forked from inspec/inspec-alicloud
-
Notifications
You must be signed in to change notification settings - Fork 0
/
alicloud_security_groups.rb
61 lines (50 loc) · 1.58 KB
/
alicloud_security_groups.rb
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
# frozen_string_literal: true
require "alicloud_backend"
class AliCloudSecurityGroups < AliCloudResourceBase
name "alicloud_security_groups"
desc "Verifies settings for AliCloud Security Groups in bulk"
example "
# Verify that you have security groups defined
describe alicloud_security_groups do
it { should exist }
end
# Verify you have more than the default security group
describe alicloud_security_groups do
its('entries.count') { should be > 1 }
end
"
attr_reader :table
# FilterTable setup
FilterTable.create
.register_column(:group_ids, field: :group_id)
.register_column(:group_descriptions, field: :group_description)
.register_column(:vpc_ids, field: :vpc_id)
.register_column(:tags, field: :tags)
.install_filter_methods_on_resource(self, :table)
def initialize(opts = {})
super(opts)
validate_parameters
@table = fetch_data
end
def fetch_data
security_group_rows = []
catch_alicloud_errors do
@security_groups = @alicloud.ecs_client.request(
action: "DescribeSecurityGroups",
params: {
"RegionId": opts[:region],
}
)["SecurityGroups"]["SecurityGroup"]
end
return [] if !@security_groups || @security_groups.empty?
@security_groups.map do |security_group|
security_group_rows += [{
group_id: security_group["SecurityGroupId"],
group_description: security_group["Description"],
vpc_id: security_group["VpcId"],
tags: security_group["Tags"]["Tag"],
}]
end
@table = security_group_rows
end
end