forked from widdix/aws-cf-templates
-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathvpc-flow-logs-s3.yaml
113 lines (113 loc) · 3.93 KB
/
vpc-flow-logs-s3.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
---
# Copyright 2018 widdix GmbH
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
AWSTemplateFormatVersion: '2010-09-09'
Description: 'VPC: Publish flow logs to S3, a cloudonaut.io template'
Metadata:
'AWS::CloudFormation::Interface':
ParameterGroups:
- Label:
default: 'Parent Stacks'
Parameters:
- ParentVPCStack
- Label:
default: 'Flow Logs Parameters'
Parameters:
- ExternalLogBucket
- LogFilePrefix
- TrafficType
Parameters:
ParentVPCStack:
Description: 'Stack name of parent VPC stack based on vpc/vpc-*azs.yaml template.'
Type: String
ExternalLogBucket:
Description: 'Optional The name of an S3 bucket where you want to store flow logs. If you leave this empty, the Amazon S3 bucket is created for you.'
Type: String
Default: ''
LogFilePrefix:
Description: 'Optional The log file prefix.'
Type: String
Default: ''
TrafficType:
Description: 'The type of traffic to log.'
Type: String
Default: REJECT
AllowedValues:
- ACCEPT
- REJECT
- ALL
Conditions:
InternalBucket: !Equals [!Ref ExternalLogBucket, '']
ExternalBucket: !Not [!Equals [!Ref ExternalLogBucket, '']]
HasLogFilePrefix: !Not [!Equals [!Ref LogFilePrefix, '']]
Resources:
LogBucket:
Condition: InternalBucket
Type: 'AWS::S3::Bucket'
Properties: {}
LogBucketPolicy:
Condition: InternalBucket
Type: 'AWS::S3::BucketPolicy'
Properties:
Bucket: !Ref LogBucket
PolicyDocument:
Version: '2012-10-17'
Statement: # https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-s3.html#flow-logs-s3-permissions
- Sid: AWSLogDeliveryWrite
Effect: Allow
Principal:
Service: 'delivery.logs.amazonaws.com'
Action: 's3:PutObject'
Resource: !If [HasLogFilePrefix, !Sub '${LogBucket.Arn}/${LogFilePrefix}/AWSLogs/${AWS::AccountId}/*', !Sub '${LogBucket.Arn}/AWSLogs/${AWS::AccountId}/*']
Condition:
StringEquals:
's3:x-amz-acl': 'bucket-owner-full-control'
- Sid: AWSLogDeliveryAclCheck
Effect: Allow
Principal:
Service: 'delivery.logs.amazonaws.com'
Action: 's3:GetBucketAcl'
Resource: !GetAtt 'LogBucket.Arn'
FlowLogInternalBucket:
Condition: InternalBucket
DependsOn: LogBucketPolicy
Type: 'AWS::EC2::FlowLog'
Properties:
LogDestination: !If [HasLogFilePrefix, !Sub '${LogBucket.Arn}/${LogFilePrefix}/', !GetAtt 'LogBucket.Arn']
LogDestinationType: s3
ResourceId: {'Fn::ImportValue': !Sub '${ParentVPCStack}-VPC'}
ResourceType: 'VPC'
TrafficType: !Ref TrafficType
FlowLogExternalBucket:
Condition: ExternalBucket
Type: 'AWS::EC2::FlowLog'
Properties:
LogDestination: !If [HasLogFilePrefix, !Sub 'arn:aws:s3:::${ExternalLogBucket}/${LogFilePrefix}/', !Sub 'arn:aws:s3:::${ExternalLogBucket}']
LogDestinationType: s3
ResourceId: {'Fn::ImportValue': !Sub '${ParentVPCStack}-VPC'}
ResourceType: 'VPC'
TrafficType: !Ref TrafficType
Outputs:
TemplateID:
Description: 'cloudonaut.io template id.'
Value: 'vpc/vpc-flow-logs-s3'
TemplateVersion:
Description: 'cloudonaut.io template version.'
Value: '__VERSION__'
StackName:
Description: 'Stack name.'
Value: !Sub '${AWS::StackName}'
LogBucketName:
Description: 'Log bucket name.'
Value: !If [InternalBucket, !Ref LogBucket, !Ref ExternalLogBucket]