Control: WAF regional web ACL should have at least one rule or rule group attached
Description
This control checks if a WAF regional Web ACL contains any WAF rules or rule groups. The rule is non compliant if there are no WAF rules or rule groups present within a Web ACL.
Usage
Run the control in your terminal:
powerpipe control run terraform_aws_compliance.control.waf_regional_web_acl_rule_attached
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run terraform_aws_compliance.control.waf_regional_web_acl_rule_attached --share
SQL
This control uses a named query:
select address as resource, case when (attributes_std -> 'rule') is not null then 'ok' else 'alarm' end as status, split_part(address, '.', 2) || case when (attributes_std -> 'rule') is not null then ' has rule(s) attached' else ' has no attached rules' end || '.' reason , path || ':' || start_linefrom terraform_resourcewhere type = 'aws_wafregional_web_acl';