Skip to content
This repository was archived by the owner on Nov 10, 2025. It is now read-only.

Commit 19c318f

Browse files
committed
update to v2.0.2
1 parent b87862e commit 19c318f

File tree

7 files changed

+30
-24
lines changed

7 files changed

+30
-24
lines changed

CHANGELOG.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,12 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
66
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
77

8+
## [2.0.2] - 2022-05-09
9+
10+
### Changed
11+
12+
- Fix: Enforce encrypted access to config S3 buckets
13+
814
## [2.0.1] - 2022-04-14
915

1016
### Changed

deployment/aws-fms-automations.template

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"Description": "(SO0134) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations. Version v2.0.1",
2+
"Description": "(SO0134) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations. Version v2.0.2",
33
"AWSTemplateFormatVersion": "2010-09-09",
44
"Metadata": {
55
"AWS::CloudFormation::Interface": {
@@ -38,7 +38,7 @@
3838
},
3939
"Solution": {
4040
"SolutionId": "SO0134",
41-
"SolutionVersion": "v2.0.1"
41+
"SolutionVersion": "v2.0.2"
4242
}
4343
}
4444
},
@@ -286,7 +286,7 @@
286286
"S3Bucket": {
287287
"Fn::Sub": "solutions-${AWS::Region}"
288288
},
289-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/asset7d121ff6b5b2240d66521bfba24c9137d4e487d4d88b503015120636a794733f.zip"
289+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/assetb0fb6af9debb07eea6c649c1b1b91b817f8edecd385f04b04ef9f844e23bc0a6.zip"
290290
},
291291
"Role": {
292292
"Fn::GetAtt": [
@@ -447,7 +447,7 @@
447447
"S3Bucket": {
448448
"Fn::Sub": "solutions-${AWS::Region}"
449449
},
450-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/asset543c7a94b144a6259669eaf884305607b7a9abe85c43e4bfe62f9190ace37916.zip"
450+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset543c7a94b144a6259669eaf884305607b7a9abe85c43e4bfe62f9190ace37916.zip"
451451
},
452452
"Role": {
453453
"Fn::GetAtt": [
@@ -772,7 +772,7 @@
772772
"S3Bucket": {
773773
"Fn::Sub": "solutions-${AWS::Region}"
774774
},
775-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/assetcbc212180b21e031789014eb0d449ba42dc4902aeb261396a6c2a5fddda23eca.zip"
775+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset0179e7fbf546a23833885fe474c28e3679edfd838bb7427522423f00cef71682.zip"
776776
},
777777
"Role": {
778778
"Fn::GetAtt": [
@@ -895,7 +895,7 @@
895895
"ComplianceStack": {
896896
"Type": "AWS::CloudFormation::Stack",
897897
"Properties": {
898-
"TemplateURL": "https://solutions-reference.s3.amazonaws.com/aws-firewall-manager-automations-for-aws-organizations/v2.0.1/aws-fms-compliance.template",
898+
"TemplateURL": "https://solutions-reference.s3.amazonaws.com/aws-firewall-manager-automations-for-aws-organizations/v2.0.2/aws-fms-compliance.template",
899899
"Parameters": {
900900
"MetricsQueue": {
901901
"Fn::GetAtt": [
@@ -923,7 +923,7 @@
923923
"PolicyStack": {
924924
"Type": "AWS::CloudFormation::Stack",
925925
"Properties": {
926-
"TemplateURL": "https://solutions-reference.s3.amazonaws.com/aws-firewall-manager-automations-for-aws-organizations/v2.0.1/aws-fms-policy.template",
926+
"TemplateURL": "https://solutions-reference.s3.amazonaws.com/aws-firewall-manager-automations-for-aws-organizations/v2.0.2/aws-fms-policy.template",
927927
"Parameters": {
928928
"PolicyTable": {
929929
"Ref": "FMSTable84B8646C"

deployment/aws-fms-compliance.template

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"Description": "(SO0134-cr) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations compliance reporter resources. Version v2.0.1",
2+
"Description": "(SO0134-cr) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations compliance reporter resources. Version v2.0.2",
33
"AWSTemplateFormatVersion": "2010-09-09",
44
"Metadata": {
55
"AWS::CloudFormation::Interface": {
@@ -41,7 +41,7 @@
4141
},
4242
"Solution": {
4343
"SolutionId": "SO0134",
44-
"SolutionVersion": "v2.0.1"
44+
"SolutionVersion": "v2.0.2"
4545
}
4646
}
4747
},
@@ -320,7 +320,7 @@
320320
"S3Bucket": {
321321
"Fn::Sub": "solutions-${AWS::Region}"
322322
},
323-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/assetd47dad2be31cff0db7cf6349460680f6a94f0391344f22bbfc66d6d4ddaf123f.zip"
323+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset88636237c0e4a294ce83c7bf4f72b753d5d8c3cc8b14d7f8063ad3153278678e.zip"
324324
},
325325
"Role": {
326326
"Fn::GetAtt": [

deployment/aws-fms-demo.template

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"Description": "(SO0134D) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations demo resources. Version v2.0.1",
2+
"Description": "(SO0134D) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations demo resources. Version v2.0.2",
33
"AWSTemplateFormatVersion": "2010-09-09",
44
"Resources": {
55
"testcloudfronts3S3LoggingBucket90D239DD": {

deployment/aws-fms-policy.template

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"Description": "(SO0134-po) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations. Version v2.0.1",
2+
"Description": "(SO0134-po) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations. Version v2.0.2",
33
"AWSTemplateFormatVersion": "2010-09-09",
44
"Metadata": {
55
"AWS::CloudFormation::Interface": {
@@ -64,7 +64,7 @@
6464
},
6565
"Solution": {
6666
"SolutionId": "SO0134",
67-
"SolutionVersion": "v2.0.1"
67+
"SolutionVersion": "v2.0.2"
6868
}
6969
}
7070
},
@@ -297,7 +297,7 @@
297297
{
298298
"Ref": "ManifestBucket46C412A5"
299299
},
300-
"\",\"CopySource\":\"solutions-reference/aws-firewall-manager-automations-for-aws-organizations/v2.0.1/policy_manifest.json\",\"Key\":\"policy_manifest.json\"},\"physicalResourceId\":{\"id\":\"1649957921854\"}}"
300+
"\",\"CopySource\":\"solutions-reference/aws-firewall-manager-automations-for-aws-organizations/v2.0.2/policy_manifest.json\",\"Key\":\"policy_manifest.json\"},\"physicalResourceId\":{\"id\":\"1652122161364\"}}"
301301
]
302302
]
303303
},
@@ -353,7 +353,7 @@
353353
"S3Bucket": {
354354
"Fn::Sub": "solutions-${AWS::Region}"
355355
},
356-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/asset70893b631249dc61260989e92e90d60ae94fbbec490a1e065680d77383084d8d.zip"
356+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset70893b631249dc61260989e92e90d60ae94fbbec490a1e065680d77383084d8d.zip"
357357
},
358358
"Role": {
359359
"Fn::GetAtt": [
@@ -499,7 +499,7 @@
499499
"S3Bucket": {
500500
"Fn::Sub": "solutions-${AWS::Region}"
501501
},
502-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/assete44617e41a42d04987a954188ec99b79d6bd0a40dba3e296c5e68ecf9bae774e.zip"
502+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset20a6ddee216fc547e092b7d7269e7d861280ad0a4e13e97cc0e7157ce3e4cfa2.zip"
503503
},
504504
"Role": {
505505
"Fn::GetAtt": [

deployment/aws-fms-prereq.template

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"Description": "(SO0134N) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations. Version v2.0.1",
2+
"Description": "(SO0134N) - The AWS CloudFormation template for deployment of the aws-firewall-manager-automations-for-aws-organizations. Version v2.0.2",
33
"AWSTemplateFormatVersion": "2010-09-09",
44
"Metadata": {
55
"AWS::CloudFormation::Interface": {
@@ -48,7 +48,7 @@
4848
},
4949
"Solution": {
5050
"SolutionId": "SO0134N",
51-
"SolutionVersion": "v2.0.1",
51+
"SolutionVersion": "v2.0.2",
5252
"GlobalStackSetName": "FMS-EnableConfig-Global",
5353
"RegionalStackSetName": "FMS-EnableConfig-Regional"
5454
}
@@ -96,7 +96,7 @@
9696
"S3Bucket": {
9797
"Fn::Sub": "solutions-${AWS::Region}"
9898
},
99-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/asset7d121ff6b5b2240d66521bfba24c9137d4e487d4d88b503015120636a794733f.zip"
99+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/assetb0fb6af9debb07eea6c649c1b1b91b817f8edecd385f04b04ef9f844e23bc0a6.zip"
100100
},
101101
"Role": {
102102
"Fn::GetAtt": [
@@ -244,7 +244,7 @@
244244
"S3Bucket": {
245245
"Fn::Sub": "solutions-${AWS::Region}"
246246
},
247-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/asset543c7a94b144a6259669eaf884305607b7a9abe85c43e4bfe62f9190ace37916.zip"
247+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset543c7a94b144a6259669eaf884305607b7a9abe85c43e4bfe62f9190ace37916.zip"
248248
},
249249
"Role": {
250250
"Fn::GetAtt": [
@@ -384,7 +384,7 @@
384384
"S3Bucket": {
385385
"Fn::Sub": "solutions-${AWS::Region}"
386386
},
387-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/asset24a001b98f37514aaeedadeb46bf816090c31d13c5904895b4a3eaa7139371a4.zip"
387+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset2ce0363386151b1ade9f4327e5fba71018394df8f106609a4a5fab0fd38ebf36.zip"
388388
},
389389
"Role": {
390390
"Fn::GetAtt": [
@@ -626,7 +626,7 @@
626626
"S3Bucket": {
627627
"Fn::Sub": "solutions-${AWS::Region}"
628628
},
629-
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.1/asset543c7a94b144a6259669eaf884305607b7a9abe85c43e4bfe62f9190ace37916.zip"
629+
"S3Key": "aws-firewall-manager-automations-for-aws-organizations/v2.0.2/asset543c7a94b144a6259669eaf884305607b7a9abe85c43e4bfe62f9190ace37916.zip"
630630
},
631631
"Role": {
632632
"Fn::GetAtt": [

source/services/preReqManager/lib/enableConfig.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -163,8 +163,8 @@
163163
"Effect":"Deny",
164164
"Principal": "*",
165165
"Resource": [
166-
"arn:aws:s3:::${ConfigBucket}/*",
167-
"arn:aws:s3:::${ConfigBucket}"
166+
{ "Fn::Sub": "arn:aws:s3:::${ConfigBucket}/*" },
167+
{ "Fn::Sub": "arn:aws:s3:::${ConfigBucket}" }
168168
],
169169
"Condition":{
170170
"Bool":

0 commit comments

Comments
 (0)