-
Notifications
You must be signed in to change notification settings - Fork 16
/
test.rego
83 lines (74 loc) · 2.37 KB
/
test.rego
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
package compliance.cis_azure.rules.cis_7_1
import data.compliance.policy.azure.data_adapter
import data.lib.test
valid_bastion = {
"extendedLocation": null,
"id": "/subscriptions/sub-id/resourceGroups/cloudbeat/providers/Microsoft.Network/bastionHosts/cloudbeat",
"identity": null,
"kind": "",
"location": "eastus",
"managedBy": "",
"name": "cloudbeat",
"plan": null,
"properties": {
"disableCopyPaste": false,
"dnsName": "dns.bastion.azure.com",
"enableIpConnect": false,
"enableKerberos": false,
"enableShareableLink": false,
"enableTunneling": false,
"ipConfigurations": [{
"etag": "W/\"57925490-08e8-4f8e-9a75-e66f4c54f7e2\"",
"id": "/subscriptions/sub-id/resourceGroups/cloudbeat/providers/Microsoft.Network/bastionHosts/cloudbeat/bastionHostIpConfigurations/IpConf",
"name": "IpConf",
"properties": {
"privateIPAllocationMethod": "Dynamic",
"provisioningState": "Succeeded",
"publicIPAddress": {
"id": "/subscriptions/sub-id/resourceGroups/cloudbeat/providers/Microsoft.Network/publicIPAddresses/cloudbeatBastion-ip",
"resourceGroup": "cloudbeat",
},
"subnet": {
"id": "/subscriptions/sub-id/resourceGroups/cloudbeat/providers/Microsoft.Network/virtualNetworks/cloudbeatBastion/subnets/AzureBastionSubnet",
"resourceGroup": "cloudbeat",
},
},
"resourceGroup": "cloudbeat",
"type": "Microsoft.Network/bastionHosts/bastionHostIpConfigurations",
}],
"provisioningState": "Succeeded",
"scaleUnits": 2,
},
"resourceGroup": "cloudbeat",
"sku": {"name": "Standard"},
"subscriptionId": "sub-id",
"tags": {},
"tenantId": "tenant-id",
"type": "microsoft.network/bastionhosts",
"zones": null,
}
generate_bastions(assets) = {
"subType": "azure-bastion",
"resource": assets,
}
test_violation {
eval_fail with input as generate_bastions([])
eval_fail with input as generate_bastions([{}])
}
test_pass {
eval_pass with input as generate_bastions([valid_bastion])
eval_pass with input as generate_bastions([valid_bastion, valid_bastion])
}
test_not_evaluated {
not_eval with input as {}
not_eval with input as {"subType": "other-type", "resource": {"assets": {}}}
}
eval_fail {
test.assert_fail(finding) with data.benchmark_data_adapter as data_adapter
}
eval_pass {
test.assert_pass(finding) with data.benchmark_data_adapter as data_adapter
}
not_eval {
not finding with data.benchmark_data_adapter as data_adapter
}