|
| 1 | +var async = require('async'); |
| 2 | +var helpers = require('../../../helpers/oracle/'); |
| 3 | + |
| 4 | +module.exports = { |
| 5 | + title: 'Boot Volume CMK Encryption', |
| 6 | + category: 'Block Storage', |
| 7 | + domain: 'Storage', |
| 8 | + description: 'Ensures that boot volumes have encryption enabled using desired protection level.', |
| 9 | + more_info: 'By default, boot volumes are encrypted using an Oracle-managed master encryption key. To have better control over the encryption process, you can use Customer-Managed Keys (CMKs).', |
| 10 | + recommended_action: 'Ensure all boot volumes have desired encryption level.', |
| 11 | + link: 'https://docs.oracle.com/en-us/iaas/Content/Security/Reference/blockstorage_security.htm#data-encryption', |
| 12 | + apis: ['vault:list', 'keys:list', 'bootVolume:list'], |
| 13 | + settings: { |
| 14 | + volume_encryption_level: { |
| 15 | + name: 'Boot Volume Encryption Level', |
| 16 | + description: 'Desired protection level for boot volumes. default: oracle-managed, cloudcmek: customer managed encryption keys, ' + |
| 17 | + 'cloudhsm: customer managed HSM encryption key', |
| 18 | + regex: '^(default|cloudcmek|cloudhsm)$', |
| 19 | + default: 'cloudcmek' |
| 20 | + } |
| 21 | + }, |
| 22 | + |
| 23 | + run: function(cache, settings, callback) { |
| 24 | + var results = []; |
| 25 | + var source = {}; |
| 26 | + var regions = helpers.regions(settings.govcloud); |
| 27 | + var keysObj = {}; |
| 28 | + |
| 29 | + let desiredEncryptionLevelStr = settings.volume_encryption_level || this.settings.volume_encryption_level.default; |
| 30 | + var desiredEncryptionLevel = helpers.PROTECTION_LEVELS.indexOf(desiredEncryptionLevelStr); |
| 31 | + |
| 32 | + async.series([ |
| 33 | + function(cb) { |
| 34 | + async.each(regions.keys, function(region, rcb) { |
| 35 | + let keys = helpers.addSource( |
| 36 | + cache, source, ['keys', 'list', region]); |
| 37 | + if (keys && keys.data && keys.data.length) helpers.listToObj(keysObj, keys.data, 'id'); |
| 38 | + rcb(); |
| 39 | + }, function() { |
| 40 | + cb(); |
| 41 | + }); |
| 42 | + }, |
| 43 | + function(cb) { |
| 44 | + async.each(regions.bootVolume, function(region, rcb) { |
| 45 | + |
| 46 | + if (helpers.checkRegionSubscription(cache, source, results, region)) { |
| 47 | + |
| 48 | + var bootVolumes = helpers.addSource(cache, source, |
| 49 | + ['bootVolume', 'list', region]); |
| 50 | + |
| 51 | + if (!bootVolumes) return rcb(); |
| 52 | + |
| 53 | + if (bootVolumes.err || !bootVolumes.data) { |
| 54 | + helpers.addResult(results, 3, |
| 55 | + 'Unable to query for boot volumes: ' + helpers.addError(bootVolumes), region); |
| 56 | + return rcb(); |
| 57 | + } |
| 58 | + |
| 59 | + if (!bootVolumes.data.length) { |
| 60 | + helpers.addResult(results, 0, 'No boot volumes found', region); |
| 61 | + return rcb(); |
| 62 | + } |
| 63 | + |
| 64 | + bootVolumes.data.forEach(bootVolume => { |
| 65 | + if (bootVolume.lifecycleState && bootVolume.lifecycleState === 'TERMINATED') return; |
| 66 | + |
| 67 | + let currentEncryptionLevel = 1; //default |
| 68 | + |
| 69 | + if (bootVolume.kmsKeyId) { |
| 70 | + currentEncryptionLevel = helpers.getProtectionLevel(keysObj[bootVolume.kmsKeyId], helpers.PROTECTION_LEVELS); |
| 71 | + } |
| 72 | + |
| 73 | + let currentEncryptionLevelStr = helpers.PROTECTION_LEVELS[currentEncryptionLevel]; |
| 74 | + |
| 75 | + if (currentEncryptionLevel >= desiredEncryptionLevel) { |
| 76 | + helpers.addResult(results, 0, |
| 77 | + `Boot volume (${bootVolume.displayName}) has encryption level ${currentEncryptionLevelStr} which is greater than or equal to ${desiredEncryptionLevelStr}`, region, bootVolume.id); |
| 78 | + } else { |
| 79 | + helpers.addResult(results, 2, |
| 80 | + `Boot volume (${bootVolume.displayName}) has encryption level ${currentEncryptionLevelStr} which is less than ${desiredEncryptionLevelStr}`, region, bootVolume.id); |
| 81 | + } |
| 82 | + }); |
| 83 | + } |
| 84 | + |
| 85 | + rcb(); |
| 86 | + }, function() { |
| 87 | + cb(); |
| 88 | + }); |
| 89 | + } |
| 90 | + ], function() { |
| 91 | + // Global checking goes here |
| 92 | + callback(null, results, source); |
| 93 | + }); |
| 94 | + } |
| 95 | +}; |
0 commit comments