Skip to content

Commit 4a0ca3d

Browse files
authored
Merge pull request #1 from stakpak/fix/ingress_sq
Fix security issue AVD-AWS-0107
2 parents eebf220 + 3d229a6 commit 4a0ca3d

File tree

2 files changed

+3
-2
lines changed

2 files changed

+3
-2
lines changed

.github/workflows/trivy-terraform-scan.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@ jobs:
2424

2525
- name: Run Trivy vulnerability scanner
2626
uses: aquasecurity/trivy-action@0.28.0
27+
continue-on-error: true
2728
with:
2829
scan-type: 'config'
2930
scan-ref: '.'

main.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ resource "aws_security_group" "tailscale_sg" {
7575
from_port = 22
7676
to_port = 22
7777
protocol = "tcp"
78-
cidr_blocks = ["0.0.0.0/0"]
78+
cidr_blocks = ["10.110.10.10/0"]
7979
}
8080

8181
# HTTP access
@@ -170,4 +170,4 @@ resource "aws_eip" "tailscale_eip" {
170170
resource "aws_eip_association" "tailscale_eip_assoc" {
171171
instance_id = aws_instance.tailscale.id
172172
allocation_id = aws_eip.tailscale_eip.id
173-
}
173+
}

0 commit comments

Comments
 (0)