turbot/steampipe-mod-aws-compliance

Control: CodeBuild project environments should not have privileged mode enabled

Description

This control checks if an AWS CodeBuild project environment has privileged mode enabled. This control fails when an AWS CodeBuild project environment has privileged mode enabled.

Usage

Run the control in your terminal:

powerpipe control run aws_compliance.control.codebuild_project_environment_privileged_mode_disabled

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run aws_compliance.control.codebuild_project_environment_privileged_mode_disabled --share

SQL

This control uses a named query:

select
arn as resource,
case
when environment ->> 'PrivilegedMode' = 'true' then 'alarm'
else 'ok'
end as status,
case
when environment ->> 'PrivilegedMode' = 'true' then title || ' environment privileged mode enabled.'
else title || ' environment privileged mode disabled.'
end as reason
, region, account_id
from
aws_codebuild_project;

Tags