turbot/steampipe-mod-aws-compliance

Query: redshiftserverless_workgroup_encryption_in_transit_enabled

Usage

powerpipe query aws_compliance.query.redshiftserverless_workgroup_encryption_in_transit_enabled

SQL

with workgroup_require_ssl_parameter_value as (
select
workgroup_arn
from
aws_redshiftserverless_workgroup as w,
jsonb_array_elements(config_parameters) as p
where
p ->> 'ParameterKey' = 'require_ssl'
and p ->> 'ParameterValue' = 'true'
)
select
w.workgroup_arn as resource,
case
when p.workgroup_arn is not null then 'ok'
else 'alarm'
end as status,
case
when p.workgroup_arn is not null then title || ' encryption in transit enabled.'
else title || ' encryption in transit disabled.'
end as reason
, region, account_id
from
aws_redshiftserverless_workgroup as w
left join workgroup_require_ssl_parameter_value as p on w.workgroup_arn = p.workgroup_arn;

Controls

The query is being used by the following controls: