cds-snc / cds-snc/forms-terraform

Add Domain Name System Security Extensions (DNSSEC) signing to Route 53 public hosted zones (CKV2_AWS_38)

Open
#562 0 comments 0 reactions 0 assignees View on GitHub
Core development
Dominant language
HCL
Stars
17
Forks
8
Avg merge
1d 12h
Merged PRs (30d)
13

Description

Implement resources to resolve following checkov policy "Ensure Domain Name System Security Extensions (DNSSEC) signing is enabled for Amazon Route 53 public hosted zones"

Search for "CKV2_AWS_38" in the infra repository in order to see places that requires modifications.

Contributor guide

Open the contributing guide

Research direction

Search the infra repository for "CKV2_AWS_38" and inspect the locations identified by the existing Checkov policy references. Start by tracing the Route 53 public hosted zone resources and determine the required DNSSEC signing resources; done means the policy no longer reports violations for those zones.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, terraform
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.