terraform-aws-control_tower_account_factory
terraform-aws-control_tower_account_factory copied to clipboard
CloudTrail Data Events S3 bucket is created even if aft_feature_cloudtrail_data_events is set to false
Terraform Version & Prov:
AFT Version: 1.12.0
(Can be found in the AFT Management Account in the SSM Parameter /aft/config/aft/version)
Terraform Version & Provider Versions
Please provide the outputs of terraform version and terraform providers from within your AFT environment
terraform version
1.6.0
terraform providers
hashicorp/aws = 5.21.0
Bug Description
S3 bucket aws-aft-logs-${ACCOUNT-ID}-${REGION} is created even if aft_feature_cloudtrail_data_events is set to false
To Reproduce Steps to reproduce the behavior:
- Set
aft_feature_cloudtrail_data_eventsasfalseforaws-ia/control_tower_account_factory/awsmodule. - Login into the AFT Management account
- See that s3 bucket
aws-aft-logs-${ACCOUNT-ID}-${REGION}exists, e.g.aws-aft-logs-11111111111-us-east-1is created
Expected behavior Bucket should not be created and remain empty if user opts out of cloudtrail data events feature.
Related Logs N/A
Additional context N/A
@anasillo thank you for reporting this. I will create an internal backlog to address this.