Skip to content

Commit dd4ff91

Browse files
daniel-citgtsorbo
andauthored
fix: add VPC Flow logs exceptions for REGIONAL_MANAGED_PROXY and INTERNAL_HTTPS_LOAD_BALANCER (#976)
Co-authored-by: Grant Sorbo <[email protected]>
1 parent 9e06ccd commit dd4ff91

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

policy-library/policies/templates/gcp_network_enable_flow_logs_v1.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,9 +62,12 @@ spec:
6262
legacy_enable_flow_logs := lib.get_default(network, "enableFlowLogs", false)
6363
log_config := lib.get_default(network, "logConfig", {})
6464
log_config_enable_flow_logs := lib.get_default(log_config, "enable", false)
65+
purpose := lib.get_default(network, "purpose", "PRIVATE")
6566
6667
log_config_enable_flow_logs != true
6768
legacy_enable_flow_logs != true
69+
purpose != "REGIONAL_MANAGED_PROXY"
70+
purpose != "INTERNAL_HTTPS_LOAD_BALANCER"
6871
6972
message := sprintf("Flow logs are disabled in subnetwork %v.", [asset.name])
7073
metadata := {"resource": asset.name}

0 commit comments

Comments
 (0)