Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Turn on CloudTrail log file validation for the management-events trail

Đang mở Phù hợp với người mới
#202 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
75/100
Loại issue
Tính năng
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
aws, terraform
Lĩnh vực
infrastructure, security

Hướng nghiên cứu

Công việc nằm trong terraform/cloudtrail.tf. Tìm tài nguyên aws_cloudtrail.management_events và đổi enable_log_file_validation thành true. Cập nhật bình luận hai dòng phía trên nó và danh sách bình luận trong phần đầu file. Chạy terraform plan để xác nhận chỉ tài nguyên đó thay đổi tại chỗ. Sau khi merge, xác minh bằng các lệnh được cung cấp aws cloudtrail describe-trailsaws s3 ls.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

complexity: small feature: security good first issue role: DevOps Engineer size: 0.5pt
Overview

We need to turn on CloudTrail log file validation for the management-events trail, so that both of the account's trails produce tamper-evident digest files. Today one trail has it on and the other has it off, which means the trail carrying the account's management events — the higher-value audit record of the two — is the one that cannot be proven unaltered.

Action Items
  • In terraform/cloudtrail.tf, change enable_log_file_validation from false to true on the aws_cloudtrail.management_events resource. It is on line 251 as of 2026-09-23 — line numbers drift, so find it by the resource name resource "aws_cloudtrail" "management_events" rather than by number.
  • Update the two-line comment immediately above that resource, which currently reads that the inconsistency is "reproduced rather than resolved -- turning it on is a live change and its own ticket." That ticket is this one, so the comment should now say the two trails agree and that validation is on for both. Leave the rest of the file's commentary alone.
  • Update the file-header comment near the top of terraform/cloudtrail.tf that lists four things deliberately not added by #191. Log file validation is one of the four; remove it from that list and leave the other three (KMS encryption, a CloudWatch Logs destination, a bucket lifecycle configuration) exactly as they are — each is still outstanding.
  • Confirm the plan shows exactly one resource changing, in place: aws_cloudtrail.management_events[0] with enable_log_file_validation: false -> true. There must be no replacement and nothing else in the diff. A replacement would destroy and recreate a trail carrying prevent_destroy, so it would fail at plan time — but check rather than rely on that.
  • Note this resource is gated on var.iam_only, so it is skipped entirely in a contributor's own AWS account and only applies in CI, where iam_only = false. A local plan with the default variable will show no change at all; that is expected and is not evidence the edit is wrong.
  • After the PR merges and the apply runs, confirm both trails report validation on: aws cloudtrail describe-trails --query 'trailList[].{Name:Name,Validation:LogFileValidationEnabled}' --output table. Both rows must read True.
  • After the PR merges, confirm digest files actually start being written, which is the real proof the setting took effect: aws s3 ls s3://aws-cloudtrail-logs-035866691871-6539ef03/AWSLogs/035866691871/CloudTrail-Digest/ --recursive | tail. Expect nothing for up to an hour — CloudTrail writes the first digest on its own schedule, not at apply time — so this step is deliberately separate from the one above and may need coming back to later in the day.
Resources/Instructions
  • terraform/cloudtrail.tf — the only file this ticket touches. The management_events trail is the second of the two declared in it; the first, tf_backend_logs, already has enable_log_file_validation = true and is the model.
  • devops-security#191 — imported both trails and both buckets as-is, and deliberately left this inconsistency in place. Its cloudtrail.tf comments name this as follow-on work.
  • Validating CloudTrail log file integrity — what the digest files are and how to verify one with aws cloudtrail validate-logs.
  • Digest files are delivered to the same bucket as the logs, under AWSLogs/<account>/CloudTrail-Digest/, and are billed as ordinary S3 objects. They are small and low-volume relative to the log files themselves, so this adds no meaningful storage cost.

Line numbers above were accurate on 2026-09-23 and may drift; locate the targets by resource name and by the quoted comment text instead.

Ngôn ngữ chính
HCL
Star
1
Fork
14
Merge trung bình
1 giờ 3 phút
Pull request đã merge (30 ngày)
23

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của hackforla/devops-security

Tất cả issue của hackforla/devops-security

Issue tương tự

Thêm issue về DevOps

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.