed the commercial us.anthropic.* inference-profile prefix; added us-gov.anthropic.* since the module claims GovCloud support.

Least-privilege / hardening

  • member-baseline: Config bucket now has versioning, a noncurrent-version lifecycle rule and a TLS-only policy (StackSet inline template and Terraform copy). Documented that accounts already running Config (e.g. Control Tower) will fail on the one-recorder-per-region limit.
  • ec2-isolation-runbook: ModifyInstanceAttribute is now also scoped to the security group being attached, which AWS lists as a resource for that action.
  • bedrock-logging-enforcement: added the aws:SourceArn condition AWS's docs show on the CloudWatch role trust policy, and a narrowly scoped iam:PassRole (that one role, Bedrock only) for the Lambda. The PassRole is precautionary - AWS's docs don't say whether it's required.

CI

  • Run Checkov on the Terraform-side member-baseline StackSet template, which neither existing Checkov step covered (this is how the missing bucket versioning slipped through).

Test plan

  • CI passes (including the new Checkov step)
  • Optionally: in a sandbox, edit an existing SG rule to 0.0.0.0/0 on port 22 with the event-driven stack deployed and confirm it is revoked within seconds

Not verified / not changed

  • Whether RDS PostgreSQL 16.13 (pinned in the gateway template) exists as an engine version - needs AWS credentials to check.
  • The gateway container runs as root; left unchanged because changing the user without testing the image risks breaking it.

… hardening

Correctness
- auto-remediate-open-ssh-rdp (event-driven): also match
  ModifySecurityGroupRules, so editing an existing rule to 0.0.0.0/0 is
  remediated in seconds instead of waiting for the Config scan. The
  modify event has no resulting CIDR, so the Lambda re-checks the whole
  group. Lambda copies and both event patterns/READMEs updated.
- claude-apps-gateway (Terraform): always take a final RDS snapshot on
  destroy. It was tied to deletion protection, which must be disabled
  before a destroy is possible, so the snapshot was skipped in exactly the
  case it was meant to protect. Now matches the CFN DeletionPolicy.
- claude-apps-gateway: allow the GovCloud inference-profile prefix
  (us-gov.anthropic.*) in the task role, since the module claims GovCloud
  support.

Least-privilege / hardening
- member-baseline: Config bucket now has versioning, a noncurrent-version
  lifecycle rule and a TLS-only bucket policy (both the StackSet inline
  template and the Terraform copy); documented the one-Config-recorder
  conflict for accounts with Config already enabled (e.g. Control Tower).
- ec2-isolation-runbook: scope ModifyInstanceAttribute to the security
  group being attached as well as the instance (AWS lists both).
- bedrock-logging-enforcement: add the docs-recommended aws:SourceArn
  condition to the CloudWatch role trust policy, and a narrowly scoped
  iam:PassRole (that role, Bedrock only) for the Lambda. The PassRole is
  precautionary - AWS's docs don't state whether it's required.

CI
- Run Checkov on the Terraform-side member-baseline StackSet template,
  which neither existing Checkov step covered.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@DustyStudy
DustyStudy merged commit 5377b6a into main Sep 18, 2026
3 checks passed
@DustyStudy
DustyStudy deleted the fix/second-pass-review branch September 18, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant