π§ AWS EC2 Instance with an auto-assigned public IP address is in a default subnet - prod.logic.yaml π’
- Contextual name: π§ prod.logic.yaml π’
- ID:
/ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
- Located in: π AWS EC2 Instance with an auto-assigned public IP address is in a default subnet π’
Flagsβ
- π’ Logic test success
- π’ Logic with extracts
- π’ Logic with test data
Input Typeβ
Type | API Name | Extracts | Extract Files | Logic Files | |
---|---|---|---|---|---|
π | π AWS EC2 Instance | CA10__CaAwsInstance__c | 12 | 2 | 54 |
Usesβ
- π AWS VPC Subnet - object.extracts.yaml
- π AWS EC2 Instance - object.extracts.yaml
- π§ͺ test-data.json
Test Results π’β
Generated at: 2025-08-29T17:46:06.286584589Z Open
Result | Id | Condition Index | Condition Text | Runtime Error |
---|---|---|---|---|
π’ | test1 | βοΈ 99 | βοΈ isDisappeared(CA10__disappearanceTime__c) | βοΈ null |
π’ | test2 | βοΈ 199 | βοΈ extract('CA10__publicIpAddress__c').isEmpty() | βοΈ null |
π’ | test4 | βοΈ 299 | βοΈ CA10__AWS_EC2_Elastic_IPs__r.has(COMPLIANT) | βοΈ null |
π’ | test5 | βοΈ 499 | βοΈ CA10__vpcSubnet__r.CA10__defaultForAz__c == false | βοΈ null |
π’ | test6 | βοΈ 599 | βοΈ CA10__vpcSubnet__r.CA10__mapPublicIpOnLaunch__c == true | βοΈ null |
π’ | test7 | βοΈ 399 | βοΈ isEmptyLookup('CA10__vpcSubnet__r') | βοΈ null |
π’ | test8 | βοΈ 600 | βοΈ otherwise | βοΈ null |
Generationβ
File | MD5 | |
---|---|---|
Open | /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/policy.yaml | 55A7FBF38BD08F2A3F87A5D9FB791FC4 |
Open | /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml | F8BD05FF9F92E6EE445E68BFE6764416 |
Open | /types/CA10__CaAwsSubnet__c/object.extracts.yaml | 7F012284F2BF194EA79A157883554CA2 |
Open | /types/CA10__CaAwsInstance__c/object.extracts.yaml | 802FA80DBDE640AF85A69B42E51E0CCD |
Open | /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/test-data.json | 4A4616F804418A47DA4350988B0C4DB5 |
Generate FULL scriptβ
java -jar repo-manager.jar policies generate FULL /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
Generate DEBUG scriptβ
java -jar repo-manager.jar policies generate DEBUG /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
Generate CAPTURE_TEST_DATA scriptβ
java -jar repo-manager.jar policies generate CAPTURE_TEST_DATA /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
Generate TESTS scriptβ
java -jar repo-manager.jar policies generate TESTS /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
Execute testsβ
java -jar repo-manager.jar policies test /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
Contentβ
inputType: "CA10__CaAwsInstance__c"
importExtracts:
- file: /types/CA10__CaAwsInstance__c/object.extracts.yaml
- file: /types/CA10__CaAwsSubnet__c/object.extracts.yaml
testData:
- file: "test-data.json"
conditions:
- status: "COMPLIANT"
currentStateMessage: "The instance does not have a public IP address."
check:
IS_EMPTY:
arg:
EXTRACT: "CA10__publicIpAddress__c"
- status: "COMPLIANT"
currentStateMessage: "The instance has an Elastic IP address."
check:
RELATED_LIST_HAS:
status: "COMPLIANT"
relationshipName: "CA10__AWS_EC2_Elastic_IPs__r"
- status: "UNDETERMINED"
currentStateMessage: "Cannot determine if the instance is in a default subnet because subnet information is missing."
check:
IS_EMPTY_LOOKUP: "CA10__vpcSubnet__r"
- status: "COMPLIANT"
currentStateMessage: "Instance has a public IP address and is located in a custom subnet."
check:
IS_EQUAL:
left:
FIELD:
path: "CA10__vpcSubnet__r.CA10__defaultForAz__c"
right:
BOOLEAN: false
- status: "INCOMPLIANT"
currentStateMessage: "The instance has an auto-assigned public IP address and is located in a default subnet."
remediationMessage: "Consider moving the instance to a custom subnet intended\
\ for public resources or removing its public IP address if internet access is not required."
check:
IS_EQUAL:
left:
FIELD:
path: "CA10__vpcSubnet__r.CA10__mapPublicIpOnLaunch__c"
right:
BOOLEAN: true
otherwise:
status: "COMPLIANT"
currentStateMessage: "The instance has an auto-assigned public IP address but\
\ the Auto-assign Public IPv4 Address subnet attribute is disabled."
relatedLists:
- relationshipName: "CA10__AWS_EC2_Elastic_IPs__r"
conditions: []
otherwise:
status: "COMPLIANT"
currentStateMessage: "This is an Elastic IP address."