eks-secrets-encrypted - AWS Config

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

eks-secrets-encrypted

Checks if Amazon Elastic Kubernetes Service clusters are configured to have Kubernetes secrets encrypted using AWS Key Management Service (KMS) keys.

  • This rule is COMPLIANT if an EKS cluster has an encryptionConfig with secrets as one of the resources.

  • This rule is also COMPLIANT if the key used to encrypt EKS secrets matches with the parameter.

  • This rule is NON_COMPLIANT if an EKS cluster does not have an encryptionConfig or if the encryptionConfig resources do not include secrets.

  • This rule is also NON_COMPLIANT if the key used to encrypt EKS secrets does not match with the parameter.

Identifier: EKS_SECRETS_ENCRYPTED

Trigger type: 定期的

AWS Region: All supported AWS regions except Asia Pacific (Osaka), Europe (Milan), US West (N. California), Africa (Cape Town) Region

パラメータ:

kmsKeyArns (オプション)
タイプ: CSV

Comma separated list of Amazon Resource Name (ARN) of the KMS key that should be used for encrypted secrets in an EKS cluster.

AWS CloudFormation テンプレート

To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.