turbot/steampipe-mod-aws-compliance

Control: ECR repositories should have lifecycle policies configured

Description

This control checks if ECR repositories have lifecycle policy configured. This rule fails if ECR repository lifecycle policy is not enabled.

Usage

Run the control in your terminal:

powerpipe control run aws_compliance.control.ecr_repository_lifecycle_policy_configured

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run aws_compliance.control.ecr_repository_lifecycle_policy_configured --share

SQL

This control uses a named query:

select
arn as resource,
case
when lifecycle_policy -> 'rules' is not null then 'ok'
else 'alarm'
end as status,
case
when lifecycle_policy -> 'rules' is not null then title || ' lifecycle policy configured.'
else title || ' lifecycle policy not configured.'
end as reason
, region, account_id
from
aws_ecr_repository;

Tags