Announcing policies validations during synthesis time with AWS Cloud Development Kit (CDK)

Announcing policies validations during synthesis time with AWS Cloud Development Kit (CDK)

AWS Cloud Development Kit (CDK) now enables developers to validate Infrastructure as Code (IaC) templates against policy-as-code tools during the development lifecycle. Developers can now receive fast and actionable feedback about security or configuration issues, as defined by organizational policies, during CDK application development cycles. By verifying compliance with organizational policies at the early stages of development, the teams can enhance the success rate of the deployment phase for their CDK applications.

On release, AWS CDK will include support for AWS CloudFormation Guard with CfnGuardValidator - A policy validation plugin which enables the use of AWS CloudFormation Guard for policy validations. A pre-defined set of AWS Control Tower proactive controls are included with the plugin.?

With plugin enabled, once your CDK application has finished synthesizing the template, the plugin is triggered automatically to validate generated CloudFormation templates against your policies. The plugin will execute policies validations, interpret the results, and provide a final report. The report presents a summary of the validation outcome (allow/deny), along with details about any detected misconfigurations. If non-compliance is found with respect to a specific policy, a root-cause analysis is provided, along with suggestions for mitigation. Customers can utilize this feature with other tools, including but not limited to KICS, Open Policy Agent (OPA), and Checkov. Developers can create validation plugins for these tools based on their organization's specific requirements and preferences.

Documentation:?

#aws #iac #policy-as-code #cloudformation #cdk

Himanshu Pant

Lead Solutions Architect @Elevation Services

1 年

Thanks for sharing!

回复

要查看或添加评论,请登录

Koustubha Kale的更多文章

  • Improve code security with native AWS tooling

    Improve code security with native AWS tooling

    A few recent improvements to AWS security tooling can help you improve your software code and gain visibility into key…

  • AWS announces AWS Payment Cryptography

    AWS announces AWS Payment Cryptography

    AWS Payment Cryptography. This service simplifies your implementation of cryptography operations used to secure data in…

  • Amazon Security Lake

    Amazon Security Lake

    Today, AWS announces the general availability of Amazon Security Lake. This service automatically centralizes security…

  • New features for AWS S3

    New features for AWS S3

    Amazon S3 on Outposts now supports local S3 Replication on Outposts Amazon S3 on Outposts now supports S3 Replication…

  • AWS Security Hub launches support for NIST SP 800-53 Rev. 5

    AWS Security Hub launches support for NIST SP 800-53 Rev. 5

    AWS Security Hub now supports automated security checks aligned to the National Institute of Standards and Technology…

  • Back to monoliths

    Back to monoliths

    Computing seems to be coming a full circle. Started with big monoliths then over time went the complete other way of…

    1 条评论
  • PRINCE2 certification experience & tips

    PRINCE2 certification experience & tips

    I recently completed PRINCE2 Foundation and Practitioner certifications. I did the training with APMG accredited…

社区洞察

其他会员也浏览了