Skip to content

Commit 48eaed3

Browse files
AkhtarAmirmatthewdfullergiorod3
authored
Feature/41 | Added AutoScaling Suspended Processes plugin, spec file (aquasecurity#331)
* SPLOIT-113: Added Plain Text Parameters plugin for CloudFormation * Added vpcEndpointAcceptance plugin and spec file * SPLOIT-113: Added Plain Text Parameters plugin for CloudFormation * Added plugin and spec file for launch wizard security groups * Refactored code in plaintextParameters plugin and spec file * SPLOIT-113: Updated custom settings * Made PR requested changes * SPLOIT-113: Added regex to check if NoEcho is enabled * Accommodated PR changes * Fixed eslint issues * Update exports.js * Fixed eslint issues * Update index.js * Update index.js * Added cloudformation in china and gov regions * Accomodated PR changes * Updated status in result of failure * SPLOIT-113: Added Plain Text Parameters plugin for CloudFormation * Added plugin and spec file for launch wizard security groups * Added vpcEndpointAcceptance plugin and spec file * Refactored code in plaintextParameters plugin and spec file * SPLOIT-113: Updated custom settings * Made PR requested changes * SPLOIT-113: Added regex to check if NoEcho is enabled * Accommodated PR changes * Fixed eslint issues * Update index.js * Update index.js * Accomodated PR changes * Updated status in result of failure * SPLOIT-113: Added Plain Text Parameters plugin for CloudFormation * Added plugin and spec file for launch wizard security groups * Added vpcEndpointAcceptance plugin and spec file * Refactored code in plaintextParameters plugin and spec file * SPLOIT-113: Updated custom settings * Made PR requested changes * SPLOIT-113: Added regex to check if NoEcho is enabled * Accommodated PR changes * Fixed eslint issues * Update index.js * Update index.js * Accomodated PR changes * Updated status in result of failure * SPLOIT-113: Added Plain Text Parameters plugin for CloudFormation * SPLOIT-113: Added Plain Text Parameters plugin for CloudFormation * Added plugin and spec file for launch wizard security groups * Added vpcEndpointAcceptance plugin and spec file * Refactored code in plaintextParameters plugin and spec file * SPLOIT-113: Updated custom settings * Made PR requested changes * SPLOIT-113: Added regex to check if NoEcho is enabled * Accommodated PR changes * Fixed eslint issues * Update exports.js * Update index.js * Update index.js * Accomodated PR changes * Updated status in result of failure * Removed unnecesary rebase changes * Feature/41: Added 'Suspended Auto Scaling Groups' plugin * Update plugins/aws/autoscaling/asgSuspendedProcesses.js Co-authored-by: Gio Rodriguez <[email protected]> Co-authored-by: Matt Fuller <[email protected]> Co-authored-by: Gio Rodriguez <[email protected]>
1 parent fe8f41a commit 48eaed3

3 files changed

Lines changed: 237 additions & 0 deletions

File tree

‎exports.js‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ module.exports = {
88
'asgActiveNotifications' : require(__dirname + '/plugins/aws/autoscaling/asgActiveNotifications.js'),
99
'emptyASG' : require(__dirname + '/plugins/aws/autoscaling/emptyASG.js'),
1010
'asgMissingELB' : require(__dirname + '/plugins/aws/autoscaling/asgMissingELB.js'),
11+
'asgSuspendedProcesses' : require(__dirname + '/plugins/aws/autoscaling/asgSuspendedProcesses.js'),
1112
'workgroupEncrypted' : require(__dirname + '/plugins/aws/athena/workgroupEncrypted.js'),
1213
'workgroupEnforceConfiguration' : require(__dirname + '/plugins/aws/athena/workgroupEnforceConfiguration.js'),
1314
'publicS3Origin' : require(__dirname + '/plugins/aws/cloudfront/publicS3Origin.js'),
Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,58 @@
1+
var async = require('async');
2+
var helpers = require('../../../helpers/aws');
3+
4+
module.exports = {
5+
title: 'Suspended AutoScaling Groups',
6+
category: 'AutoScaling',
7+
description: 'Ensures that there are no Amazon AutoScaling groups with suspended processes.',
8+
more_info: 'AutoScaling groups should not have any suspended processes to avoid disrupting the AutoScaling workflow.',
9+
link: 'https://docs.aws.amazon.com/autoscaling/ec2/userguide/as-suspend-resume-processes.html',
10+
recommended_action: 'Update the AutoScaling group to resume the suspended processes.',
11+
apis: ['AutoScaling:describeAutoScalingGroups'],
12+
13+
run: function(cache, settings, callback) {
14+
var results = [];
15+
var source = {};
16+
var regions = helpers.regions(settings);
17+
18+
async.each(regions.autoscaling, function(region, rcb){
19+
var describeAutoScalingGroups = helpers.addSource(cache, source,
20+
['autoscaling', 'describeAutoScalingGroups', region]);
21+
22+
if (!describeAutoScalingGroups) return rcb();
23+
24+
if (describeAutoScalingGroups.err || !describeAutoScalingGroups.data) {
25+
helpers.addResult(results, 3,
26+
`Unable to query for AutoScaling groups: ${helpers.addError(describeAutoScalingGroups)}`, region);
27+
return rcb();
28+
}
29+
30+
if (!describeAutoScalingGroups.data.length) {
31+
helpers.addResult(results, 0, 'No AutoScaling groups found', region);
32+
return rcb();
33+
}
34+
35+
describeAutoScalingGroups.data.forEach(function(asg){
36+
if (!asg.SuspendedProcesses || !asg.SuspendedProcesses.length) {
37+
helpers.addResult(results, 0,
38+
`AutoScaling group "${asg.AutoScalingGroupName}" does not have any suspended processes`,
39+
region, asg.AutoScalingGroupARN);
40+
}
41+
else {
42+
var suspendedProcesses = [];
43+
asg.SuspendedProcesses.forEach(function(process) {
44+
suspendedProcesses.push(process.ProcessName);
45+
});
46+
47+
helpers.addResult(results, 2,
48+
`AutoScaling group "${asg.AutoScalingGroupName}" has these suspended processes: ${suspendedProcesses.join(', ')}`,
49+
region, asg.AutoScalingGroupARN);
50+
}
51+
});
52+
53+
rcb();
54+
}, function(){
55+
callback(null, results, source);
56+
});
57+
}
58+
};
Lines changed: 178 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,178 @@
1+
var expect = require('chai').expect;
2+
const asgSuspendedProcesses = require('./asgSuspendedProcesses');
3+
4+
const autoScalingGroups = [
5+
{
6+
"AutoScalingGroupName": "auto-scaling-test-group",
7+
"AutoScalingGroupARN": "arn:aws:autoscaling:us-east-1:111122223333:autoScalingGroup:e83ceb12-2760-4a92-a374-3df611331bdc:autoScalingGroupName/auto-scaling-test-group",
8+
"LaunchTemplate": {
9+
"LaunchTemplateId": "lt-0f1f6b356026abc86",
10+
"LaunchTemplateName": "auto-scaling-template",
11+
"Version": "$Default"
12+
},
13+
"MinSize": 1,
14+
"MaxSize": 1,
15+
"DesiredCapacity": 1,
16+
"DefaultCooldown": 300,
17+
"AvailabilityZones": [
18+
"us-east-1a"
19+
],
20+
"LoadBalancerNames": [],
21+
"TargetGroupARNs": [],
22+
"HealthCheckType": "EC2",
23+
"HealthCheckGracePeriod": 300,
24+
"Instances": [
25+
{
26+
"InstanceId": "i-093267d7a579c4bee",
27+
"InstanceType": "t2.micro",
28+
"AvailabilityZone": "us-east-1a",
29+
"LifecycleState": "InService",
30+
"HealthStatus": "Healthy",
31+
"LaunchTemplate": {
32+
"LaunchTemplateId": "lt-0f1f6b356026abc86",
33+
"LaunchTemplateName": "auto-scaling-template",
34+
"Version": "1"
35+
},
36+
"ProtectedFromScaleIn": false
37+
}
38+
],
39+
"CreatedTime": "2020-08-18T23:12:00.954Z",
40+
"SuspendedProcesses": [],
41+
"VPCZoneIdentifier": "subnet-06aa0f60",
42+
"EnabledMetrics": [],
43+
"Tags": [],
44+
"TerminationPolicies": [
45+
"Default"
46+
],
47+
"NewInstancesProtectedFromScaleIn": false,
48+
"ServiceLinkedRoleARN": "arn:aws:iam::111122223333:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling"
49+
},
50+
{
51+
"AutoScalingGroupName": "auto-scaling-test-group",
52+
"AutoScalingGroupARN": "arn:aws:autoscaling:us-east-1:111122223333:autoScalingGroup:e83ceb12-2760-4a92-a374-3df611331bdc:autoScalingGroupName/auto-scaling-test-group",
53+
"LaunchTemplate": {
54+
"LaunchTemplateId": "lt-0f1f6b356026abc86",
55+
"LaunchTemplateName": "auto-scaling-template",
56+
"Version": "$Default"
57+
},
58+
"MinSize": 1,
59+
"MaxSize": 1,
60+
"DesiredCapacity": 1,
61+
"DefaultCooldown": 300,
62+
"AvailabilityZones": [
63+
"us-east-1a"
64+
],
65+
"LoadBalancerNames": [],
66+
"TargetGroupARNs": [],
67+
"HealthCheckType": "EC2",
68+
"HealthCheckGracePeriod": 300,
69+
"Instances": [],
70+
"CreatedTime": "2020-08-18T23:12:00.954Z",
71+
"SuspendedProcesses": [
72+
{
73+
"ProcessName": "Launch",
74+
"SuspensionReason": "User suspended at 2020-09-19T17:30:30Z"
75+
},
76+
{
77+
"ProcessName": "Terminate",
78+
"SuspensionReason": "User suspended at 2020-09-19T17:56:14Z"
79+
}
80+
],
81+
"VPCZoneIdentifier": "subnet-06aa0f60",
82+
"EnabledMetrics": [],
83+
"Tags": [],
84+
"TerminationPolicies": [
85+
"Default"
86+
],
87+
"NewInstancesProtectedFromScaleIn": false,
88+
"ServiceLinkedRoleARN": "arn:aws:iam::111122223333:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling"
89+
},
90+
];
91+
92+
93+
94+
const createCache = (asgs) => {
95+
return {
96+
autoscaling: {
97+
describeAutoScalingGroups: {
98+
'us-east-1': {
99+
err: null,
100+
data: asgs
101+
},
102+
},
103+
},
104+
};
105+
};
106+
107+
const createErrorCache = () => {
108+
return {
109+
autoscaling: {
110+
describeAutoScalingGroups: {
111+
'us-east-1': {
112+
err: {
113+
message: 'error describing auto scaling groups'
114+
},
115+
},
116+
},
117+
},
118+
};
119+
};
120+
121+
const createNullCache = () => {
122+
return {
123+
autoscaling: {
124+
describeAutoScalingGroups: {
125+
'us-east-1': null,
126+
},
127+
},
128+
};
129+
};
130+
131+
describe('asgSuspendedProcesses', function () {
132+
describe('run', function () {
133+
it('should PASS if AutoScaling group does not have any suspended process', function (done) {
134+
const cache = createCache([autoScalingGroups[0]]);
135+
asgSuspendedProcesses.run(cache, {}, (err, results) => {
136+
expect(results.length).to.equal(1);
137+
expect(results[0].status).to.equal(0);
138+
done();
139+
});
140+
});
141+
142+
it('should FAIL if AutoScaling group has suspended processes', function (done) {
143+
const cache = createCache([autoScalingGroups[1]]);
144+
asgSuspendedProcesses.run(cache, {}, (err, results) => {
145+
expect(results.length).to.equal(1);
146+
expect(results[0].status).to.equal(2);
147+
done();
148+
});
149+
});
150+
151+
it('should PASS if no AutoScaling groups found ', function (done) {
152+
const cache = createCache([]);
153+
asgSuspendedProcesses.run(cache, {}, (err, results) => {
154+
expect(results.length).to.equal(1);
155+
expect(results[0].status).to.equal(0);
156+
done();
157+
});
158+
});
159+
160+
it('should UNKNOWN if an error occurs while describing AutoScaling groups', function (done) {
161+
const cache = createErrorCache();
162+
asgSuspendedProcesses.run(cache, {}, (err, results) => {
163+
expect(results.length).to.equal(1);
164+
expect(results[0].status).to.equal(3);
165+
done();
166+
});
167+
});
168+
169+
it('should not return anything if unable to query for AutoScaling groups', function (done) {
170+
const cache = createNullCache();
171+
asgSuspendedProcesses.run(cache, {}, (err, results) => {
172+
expect(results.length).to.equal(0);
173+
done();
174+
});
175+
});
176+
177+
});
178+
});

0 commit comments

Comments
 (0)