We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent ca95394 commit 499d864Copy full SHA for 499d864
cis-oci-benchmark/cis_iam_rules.rego
@@ -7,16 +7,16 @@ import input as tfplan
7
bad_combo := {"allow group to manage" , "all-resources"}
8
9
bad_pairs := {
10
- "Allow": "manage",
11
- "group": "v3-app-admin-group"
+ "com-admin": "to read all-resources",
+ # "groups": "to manage groups in tenancy"
12
}
13
14
bad_combination_policies contains bad_policy.address if {
15
bad_policy := tfplan.resource_changes[_]
16
bad_policy.type == "oci_identity_policy"
17
statements := bad_policy.change.after.statements
18
- some statement in statements
19
- some key, value in bad_pairs
20
- contains(statement, key)
21
- contains(statement, value)
+ some statement in statements
+ some key, value in bad_pairs
+ contains(statement, value)
+ # contains(statement, value)
22
0 commit comments