Overview

Auto remediation configuration to stop or terminate EC2 instances with public IP addresses. Detection uses a managed AWS Config Rule and remediation is with SSM Automation.

This config rule supports Auto Remediation actions using SSM Automation triggered with CloudWatch Events. The following actions are supported:

  • Stop Instance: Non-compliant instances are stopped.
  • Terminate Instance: Non-compliant instances are terminated. (Be careful when selecting this option to not accidentally terminate existing resources).

In addition to an action, a notification using an SNS Topic can be added to send a custom message when a non-compliant resource is detected.

Configuration Templates

Items
4
Size
2.6 KB
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
  ConfigRule:
    Type: 'AWS::Config::ConfigRule'
    Properties:
      ConfigRuleName: ec2-instance-no-public-ip
      Description: >-
        Auto remediation configuration to stop or terminate EC2 instances with
        public IP addresses. Detection uses a managed AWS Config Rule and
        remediation is with SSM Automation.
      Scope:
        ComplianceResourceTypes:
          - 'AWS::EC2::Instance'
      Source:
        Owner: AWS
        SourceIdentifier: EC2_INSTANCE_NO_PUBLIC_IP
  AuoRemediationEventRule:
    Type: 'AWS::Events::Rule'
    Properties:
      Name: auto-remediate-ec2-instance-no-public-ip
      Description: 'auto remediation rule for config rule: ec2-instance-no-public-ip'
      State: ENABLED
      EventPattern:
        detail-type:
          - Config Rules Compliance Change
        source:
          - aws.config
        detail:
          newEvaluationResult:
            complianceType:
              - NON_COMPLIANT
          configRuleARN:
            - 'Fn::GetAtt':
                - ConfigRule
                - Arn
      Targets:
        - Id: RemediationAction
          RoleArn:
            'Fn::GetAtt':
              - AutoRemediationIamRole
              - Arn
          Arn:
            'Fn::Sub': >-
              arn:aws:ssm:${AWS::Region}:${AWS::AccountId}:automation-definition/AWS-StopEC2Instance
          InputTransformer:
            InputPathsMap:
              instance_id: $.detail.resourceId
            InputTemplate:
              'Fn::Sub': >-
                {"InstanceId":[<instance_id>],"AutomationAssumeRole":["${AutoRemediationIamRole.Arn}"]}
  AutoRemediationIamRole:
    Type: 'AWS::IAM::Role'
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - ec2.amazonaws.com
                - events.amazonaws.com
                - ssm.amazonaws.com
            Action:
              - 'sts:AssumeRole'
      ManagedPolicyArns:
        - 'arn:aws:iam::aws:policy/service-role/AmazonSSMAutomationRole'
      Policies: []
  AutomationPassRolePolicy:
    Type: 'AWS::IAM::Policy'
    Properties:
      PolicyName: passAutomationRole
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Action:
              - 'iam:PassRole'
            Resource:
              'Fn::GetAtt':
                - AutoRemediationIamRole
                - Arn
      Roles:
        - Ref: AutoRemediationIamRole
Parameters: {}
Metadata: {}
Conditions: {}

Actions



Rule Parameters

No rule paramters
 
  
* Required field

Sources and Documentation

Configuration Source: AWS Documentation

Additional Documentation: