Winch Labs

Reference

The rule catalog

Generated from the source tree by cmd/docsgen. Do not edit: your change would be overwritten on the next run, and the point of this page is that it cannot disagree with the binary.

Catalog rules are opt-in: nothing here runs until your organisation adopts it, individually or through a profile. They are re-expressed in Garboard's own rule language rather than copied, and each cites the upstream check it mirrors in source_id so you can compare them yourself.

RuleSeverityUpstreamWhat it checks
lib.aws.apigateway_access_logswarnCKV_AWS_76API Gateway stage declares no access logging
lib.aws.apigateway_xrayinfoAPI Gateway stage does not state X-Ray tracing
lib.aws.backup_vault_customer_managed_keyinfoCKV_AWS_166Backup vault uses the default encryption key
lib.aws.cloudfront_web_aclinfoCloudFront distribution has no WAF association
lib.aws.cloudtrail_kms_keywarnCKV_AWS_35CloudTrail trail uses default log encryption
lib.aws.cloudtrail_log_file_validationwarnCKV_AWS_36CloudTrail trail does not state log file validation
lib.aws.cloudtrail_logging_enabledcriticalCloudTrail trail is switched off
lib.aws.cloudtrail_multi_regionwarnCKV_AWS_67CloudTrail trail is not stated as multi-region
lib.aws.cloudwatch_log_group_kmsinfoCKV_AWS_158CloudWatch log group uses default log encryption
lib.aws.cloudwatch_log_group_retentionwarnCKV_AWS_66CloudWatch log group keeps logs forever
lib.aws.docdb_storage_encryptedwarnCKV_AWS_74DocumentDB cluster does not state storage encryption
lib.aws.dynamodb_customer_managed_keyinfoCKV_AWS_119DynamoDB table uses the AWS-owned encryption key
lib.aws.dynamodb_point_in_time_recoverywarnCKV_AWS_28DynamoDB table has no point-in-time recovery block
lib.aws.ebs_volume_customer_managed_keyinfoCKV_AWS_189EBS volume uses the default EBS encryption key
lib.aws.ebs_volume_encryptedcriticalCKV_AWS_3EBS volume disables encryption
lib.aws.ec2_detailed_monitoringinfoCKV_AWS_126EC2 instance does not state detailed monitoring
lib.aws.ec2_metadata_optionswarnCKV_AWS_79EC2 instance declares no instance metadata options
lib.aws.ec2_public_ipwarnCKV_AWS_88EC2 instance takes a public IP address
lib.aws.ecr_immutable_tagswarnCKV_AWS_51ECR repository allows tags to be overwritten
lib.aws.ecr_kms_encryptioninfoCKV_AWS_136ECR repository uses the default registry encryption
lib.aws.ecr_scan_on_pushwarnCKV_AWS_163ECR repository declares no image scanning
lib.aws.ecs_cluster_settinginfoCKV_AWS_65ECS cluster declares no cluster settings
lib.aws.efs_encryptedwarnCKV_AWS_42EFS file system does not state encryption at rest
lib.aws.eks_control_plane_loggingwarnCKV_AWS_37EKS cluster enables no control plane logging
lib.aws.eks_secrets_encryptionwarnCKV_AWS_58EKS cluster declares no envelope encryption for secrets
lib.aws.elasticache_at_rest_encryptionwarnCKV_AWS_29ElastiCache replication group does not state at-rest encryption
lib.aws.elasticache_customer_managed_keyinfoCKV_AWS_191ElastiCache replication group uses the default encryption key
lib.aws.elasticache_transit_encryptionwarnCKV_AWS_30ElastiCache replication group does not state in-transit encryption
lib.aws.iam_password_require_lowercasewarnCKV_AWS_11Account password policy drops the lowercase requirement
lib.aws.iam_password_require_numberswarnCKV_AWS_12Account password policy drops the digit requirement
lib.aws.iam_password_require_symbolswarnCKV_AWS_14Account password policy drops the symbol requirement
lib.aws.iam_password_require_uppercasewarnCKV_AWS_15Account password policy drops the uppercase requirement
lib.aws.kms_key_rotationwarnCKV_AWS_7KMS key does not state automatic rotation
lib.aws.lambda_dead_letter_queueinfoCKV_AWS_116Lambda function declares no dead letter queue
lib.aws.lambda_environment_customer_managed_keyinfoCKV_AWS_173Lambda environment variables use the default encryption key
lib.aws.lambda_reserved_concurrencyinfoCKV_AWS_115Lambda function sets no concurrency limit
lib.aws.lambda_tracinginfoCKV_AWS_50Lambda function declares no tracing configuration
lib.aws.launch_template_metadata_optionswarnCKV_AWS_79Launch template declares no instance metadata options
lib.aws.lb_access_logsinfoCKV_AWS_91Load balancer declares no access logging
lib.aws.lb_deletion_protectionwarnCKV_AWS_150Load balancer opts out of deletion protection
lib.aws.lb_drop_invalid_headersinfoCKV_AWS_131Load balancer does not state header sanitisation
lib.aws.rds_auto_minor_upgradeinfoCKV_AWS_226RDS opts out of automatic minor version upgrades
lib.aws.rds_backup_retentionwarnCKV_AWS_133RDS instance configures no backup retention
lib.aws.rds_cluster_backup_retentionwarnCKV_AWS_133Aurora cluster configures no backup retention
lib.aws.rds_cluster_deletion_protectionwarnCKV_AWS_139Aurora cluster opts out of deletion protection
lib.aws.rds_cluster_storage_encryptedcriticalCKV_AWS_96Aurora cluster disables storage encryption
lib.aws.rds_multi_azwarnCKV_AWS_157RDS instance opts out of Multi-AZ
lib.aws.rds_publicly_accessiblecriticalCKV_AWS_17RDS instance is reachable from the internet
lib.aws.rds_storage_encryptedcriticalCKV_AWS_16RDS instance disables storage encryption
lib.aws.redshift_encryptedwarnCKV_AWS_64Redshift cluster does not state encryption at rest
lib.aws.redshift_publicly_accessiblecriticalRedshift cluster is reachable from the internet
lib.aws.s3_bucket_aclcriticalCKV_AWS_20S3 ACL grants access beyond the bucket owner
lib.aws.s3_public_access_block_aclswarnS3 public access block permits public ACLs
lib.aws.s3_public_access_block_ignore_aclswarnS3 public access block honours existing public ACLs
lib.aws.s3_public_access_block_policywarnS3 public access block permits public bucket policies
lib.aws.s3_public_access_block_restrictwarnS3 public access block does not restrict cross-account policies
lib.aws.secretsmanager_customer_managed_keyinfoCKV_AWS_149Secrets Manager secret uses the default encryption key
lib.aws.security_group_descriptioninfoCKV_AWS_23Security group has no description
lib.aws.sns_topic_encryptedwarnCKV_AWS_26SNS topic has no server-side encryption key
lib.aws.sqs_queue_customer_managed_keyinfoCKV_AWS_27SQS queue uses the default encryption key
lib.azure.acr_admin_accountwarnContainer registry enables the admin account
lib.azure.acr_public_network_accessinfoContainer registry is open to all networks
lib.azure.aks_azure_policyinfoAKS cluster does not state the Azure Policy add-on
lib.azure.aks_http_application_routingwarnAKS cluster enables the HTTP application routing add-on
lib.azure.aks_local_accountsinfoAKS cluster does not state local account handling
lib.azure.aks_private_clusterwarnAKS cluster does not state a private API server
lib.azure.aks_role_based_access_controlcriticalAKS cluster disables Kubernetes RBAC
lib.azure.cosmosdb_public_network_accesswarnCosmos DB account is open to all networks
lib.azure.function_app_https_onlywarnFunction app does not state HTTPS-only
lib.azure.key_vault_key_expiryinfoKey vault key has no expiration date
lib.azure.key_vault_network_aclswarnKey vault declares no network ACLs
lib.azure.key_vault_public_network_accessinfoKey vault is open to all networks
lib.azure.key_vault_purge_protectionwarnKey vault does not state purge protection
lib.azure.key_vault_secret_expiryinfoKey vault secret has no expiration date
lib.azure.managed_disk_encryption_setinfoManaged disk uses platform-managed encryption keys
lib.azure.mssql_database_encryptioncriticalSQL database disables transparent data encryption
lib.azure.mssql_min_tls_versionwarnSQL server accepts TLS below 1.2
lib.azure.mssql_public_network_accesswarnSQL server is open to all networks
lib.azure.redis_min_tls_versionwarnRedis cache accepts TLS below 1.2
lib.azure.storage_container_public_accesscriticalazure-storage-no-public-accessStorage container allows anonymous access
lib.azure.storage_min_tls_versionwarnazure-storage-use-secure-tls-policyStorage account accepts TLS below 1.2
lib.azure.storage_nested_items_publicwarnStorage account allows containers to be made public
lib.azure.storage_public_network_accesswarnStorage account is open to all networks
lib.azure.storage_shared_access_keyinfoStorage account allows shared key authorisation
lib.azure.vm_password_authenticationwarnazure-compute-disable-password-authenticationLinux VM allows password authentication over SSH
lib.azure.web_app_https_onlywarnWeb app does not state HTTPS-only
lib.gcp.artifact_registry_customer_managed_keyinfoArtifact Registry repository uses Google-managed encryption keys
lib.gcp.bigquery_dataset_customer_managed_keyinfoBigQuery dataset uses Google-managed encryption keys
lib.gcp.bigtable_deletion_protectioninfoBigtable instance opts out of deletion protection
lib.gcp.cloudfunction_ingress_settingsinfoCloud Function accepts requests from the internet
lib.gcp.compute_disk_customer_managed_keyinfogoogle-compute-disk-encryption-customer-keyCompute disk uses Google-managed encryption keys
lib.gcp.compute_ip_forwardinginfogoogle-compute-no-ip-forwardingCompute instance enables IP forwarding
lib.gcp.compute_shielded_vminfoCompute instance declares no Shielded VM configuration
lib.gcp.dns_managed_zone_dnssecwarnManaged DNS zone declares no DNSSEC configuration
lib.gcp.gke_binary_authorizationinfoGKE cluster declares no binary authorization
lib.gcp.gke_database_encryptionwarnGKE cluster declares no application-layer secrets encryption
lib.gcp.gke_legacy_abacwarngoogle-gke-use-rbac-permissionsGKE cluster enables legacy ABAC
lib.gcp.gke_network_policyinfogoogle-gke-enable-network-policyGKE cluster declares no network policy
lib.gcp.gke_private_clusterwarngoogle-gke-enable-private-clusterGKE cluster declares no private cluster configuration
lib.gcp.gke_remove_default_node_poolinfoGKE cluster does not state removal of the default node pool
lib.gcp.gke_shielded_nodesinfogoogle-gke-node-shielding-enabledGKE cluster does not state shielded nodes
lib.gcp.kms_key_rotation_periodwarnKMS crypto key has no rotation period
lib.gcp.pubsub_topic_customer_managed_keyinfoPub/Sub topic uses Google-managed encryption keys
lib.gcp.redis_transit_encryptionwarnMemorystore Redis instance does not require TLS
lib.gcp.spanner_deletion_protectioninfoSpanner database opts out of deletion protection
lib.gcp.sql_deletion_protectionwarnCloud SQL instance opts out of deletion protection
lib.gcp.storage_logginginfoStorage bucket declares no access logging
lib.gcp.storage_public_access_preventionwarnStorage bucket does not enforce public access prevention
lib.gcp.storage_uniform_bucket_level_accesswarnStorage bucket does not state uniform bucket-level access
lib.gcp.storage_versioninginfoStorage bucket declares no versioning
lib.gcp.subnetwork_flow_logswarngoogle-compute-enable-vpc-flow-logsSubnetwork declares no VPC flow logs
lib.gcp.subnetwork_private_google_accessinfoSubnetwork does not state private Google access

112 catalog rules.