Control: OpenSearch domain should not use the default security group
Description
This control checks whether OpenSearch domains are configured to use the default security group. This control fails if the OpenSearch domain uses the default security group.
Usage
Run the control in your terminal:
powerpipe control run terraform_aws_compliance.control.opensearch_domain_use_default_security_group
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run terraform_aws_compliance.control.opensearch_domain_use_default_security_group --share
SQL
This control uses a named query:
select address as resource, case when (attributes_std -> 'vpc_options' ->> 'security_group_ids') is not null then 'ok' else 'alarm' end status, split_part(address, '.', 2) || case when (attributes_std -> 'vpc_options' ->> 'security_group_ids') is not null then ' default security group not set' else ' default security group set' end || '.' reason , path || ':' || start_linefrom terraform_resourcewhere type = 'aws_opensearch_domain';