π§ AWS Redshift Cluster is not required to use encryption in transit - prod.logic.yamlπ’
- Contextual name: π§ prod.logic.yamlπ’
- ID:
/ce/ca/aws/redshift/cluster-ecryption-in-transit/prod.logic.yaml - Tags:
- π’ Logic test success
- π’ Logic with extracts
- π’ Logic with test data
Usesβ
- π AWS Redshift Cluster
- π AWS Redshift Cluster - object.extracts.yaml
- π AWS Redshift Cluster Parameter - object.extracts.yaml
- π§ͺ test-data.json
Test Results π’β
Generated at: 2025-11-20T13:28:57.532404264Z Open
| Result | Id | Condition Index | Condition Text | Runtime Error |
|---|---|---|---|---|
| π’ | test1 | βοΈ 99 | βοΈ isDisappeared(CA10__disappearanceTime__c) | βοΈ null |
| π’ | test2 | βοΈ 299 | βοΈ CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r.has(INCOMPLIANT) | βοΈ null |
| π’ | test3 | βοΈ 399 | βοΈ CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r.has(COMPLIANT) | βοΈ null |
| π’ | test4 | βοΈ 599 | βοΈ CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r.has(INAPPLICABLE) | βοΈ null |
| π’ | test5 | βοΈ 600 | βοΈ otherwise | βοΈ null |
| π’ | test6 | βοΈ 199 | βοΈ extract('CA10__status__c') != 'available' | βοΈ null |
Generation Bundleβ
| File | MD5 | |
|---|---|---|
| Open | /ce/ca/aws/redshift/cluster-ecryption-in-transit/policy.yaml | 6FBAB805A930963C771DF5C706E07F01 |
| Open | /ce/ca/aws/redshift/cluster-ecryption-in-transit/prod.logic.yaml | 9CAEAA48EE8030792850F0C6CDE7EE39 |
| Open | /ce/ca/aws/redshift/cluster-ecryption-in-transit/test-data.json | BE37B50E659B401ABE07D1C957671EDA |
| Open | /types/CA10__CaAwsRedshiftCluster__c/object.extracts.yaml | 0B799D033E0DBD261DF12B8BA7E202C8 |
| Open | /types/CA10__CaAwsRedshiftClusterParameter__c/object.extracts.yaml | 624055E6B8A930F67D8AD5CE51291BB0 |
Available Commandsβ
repo-manager policies generate FULL /ce/ca/aws/redshift/cluster-ecryption-in-transit/prod.logic.yaml
repo-manager policies generate DEBUG /ce/ca/aws/redshift/cluster-ecryption-in-transit/prod.logic.yaml
repo-manager policies generate CAPTURE_TEST_DATA /ce/ca/aws/redshift/cluster-ecryption-in-transit/prod.logic.yaml
repo-manager policies generate TESTS /ce/ca/aws/redshift/cluster-ecryption-in-transit/prod.logic.yaml
# Execute tests
repo-manager policies test /ce/ca/aws/redshift/cluster-ecryption-in-transit/prod.logic.yaml
Contentβ
---
inputType: "CA10__CaAwsRedshiftCluster__c"
importExtracts:
- file: "/types/CA10__CaAwsRedshiftClusterParameter__c/object.extracts.yaml"
- file: "/types/CA10__CaAwsRedshiftCluster__c/object.extracts.yaml"
testData:
- file: "test-data.json"
conditions:
- status: "INAPPLICABLE"
currentStateMessage: "The Cluster is not available."
check:
NOT_EQUAL:
left:
EXTRACT: "CA10__status__c"
right:
TEXT: "available"
- status: "INCOMPLIANT"
currentStateMessage: "The Redshift Cluster require_ssl parameter is set to false."
remediationMessage: "Consider enabling require_ssl parameter for the Cluster."
check:
RELATED_LIST_HAS:
status: "INCOMPLIANT"
relationshipName: "CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r"
- status: "COMPLIANT"
currentStateMessage: "The Redshift Cluster require_ssl parameter is set to true."
check:
RELATED_LIST_HAS:
status: "COMPLIANT"
relationshipName: "CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r"
- status: "UNDETERMINED"
currentStateMessage: "Unexpected value for the require_ssl parameter. It is not set to true/false."
check:
RELATED_LIST_HAS:
status: "UNDETERMINED"
relationshipName: "CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r"
- status: "UNDETERMINED"
currentStateMessage: "The require_ssl parameter does not exist in the CMDB."
check:
RELATED_LIST_HAS:
status: "INAPPLICABLE"
relationshipName: "CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r"
otherwise:
status: "UNDETERMINED"
currentStateMessage: "The Redshift Cluster parameters do not exist in the CMDB."
relatedLists:
- relationshipName: "CA10A2__AWS_Redshift_Cluster_ParameterGroup_Link__r"
conditions:
- status: "INCOMPLIANT"
currentStateMessage: "The require_ssl parameter is set to false."
remediationMessage: "Consider enabling require_ssl parameter."
check:
RELATED_LIST_HAS:
status: "INCOMPLIANT"
relationshipName: "CA10A2__parameterGroup__r.CA10__AWS_Redshift_Cluster_Parameters__r"
- status: "COMPLIANT"
currentStateMessage: "The require_ssl parameter is set to true."
check:
RELATED_LIST_HAS:
status: "COMPLIANT"
relationshipName: "CA10A2__parameterGroup__r.CA10__AWS_Redshift_Cluster_Parameters__r"
- status: "UNDETERMINED"
currentStateMessage: "Unexpected value for the require_ssl parameter. It is not set to true/false."
check:
RELATED_LIST_HAS:
status: "UNDETERMINED"
relationshipName: "CA10A2__parameterGroup__r.CA10__AWS_Redshift_Cluster_Parameters__r"
otherwise:
status: "INAPPLICABLE"
currentStateMessage: "The require_ssl parameter does not exist in the CMDB."
relatedLists:
- relationshipName: "CA10A2__parameterGroup__r.CA10__AWS_Redshift_Cluster_Parameters__r"
conditions:
- status: "INAPPLICABLE"
currentStateMessage: "This is an unrelated parameter."
check:
NOT_EQUAL:
left:
EXTRACT: "CA10__parameterName__c"
right:
TEXT: "require_ssl"
- status: "INCOMPLIANT"
currentStateMessage: "The require_ssl parameter is not set to false."
check:
IS_EQUAL:
left:
EXTRACT: "CA10__parameterValue__c"
right:
TEXT: "false"
- status: "COMPLIANT"
currentStateMessage: "The require_ssl parameter is not set to true."
check:
IS_EQUAL:
left:
EXTRACT: "CA10__parameterValue__c"
right:
TEXT: "true"
otherwise:
status: "UNDETERMINED"
currentStateMessage: "Unexpected values in the fields."