Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Mods
AWS
Loading controls...

Control: AWS > Route 53 Resolver > Resolver Rule > Allowed > Region

Take an action when an AWS Route 53 Resolver resolver rule is created in a region that is not allowed.

The Allowed > Region control checks if the resolver rule is created in an allowed region based on the Allowed > Region > * policies. If the resolver rule is created in a region that is not in the allowed list, this control raises an alarm and takes the defined enforcement action.

For any enforcement actions that specify if new, e.g., Enforce: Delete if region not allowed and resolver rule is new, this control will only take the enforcement actions for resources created within the last 60 minutes.

Resource Types

This control targets the following resource types:

  • AWS > Route 53 Resolver > Resolver Rule

Policies

The following policies can be used to configure this control:

  • AWS > Route 53 Resolver > Resolver Rule > Allowed > Region

This control type relies on these other policies when running actions:

  • AWS > Route 53 Resolver > Resolver Rule > Allowed > Region > Regions

Permissions

Cloud permissions used by this control and its actions:

  • route53resolver:DeleteResolverRule
  • route53resolver:DisassociateResolverRule

Category

  • Resource > Allowed

In Your Workspace

  • Controls by Resource report
  • Controls by Control Type report

Developers

    Control Type URI
    • tmod:@turbot/aws-route53resolver#/control/types/resolverRuleAllowedRegion
  • Category URI
    • tmod:@turbot/turbot#/control/categories/resourceAllowed
  • GraphQL
    • query controlType(id: "tmod:@turbot/aws-route53resolver#/control/types/resolverRuleAllowedRegion") { … }
    • query controls(filter: "controlTypeId:'tmod:@turbot/aws-route53resolver#/control/types/resolverRuleAllowedRegion'") { … }
  • CLI
    • Get Controls
    • turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-route53resolver#/control/types/resolverRuleAllowedRegion"
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy
181
Mods
521
Resource Types
9,177
Policies
3,582
Controls
1,955
Quick Actions
547
IAM