@@ -43,6 +43,7 @@ resources:
43
43
parameter_value : " No"
44
44
- parameter_key : pDeployPatchMgrSolution
45
45
parameter_value : " No"
46
+
46
47
# Account Alternate Contacts Solution Parameters
47
48
- parameter_key : pExcludeAlternateContactAccountTags
48
49
parameter_value : " "
@@ -118,7 +119,7 @@ resources:
118
119
parameter_value : " "
119
120
- parameter_key : pConformancePackExcludedAccounts
120
121
parameter_value : " "
121
-
122
+
122
123
# Detective Solution
123
124
- parameter_key : pDatasourcePackages
124
125
parameter_value : " ASFF_SECURITYHUB_FINDING, EKS_AUDIT"
@@ -144,6 +145,10 @@ resources:
144
145
# GuardDuty Solution
145
146
- parameter_key : pDisableGuardDuty
146
147
parameter_value : " No"
148
+ - parameter_key : pGuardDutyCustomerGovernedRegionsOnly
149
+ parameter_value : " true"
150
+ - parameter_key : pGuardDutyEnabledRegions
151
+ parameter_value : " "
147
152
- parameter_key : pAutoEnableS3Logs
148
153
parameter_value : " true"
149
154
- parameter_key : pAutoEnableKubernetesAuditLogs
@@ -152,10 +157,14 @@ resources:
152
157
parameter_value : " true"
153
158
- parameter_key : pEnableRdsLoginEvents
154
159
parameter_value : " true"
155
- - parameter_key : pEnableEksRuntimeMonitoring
160
+ - parameter_key : pEnableRuntimeMonitoring
156
161
parameter_value : " true"
157
162
- parameter_key : pEnableEksAddonManagement
158
163
parameter_value : " true"
164
+ - parameter_key : pEnableEcsFargateAgentManagement
165
+ parameter_value : " true"
166
+ - parameter_key : pEnableEc2AgentManagement
167
+ parameter_value : " true"
159
168
- parameter_key : pEnableLambdaNetworkLogs
160
169
parameter_value : " true"
161
170
- parameter_key : pGuardDutyFindingPublishingFrequency
@@ -238,141 +247,47 @@ resources:
238
247
parameter_value : " SPECIFIED_REGIONS"
239
248
240
249
# Patch Manager Solution
241
- - parameter_key : pPatchMgmtRoleName
242
- parameter_value : " sra-patch-mgmt-configuration"
243
- # Window 1
244
- - parameter_key : pPatchMgmtMaintWindow1Name
245
- parameter_value : " Update_SSM"
246
- - parameter_key : pPatchMgmtMaintWindow1Desc
247
- parameter_value : " Maintenance Window update the SSM Agent on managed Instances"
250
+ - parameter_key : pDisablePatchMgmt
251
+ parameter_value : " false"
248
252
- parameter_key : pPatchMgmtMaintWindow1Schedule
249
- parameter_value : " cron(0 0 1 ? * WED *)"
253
+ parameter_value : " cron(0 0 1 ? * THU *)"
250
254
- parameter_key : pPatchMgmtMaintWindow1Duration
251
255
parameter_value : " 6"
252
256
- parameter_key : pPatchMgmtMaintWindow1Cutoff
253
257
parameter_value : " 1"
254
- - parameter_key : pPatchMgmtMaintWindow1TZ
255
- parameter_value : " America/New_York"
256
- - parameter_key : pPatchMgmtTask1Name
257
- parameter_value : " Update_SSM"
258
- - parameter_key : pPatchMgmtTask1Desc
259
- parameter_value : " Task to update SSM Agent"
260
258
- parameter_key : pPatchMgmtTask1RunCmd
261
259
parameter_value : " AWS-UpdateSSMAgent"
262
- - parameter_key : pPatchMgmtTask1Operation
263
- parameter_value : " Scan"
264
- - parameter_key : pPatchMgmtTask1RebootOption
265
- parameter_value : " RebootIfNeeded"
266
- - parameter_key : pPatchMgmtTarget1Name
267
- parameter_value : " Update_SSM"
268
- - parameter_key : pPatchMgmtTarget1Desc
269
- parameter_value : " Targets to update SSM Agent on"
270
260
- parameter_key : pPatchMgmtTarget1Value1
271
261
parameter_value : " Linux"
272
262
- parameter_key : pPatchMgmtTarget1Value2
273
263
parameter_value : " Windows"
274
- # Window 2
275
- - parameter_key : pPatchMgmtMaintWindow2Name
276
- parameter_value : " Windows_Scan"
277
- - parameter_key : pPatchMgmtMaintWindow2Desc
278
- parameter_value : " Maintenance Window to scan Windows Instances"
279
264
- parameter_key : pPatchMgmtMaintWindow2Schedule
280
- parameter_value : " cron(0 0 1 ? * THU *)"
265
+ parameter_value : " cron(0 0 1 ? * WED *)"
281
266
- parameter_key : pPatchMgmtMaintWindow2Duration
282
267
parameter_value : " 6"
283
268
- parameter_key : pPatchMgmtMaintWindow2Cutoff
284
269
parameter_value : " 1"
285
- - parameter_key : pPatchMgmtMaintWindow2TZ
270
+ - parameter_key : pPatchMgmtMaintWindowTZ
286
271
parameter_value : " America/New_York"
287
- - parameter_key : pPatchMgmtTask2Name
288
- parameter_value : " Windows_Scan"
289
- - parameter_key : pPatchMgmtTask2Desc
290
- parameter_value : " Task to scan Windows Instances"
272
+ - parameter_key : pPatchMgmtTaskRebootOption
273
+ parameter_value : " RebootIfNeeded"
291
274
- parameter_key : pPatchMgmtTask2RunCmd
292
275
parameter_value : " AWS-RunPatchBaseline"
293
- - parameter_key : pPatchMgmtTask2Operation
294
- parameter_value : " Scan"
295
- - parameter_key : pPatchMgmtTask2RebootOption
296
- parameter_value : " RebootIfNeeded"
297
- - parameter_key : pPatchMgmtTarget2Name
298
- parameter_value : " Windows_Scan"
299
- - parameter_key : pPatchMgmtTarget2Desc
300
- parameter_value : " Targets to run the command to scan for Windows updates"
301
276
- parameter_key : pPatchMgmtTarget2Value1
302
277
parameter_value : " Windows"
303
- # Window 3
304
- - parameter_key : pPatchMgmtMaintWindow3Name
305
- parameter_value : " Linux_Scan"
306
- - parameter_key : pPatchMgmtMaintWindow3Desc
307
- parameter_value : " Maintenance Window scan Linux Instances"
278
+ - parameter_key : pPatchMgmtTaskOperation
279
+ parameter_value : " Scan"
308
280
- parameter_key : pPatchMgmtMaintWindow3Schedule
309
281
parameter_value : " cron(0 0 1 ? * FRI *)"
310
282
- parameter_key : pPatchMgmtMaintWindow3Duration
311
283
parameter_value : " 6"
312
- - parameter_key : pPatchMgmtMaintWindow3utoff
284
+ - parameter_key : pPatchMgmtMaintWindow3Cutoff
313
285
parameter_value : " 1"
314
- - parameter_key : pPatchMgmtMaintWindow3TZ
315
- parameter_value : " America/New_York"
316
- - parameter_key : pPatchMgmtTask3Name
317
- parameter_value : " Linux_Scan"
318
- - parameter_key : pPatchMgmtTask3Desc
319
- parameter_value : " Task to scan Linux Instances"
320
286
- parameter_key : pPatchMgmtTask3RunCmd
321
287
parameter_value : " AWS-RunPatchBaseline"
322
- - parameter_key : pPatchMgmtTask3Operation
323
- parameter_value : " Scan"
324
- - parameter_key : pPatchMgmtTask3RebootOption
325
- parameter_value : " RebootIfNeeded"
326
- - parameter_key : pPatchMgmtTarget3Name
327
- parameter_value : " Linux_Scan"
328
- - parameter_key : pPatchMgmtTarget3Desc
329
- parameter_value : " Targets to run the command to scan for Linux updates"
330
288
- parameter_key : pPatchMgmtTarget3Value1
331
289
parameter_value : " Linux"
332
290
333
- # Patch Manager Solution
334
- - parameter_key : pDisablePatchMgmt
335
- parameter_value : ' false'
336
- # Window 1
337
- - parameter_key : pPatchMgmtMaintWindow1Schedule
338
- parameter_value : ' cron(0 0 1 ? * THU *)'
339
- - parameter_key : pPatchMgmtMaintWindow1Duration
340
- parameter_value : ' 6'
341
- - parameter_key : pPatchMgmtMaintWindow1Cutoff
342
- parameter_value : ' 1'
343
- - parameter_key : pPatchMgmtTask1RunCmd
344
- parameter_value : ' AWS-UpdateSSMAgent'
345
- - parameter_key : pPatchMgmtTarget1Value1
346
- parameter_value : ' Linux'
347
- - parameter_key : pPatchMgmtTarget1Value2
348
- parameter_value : ' Windows'
349
- - parameter_key : pPatchMgmtMaintWindow2Schedule
350
- parameter_value : ' cron(0 0 1 ? * WED *)'
351
- - parameter_key : pPatchMgmtMaintWindow2Duration
352
- parameter_value : ' 6'
353
- - parameter_key : pPatchMgmtMaintWindow2Cutoff
354
- parameter_value : ' 1'
355
- - parameter_key : pPatchMgmtMaintWindowTZ
356
- parameter_value : ' America/New_York'
357
- - parameter_key : pPatchMgmtTaskRebootOption
358
- parameter_value : ' RebootIfNeeded'
359
- - parameter_key : pPatchMgmtTask2RunCmd
360
- parameter_value : ' AWS-RunPatchBaseline'
361
- - parameter_key : pPatchMgmtTarget2Value1
362
- parameter_value : ' Windows'
363
- - parameter_key : pPatchMgmtTaskOperation
364
- parameter_value : ' Scan'
365
- - parameter_key : pPatchMgmtMaintWindow3Schedule
366
- parameter_value : ' cron(0 0 1 ? * FRI *)'
367
- - parameter_key : pPatchMgmtMaintWindow3Duration
368
- parameter_value : ' 6'
369
- - parameter_key : pPatchMgmtMaintWindow3Cutoff
370
- parameter_value : ' 1'
371
- - parameter_key : pPatchMgmtTask3RunCmd
372
- parameter_value : ' AWS-RunPatchBaseline'
373
- - parameter_key : pPatchMgmtTarget3Value1
374
- parameter_value : ' Linux'
375
-
376
291
# Common Properties
377
292
- parameter_key : pSRAAlarmEmail
378
293
parameter_value : " "
0 commit comments