Reference
The rule catalog
Generated from the source tree by cmd/docsgen. Do not edit: your change would be overwritten on the next run, and the point of this page is that it cannot disagree with the binary.
Catalog rules are opt-in: nothing here runs until your organisation adopts it, individually or through a profile. They are re-expressed in Garboard's own rule language rather than copied, and each cites the upstream check it mirrors in source_id so you can compare them yourself.
| Rule | Severity | Upstream | What it checks |
|---|---|---|---|
lib.aws.apigateway_access_logs | warn | CKV_AWS_76 | API Gateway stage declares no access logging |
lib.aws.apigateway_xray | info | — | API Gateway stage does not state X-Ray tracing |
lib.aws.backup_vault_customer_managed_key | info | CKV_AWS_166 | Backup vault uses the default encryption key |
lib.aws.cloudfront_web_acl | info | — | CloudFront distribution has no WAF association |
lib.aws.cloudtrail_kms_key | warn | CKV_AWS_35 | CloudTrail trail uses default log encryption |
lib.aws.cloudtrail_log_file_validation | warn | CKV_AWS_36 | CloudTrail trail does not state log file validation |
lib.aws.cloudtrail_logging_enabled | critical | — | CloudTrail trail is switched off |
lib.aws.cloudtrail_multi_region | warn | CKV_AWS_67 | CloudTrail trail is not stated as multi-region |
lib.aws.cloudwatch_log_group_kms | info | CKV_AWS_158 | CloudWatch log group uses default log encryption |
lib.aws.cloudwatch_log_group_retention | warn | CKV_AWS_66 | CloudWatch log group keeps logs forever |
lib.aws.docdb_storage_encrypted | warn | CKV_AWS_74 | DocumentDB cluster does not state storage encryption |
lib.aws.dynamodb_customer_managed_key | info | CKV_AWS_119 | DynamoDB table uses the AWS-owned encryption key |
lib.aws.dynamodb_point_in_time_recovery | warn | CKV_AWS_28 | DynamoDB table has no point-in-time recovery block |
lib.aws.ebs_volume_customer_managed_key | info | CKV_AWS_189 | EBS volume uses the default EBS encryption key |
lib.aws.ebs_volume_encrypted | critical | CKV_AWS_3 | EBS volume disables encryption |
lib.aws.ec2_detailed_monitoring | info | CKV_AWS_126 | EC2 instance does not state detailed monitoring |
lib.aws.ec2_metadata_options | warn | CKV_AWS_79 | EC2 instance declares no instance metadata options |
lib.aws.ec2_public_ip | warn | CKV_AWS_88 | EC2 instance takes a public IP address |
lib.aws.ecr_immutable_tags | warn | CKV_AWS_51 | ECR repository allows tags to be overwritten |
lib.aws.ecr_kms_encryption | info | CKV_AWS_136 | ECR repository uses the default registry encryption |
lib.aws.ecr_scan_on_push | warn | CKV_AWS_163 | ECR repository declares no image scanning |
lib.aws.ecs_cluster_setting | info | CKV_AWS_65 | ECS cluster declares no cluster settings |
lib.aws.efs_encrypted | warn | CKV_AWS_42 | EFS file system does not state encryption at rest |
lib.aws.eks_control_plane_logging | warn | CKV_AWS_37 | EKS cluster enables no control plane logging |
lib.aws.eks_secrets_encryption | warn | CKV_AWS_58 | EKS cluster declares no envelope encryption for secrets |
lib.aws.elasticache_at_rest_encryption | warn | CKV_AWS_29 | ElastiCache replication group does not state at-rest encryption |
lib.aws.elasticache_customer_managed_key | info | CKV_AWS_191 | ElastiCache replication group uses the default encryption key |
lib.aws.elasticache_transit_encryption | warn | CKV_AWS_30 | ElastiCache replication group does not state in-transit encryption |
lib.aws.iam_password_require_lowercase | warn | CKV_AWS_11 | Account password policy drops the lowercase requirement |
lib.aws.iam_password_require_numbers | warn | CKV_AWS_12 | Account password policy drops the digit requirement |
lib.aws.iam_password_require_symbols | warn | CKV_AWS_14 | Account password policy drops the symbol requirement |
lib.aws.iam_password_require_uppercase | warn | CKV_AWS_15 | Account password policy drops the uppercase requirement |
lib.aws.kms_key_rotation | warn | CKV_AWS_7 | KMS key does not state automatic rotation |
lib.aws.lambda_dead_letter_queue | info | CKV_AWS_116 | Lambda function declares no dead letter queue |
lib.aws.lambda_environment_customer_managed_key | info | CKV_AWS_173 | Lambda environment variables use the default encryption key |
lib.aws.lambda_reserved_concurrency | info | CKV_AWS_115 | Lambda function sets no concurrency limit |
lib.aws.lambda_tracing | info | CKV_AWS_50 | Lambda function declares no tracing configuration |
lib.aws.launch_template_metadata_options | warn | CKV_AWS_79 | Launch template declares no instance metadata options |
lib.aws.lb_access_logs | info | CKV_AWS_91 | Load balancer declares no access logging |
lib.aws.lb_deletion_protection | warn | CKV_AWS_150 | Load balancer opts out of deletion protection |
lib.aws.lb_drop_invalid_headers | info | CKV_AWS_131 | Load balancer does not state header sanitisation |
lib.aws.rds_auto_minor_upgrade | info | CKV_AWS_226 | RDS opts out of automatic minor version upgrades |
lib.aws.rds_backup_retention | warn | CKV_AWS_133 | RDS instance configures no backup retention |
lib.aws.rds_cluster_backup_retention | warn | CKV_AWS_133 | Aurora cluster configures no backup retention |
lib.aws.rds_cluster_deletion_protection | warn | CKV_AWS_139 | Aurora cluster opts out of deletion protection |
lib.aws.rds_cluster_storage_encrypted | critical | CKV_AWS_96 | Aurora cluster disables storage encryption |
lib.aws.rds_multi_az | warn | CKV_AWS_157 | RDS instance opts out of Multi-AZ |
lib.aws.rds_publicly_accessible | critical | CKV_AWS_17 | RDS instance is reachable from the internet |
lib.aws.rds_storage_encrypted | critical | CKV_AWS_16 | RDS instance disables storage encryption |
lib.aws.redshift_encrypted | warn | CKV_AWS_64 | Redshift cluster does not state encryption at rest |
lib.aws.redshift_publicly_accessible | critical | — | Redshift cluster is reachable from the internet |
lib.aws.s3_bucket_acl | critical | CKV_AWS_20 | S3 ACL grants access beyond the bucket owner |
lib.aws.s3_public_access_block_acls | warn | — | S3 public access block permits public ACLs |
lib.aws.s3_public_access_block_ignore_acls | warn | — | S3 public access block honours existing public ACLs |
lib.aws.s3_public_access_block_policy | warn | — | S3 public access block permits public bucket policies |
lib.aws.s3_public_access_block_restrict | warn | — | S3 public access block does not restrict cross-account policies |
lib.aws.secretsmanager_customer_managed_key | info | CKV_AWS_149 | Secrets Manager secret uses the default encryption key |
lib.aws.security_group_description | info | CKV_AWS_23 | Security group has no description |
lib.aws.sns_topic_encrypted | warn | CKV_AWS_26 | SNS topic has no server-side encryption key |
lib.aws.sqs_queue_customer_managed_key | info | CKV_AWS_27 | SQS queue uses the default encryption key |
lib.azure.acr_admin_account | warn | — | Container registry enables the admin account |
lib.azure.acr_public_network_access | info | — | Container registry is open to all networks |
lib.azure.aks_azure_policy | info | — | AKS cluster does not state the Azure Policy add-on |
lib.azure.aks_http_application_routing | warn | — | AKS cluster enables the HTTP application routing add-on |
lib.azure.aks_local_accounts | info | — | AKS cluster does not state local account handling |
lib.azure.aks_private_cluster | warn | — | AKS cluster does not state a private API server |
lib.azure.aks_role_based_access_control | critical | — | AKS cluster disables Kubernetes RBAC |
lib.azure.cosmosdb_public_network_access | warn | — | Cosmos DB account is open to all networks |
lib.azure.function_app_https_only | warn | — | Function app does not state HTTPS-only |
lib.azure.key_vault_key_expiry | info | — | Key vault key has no expiration date |
lib.azure.key_vault_network_acls | warn | — | Key vault declares no network ACLs |
lib.azure.key_vault_public_network_access | info | — | Key vault is open to all networks |
lib.azure.key_vault_purge_protection | warn | — | Key vault does not state purge protection |
lib.azure.key_vault_secret_expiry | info | — | Key vault secret has no expiration date |
lib.azure.managed_disk_encryption_set | info | — | Managed disk uses platform-managed encryption keys |
lib.azure.mssql_database_encryption | critical | — | SQL database disables transparent data encryption |
lib.azure.mssql_min_tls_version | warn | — | SQL server accepts TLS below 1.2 |
lib.azure.mssql_public_network_access | warn | — | SQL server is open to all networks |
lib.azure.redis_min_tls_version | warn | — | Redis cache accepts TLS below 1.2 |
lib.azure.storage_container_public_access | critical | azure-storage-no-public-access | Storage container allows anonymous access |
lib.azure.storage_min_tls_version | warn | azure-storage-use-secure-tls-policy | Storage account accepts TLS below 1.2 |
lib.azure.storage_nested_items_public | warn | — | Storage account allows containers to be made public |
lib.azure.storage_public_network_access | warn | — | Storage account is open to all networks |
lib.azure.storage_shared_access_key | info | — | Storage account allows shared key authorisation |
lib.azure.vm_password_authentication | warn | azure-compute-disable-password-authentication | Linux VM allows password authentication over SSH |
lib.azure.web_app_https_only | warn | — | Web app does not state HTTPS-only |
lib.gcp.artifact_registry_customer_managed_key | info | — | Artifact Registry repository uses Google-managed encryption keys |
lib.gcp.bigquery_dataset_customer_managed_key | info | — | BigQuery dataset uses Google-managed encryption keys |
lib.gcp.bigtable_deletion_protection | info | — | Bigtable instance opts out of deletion protection |
lib.gcp.cloudfunction_ingress_settings | info | — | Cloud Function accepts requests from the internet |
lib.gcp.compute_disk_customer_managed_key | info | google-compute-disk-encryption-customer-key | Compute disk uses Google-managed encryption keys |
lib.gcp.compute_ip_forwarding | info | google-compute-no-ip-forwarding | Compute instance enables IP forwarding |
lib.gcp.compute_shielded_vm | info | — | Compute instance declares no Shielded VM configuration |
lib.gcp.dns_managed_zone_dnssec | warn | — | Managed DNS zone declares no DNSSEC configuration |
lib.gcp.gke_binary_authorization | info | — | GKE cluster declares no binary authorization |
lib.gcp.gke_database_encryption | warn | — | GKE cluster declares no application-layer secrets encryption |
lib.gcp.gke_legacy_abac | warn | google-gke-use-rbac-permissions | GKE cluster enables legacy ABAC |
lib.gcp.gke_network_policy | info | google-gke-enable-network-policy | GKE cluster declares no network policy |
lib.gcp.gke_private_cluster | warn | google-gke-enable-private-cluster | GKE cluster declares no private cluster configuration |
lib.gcp.gke_remove_default_node_pool | info | — | GKE cluster does not state removal of the default node pool |
lib.gcp.gke_shielded_nodes | info | google-gke-node-shielding-enabled | GKE cluster does not state shielded nodes |
lib.gcp.kms_key_rotation_period | warn | — | KMS crypto key has no rotation period |
lib.gcp.pubsub_topic_customer_managed_key | info | — | Pub/Sub topic uses Google-managed encryption keys |
lib.gcp.redis_transit_encryption | warn | — | Memorystore Redis instance does not require TLS |
lib.gcp.spanner_deletion_protection | info | — | Spanner database opts out of deletion protection |
lib.gcp.sql_deletion_protection | warn | — | Cloud SQL instance opts out of deletion protection |
lib.gcp.storage_logging | info | — | Storage bucket declares no access logging |
lib.gcp.storage_public_access_prevention | warn | — | Storage bucket does not enforce public access prevention |
lib.gcp.storage_uniform_bucket_level_access | warn | — | Storage bucket does not state uniform bucket-level access |
lib.gcp.storage_versioning | info | — | Storage bucket declares no versioning |
lib.gcp.subnetwork_flow_logs | warn | google-compute-enable-vpc-flow-logs | Subnetwork declares no VPC flow logs |
lib.gcp.subnetwork_private_google_access | info | — | Subnetwork does not state private Google access |
112 catalog rules.
