guardrails-samples
guardrails-samples copied to clipboard
Add policy pack - AWS Account Disconnection Prep
Control objective* A set of policy settings to remove Guardrails-managed resources from an AWS Account. This is independent of CMDB policy settings to cut down the number of resources in the Guardrails CMDB for a given account.
Remediation Set these policy settings to the values indicated:
-
AWS > Turbot > Permissions
set toEnforce: None
. -
AWS > Turbot > Audit Trail
set toEnforce: Not configured
. -
AWS > Turbot > Event Handlers
set toEnforce: Not configured
. -
AWS > Turbot > Event Handlers [Global]
set toEnforce: Not configured
. -
AWS > Turbot > Service Roles
set toEnforce: Not configured
. -
AWS > Turbot > Logging > Bucket
set toEnforce: Not configured
. -
AWS > Turbot > Event Poller
toDisabled
.
Categories I don't see a category that cleanly fits this requirement.
Additional context Reference: AWS Account Decommission Docs