如何仅对前缀为important-的S3桶应用AWS Config规则s3-bucket-logging-enabled
问题描述
我拥有数百个S3存储桶,其中仅有少数重要存储桶,这些桶的命名均以important-为前缀,示例如下:
example-s3-bucket-1 example-s3-bucket-2 important-s3-bucket-1 example-s3-bucket-3 important-s3-bucket-2 ...
我希望仅对以important-开头的存储桶运行AWS的s3-bucket-logging-enabled Config规则,忽略其他所有存储桶。该规则详情如下:
# s3-bucket-logging-enabled Config Rule Description: Checks if logging is enabled for your S3 buckets. The rule is NON_COMPLIANT if logging is not enabled. Enabled evaluation mode: DETECTIVE Detective evaluation trigger type: Oversized configuration changes Configuration changes Scope of changes: Resources Resource types: S3 Bucket Parameters: targetBucket - Target S3 bucket for storing server access logs. targetPrefix - Prefix of the S3 bucket for storing server access logs.
解决方案
控制台配置步骤
- 登录AWS Config控制台,找到
s3-bucket-logging-enabled规则,点击「编辑规则」。
- 登录AWS Config控制台,找到
- 在「范围」设置区域:
- 确认已勾选「包括特定资源类型」,并选中「AWS::S3::Bucket」。
- 展开「资源过滤器」,点击「添加过滤器」:
- 选择「资源名称」作为过滤属性;
- 匹配条件选择「开头为」;
- 输入过滤值
important-。
- 在「范围」设置区域:
- 检查规则参数
targetBucket和targetPrefix是否已正确配置为日志存储桶及前缀,若未配置则补充完整。
- 检查规则参数
- 保存规则配置。
AWS CLI配置方式
如果习惯用命令行,可执行以下命令(替换占位符为实际值):
aws configservice put-config-rule \ --config-rule-name s3-bucket-logging-enabled \ --source '{"Owner":"AWS","SourceIdentifier":"S3_BUCKET_LOGGING_ENABLED"}' \ --scope '{"ComplianceResourceTypes":["AWS::S3::Bucket"],"ComplianceResourceNameFilters":["important-*"]}' \ --parameters '{"targetBucket":{"Value":"your-target-log-bucket"},"targetPrefix":{"Value":"s3-access-logs/"}}'
配置完成后,AWS Config将仅针对名称以important-开头的S3存储桶执行s3-bucket-logging-enabled规则的合规性检查,其余存储桶会被排除在评估范围外。
内容的提问来源于stack exchange,提问作者NOAA Cloud Dev
相关产品推荐
相关产品推荐

