guardrails-samples icon indicating copy to clipboard operation
guardrails-samples copied to clipboard

Amend policy pack - Use Active controls to clean up old Elastic IPs

Open Joeturbot opened this issue 6 months ago • 1 comments

Control objective* Add Active and Active > Age policy settings to the Enforce AWS VPC Elastic IPs to Not Be Unassociated policy pack. At present, the PP only cleans up new Elastic IPs while alarming on older EIPs. The addition of Active and Active > Age provides the capacity to clean up all EIPs, regardless of age.

Remediation Use the EIP Active control to clean up older EIPs that wouldn't be removed by the Approved policy.

Additional Context Slack: https://turbothq.slack.com/archives/C06DF1TE16D/p1721761219455949

Joeturbot avatar Jul 29 '24 13:07 Joeturbot