π§ AWS S3 Access Point is not configured to block public access - prod.logic.yamlπ’
- Contextual name: π§ prod.logic.yamlπ’
- ID:
/ce/ca/aws/s3/access-point-block-public-access/prod.logic.yaml - Tags:
- π’ Logic test success
- π’ Logic with extracts
- π’ Logic with test data
Usesβ
Test Results π’β
Generated at: 2025-11-20T13:28:57.583051358Z Open
| Result | Id | Condition Index | Condition Text | Runtime Error |
|---|---|---|---|---|
| π’ | test1 | βοΈ 199 | βοΈ extract('CA10A1__blockPublicAcls__c') != 'Yes' || extract('CA10A1__blockPublicPolicy__c') != 'Yes' || extract('CA10A1__ignorePublicAcls__c') != 'Yes' || extract('CA10A1__restrictPublicBuckets__c') != 'Yes' | βοΈ null |
| π’ | test2 | βοΈ 200 | βοΈ otherwise | βοΈ null |
| π’ | test3 | βοΈ 99 | βοΈ isDisappeared(CA10A1__disappearanceTime__c) | βοΈ null |
Generation Bundleβ
| File | MD5 | |
|---|---|---|
| Open | /ce/ca/aws/s3/access-point-block-public-access/policy.yaml | 0B75BD4DDC8D0350CE5B49C5F28E1A64 |
| Open | /ce/ca/aws/s3/access-point-block-public-access/prod.logic.yaml | 8870285330D39B89E9AA3AD645D2533D |
| Open | /ce/ca/aws/s3/access-point-block-public-access/test-data.json | 289C5F24723E2816138A0D18A459AA54 |
| Open | /types/CA10A1__CaAwsS3AccessPoint__c/object.extracts.yaml | C4AE44407725A35D6C756B35066C74E1 |
Available Commandsβ
repo-manager policies generate FULL /ce/ca/aws/s3/access-point-block-public-access/prod.logic.yaml
repo-manager policies generate DEBUG /ce/ca/aws/s3/access-point-block-public-access/prod.logic.yaml
repo-manager policies generate CAPTURE_TEST_DATA /ce/ca/aws/s3/access-point-block-public-access/prod.logic.yaml
repo-manager policies generate TESTS /ce/ca/aws/s3/access-point-block-public-access/prod.logic.yaml
# Execute tests
repo-manager policies test /ce/ca/aws/s3/access-point-block-public-access/prod.logic.yaml
Contentβ
---
inputType: "CA10A1__CaAwsS3AccessPoint__c"
testData:
- file: "test-data.json"
importExtracts:
- file: "/types/CA10A1__CaAwsS3AccessPoint__c/object.extracts.yaml"
conditions:
- status: "INCOMPLIANT"
currentStateMessage: "The S3 Access Point is not configured to block public access."
remediationMessage: "Consider configuring the S3 Access Point to block all public access settings."
check:
OR:
args:
- NOT_EQUAL:
left:
EXTRACT: CA10A1__blockPublicAcls__c
right:
TEXT: "Yes"
- NOT_EQUAL:
left:
EXTRACT: CA10A1__blockPublicPolicy__c
right:
TEXT: "Yes"
- NOT_EQUAL:
left:
EXTRACT: CA10A1__ignorePublicAcls__c
right:
TEXT: "Yes"
- NOT_EQUAL:
left:
EXTRACT: CA10A1__restrictPublicBuckets__c
right:
TEXT: "Yes"
otherwise:
status: "COMPLIANT"
currentStateMessage: "The S3 Access Point is configured to block all public access."