Skip to content

Conversation

boueya
Copy link
Contributor

@boueya boueya commented Dec 11, 2024

Added a few clarifying updates to the documentation.


Bug fix for: Issue 156

Currently, the script does not deploy a lambda code layer directory when the --solution_directory argument is passed. I've updated the logic to add this.


Update for: Issue 273

Currently, in Control Tower enabled environments, the sra-easy-setup deploys a control tower custom role for the ConfigRecorder and is picked up as a Critical finding in SecurityHub because security guidance recommends the use of a service linked role. The custom role however only has a Config managed policy applied to it.

Because this managed policy doesn't appear to provide additional access not included in the ConfigRecorder service linked role, I've replaced the custom role with the service linked role.


By submitting this pull request, I confirm that my contribution is made under the terms of the [Apache 2.0 license].

Apache 2.0 License

@boueya boueya closed this Dec 13, 2024
@boueya boueya reopened this Jan 7, 2025
@boueya boueya closed this Jan 8, 2025
@boueya
Copy link
Contributor Author

boueya commented Jan 8, 2025

I messed up my branching with this pull request. I've recreated them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant