guardrails-samples
guardrails-samples copied to clipboard
Amend policy pack - Use Active controls to clean up old Elastic IPs
Control objective* Add Active and Active > Age policy settings to the Enforce AWS VPC Elastic IPs to Not Be Unassociated policy pack. At present, the PP only cleans up new Elastic IPs while alarming on older EIPs. The addition of Active and Active > Age provides the capacity to clean up all EIPs, regardless of age.
Remediation Use the EIP Active control to clean up older EIPs that wouldn't be removed by the Approved policy.
Additional Context Slack: https://turbothq.slack.com/archives/C06DF1TE16D/p1721761219455949