🧠 AWS EC2 Instance with an auto-assigned public IP address is in a default subnet - prod.logic.yaml🟢
- Contextual name: 🧠 prod.logic.yaml🟢
- ID:
/ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml - Tags:
Uses
- 📗 AWS EC2 Instance
- 🔌 AWS EC2 Instance - object.extracts.yaml
- 🔌 AWS VPC Subnet - object.extracts.yaml
- 🧪 test-data.json
Test Results 🟢
Generated at: 2026-02-10T22:32:44.083056849Z Open
| Result | Id | Condition Index | Condition Text | Runtime Error |
|---|---|---|---|---|
| 🟢 | test1 | ✔️ 99 | ✔️ isDisappeared(CA10__disappearanceTime__c) | ✔️ null |
| 🟢 | test2 | ✔️ 199 | ✔️ extract('CA10__publicIpAddress__c').isEmpty() | ✔️ null |
| 🟢 | test4 | ✔️ 299 | ✔️ CA10__AWS_EC2_Elastic_IPs__r.has(COMPLIANT) | ✔️ null |
| 🟢 | test5 | ✔️ 499 | ✔️ extract('CA10__vpcSubnet__r.CA10__defaultForAz__c') == false | ✔️ null |
| 🟢 | test6 | ✔️ 599 | ✔️ extract('CA10__vpcSubnet__r.CA10__mapPublicIpOnLaunch__c') == true | ✔️ null |
| 🟢 | test7 | ✔️ 399 | ✔️ isEmptyLookup('CA10__vpcSubnet__r') | ✔️ null |
| 🟢 | test8 | ✔️ 600 | ✔️ otherwise | ✔️ null |
Generation Bundle
| File | MD5 | |
|---|---|---|
| Open | /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/policy.yaml | 55A7FBF38BD08F2A3F87A5D9FB791FC4 |
| Open | /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml | 6B4FA04AB0091A85D6E318FC63A0779A |
| Open | /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/test-data.json | 9673F7BC65AC1A351E9911A2C63B6C0C |
| Open | /types/CA10__CaAwsInstance__c/object.extracts.yaml | BA4E6733C7AF791FAB57658956CE24DF |
| Open | /types/CA10__CaAwsSubnet__c/object.extracts.yaml | 393E30CD97C9DEE73FA18A1456EE4CBD |
Available Commands
repo-manager policies generate FULL /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
repo-manager policies generate DEBUG /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
repo-manager policies generate CAPTURE_TEST_DATA /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
repo-manager policies generate TESTS /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
# Execute tests
repo-manager policies test /ce/ca/aws/ec2/instance-with-public-ip-in-default-subnet/prod.logic.yaml
Content
inputType: "CA10__CaAwsInstance__c"
importExtracts:
- file: /types/CA10__CaAwsInstance__c/object.extracts.yaml
- file: /types/CA10__CaAwsSubnet__c/object.extracts.yaml
testData:
- file: "test-data.json"
conditions:
- status: "COMPLIANT"
currentStateMessage: "The instance does not have a public IP address."
check:
IS_EMPTY:
arg:
EXTRACT: "CA10__publicIpAddress__c"
- status: "COMPLIANT"
currentStateMessage: "The instance has an Elastic IP address."
check:
RELATED_LIST_HAS:
status: "COMPLIANT"
relationshipName: "CA10__AWS_EC2_Elastic_IPs__r"
- status: "UNDETERMINED"
currentStateMessage: "Cannot determine if the instance is in a default subnet because subnet information is missing."
check:
IS_EMPTY_LOOKUP: "CA10__vpcSubnet__r"
- status: "COMPLIANT"
currentStateMessage: "Instance has a public IP address and is located in a custom subnet."
check:
IS_EQUAL:
left:
EXTRACT: "CA10__vpcSubnet__r.CA10__defaultForAz__c"
right:
BOOLEAN: false
- status: "INCOMPLIANT"
currentStateMessage: "The instance has an auto-assigned public IP address and is located in a default subnet."
remediationMessage: "Move the instance to a custom subnet intended\
\ for public resources or remove its public IP address if internet access is not required."
check:
IS_EQUAL:
left:
EXTRACT: "CA10__vpcSubnet__r.CA10__mapPublicIpOnLaunch__c"
right:
BOOLEAN: true
otherwise:
status: "COMPLIANT"
currentStateMessage: "The instance has an auto-assigned public IP address but\
\ the Auto-assign Public IPv4 Address subnet attribute is disabled."
relatedLists:
- relationshipName: "CA10__AWS_EC2_Elastic_IPs__r"
conditions: []
otherwise:
status: "COMPLIANT"
currentStateMessage: "This is an Elastic IP address."