All files / lib secure-root-user.ts

100% Statements 13/13
100% Branches 0/0
100% Functions 1/1
100% Lines 13/13

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60                                2x 2x   2x 2x     2x   2x       2x   2x             2x                   2x 2x   2x     2x          
/*
Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
 
Licensed under the Apache License, Version 2.0 (the "License").
You may not use this file except in compliance with the License.
You may obtain a copy of the License at
 
    http://www.apache.org/licenses/LICENSE-2.0
 
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
 
import * as core from "@aws-cdk/core";
import * as config from "@aws-cdk/aws-config";
import * as sns from '@aws-cdk/aws-sns'
import * as targets from '@aws-cdk/aws-events-targets';
import {ConfigRecorder} from "./aws-config-recorder";
 
 
export class SecureRootUser extends core.Construct {
  constructor(scope: core.Construct, id: string, snsTopic: sns.Topic) {
    super(scope, id);
 
 
    // Enforce MFA
    const configRecorder = new ConfigRecorder(this, "ConfigRecorder");
 
    const enforceMFARule = new config.ManagedRule(this, "EnableRootMfa", {
      identifier: "ROOT_ACCOUNT_MFA_ENABLED",
      maximumExecutionFrequency:
      config.MaximumExecutionFrequency.TWENTY_FOUR_HOURS,
    });
 
    // Enforce No root access key
    const enforceNoAccessKeyRule = new config.ManagedRule(
      this,
      "NoRootAccessKey",
      {
        identifier: "IAM_ROOT_ACCESS_KEY_CHECK",
        maximumExecutionFrequency:
        config.MaximumExecutionFrequency.TWENTY_FOUR_HOURS,
      }
    );
 
    enforceMFARule.node.addDependency(configRecorder);
    enforceNoAccessKeyRule.node.addDependency(configRecorder);
 
    enforceMFARule.onComplianceChange('ComplianceChange', {
      target: new targets.SnsTopic(snsTopic)
    });
    enforceNoAccessKeyRule.onComplianceChange('ComplianceChange', {
      target: new targets.SnsTopic(snsTopic)
    });
  }
}