Skip to content

Commit 313ea9d

Browse files
IevIeievgeniia ieromenko
and
ievgeniia ieromenko
authored
manifest update (#266)
Co-authored-by: ievgeniia ieromenko <ieviero@amazon.com>
1 parent da92841 commit 313ea9d

File tree

1 file changed

+21
-106
lines changed
  • aws_sra_examples/easy_setup/customizations_for_aws_control_tower

1 file changed

+21
-106
lines changed

aws_sra_examples/easy_setup/customizations_for_aws_control_tower/manifest.yaml

Lines changed: 21 additions & 106 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,7 @@ resources:
4343
parameter_value: "No"
4444
- parameter_key: pDeployPatchMgrSolution
4545
parameter_value: "No"
46+
4647
# Account Alternate Contacts Solution Parameters
4748
- parameter_key: pExcludeAlternateContactAccountTags
4849
parameter_value: ""
@@ -118,7 +119,7 @@ resources:
118119
parameter_value: ""
119120
- parameter_key: pConformancePackExcludedAccounts
120121
parameter_value: ""
121-
122+
122123
# Detective Solution
123124
- parameter_key: pDatasourcePackages
124125
parameter_value: "ASFF_SECURITYHUB_FINDING, EKS_AUDIT"
@@ -144,6 +145,10 @@ resources:
144145
# GuardDuty Solution
145146
- parameter_key: pDisableGuardDuty
146147
parameter_value: "No"
148+
- parameter_key: pGuardDutyCustomerGovernedRegionsOnly
149+
parameter_value: "true"
150+
- parameter_key: pGuardDutyEnabledRegions
151+
parameter_value: ""
147152
- parameter_key: pAutoEnableS3Logs
148153
parameter_value: "true"
149154
- parameter_key: pAutoEnableKubernetesAuditLogs
@@ -152,10 +157,14 @@ resources:
152157
parameter_value: "true"
153158
- parameter_key: pEnableRdsLoginEvents
154159
parameter_value: "true"
155-
- parameter_key: pEnableEksRuntimeMonitoring
160+
- parameter_key: pEnableRuntimeMonitoring
156161
parameter_value: "true"
157162
- parameter_key: pEnableEksAddonManagement
158163
parameter_value: "true"
164+
- parameter_key: pEnableEcsFargateAgentManagement
165+
parameter_value: "true"
166+
- parameter_key: pEnableEc2AgentManagement
167+
parameter_value: "true"
159168
- parameter_key: pEnableLambdaNetworkLogs
160169
parameter_value: "true"
161170
- parameter_key: pGuardDutyFindingPublishingFrequency
@@ -238,141 +247,47 @@ resources:
238247
parameter_value: "SPECIFIED_REGIONS"
239248

240249
# Patch Manager Solution
241-
- parameter_key: pPatchMgmtRoleName
242-
parameter_value: "sra-patch-mgmt-configuration"
243-
# Window 1
244-
- parameter_key: pPatchMgmtMaintWindow1Name
245-
parameter_value: "Update_SSM"
246-
- parameter_key: pPatchMgmtMaintWindow1Desc
247-
parameter_value: "Maintenance Window update the SSM Agent on managed Instances"
250+
- parameter_key: pDisablePatchMgmt
251+
parameter_value: "false"
248252
- parameter_key: pPatchMgmtMaintWindow1Schedule
249-
parameter_value: "cron(0 0 1 ? * WED *)"
253+
parameter_value: "cron(0 0 1 ? * THU *)"
250254
- parameter_key: pPatchMgmtMaintWindow1Duration
251255
parameter_value: "6"
252256
- parameter_key: pPatchMgmtMaintWindow1Cutoff
253257
parameter_value: "1"
254-
- parameter_key: pPatchMgmtMaintWindow1TZ
255-
parameter_value: "America/New_York"
256-
- parameter_key: pPatchMgmtTask1Name
257-
parameter_value: "Update_SSM"
258-
- parameter_key: pPatchMgmtTask1Desc
259-
parameter_value: "Task to update SSM Agent"
260258
- parameter_key: pPatchMgmtTask1RunCmd
261259
parameter_value: "AWS-UpdateSSMAgent"
262-
- parameter_key: pPatchMgmtTask1Operation
263-
parameter_value: "Scan"
264-
- parameter_key: pPatchMgmtTask1RebootOption
265-
parameter_value: "RebootIfNeeded"
266-
- parameter_key: pPatchMgmtTarget1Name
267-
parameter_value: "Update_SSM"
268-
- parameter_key: pPatchMgmtTarget1Desc
269-
parameter_value: "Targets to update SSM Agent on"
270260
- parameter_key: pPatchMgmtTarget1Value1
271261
parameter_value: "Linux"
272262
- parameter_key: pPatchMgmtTarget1Value2
273263
parameter_value: "Windows"
274-
# Window 2
275-
- parameter_key: pPatchMgmtMaintWindow2Name
276-
parameter_value: "Windows_Scan"
277-
- parameter_key: pPatchMgmtMaintWindow2Desc
278-
parameter_value: "Maintenance Window to scan Windows Instances"
279264
- parameter_key: pPatchMgmtMaintWindow2Schedule
280-
parameter_value: "cron(0 0 1 ? * THU *)"
265+
parameter_value: "cron(0 0 1 ? * WED *)"
281266
- parameter_key: pPatchMgmtMaintWindow2Duration
282267
parameter_value: "6"
283268
- parameter_key: pPatchMgmtMaintWindow2Cutoff
284269
parameter_value: "1"
285-
- parameter_key: pPatchMgmtMaintWindow2TZ
270+
- parameter_key: pPatchMgmtMaintWindowTZ
286271
parameter_value: "America/New_York"
287-
- parameter_key: pPatchMgmtTask2Name
288-
parameter_value: "Windows_Scan"
289-
- parameter_key: pPatchMgmtTask2Desc
290-
parameter_value: "Task to scan Windows Instances"
272+
- parameter_key: pPatchMgmtTaskRebootOption
273+
parameter_value: "RebootIfNeeded"
291274
- parameter_key: pPatchMgmtTask2RunCmd
292275
parameter_value: "AWS-RunPatchBaseline"
293-
- parameter_key: pPatchMgmtTask2Operation
294-
parameter_value: "Scan"
295-
- parameter_key: pPatchMgmtTask2RebootOption
296-
parameter_value: "RebootIfNeeded"
297-
- parameter_key: pPatchMgmtTarget2Name
298-
parameter_value: "Windows_Scan"
299-
- parameter_key: pPatchMgmtTarget2Desc
300-
parameter_value: "Targets to run the command to scan for Windows updates"
301276
- parameter_key: pPatchMgmtTarget2Value1
302277
parameter_value: "Windows"
303-
# Window 3
304-
- parameter_key: pPatchMgmtMaintWindow3Name
305-
parameter_value: "Linux_Scan"
306-
- parameter_key: pPatchMgmtMaintWindow3Desc
307-
parameter_value: "Maintenance Window scan Linux Instances"
278+
- parameter_key: pPatchMgmtTaskOperation
279+
parameter_value: "Scan"
308280
- parameter_key: pPatchMgmtMaintWindow3Schedule
309281
parameter_value: "cron(0 0 1 ? * FRI *)"
310282
- parameter_key: pPatchMgmtMaintWindow3Duration
311283
parameter_value: "6"
312-
- parameter_key: pPatchMgmtMaintWindow3utoff
284+
- parameter_key: pPatchMgmtMaintWindow3Cutoff
313285
parameter_value: "1"
314-
- parameter_key: pPatchMgmtMaintWindow3TZ
315-
parameter_value: "America/New_York"
316-
- parameter_key: pPatchMgmtTask3Name
317-
parameter_value: "Linux_Scan"
318-
- parameter_key: pPatchMgmtTask3Desc
319-
parameter_value: "Task to scan Linux Instances"
320286
- parameter_key: pPatchMgmtTask3RunCmd
321287
parameter_value: "AWS-RunPatchBaseline"
322-
- parameter_key: pPatchMgmtTask3Operation
323-
parameter_value: "Scan"
324-
- parameter_key: pPatchMgmtTask3RebootOption
325-
parameter_value: "RebootIfNeeded"
326-
- parameter_key: pPatchMgmtTarget3Name
327-
parameter_value: "Linux_Scan"
328-
- parameter_key: pPatchMgmtTarget3Desc
329-
parameter_value: "Targets to run the command to scan for Linux updates"
330288
- parameter_key: pPatchMgmtTarget3Value1
331289
parameter_value: "Linux"
332290

333-
# Patch Manager Solution
334-
- parameter_key: pDisablePatchMgmt
335-
parameter_value: 'false'
336-
# Window 1
337-
- parameter_key: pPatchMgmtMaintWindow1Schedule
338-
parameter_value: 'cron(0 0 1 ? * THU *)'
339-
- parameter_key: pPatchMgmtMaintWindow1Duration
340-
parameter_value: '6'
341-
- parameter_key: pPatchMgmtMaintWindow1Cutoff
342-
parameter_value: '1'
343-
- parameter_key: pPatchMgmtTask1RunCmd
344-
parameter_value: 'AWS-UpdateSSMAgent'
345-
- parameter_key: pPatchMgmtTarget1Value1
346-
parameter_value: 'Linux'
347-
- parameter_key: pPatchMgmtTarget1Value2
348-
parameter_value: 'Windows'
349-
- parameter_key: pPatchMgmtMaintWindow2Schedule
350-
parameter_value: 'cron(0 0 1 ? * WED *)'
351-
- parameter_key: pPatchMgmtMaintWindow2Duration
352-
parameter_value: '6'
353-
- parameter_key: pPatchMgmtMaintWindow2Cutoff
354-
parameter_value: '1'
355-
- parameter_key: pPatchMgmtMaintWindowTZ
356-
parameter_value: 'America/New_York'
357-
- parameter_key: pPatchMgmtTaskRebootOption
358-
parameter_value: 'RebootIfNeeded'
359-
- parameter_key: pPatchMgmtTask2RunCmd
360-
parameter_value: 'AWS-RunPatchBaseline'
361-
- parameter_key: pPatchMgmtTarget2Value1
362-
parameter_value: 'Windows'
363-
- parameter_key: pPatchMgmtTaskOperation
364-
parameter_value: 'Scan'
365-
- parameter_key: pPatchMgmtMaintWindow3Schedule
366-
parameter_value: 'cron(0 0 1 ? * FRI *)'
367-
- parameter_key: pPatchMgmtMaintWindow3Duration
368-
parameter_value: '6'
369-
- parameter_key: pPatchMgmtMaintWindow3Cutoff
370-
parameter_value: '1'
371-
- parameter_key: pPatchMgmtTask3RunCmd
372-
parameter_value: 'AWS-RunPatchBaseline'
373-
- parameter_key: pPatchMgmtTarget3Value1
374-
parameter_value: 'Linux'
375-
376291
# Common Properties
377292
- parameter_key: pSRAAlarmEmail
378293
parameter_value: ""

0 commit comments

Comments
 (0)