Skip to content
This repository has been archived by the owner on Dec 20, 2024. It is now read-only.

Commit

Permalink
fix: checkov security error
Browse files Browse the repository at this point in the history
  • Loading branch information
DamienJabs committed Nov 19, 2024
1 parent 75c672a commit 172b2c3
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 25 deletions.
14 changes: 2 additions & 12 deletions modules/mysql/sql.tf
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,8 @@ resource "random_id" "this" {
byte_length = 4
}

resource "google_storage_bucket" "logging_bucket" {
name = "bucket-access-logs"
location = "europe-west3"
project = var.project_id
force_destroy = true
}

#checkov:skip=CKV_GCP_62:Bucket should log access
# Skipped because this bucket doesn't need log access
resource "google_storage_bucket" "script" {
count = var.init_custom_sql_script != "" ? 1 : 0
name = "sql-script-${random_id.this[0].hex}"
Expand All @@ -21,11 +16,6 @@ resource "google_storage_bucket" "script" {
versioning {
enabled = true
}

logging {
log_bucket = google_storage_bucket.logging_bucket.name
log_object_prefix = "access_logs/"
}
}

resource "google_storage_bucket_object" "sql_script" {
Expand Down
15 changes: 2 additions & 13 deletions modules/postgresql/sql.tf
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,8 @@ resource "random_id" "this" {
count = var.init_custom_sql_script != "" ? 1 : 0
byte_length = 4
}

resource "google_storage_bucket" "logging_bucket" {
name = "bucket-access-logs"
location = "europe-west3"
project = var.project_id
force_destroy = true
}

#checkov:skip=CKV_GCP_62:Bucket should log access
# Skipped because this bucket doesn't need log access
resource "google_storage_bucket" "script" {
count = var.init_custom_sql_script != "" ? 1 : 0
name = "sql-script-${random_id.this[0].hex}"
Expand All @@ -21,11 +15,6 @@ resource "google_storage_bucket" "script" {
versioning {
enabled = true
}

logging {
log_bucket = google_storage_bucket.logging_bucket.name
log_object_prefix = "access_logs/"
}
}

resource "google_storage_bucket_object" "sql_script" {
Expand Down

0 comments on commit 172b2c3

Please sign in to comment.