You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T10:17:26Z INFO [vulndb] Need to update DB
2024-12-18T10:17:26Z INFO [vulndb] Downloading vulnerability DB...
2024-12-18T10:17:26Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T10:17:29Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T10:17:29Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T10:17:29Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T10:17:29Z INFO [misconfig] Need to update the built-in checks
2024-12-18T10:17:29Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2024-12-18T10:17:29Z INFO [secret] Secret scanning is enabled
2024-12-18T10:17:29Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T10:17:29Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-18T10:17:30Z INFO [terraform scanner] Scanning root module file_path="."
2024-12-18T10:17:30Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2024-12-18T10:17:30Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:38Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T10:17:39Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"
2024-12-18T10:17:39Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"
2024-12-18T10:17:39Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"
2024-12-18T10:17:41Z INFO Number of language-specific files num=0
2024-12-18T10:17:41Z INFO Detected config files num=15
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2024-12-18 10:17:43,650 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,650 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.6.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.7.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,652 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,652 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,652 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,655 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,655 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,655 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,655 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,655 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/ec2-instance/aws:5.7.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,656 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 10:17:43,656 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 160, Failed checks: 0, Skipped checks: 155
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T10:17:26Z INFO [vulndb] Need to update DB
2024-12-18T10:17:26Z INFO [vulndb] Downloading vulnerability DB...2024-12-18T10:17:26Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T10:17:29Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T10:17:29Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T10:17:29Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T10:17:29Z INFO [misconfig] Need to update the built-in checks
2024-12-18T10:17:29Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2024-12-18T10:17:29Z INFO [secret] Secret scanning is enabled
2024-12-18T10:17:29Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T10:17:29Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2024-12-18T10:17:30Z INFO [terraformscanner] Scanning root module file_path="."2024-12-18T10:17:30Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2024-12-18T10:17:30Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:38Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T10:17:39Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"2024-12-18T10:17:39Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"2024-12-18T10:17:39Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"2024-12-18T10:17:41Z INFO Number of language-specific files num=02024-12-18T10:17:41Z INFO Detected config files num=15trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T11:41:58Z INFO [vulndb] Need to update DB
2024-12-18T11:41:58Z INFO [vulndb] Downloading vulnerability DB...
2024-12-18T11:41:58Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T11:42:00Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T11:42:00Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T11:42:00Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T11:42:00Z INFO [misconfig] Need to update the built-in checks
2024-12-18T11:42:00Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2024-12-18T11:42:00Z INFO [secret] Secret scanning is enabled
2024-12-18T11:42:00Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T11:42:00Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-18T11:42:02Z INFO [terraform scanner] Scanning root module file_path="."
2024-12-18T11:42:02Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2024-12-18T11:42:02Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2024-12-18T11:42:07Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:08Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T11:42:09Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"
2024-12-18T11:42:09Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"
2024-12-18T11:42:09Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"
2024-12-18T11:42:10Z INFO Number of language-specific files num=0
2024-12-18T11:42:10Z INFO Detected config files num=15
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2024-12-18 11:42:12,400 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,400 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,400 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.6.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.7.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,402 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,402 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,402 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,405 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,405 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,405 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,405 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,406 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/ec2-instance/aws:5.7.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,406 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 11:42:12,406 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 170, Failed checks: 0, Skipped checks: 158
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T11:41:58Z INFO [vulndb] Need to update DB
2024-12-18T11:41:58Z INFO [vulndb] Downloading vulnerability DB...2024-12-18T11:41:58Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T11:42:00Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T11:42:00Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T11:42:00Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T11:42:00Z INFO [misconfig] Need to update the built-in checks
2024-12-18T11:42:00Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2024-12-18T11:42:00Z INFO [secret] Secret scanning is enabled
2024-12-18T11:42:00Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T11:42:00Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2024-12-18T11:42:02Z INFO [terraformscanner] Scanning root module file_path="."2024-12-18T11:42:02Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2024-12-18T11:42:02Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2024-12-18T11:42:07Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:08Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T11:42:09Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"2024-12-18T11:42:09Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"2024-12-18T11:42:09Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"2024-12-18T11:42:10Z INFO Number of language-specific files num=02024-12-18T11:42:10Z INFO Detected config files num=15trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T12:18:59Z INFO [vulndb] Need to update DB
2024-12-18T12:18:59Z INFO [vulndb] Downloading vulnerability DB...
2024-12-18T12:18:59Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T12:19:01Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T12:19:01Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T12:19:01Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T12:19:01Z INFO [misconfig] Need to update the built-in checks
2024-12-18T12:19:01Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2024-12-18T12:19:02Z INFO [secret] Secret scanning is enabled
2024-12-18T12:19:02Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T12:19:02Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-18T12:19:04Z INFO [terraform scanner] Scanning root module file_path="."
2024-12-18T12:19:04Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2024-12-18T12:19:04Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T12:19:17Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"
2024-12-18T12:19:17Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"
2024-12-18T12:19:17Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"
2024-12-18T12:19:18Z INFO Number of language-specific files num=0
2024-12-18T12:19:18Z INFO Detected config files num=15
trivy_exitcode=0
</details> #### `Checkov Scan` Failed
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2024-12-18 12:19:21,130 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,130 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,131 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,131 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,131 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.6.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,134 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,134 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.7.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,134 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,134 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,135 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,135 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,135 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,135 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,135 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,135 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,136 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,136 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/ec2-instance/aws:5.7.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,136 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 12:19:21,136 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 170, Failed checks: 1, Skipped checks: 158
Check: CKV_AWS_370: "Ensure Amazon SageMaker model uses network isolation"
FAILED for resource: aws_sagemaker_model.mxbai_rerank_xsmall_model
File: /sagemaker-jumpstart.tf:104-121
Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-networking-policies/bc-aws-370
104 | resource "aws_sagemaker_model" "mxbai_rerank_xsmall_model" {
105 | count = terraform.workspace == "analytical-platform-compute-development" ? 1 : 0 # Creates IAM role if not provided
106 | name = "mxbai-rerank-xsmall-model"
107 | execution_role_arn = aws_iam_role.sagemaker_execution_role[0].arn
108 | tags = local.tags
109 |
110 | primary_container {
111 | # image = "764974769150.dkr.ecr.eu-west-2.amazonaws.com/tei:2.0.1-tei1.2.3-gpu-py310-cu122-ubuntu22.04"
112 | image = "public.ecr.aws/sagemaker/sagemaker-distribution:2-gpu"
113 | environment = {
114 | HF_MODEL_ID = "mixedbread-ai/mxbai-rerank-xsmall-v1"
115 | }
116 | }
117 |
118 | lifecycle {
119 | create_before_destroy = true
120 | }
121 | }
checkov_exitcode=1
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T12:18:59Z INFO [vulndb] Need to update DB
2024-12-18T12:18:59Z INFO [vulndb] Downloading vulnerability DB...2024-12-18T12:18:59Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T12:19:01Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T12:19:01Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T12:19:01Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T12:19:01Z INFO [misconfig] Need to update the built-in checks
2024-12-18T12:19:01Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2024-12-18T12:19:02Z INFO [secret] Secret scanning is enabled
2024-12-18T12:19:02Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T12:19:02Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2024-12-18T12:19:04Z INFO [terraformscanner] Scanning root module file_path="."2024-12-18T12:19:04Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2024-12-18T12:19:04Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T12:19:17Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"2024-12-18T12:19:17Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"2024-12-18T12:19:17Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"2024-12-18T12:19:18Z INFO Number of language-specific files num=02024-12-18T12:19:18Z INFO Detected config files num=15trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T14:49:57Z INFO [vulndb] Need to update DB
2024-12-18T14:49:57Z INFO [vulndb] Downloading vulnerability DB...
2024-12-18T14:49:57Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T14:49:59Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-18T14:49:59Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T14:49:59Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T14:49:59Z INFO [misconfig] Need to update the built-in checks
2024-12-18T14:49:59Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2024-12-18T14:50:00Z INFO [secret] Secret scanning is enabled
2024-12-18T14:50:00Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T14:50:00Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-18T14:50:01Z INFO [terraform scanner] Scanning root module file_path="."
2024-12-18T14:50:01Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2024-12-18T14:50:01Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:13Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-18T14:50:14Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"
2024-12-18T14:50:14Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"
2024-12-18T14:50:14Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"
2024-12-18T14:50:16Z INFO Number of language-specific files num=0
2024-12-18T14:50:16Z INFO Detected config files num=15
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2024-12-18 14:50:19,185 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,186 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,186 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,186 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,186 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.6.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,186 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,186 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.7.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,187 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,187 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,187 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,187 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,187 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,187 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,188 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,188 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,188 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,188 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/ec2-instance/aws:5.7.1 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,188 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-18 14:50:19,188 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 171, Failed checks: 0, Skipped checks: 158
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-18T14:49:57Z INFO [vulndb] Need to update DB
2024-12-18T14:49:57Z INFO [vulndb] Downloading vulnerability DB...2024-12-18T14:49:57Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T14:49:59Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-18T14:49:59Z INFO [vuln] Vulnerability scanning is enabled
2024-12-18T14:49:59Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-18T14:49:59Z INFO [misconfig] Need to update the built-in checks
2024-12-18T14:49:59Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2024-12-18T14:50:00Z INFO [secret] Secret scanning is enabled
2024-12-18T14:50:00Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-18T14:50:00Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2024-12-18T14:50:01Z INFO [terraformscanner] Scanning root module file_path="."2024-12-18T14:50:01Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2024-12-18T14:50:01Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:13Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-18T14:50:14Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"2024-12-18T14:50:14Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"2024-12-18T14:50:14Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"2024-12-18T14:50:16Z INFO Number of language-specific files num=02024-12-18T14:50:16Z INFO Detected config files num=15trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-19T12:10:55Z INFO [vulndb] Need to update DB
2024-12-19T12:10:55Z INFO [vulndb] Downloading vulnerability DB...
2024-12-19T12:10:55Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-19T12:10:58Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-19T12:10:58Z INFO [vuln] Vulnerability scanning is enabled
2024-12-19T12:10:58Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-19T12:10:58Z INFO [misconfig] Need to update the built-in checks
2024-12-19T12:10:58Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2024-12-19T12:10:58Z INFO [secret] Secret scanning is enabled
2024-12-19T12:10:58Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-19T12:10:58Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-19T12:10:59Z INFO [terraform scanner] Scanning root module file_path="."
2024-12-19T12:10:59Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2024-12-19T12:10:59Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2024-12-19T12:11:06Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:07Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T12:11:08Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"
2024-12-19T12:11:08Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"
2024-12-19T12:11:08Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"
2024-12-19T12:11:09Z INFO Number of language-specific files num=0
2024-12-19T12:11:09Z INFO Detected config files num=15
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2024-12-19 12:11:12,272 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,272 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,273 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,273 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,273 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.6.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,273 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,273 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.7.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,273 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,274 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,274 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,274 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,274 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,274 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,274 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,274 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,275 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,275 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/ec2-instance/aws:5.7.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,275 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 12:11:12,275 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 172, Failed checks: 0, Skipped checks: 158
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-19T12:10:55Z INFO [vulndb] Need to update DB
2024-12-19T12:10:55Z INFO [vulndb] Downloading vulnerability DB...2024-12-19T12:10:55Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-19T12:10:58Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-19T12:10:58Z INFO [vuln] Vulnerability scanning is enabled
2024-12-19T12:10:58Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-19T12:10:58Z INFO [misconfig] Need to update the built-in checks
2024-12-19T12:10:58Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2024-12-19T12:10:58Z INFO [secret] Secret scanning is enabled
2024-12-19T12:10:58Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-19T12:10:58Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2024-12-19T12:10:59Z INFO [terraformscanner] Scanning root module file_path="."2024-12-19T12:10:59Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2024-12-19T12:10:59Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2024-12-19T12:11:06Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:07Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T12:11:08Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"2024-12-19T12:11:08Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"2024-12-19T12:11:08Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"2024-12-19T12:11:09Z INFO Number of language-specific files num=02024-12-19T12:11:09Z INFO Detected config files num=15trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-19T13:22:11Z INFO [vulndb] Need to update DB
2024-12-19T13:22:11Z INFO [vulndb] Downloading vulnerability DB...
2024-12-19T13:22:11Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-19T13:22:14Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-19T13:22:14Z INFO [vuln] Vulnerability scanning is enabled
2024-12-19T13:22:14Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-19T13:22:14Z INFO [misconfig] Need to update the built-in checks
2024-12-19T13:22:14Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2024-12-19T13:22:14Z INFO [secret] Secret scanning is enabled
2024-12-19T13:22:14Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-19T13:22:14Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-19T13:22:16Z INFO [terraform scanner] Scanning root module file_path="."
2024-12-19T13:22:16Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2024-12-19T13:22:16Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2024-12-19T13:22:21Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:22Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:22:23Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"
2024-12-19T13:22:23Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"
2024-12-19T13:22:23Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"
2024-12-19T13:22:23Z INFO Number of language-specific files num=0
2024-12-19T13:22:23Z INFO Detected config files num=15
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2024-12-19 13:22:26,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.6.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.7.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,372 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,372 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,372 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,372 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,372 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,372 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,372 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,373 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,373 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,373 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/ec2-instance/aws:5.7.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,373 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:22:26,373 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 172, Failed checks: 0, Skipped checks: 158
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-19T13:22:11Z INFO [vulndb] Need to update DB
2024-12-19T13:22:11Z INFO [vulndb] Downloading vulnerability DB...2024-12-19T13:22:11Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-19T13:22:14Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-19T13:22:14Z INFO [vuln] Vulnerability scanning is enabled
2024-12-19T13:22:14Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-19T13:22:14Z INFO [misconfig] Need to update the built-in checks
2024-12-19T13:22:14Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2024-12-19T13:22:14Z INFO [secret] Secret scanning is enabled
2024-12-19T13:22:14Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-19T13:22:14Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2024-12-19T13:22:16Z INFO [terraformscanner] Scanning root module file_path="."2024-12-19T13:22:16Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2024-12-19T13:22:16Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2024-12-19T13:22:21Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:22Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:22:23Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"2024-12-19T13:22:23Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"2024-12-19T13:22:23Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"2024-12-19T13:22:23Z INFO Number of language-specific files num=02024-12-19T13:22:23Z INFO Detected config files num=15trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-19T13:42:34Z INFO [vulndb] Need to update DB
2024-12-19T13:42:34Z INFO [vulndb] Downloading vulnerability DB...
2024-12-19T13:42:34Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-19T13:42:36Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2024-12-19T13:42:36Z INFO [vuln] Vulnerability scanning is enabled
2024-12-19T13:42:36Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-19T13:42:36Z INFO [misconfig] Need to update the built-in checks
2024-12-19T13:42:36Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2024-12-19T13:42:37Z INFO [secret] Secret scanning is enabled
2024-12-19T13:42:37Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-19T13:42:37Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-19T13:42:38Z INFO [terraform scanner] Scanning root module file_path="."
2024-12-19T13:42:38Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2024-12-19T13:42:38Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:44Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2024-12-19T13:42:45Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"
2024-12-19T13:42:45Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"
2024-12-19T13:42:45Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"
2024-12-19T13:42:46Z INFO Number of language-specific files num=0
2024-12-19T13:42:46Z INFO Detected config files num=15
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2024-12-19 13:42:48,875 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,875 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,875 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,875 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,875 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.6.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,876 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,876 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.7.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,876 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,876 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,876 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,876 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,877 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,877 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,877 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,877 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.29.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,877 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,877 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/ec2-instance/aws:5.7.1 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,878 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.15.0 (for external modules, the --download-external-modules flag is required)
2024-12-19 13:42:48,878 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 172, Failed checks: 0, Skipped checks: 158
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2024-12-19T13:42:34Z INFO [vulndb] Need to update DB
2024-12-19T13:42:34Z INFO [vulndb] Downloading vulnerability DB...2024-12-19T13:42:34Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-19T13:42:36Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2024-12-19T13:42:36Z INFO [vuln] Vulnerability scanning is enabled
2024-12-19T13:42:36Z INFO [misconfig] Misconfiguration scanning is enabled
2024-12-19T13:42:36Z INFO [misconfig] Need to update the built-in checks
2024-12-19T13:42:36Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2024-12-19T13:42:37Z INFO [secret] Secret scanning is enabled
2024-12-19T13:42:37Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-19T13:42:37Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2024-12-19T13:42:38Z INFO [terraformscanner] Scanning root module file_path="."2024-12-19T13:42:38Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2024-12-19T13:42:38Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="2 errors occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:44Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2024-12-19T13:42:45Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:52"2024-12-19T13:42:45Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/node_groups.tf:247"2024-12-19T13:42:45Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=97a08c8aff5dbf51a86b4c8cd88a858336cd0208/main.tf:51"2024-12-19T13:42:46Z INFO Number of language-specific files num=02024-12-19T13:42:46Z INFO Detected config files num=15trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:10:18Z INFO [vulndb] Need to update DB
2025-01-09T12:10:18Z INFO [vulndb] Downloading vulnerability DB...
2025-01-09T12:10:18Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:10:20Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:10:20Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:10:20Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:10:20Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:10:20Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-09T12:10:21Z INFO [secret] Secret scanning is enabled
2025-01-09T12:10:21Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:10:21Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-09T12:10:24Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-09T12:10:24Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-09T12:10:24Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:33Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:10:34Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-09T12:10:34Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-09T12:10:34Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-09T12:10:34Z INFO Number of language-specific files num=0
2025-01-09T12:10:34Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-09 12:10:36,586 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,586 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,586 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,586 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,586 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,587 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,587 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,587 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,587 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,587 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,587 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,587 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,588 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,588 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,588 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,588 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,588 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,588 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,589 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,589 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:10:36,589 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:10:18Z INFO [vulndb] Need to update DB
2025-01-09T12:10:18Z INFO [vulndb] Downloading vulnerability DB...2025-01-09T12:10:18Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:10:20Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:10:20Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:10:20Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:10:20Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:10:20Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-09T12:10:21Z INFO [secret] Secret scanning is enabled
2025-01-09T12:10:21Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:10:21Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-09T12:10:24Z INFO [terraformscanner] Scanning root module file_path="."2025-01-09T12:10:24Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-09T12:10:24Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:33Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:10:34Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-09T12:10:34Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-09T12:10:34Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-09T12:10:34Z INFO Number of language-specific files num=02025-01-09T12:10:34Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:16:15Z INFO [vulndb] Need to update DB
2025-01-09T12:16:15Z INFO [vulndb] Downloading vulnerability DB...
2025-01-09T12:16:15Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:16:18Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:16:18Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:16:18Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:16:18Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:16:18Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-09T12:16:18Z INFO [secret] Secret scanning is enabled
2025-01-09T12:16:18Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:16:18Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-09T12:16:21Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-09T12:16:21Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-09T12:16:21Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:28Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:29Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:16:30Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-09T12:16:30Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-09T12:16:30Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-09T12:16:30Z INFO Number of language-specific files num=0
2025-01-09T12:16:30Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-09 12:16:33,043 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,043 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,043 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,043 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,043 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,044 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:16:33,046 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:16:15Z INFO [vulndb] Need to update DB
2025-01-09T12:16:15Z INFO [vulndb] Downloading vulnerability DB...2025-01-09T12:16:15Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:16:18Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:16:18Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:16:18Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:16:18Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:16:18Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-09T12:16:18Z INFO [secret] Secret scanning is enabled
2025-01-09T12:16:18Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:16:18Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-09T12:16:21Z INFO [terraformscanner] Scanning root module file_path="."2025-01-09T12:16:21Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-09T12:16:21Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:28Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:29Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:16:30Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-09T12:16:30Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-09T12:16:30Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-09T12:16:30Z INFO Number of language-specific files num=02025-01-09T12:16:30Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:18:24Z INFO [vulndb] Need to update DB
2025-01-09T12:18:24Z INFO [vulndb] Downloading vulnerability DB...
2025-01-09T12:18:24Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:18:26Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:18:26Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:18:26Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:18:26Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:18:26Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-09T12:18:27Z INFO [secret] Secret scanning is enabled
2025-01-09T12:18:27Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:18:27Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-09T12:18:28Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-09T12:18:28Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-09T12:18:29Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:34Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:18:35Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-09T12:18:35Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-09T12:18:35Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-09T12:18:36Z INFO Number of language-specific files num=0
2025-01-09T12:18:36Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-09 12:18:39,221 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,221 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,221 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,221 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,221 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,222 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,222 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,222 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,222 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,222 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,225 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,225 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,226 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,226 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,226 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,226 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,226 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,226 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,226 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,227 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:18:39,227 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:18:24Z INFO [vulndb] Need to update DB
2025-01-09T12:18:24Z INFO [vulndb] Downloading vulnerability DB...2025-01-09T12:18:24Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:18:26Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:18:26Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:18:26Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:18:26Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:18:26Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-09T12:18:27Z INFO [secret] Secret scanning is enabled
2025-01-09T12:18:27Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:18:27Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-09T12:18:28Z INFO [terraformscanner] Scanning root module file_path="."2025-01-09T12:18:28Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-09T12:18:29Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:34Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:18:35Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-09T12:18:35Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-09T12:18:35Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-09T12:18:36Z INFO Number of language-specific files num=02025-01-09T12:18:36Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:24:30Z INFO [vulndb] Need to update DB
2025-01-09T12:24:30Z INFO [vulndb] Downloading vulnerability DB...
2025-01-09T12:24:30Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:24:32Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-09T12:24:32Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:24:32Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:24:32Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:24:32Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-09T12:24:32Z INFO [secret] Secret scanning is enabled
2025-01-09T12:24:32Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:24:32Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-09T12:24:34Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-09T12:24:34Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-09T12:24:34Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:40Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-09T12:24:41Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-09T12:24:41Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-09T12:24:41Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-09T12:24:42Z INFO Number of language-specific files num=0
2025-01-09T12:24:42Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-09 12:24:45,037 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,038 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,039 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,044 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,044 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-09 12:24:45,045 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-09T12:24:30Z INFO [vulndb] Need to update DB
2025-01-09T12:24:30Z INFO [vulndb] Downloading vulnerability DB...2025-01-09T12:24:30Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:24:32Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-09T12:24:32Z INFO [vuln] Vulnerability scanning is enabled
2025-01-09T12:24:32Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-09T12:24:32Z INFO [misconfig] Need to update the built-in checks
2025-01-09T12:24:32Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-09T12:24:32Z INFO [secret] Secret scanning is enabled
2025-01-09T12:24:32Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-09T12:24:32Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-09T12:24:34Z INFO [terraformscanner] Scanning root module file_path="."2025-01-09T12:24:34Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-09T12:24:34Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:40Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-09T12:24:41Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-09T12:24:41Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-09T12:24:41Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-09T12:24:42Z INFO Number of language-specific files num=02025-01-09T12:24:42Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:15:55Z INFO [vulndb] Need to update DB
2025-01-10T09:15:55Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T09:15:55Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:15:58Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:15:58Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:15:58Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:15:58Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:15:58Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2025-01-10T09:15:58Z INFO [secret] Secret scanning is enabled
2025-01-10T09:15:58Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:15:58Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T09:16:01Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T09:16:01Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T09:16:01Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T09:16:11Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:12Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:16:13Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T09:16:13Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T09:16:13Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T09:16:13Z INFO Number of language-specific files num=0
2025-01-10T09:16:13Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 09:16:16,251 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,252 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,252 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,252 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,252 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,252 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,252 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,253 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,253 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,253 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,253 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,253 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,253 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,254 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,254 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,254 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,254 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,254 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,254 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,258 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:16:16,258 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:15:55Z INFO [vulndb] Need to update DB
2025-01-10T09:15:55Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T09:15:55Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:15:58Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:15:58Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:15:58Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:15:58Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:15:58Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2025-01-10T09:15:58Z INFO [secret] Secret scanning is enabled
2025-01-10T09:15:58Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:15:58Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T09:16:01Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T09:16:01Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T09:16:01Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T09:16:11Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:12Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:16:13Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T09:16:13Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T09:16:13Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T09:16:13Z INFO Number of language-specific files num=02025-01-10T09:16:13Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:40:28Z INFO [vulndb] Need to update DB
2025-01-10T09:40:28Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T09:40:28Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:40:30Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:40:30Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:40:30Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:40:30Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:40:30Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2025-01-10T09:40:30Z INFO [secret] Secret scanning is enabled
2025-01-10T09:40:30Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:40:30Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T09:40:31Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T09:40:31Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T09:40:31Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:40:38Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T09:40:38Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T09:40:38Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T09:40:39Z INFO Number of language-specific files num=0
2025-01-10T09:40:39Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 09:40:42,393 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,394 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,396 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,397 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,398 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,398 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,398 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,398 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,398 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,398 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,401 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,402 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:40:42,402 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:40:28Z INFO [vulndb] Need to update DB
2025-01-10T09:40:28Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T09:40:28Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:40:30Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:40:30Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:40:30Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:40:30Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:40:30Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2025-01-10T09:40:30Z INFO [secret] Secret scanning is enabled
2025-01-10T09:40:30Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:40:30Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T09:40:31Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T09:40:31Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T09:40:31Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:40:38Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T09:40:38Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T09:40:38Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T09:40:39Z INFO Number of language-specific files num=02025-01-10T09:40:39Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:43:20Z INFO [vulndb] Need to update DB
2025-01-10T09:43:20Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T09:43:20Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:43:22Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:43:22Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:43:22Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:43:22Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:43:22Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-10T09:43:23Z INFO [secret] Secret scanning is enabled
2025-01-10T09:43:23Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:43:23Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T09:43:24Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T09:43:24Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T09:43:24Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:36Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:37Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:43:38Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T09:43:38Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T09:43:38Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T09:43:39Z INFO Number of language-specific files num=0
2025-01-10T09:43:39Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 09:43:42,816 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,816 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,816 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,816 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,816 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,817 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,817 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,820 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,820 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,820 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,820 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,821 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,821 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,821 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,821 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,821 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,821 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,821 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,822 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,825 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:43:42,825 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:43:20Z INFO [vulndb] Need to update DB
2025-01-10T09:43:20Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T09:43:20Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:43:22Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:43:22Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:43:22Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:43:22Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:43:22Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-10T09:43:23Z INFO [secret] Secret scanning is enabled
2025-01-10T09:43:23Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:43:23Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T09:43:24Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T09:43:24Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T09:43:24Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:36Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:37Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:43:38Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T09:43:38Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T09:43:38Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T09:43:39Z INFO Number of language-specific files num=02025-01-10T09:43:39Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:46:02Z INFO [vulndb] Need to update DB
2025-01-10T09:46:02Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T09:46:02Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:46:04Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:46:04Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:46:04Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:46:04Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:46:04Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2025-01-10T09:46:04Z INFO [secret] Secret scanning is enabled
2025-01-10T09:46:04Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:46:04Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T09:46:06Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T09:46:06Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T09:46:06Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:16Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:17Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:46:18Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T09:46:18Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T09:46:18Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T09:46:18Z INFO Number of language-specific files num=0
2025-01-10T09:46:18Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 09:46:21,692 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,692 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,692 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,694 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,694 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,694 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,695 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,695 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,695 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,695 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,695 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,695 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,695 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:46:21,696 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 177, Failed checks: 0, Skipped checks: 164
checkov_exitcode=0
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:46:02Z INFO [vulndb] Need to update DB
2025-01-10T09:46:02Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T09:46:02Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:46:04Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:46:04Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:46:04Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:46:04Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:46:04Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2025-01-10T09:46:04Z INFO [secret] Secret scanning is enabled
2025-01-10T09:46:04Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:46:04Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T09:46:06Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T09:46:06Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T09:46:06Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:16Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:17Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:46:18Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T09:46:18Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T09:46:18Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T09:46:18Z INFO Number of language-specific files num=02025-01-10T09:46:18Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:56:43Z INFO [vulndb] Need to update DB
2025-01-10T09:56:43Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T09:56:43Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:56:45Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T09:56:45Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:56:45Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:56:45Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:56:45Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-10T09:56:45Z INFO [secret] Secret scanning is enabled
2025-01-10T09:56:45Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:56:45Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T09:56:46Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T09:56:46Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T09:56:46Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T09:56:51Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:52Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T09:56:53Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T09:56:53Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T09:56:53Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T09:56:54Z INFO Number of language-specific files num=0
2025-01-10T09:56:54Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Failed
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 09:56:57,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,371 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,372 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,374 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,374 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,375 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,376 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,376 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,376 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,376 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,376 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,376 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,376 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 09:56:57,377 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 174, Failed checks: 1, Skipped checks: 162
Check: CKV_AWS_98: "Ensure all data stored in the Sagemaker Endpoint is securely encrypted at rest"
FAILED for resource: aws_sagemaker_endpoint_configuration.huggingface_async
File: /sagemaker-jumpstart.tf:245-268
Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-general-policies/bc-aws-general-40
245 | resource "aws_sagemaker_endpoint_configuration" "huggingface_async" {
246 | count = terraform.workspace == "analytical-platform-compute-development" && local.sagemaker_endpoint_type.asynchronous ? 1 : 0
247 | name = "${local.name_prefix}-ep-config-${random_string.resource_id[0].result}"
248 |
249 | tags = local.tags
250 |
251 |
252 | production_variants {
253 | variant_name = "AllTraffic"
254 | model_name = aws_sagemaker_model.model_with_hub_model[0].name
255 | initial_instance_count = local.instance_count
256 | instance_type = local.instance_type
257 | }
258 | async_inference_config {
259 | output_config {
260 | s3_output_path = local.async_config.s3_output_path
261 | s3_failure_path = local.async_config.s3_failure_path
262 | notification_config {
263 | error_topic = local.async_config.sns_error_topic
264 | success_topic = local.async_config.sns_success_topic
265 | }
266 | }
267 | }
268 | }
checkov_exitcode=1
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T09:56:43Z INFO [vulndb] Need to update DB
2025-01-10T09:56:43Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T09:56:43Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:56:45Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T09:56:45Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T09:56:45Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T09:56:45Z INFO [misconfig] Need to update the built-in checks
2025-01-10T09:56:45Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-10T09:56:45Z INFO [secret] Secret scanning is enabled
2025-01-10T09:56:45Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T09:56:45Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T09:56:46Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T09:56:46Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T09:56:46Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T09:56:51Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:52Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T09:56:53Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T09:56:53Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T09:56:53Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T09:56:54Z INFO Number of language-specific files num=02025-01-10T09:56:54Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T10:02:17Z INFO [vulndb] Need to update DB
2025-01-10T10:02:17Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T10:02:17Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T10:02:19Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T10:02:19Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T10:02:19Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T10:02:19Z INFO [misconfig] Need to update the built-in checks
2025-01-10T10:02:19Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [---------------------------------------------------------] 100.00% ? p/s 0s2025-01-10T10:02:19Z INFO [secret] Secret scanning is enabled
2025-01-10T10:02:19Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T10:02:19Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T10:02:21Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T10:02:21Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T10:02:21Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T10:02:31Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:32Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:02:33Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T10:02:33Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T10:02:33Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T10:02:34Z INFO Number of language-specific files num=0
2025-01-10T10:02:34Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Failed
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 10:02:37,245 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,245 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,245 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,245 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,245 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,246 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,246 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,246 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,246 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,246 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,247 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,247 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,247 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,247 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,247 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,248 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,248 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,248 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,248 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,248 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:02:37,248 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 174, Failed checks: 1, Skipped checks: 162
Check: CKV_AWS_98: "Ensure all data stored in the Sagemaker Endpoint is securely encrypted at rest"
FAILED for resource: aws_sagemaker_endpoint_configuration.huggingface_async
File: /sagemaker-jumpstart.tf:245-268
Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-general-policies/bc-aws-general-40
245 | resource "aws_sagemaker_endpoint_configuration" "huggingface_async" {
246 | count = terraform.workspace == "analytical-platform-compute-development" && local.sagemaker_endpoint_type.asynchronous ? 1 : 0
247 | name = "${local.name_prefix}-ep-config-${random_string.resource_id[0].result}"
248 |
249 | tags = local.tags
250 |
251 |
252 | production_variants {
253 | variant_name = "AllTraffic"
254 | model_name = aws_sagemaker_model.model_with_hub_model[0].name
255 | initial_instance_count = local.instance_count
256 | instance_type = local.instance_type
257 | }
258 | async_inference_config {
259 | output_config {
260 | s3_output_path = local.async_config.s3_output_path
261 | s3_failure_path = local.async_config.s3_failure_path
262 | notification_config {
263 | error_topic = local.async_config.sns_error_topic
264 | success_topic = local.async_config.sns_success_topic
265 | }
266 | }
267 | }
268 | }
checkov_exitcode=1
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T10:02:17Z INFO [vulndb] Need to update DB
2025-01-10T10:02:17Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T10:02:17Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T10:02:19Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T10:02:19Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T10:02:19Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T10:02:19Z INFO [misconfig] Need to update the built-in checks
2025-01-10T10:02:19Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [---------------------------------------------------------] 100.00%? p/s 0s2025-01-10T10:02:19Z INFO [secret] Secret scanning is enabled
2025-01-10T10:02:19Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T10:02:19Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T10:02:21Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T10:02:21Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T10:02:21Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T10:02:31Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:32Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:02:33Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T10:02:33Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T10:02:33Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T10:02:34Z INFO Number of language-specific files num=02025-01-10T10:02:34Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T10:20:49Z INFO [vulndb] Need to update DB
2025-01-10T10:20:49Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T10:20:49Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T10:20:52Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T10:20:52Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T10:20:52Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T10:20:52Z INFO [misconfig] Need to update the built-in checks
2025-01-10T10:20:52Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-10T10:20:52Z INFO [secret] Secret scanning is enabled
2025-01-10T10:20:52Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T10:20:52Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T10:20:54Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T10:20:54Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T10:20:55Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:00Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:01Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:21:01Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:01Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:01Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T10:21:01Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:01Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T10:21:01Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T10:21:01Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T10:21:01Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T10:21:01Z INFO Number of language-specific files num=0
2025-01-10T10:21:01Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Failed
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 10:21:04,343 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,343 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,344 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,344 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,344 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,344 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,344 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,344 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,345 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,345 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,345 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,345 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,345 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,345 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,346 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,346 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,346 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,346 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,346 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,346 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 10:21:04,347 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 174, Failed checks: 1, Skipped checks: 162
Check: CKV_AWS_98: "Ensure all data stored in the Sagemaker Endpoint is securely encrypted at rest"
FAILED for resource: aws_sagemaker_endpoint_configuration.huggingface_async
File: /sagemaker-jumpstart.tf:241-264
Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-general-policies/bc-aws-general-40
241 | resource "aws_sagemaker_endpoint_configuration" "huggingface_async" {
242 | count = terraform.workspace == "analytical-platform-compute-development" && local.sagemaker_endpoint_type.asynchronous ? 1 : 0
243 | name = "${local.name_prefix}-ep-config-${random_string.resource_id[0].result}"
244 |
245 | tags = local.tags
246 |
247 |
248 | production_variants {
249 | variant_name = "AllTraffic"
250 | model_name = aws_sagemaker_model.model_with_hub_model[0].name
251 | initial_instance_count = local.instance_count
252 | instance_type = local.instance_type
253 | }
254 | async_inference_config {
255 | output_config {
256 | s3_output_path = local.async_config.s3_output_path
257 | s3_failure_path = local.async_config.s3_failure_path
258 | # notification_config {
259 | # error_topic = local.async_config.sns_error_topic
260 | # success_topic = local.async_config.sns_success_topic
261 | # }
262 | }
263 | }
264 | }
checkov_exitcode=1
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T10:20:49Z INFO [vulndb] Need to update DB
2025-01-10T10:20:49Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T10:20:49Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T10:20:52Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T10:20:52Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T10:20:52Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T10:20:52Z INFO [misconfig] Need to update the built-in checks
2025-01-10T10:20:52Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-10T10:20:52Z INFO [secret] Secret scanning is enabled
2025-01-10T10:20:52Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T10:20:52Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T10:20:54Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T10:20:54Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T10:20:55Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:00Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:01Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:21:01Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:01Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:01Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T10:21:01Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:01Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T10:21:01Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T10:21:01Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T10:21:01Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T10:21:01Z INFO Number of language-specific files num=02025-01-10T10:21:01Z INFO Detected config files num=14trivy_exitcode=0
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T11:38:59Z INFO [vulndb] Need to update DB
2025-01-10T11:38:59Z INFO [vulndb] Downloading vulnerability DB...
2025-01-10T11:38:59Z INFO [vulndb] Downloading artifact... repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T11:39:01Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"
2025-01-10T11:39:01Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T11:39:01Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T11:39:01Z INFO [misconfig] Need to update the built-in checks
2025-01-10T11:39:01Z INFO [misconfig] Downloading the built-in checks...
160.80 KiB / 160.80 KiB [------------------------------------------------------] 100.00% ? p/s 100ms2025-01-10T11:39:01Z INFO [secret] Secret scanning is enabled
2025-01-10T11:39:01Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T11:39:01Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2025-01-10T11:39:05Z INFO [terraform scanner] Scanning root module file_path="."
2025-01-10T11:39:05Z WARN [terraform parser] Variable values was not found in the environment or variable files. Evaluating may not work correctly. module="root" variables="networking"
2025-01-10T11:39:05Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.transit_gateway_routes" value="cty.NilVal"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.aws_ec2_tag.cluster_primary_security_group" value="cty.NilVal"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]" err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:10Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["airflow-high-memory"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:11Z ERROR [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable. block="module.eks.module.eks_managed_node_group["general"].aws_iam_role_policy_attachment.this" value="cty.NilVal"
2025-01-10T11:39:11Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:11Z ERROR [terraform evaluator] Failed to expand dynamic block. block="module.eks.module.eks_managed_node_group["general"].aws_launch_template.this[0]" err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"
2025-01-10T11:39:11Z INFO [terraform executor] Ignore finding rule="aws-ec2-no-public-egress-sgr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"
2025-01-10T11:39:11Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"
2025-01-10T11:39:11Z INFO [terraform executor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr" range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"
2025-01-10T11:39:11Z INFO Number of language-specific files num=0
2025-01-10T11:39:11Z INFO Detected config files num=14
trivy_exitcode=0
</details> #### `Checkov Scan` Failed
<details><summary>Show Output</summary>
```hcl
*****************************
Checkov will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Checkov in terraform/environments/analytical-platform-compute
Excluding the following checks: CKV_GIT_1,CKV_AWS_126,CKV2_AWS_38,CKV2_AWS_39
2025-01-10 11:39:14,648 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,648 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,648 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-github-oidc-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,648 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.52.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,649 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/cloudwatch/aws//modules/log-group:5.7.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,649 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/kms/aws:3.1.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,649 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks-pod-identity/aws:1.9.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,649 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.3.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,649 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/rds/aws:6.10.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,649 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/security-group/aws:5.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,649 [MainThread ] [WARNI] Failed to download module ministryofjustice/observability-platform-tenant/aws:1.2.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,650 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws//modules/vpc-endpoints:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,650 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/secrets-manager/aws:1.3.1 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,650 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,650 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/eks/aws//modules/karpenter:20.31.6 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,650 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/route53/aws//modules/zones:4.1.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/vpc/aws:5.17.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-assumable-role:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/iam/aws//modules/iam-policy:5.48.0 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/s3-bucket/aws:4.2.2 (for external modules, the --download-external-modules flag is required)
2025-01-10 11:39:14,651 [MainThread ] [WARNI] Failed to download module terraform-aws-modules/managed-service-prometheus/aws:3.0.0 (for external modules, the --download-external-modules flag is required)
terraform scan results:
Passed checks: 174, Failed checks: 1, Skipped checks: 162
Check: CKV_AWS_98: "Ensure all data stored in the Sagemaker Endpoint is securely encrypted at rest"
FAILED for resource: aws_sagemaker_endpoint_configuration.huggingface_async
File: /sagemaker-jumpstart.tf:241-264
Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-general-policies/bc-aws-general-40
241 | resource "aws_sagemaker_endpoint_configuration" "huggingface_async" {
242 | count = terraform.workspace == "analytical-platform-compute-development" && local.sagemaker_endpoint_type.asynchronous ? 1 : 0
243 | name = "${local.name_prefix}-ep-config-${random_string.resource_id[0].result}"
244 |
245 | tags = local.tags
246 |
247 |
248 | production_variants {
249 | variant_name = "AllTraffic"
250 | model_name = aws_sagemaker_model.model_with_hub_model[0].name
251 | initial_instance_count = local.instance_count
252 | instance_type = local.instance_type
253 | }
254 | async_inference_config {
255 | output_config {
256 | s3_output_path = local.async_config.s3_output_path
257 | s3_failure_path = local.async_config.s3_failure_path
258 | # notification_config {
259 | # error_topic = local.async_config.sns_error_topic
260 | # success_topic = local.async_config.sns_success_topic
261 | # }
262 | }
263 | }
264 | }
checkov_exitcode=1
CTFLint Scan Success
Show Output
*****************************
Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version:0.9.1)
tflint will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running tflint in terraform/environments/analytical-platform-compute
Excluding the following checks: terraform_unused_declarations
tflint_exitcode=0
Trivy Scan Success
Show Output
*****************************
Trivy will check the following folders:
terraform/environments/analytical-platform-compute
*****************************
Running Trivy in terraform/environments/analytical-platform-compute
2025-01-10T11:38:59Z INFO [vulndb] Need to update DB
2025-01-10T11:38:59Z INFO [vulndb] Downloading vulnerability DB...2025-01-10T11:38:59Z INFO [vulndb] Downloading artifact...repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T11:39:01Z INFO [vulndb] Artifact successfully downloaded repo="public.ecr.aws/aquasecurity/trivy-db:2"2025-01-10T11:39:01Z INFO [vuln] Vulnerability scanning is enabled
2025-01-10T11:39:01Z INFO [misconfig] Misconfiguration scanning is enabled
2025-01-10T11:39:01Z INFO [misconfig] Need to update the built-in checks
2025-01-10T11:39:01Z INFO [misconfig] Downloading the built-in checks...160.80 KiB /160.80 KiB [------------------------------------------------------] 100.00%? p/s 100ms2025-01-10T11:39:01Z INFO [secret] Secret scanning is enabled
2025-01-10T11:39:01Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2025-01-10T11:39:01Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection2025-01-10T11:39:05Z INFO [terraformscanner] Scanning root module file_path="."2025-01-10T11:39:05Z WARN [terraformparser] Variable values was not found in the environment or variable files. Evaluating may not work correctly.module="root"variables="networking"2025-01-10T11:39:05Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.transit_gateway_routes"value="cty.NilVal"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.aws_ec2_tag.cluster_primary_security_group"value="cty.NilVal"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks_cluster_logs_kms.data.aws_iam_policy_document.this[0]"err="1 error occurred:\n\t* invalid for-each in data.aws_iam_policy_document.this[0].dynamic.statement.content.dynamic.condition block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:10Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"airflow-high-memory\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:11Z ERROR [terraformevaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.block="module.eks.module.eks_managed_node_group[\"general\"].aws_iam_role_policy_attachment.this"value="cty.NilVal"2025-01-10T11:39:11Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:11Z ERROR [terraformevaluator] Failed to expand dynamic block.block="module.eks.module.eks_managed_node_group[\"general\"].aws_launch_template.this[0]"err="1 error occurred:\n\t* invalid for-each in aws_launch_template.this[0].dynamic.block_device_mappings block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"2025-01-10T11:39:11Z INFO [terraformexecutor] Ignore finding rule="aws-ec2-no-public-egress-sgr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/node_groups.tf:247"2025-01-10T11:39:11Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:69"2025-01-10T11:39:11Z INFO [terraformexecutor] Ignore finding rule="aws-eks-no-public-cluster-access-to-cidr"range="git::https:/github.com/terraform-aws-modules/terraform-aws-eks?ref=a713f6f464eb579a39918f60f130a5fbb77a6b30/main.tf:70"2025-01-10T11:39:11Z INFO Number of language-specific files num=02025-01-10T11:39:11Z INFO Detected config files num=14trivy_exitcode=0
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request: