{"id":19978324,"url":"https://github.com/geekcell/terraform-aws-config-rules","last_synced_at":"2025-11-25T15:04:40.658Z","repository":{"id":150854005,"uuid":"598851468","full_name":"geekcell/terraform-aws-config-rules","owner":"geekcell","description":"Terraform module to provision an AWS Config Ruleset.","archived":false,"fork":false,"pushed_at":"2023-06-28T09:27:05.000Z","size":35,"stargazers_count":0,"open_issues_count":0,"forks_count":1,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-03-01T18:48:52.111Z","etag":null,"topics":["aws","config","config-rules","terraform","terraform-module"],"latest_commit_sha":null,"homepage":"https://www.geekcell.io","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/geekcell.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-02-07T23:39:54.000Z","updated_at":"2023-05-11T12:56:24.000Z","dependencies_parsed_at":null,"dependency_job_id":"125d2508-b9ce-45ca-9288-83964f09b76d","html_url":"https://github.com/geekcell/terraform-aws-config-rules","commit_stats":null,"previous_names":[],"tags_count":4,"template":false,"template_full_name":"geekcell/terraform-aws-module-template","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-config-rules","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-config-rules/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-config-rules/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-config-rules/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/geekcell","download_url":"https://codeload.github.com/geekcell/terraform-aws-config-rules/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":241411543,"owners_count":19958753,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws","config","config-rules","terraform","terraform-module"],"created_at":"2024-11-13T03:32:53.014Z","updated_at":"2025-11-25T15:04:35.614Z","avatar_url":"https://github.com/geekcell.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003c!-- BEGIN_TF_DOCS --\u003e\n[![Geek Cell GmbH](https://raw.githubusercontent.com/geekcell/.github/main/geekcell-github-banner.png)](https://www.geekcell.io/)\n\n### Code Quality\n[![License](https://img.shields.io/github/license/geekcell/terraform-aws-config-rules)](https://github.com/geekcell/terraform-aws-config-rules/blob/master/LICENSE)\n[![GitHub release (latest tag)](https://img.shields.io/github/v/release/geekcell/terraform-aws-config-rules?logo=github\u0026sort=semver)](https://github.com/geekcell/terraform-aws-config-rules/releases)\n[![Release](https://github.com/geekcell/terraform-aws-config-rules/actions/workflows/release.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-config-rules/actions/workflows/release.yaml)\n[![Validate](https://github.com/geekcell/terraform-aws-config-rules/actions/workflows/validate.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-config-rules/actions/workflows/validate.yaml)\n[![Lint](https://github.com/geekcell/terraform-aws-config-rules/actions/workflows/linter.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-config-rules/actions/workflows/linter.yaml)\n\n\u003c!--\nComment in if Bridgecrew is configured\n\n### Security\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/general)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=INFRASTRUCTURE+SECURITY)\n\n#### Cloud\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_aws)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+AWS+V1.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_aws_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+AWS+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_azure)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+AZURE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_azure_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+AZURE+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_gcp)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+GCP+V1.1)\n\n##### Container\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_kubernetes_16)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+KUBERNETES+V1.6)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_eks_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+EKS+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_gke_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+GKE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/cis_kubernetes)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=CIS+KUBERNETES+V1.5)\n\n#### Data protection\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/soc2)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=SOC2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/pci)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=PCI-DSS+V3.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/pci_dss_v321)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=PCI-DSS+V3.2.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/iso)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=ISO27001)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/nist)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=NIST-800-53)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/hipaa)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=HIPAA)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-config-rules/fedramp_moderate)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-config-rules\u0026benchmark=FEDRAMP+%28MODERATE%29)\n\n--\u003e\n\n# Terraform AWS Config Rules\n\nA set of AWS Config rules to be deployed using Terraform. Packed into submodules.\n\n## Inputs\n\n| Name | Description | Type | Default | Required |\n|------|-------------|------|---------|:--------:|\n| \u003ca name=\"input_acm\"\u003e\u003c/a\u003e [acm](#input\\_acm) | A map of Cloudtrail configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | n/a | yes |\n| \u003ca name=\"input_cloudtrail\"\u003e\u003c/a\u003e [cloudtrail](#input\\_cloudtrail) | A map of Cloudtrail configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled   = bool\u003cbr\u003e    bucket_id = optional(string)\u003cbr\u003e  }))\u003c/pre\u003e | n/a | yes |\n| \u003ca name=\"input_ec2\"\u003e\u003c/a\u003e [ec2](#input\\_ec2) | A map of EC2 configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | n/a | yes |\n| \u003ca name=\"input_iam\"\u003e\u003c/a\u003e [iam](#input\\_iam) | A map of IAM configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | `{}` | no |\n| \u003ca name=\"input_lb\"\u003e\u003c/a\u003e [lb](#input\\_lb) | A map of Load Balancer configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | `{}` | no |\n| \u003ca name=\"input_rds\"\u003e\u003c/a\u003e [rds](#input\\_rds) | A map of RDS configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | `{}` | no |\n| \u003ca name=\"input_s3\"\u003e\u003c/a\u003e [s3](#input\\_s3) | A map of S3 configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | `{}` | no |\n| \u003ca name=\"input_tag\"\u003e\u003c/a\u003e [tag](#input\\_tag) | A map of Tag configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | `{}` | no |\n| \u003ca name=\"input_tags\"\u003e\u003c/a\u003e [tags](#input\\_tags) | A mapping of tags to assign to all resources. | `map(string)` | `{}` | no |\n| \u003ca name=\"input_vpc\"\u003e\u003c/a\u003e [vpc](#input\\_vpc) | A map of VPC configuration options. | \u003cpre\u003emap(object({\u003cbr\u003e    enabled = bool\u003cbr\u003e  }))\u003c/pre\u003e | `{}` | no |\n\n## Outputs\n\nNo outputs.\n\n## Providers\n\nNo providers.\n\n## Resources\n\n\n# Examples\n### Full\n```hcl\nmodule \"full-example\" {\n  source = \"../..\"\n\n  acm = {\n    \"acm_certificate_expiration_check\" = {\n      \"enabled\" = true\n    }\n  }\n\n  cloudtrail = {\n    \"cloudtrail_enabled\" = {\n      \"enabled\"   = true\n      \"bucket_id\" = \"my-cloudtrail-bucket\"\n    },\n    \"cloudtrail_log_file_validation_enabled\" = {\n      \"enabled\" = true\n    },\n  }\n\n  ec2 = {\n    \"autoscaling_group_elb_healthcheck_required\" = {\n      \"enabled\" = true\n    },\n    \"ec2_volume_in_use\" = {\n      \"enabled\" = true\n    },\n    \"encrypted_volumes\" = {\n      \"enabled\" = true\n    },\n    \"instances_in_vpc\" = {\n      \"enabled\" = true\n    },\n  }\n\n  iam = {\n    \"iam_policy_no_statements_with_admin_access\" = {\n      \"enabled\" = true\n    },\n    \"iam_user_no_policies_check\" = {\n      \"enabled\" = true\n    },\n  }\n\n  lb = {\n    \"alb_http_to_https_redirection_check\" = {\n      \"enabled\" = true\n    },\n    \"elb_acm_certificate_required\" = {\n      \"enabled\" = true\n    },\n  }\n\n  rds = {\n    \"aurora_last_backup_recovery_point_created\" = {\n      \"enabled\" = true\n    },\n    \"db_instance_backup_enabled\" = {\n      \"enabled\" = true\n    },\n    \"rds_instance_public_access_check\" = {\n      \"enabled\" = true\n    },\n    \"rds_multi_az_support\" = {\n      \"enabled\" = true\n    },\n    \"rds_snapshots_public_prohibited\" = {\n      \"enabled\" = true\n    },\n    \"rds_storage_encrypted\" = {\n      \"enabled\" = true\n    },\n  }\n\n  s3 = {\n    \"s3_bucket_public_read_prohibited\" = {\n      \"enabled\" = true\n    },\n  }\n\n  tag = {\n    \"required_tags\" = {\n      \"enabled\" = true\n    },\n  }\n\n  vpc = {\n    \"eip_attached\" = {\n      \"enabled\" = true\n    },\n  }\n\n  tags = {}\n}\n```\n\u003c!-- END_TF_DOCS --\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-config-rules","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgeekcell%2Fterraform-aws-config-rules","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-config-rules/lists"}