terraform-compliance steps not distinguishing resources in plan

Viewed 81

I would like to use terraform-compliance to prevent users from creating a aws_s3_bucket_policy to attach policies to aws_s3_bucket resources and instead, I would like for them to use the aws_iam_policy_document data object.

The bucket is created using a module and the module appends the JSON from aws_iam_policy_document to the bucket's policy. I have tried all manner of step statement combinations in my feature file, but terraform compliance seems unable to distinguish between aws_iam_policy_document explicitly declared and the aws_iam_policy_document which is an attribute of the created bucket.

Here's what I want:

data "aws_iam_policy_document" "some_custom_policy" {
  foo = bar
}

module "my_s3_bucket" {
  ...
  policies = [
  {
    policy_name = "Policy name"
    policy_json = data.aws_iam_policy_document.some_custom_policy.json

  }]
}

What I want to fail:

resource "aws_s3_bucket_policy" "some_custom_policy" {
  bucket = module.my_s3_bucket.output_bucket_name
}

module "my_s3_bucket" {
  ...
}

This feature passes for both cases:

Feature: Force proper S3 bucket policy use
    Scenario: aws_s3_bucket_policy is used instead of aws_iam_policy_document for S3 buckets
        Given I have aws_s3_bucket_policy resource defined
        Then it fails

Removing the word resource from the Given step fails for both cases thus:

Forcefully failing the scenario on aws_s3_bucket_policy (module.my_s3_bucket.aws_s3_bucket_policy.s3_policy) resource

How do I get terraform-compliance to properly filter out aws_s3_bucket_policy and only allow aws_iam_policy_document?

P.S.: I know that this is not really a terraform question, but I do not have enough rep to create a new terraform-compliance tag.

1 Answers

Just tried to reproduced your scenario, but couldn't. Is it possible to post a plan.out.json (if its not confidential) as an issue on github.com/terraform-compliance/cli please ?

Here was my test tf ;

resource "aws_s3_bucket" "test" {
    bucket = "test-bucket"
}

resource "aws_s3_bucket_policy" "fail" {
    bucket = aws_s3_bucket.test.id
    policy = ""
}

and here is my feature ;

Feature: test
    Scenario: aws_s3_bucket_policy is used instead of aws_iam_policy_document for S3 buckets
        Given I have aws_s3_bucket_policy defined
        Then it fails

this is the output I got ;

Feature: test  

    Scenario: aws_s3_bucket_policy is used instead of aws_iam_policy_document for S3 buckets
        Given I have aws_s3_bucket_policy defined
        Failure: Forcefully failing the scenario on aws_s3_bucket_policy (aws_s3_bucket_policy.fail) resource
        Then it fails
       

1 features (0 passed, 1 failed)
1 scenarios (0 passed, 1 failed)
2 steps (1 passed, 1 failed)
Related