You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

tfsec v1.28.0无法识别EKS集群动态encryption_config配置问题

EKS集群已配置encryption_config但tfsec仍提示未启用密钥加密

我们的EKS集群资源已添加encryption_config配置,并通过dynamic块实现多配置项的动态添加。但运行tfsec(版本1.28.0)扫描代码时,仍收到「Cluster does not have secret encryption enabled」的检测提示。

现有代码

动态块实现的encryption_config

resource "aws_eks_cluster" "this" {
...

dynamic "encryption_config" {
    for_each = toset(var.cluster_encryption_config)

    content {
      provider {
        key_arn = encryption_config.value["provider_key_arn"]
      }
      resources = encryption_config.value["resources"]
    }
  }

}

variables.tf定义

variable "cluster_encryption_config" {
  description = "Configuration block with encryption configuration for the cluster. See examples/secrets_encryption/main.tf for example format"
  type = list(object({
    provider_key_arn = string
    resources        = list(string)
  }))
  default = []
}

问题原因及解决办法

核心原因

  1. tfsec静态分析局限性:tfsec 1.28.0版本的静态扫描逻辑无法正确识别通过dynamic块生成的encryption_config配置,尤其是变量默认值为空列表时,工具会误判未启用加密。
  2. 资源类型未指定secrets:即使配置了encryption_config,如果resources列表中未明确包含secrets,EKS实际并未启用密钥加密,tfsec的提示也会触发。

解决步骤

  1. 确保配置包含secrets资源
    传入变量时,必须在resources中指定secrets,示例配置如下:

    cluster_encryption_config = [
      {
        provider_key_arn = "arn:aws:kms:us-west-2:123456789012:key/abcd1234-5678-90ef-ghij-klmnopqrstuv"
        resources        = ["secrets"]
      }
    ]
    
  2. 添加变量验证约束
    在variables.tf中添加验证规则,强制要求至少有一个配置项包含secrets资源,避免遗漏:

    variable "cluster_encryption_config" {
      description = "Configuration block with encryption configuration for the cluster. See examples/secrets_encryption/main.tf for example format"
      type = list(object({
        provider_key_arn = string
        resources        = list(string)
      }))
      default = []
      validation {
        condition     = length([for cfg in var.cluster_encryption_config : cfg if contains(cfg.resources, "secrets")]) > 0
        error_message = "至少需要一个加密配置的resources列表包含'secrets',以启用密钥加密。"
      }
    }
    
  3. 升级tfsec或临时忽略检测

    • 优先升级tfsec到最新版本,新版本通常会修复dynamic块的识别问题;
    • 若暂时无法升级,可在aws_eks_cluster资源上方添加注释忽略该检测(仅作为临时方案):
      #tfsec:ignore:aws-eks-enable-secrets-encryption
      resource "aws_eks_cluster" "this" {
        ...
      }
      

内容的提问来源于stack exchange,提问作者Jatin Mehrotra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 04:01:16