Notes
-
For some reason, similar policies mention only
mysql
andpostgres
engines in the policyaudit
andremediation
sections. However, AWS documentation tells thatAutoMinorVersionUpgrade
attribute is supported onALL
DB engines: docs -
We've modified the
ssh
commands to include all engines (see remediation.md). -
Our policy document also accepts all engines (doesn't filter any).