Skip to content

Commit

Permalink
fix(terraform): add aws_region name to presets (aquasecurity#7184)
Browse files Browse the repository at this point in the history
  • Loading branch information
albertodonato authored and fhielpos committed Dec 20, 2024
1 parent 1a5af9d commit 4e90f95
Show file tree
Hide file tree
Showing 2 changed files with 43 additions and 1 deletion.
39 changes: 39 additions & 0 deletions pkg/iac/scanners/terraform/parser/parser_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -1745,3 +1745,42 @@ func TestTFVarsFileDoesNotExist(t *testing.T) {
_, _, err := parser.EvaluateAll(context.TODO())
assert.ErrorContains(t, err, "file does not exist")
}

func Test_AWSRegionNameDefined(t *testing.T) {

fs := testutil.CreateFS(t, map[string]string{
"code/test.tf": `
data "aws_region" "current" {}
data "aws_region" "other" {
name = "us-east-2"
}
resource "something" "blah" {
r1 = data.aws_region.current.name
r2 = data.aws_region.other.name
}
`,
})

parser := New(fs, "", OptionStopOnHCLError(true))
require.NoError(t, parser.ParseFS(context.TODO(), "code"))
modules, _, err := parser.EvaluateAll(context.TODO())
require.NoError(t, err)
require.Len(t, modules, 1)
rootModule := modules[0]

blocks := rootModule.GetResourcesByType("something")
require.Len(t, blocks, 1)
block := blocks[0]

r1 := block.GetAttribute("r1")
require.NotNil(t, r1)
assert.True(t, r1.IsResolvable())
assert.Equal(t, "current-region", r1.Value().AsString())

r2 := block.GetAttribute("r2")
require.NotNil(t, r2)
assert.True(t, r2.IsResolvable())
assert.Equal(t, "us-east-2", r2.Value().AsString())
}
5 changes: 4 additions & 1 deletion pkg/iac/terraform/presets.go
Original file line number Diff line number Diff line change
Expand Up @@ -19,13 +19,16 @@ func createPresetValues(b *Block) map[string]cty.Value {
presets["arn"] = cty.StringVal(b.ID())
}

// workaround for weird iam feature
switch b.TypeLabel() {
// workaround for weird iam feature
case "aws_iam_policy_document":
presets["json"] = cty.StringVal(b.ID())
// If the user leaves the name blank, Terraform will automatically generate a unique name
case "aws_launch_template":
presets["name"] = cty.StringVal(uuid.New().String())
// allow referencing the current region name
case "aws_region":
presets["name"] = cty.StringVal("current-region")
}

return presets
Expand Down

0 comments on commit 4e90f95

Please sign in to comment.