Skip to content

19 files changed

+1405
-0
lines changed

docs/rules/README.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1182,6 +1182,22 @@ These rules enforce best practices and naming conventions:
11821182
|aws_ssm_patch_group_invalid_baseline_id||
11831183
|aws_ssm_patch_group_invalid_patch_group||
11841184
|aws_ssm_resource_data_sync_invalid_name||
1185+
|aws_ssoadmin_account_assignment_invalid_instance_arn||
1186+
|aws_ssoadmin_account_assignment_invalid_permission_set_arn||
1187+
|aws_ssoadmin_account_assignment_invalid_principal_id||
1188+
|aws_ssoadmin_account_assignment_invalid_principal_type||
1189+
|aws_ssoadmin_account_assignment_invalid_target_id||
1190+
|aws_ssoadmin_account_assignment_invalid_target_type||
1191+
|aws_ssoadmin_managed_policy_attachment_invalid_instance_arn||
1192+
|aws_ssoadmin_managed_policy_attachment_invalid_managed_policy_arn||
1193+
|aws_ssoadmin_managed_policy_attachment_invalid_permission_set_arn||
1194+
|aws_ssoadmin_permission_set_inline_policy_invalid_inline_policy||
1195+
|aws_ssoadmin_permission_set_inline_policy_invalid_instance_arn||
1196+
|aws_ssoadmin_permission_set_inline_policy_invalid_permission_set_arn||
1197+
|aws_ssoadmin_permission_set_invalid_description||
1198+
|aws_ssoadmin_permission_set_invalid_instance_arn||
1199+
|aws_ssoadmin_permission_set_invalid_name||
1200+
|aws_ssoadmin_permission_set_invalid_relay_state||
11851201
|aws_storagegateway_cache_invalid_disk_id||
11861202
|aws_storagegateway_cache_invalid_gateway_arn||
11871203
|aws_storagegateway_cached_iscsi_volume_invalid_gateway_arn||
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
// This file generated by `generator/`. DO NOT EDIT
2+
3+
package models
4+
5+
import (
6+
"fmt"
7+
"log"
8+
"regexp"
9+
10+
hcl "github.com/hashicorp/hcl/v2"
11+
"github.com/terraform-linters/tflint-plugin-sdk/tflint"
12+
)
13+
14+
// AwsSsoadminAccountAssignmentInvalidInstanceArnRule checks the pattern is valid
15+
type AwsSsoadminAccountAssignmentInvalidInstanceArnRule struct {
16+
resourceType string
17+
attributeName string
18+
max int
19+
min int
20+
pattern *regexp.Regexp
21+
}
22+
23+
// NewAwsSsoadminAccountAssignmentInvalidInstanceArnRule returns new rule with default attributes
24+
func NewAwsSsoadminAccountAssignmentInvalidInstanceArnRule() *AwsSsoadminAccountAssignmentInvalidInstanceArnRule {
25+
return &AwsSsoadminAccountAssignmentInvalidInstanceArnRule{
26+
resourceType: "aws_ssoadmin_account_assignment",
27+
attributeName: "instance_arn",
28+
max: 1224,
29+
min: 10,
30+
pattern: regexp.MustCompile(`^arn:aws:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}$`),
31+
}
32+
}
33+
34+
// Name returns the rule name
35+
func (r *AwsSsoadminAccountAssignmentInvalidInstanceArnRule) Name() string {
36+
return "aws_ssoadmin_account_assignment_invalid_instance_arn"
37+
}
38+
39+
// Enabled returns whether the rule is enabled by default
40+
func (r *AwsSsoadminAccountAssignmentInvalidInstanceArnRule) Enabled() bool {
41+
return true
42+
}
43+
44+
// Severity returns the rule severity
45+
func (r *AwsSsoadminAccountAssignmentInvalidInstanceArnRule) Severity() string {
46+
return tflint.ERROR
47+
}
48+
49+
// Link returns the rule reference link
50+
func (r *AwsSsoadminAccountAssignmentInvalidInstanceArnRule) Link() string {
51+
return ""
52+
}
53+
54+
// Check checks the pattern is valid
55+
func (r *AwsSsoadminAccountAssignmentInvalidInstanceArnRule) Check(runner tflint.Runner) error {
56+
log.Printf("[TRACE] Check `%s` rule", r.Name())
57+
58+
return runner.WalkResourceAttributes(r.resourceType, r.attributeName, func(attribute *hcl.Attribute) error {
59+
var val string
60+
err := runner.EvaluateExpr(attribute.Expr, &val, nil)
61+
62+
return runner.EnsureNoError(err, func() error {
63+
if len(val) > r.max {
64+
runner.EmitIssueOnExpr(
65+
r,
66+
"instance_arn must be 1224 characters or less",
67+
attribute.Expr,
68+
)
69+
}
70+
if len(val) < r.min {
71+
runner.EmitIssueOnExpr(
72+
r,
73+
"instance_arn must be 10 characters or higher",
74+
attribute.Expr,
75+
)
76+
}
77+
if !r.pattern.MatchString(val) {
78+
runner.EmitIssueOnExpr(
79+
r,
80+
fmt.Sprintf(`"%s" does not match valid pattern %s`, truncateLongMessage(val), `^arn:aws:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}$`),
81+
attribute.Expr,
82+
)
83+
}
84+
return nil
85+
})
86+
})
87+
}
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
// This file generated by `generator/`. DO NOT EDIT
2+
3+
package models
4+
5+
import (
6+
"fmt"
7+
"log"
8+
"regexp"
9+
10+
hcl "github.com/hashicorp/hcl/v2"
11+
"github.com/terraform-linters/tflint-plugin-sdk/tflint"
12+
)
13+
14+
// AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule checks the pattern is valid
15+
type AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule struct {
16+
resourceType string
17+
attributeName string
18+
max int
19+
min int
20+
pattern *regexp.Regexp
21+
}
22+
23+
// NewAwsSsoadminAccountAssignmentInvalidPermissionSetArnRule returns new rule with default attributes
24+
func NewAwsSsoadminAccountAssignmentInvalidPermissionSetArnRule() *AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule {
25+
return &AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule{
26+
resourceType: "aws_ssoadmin_account_assignment",
27+
attributeName: "permission_set_arn",
28+
max: 1224,
29+
min: 10,
30+
pattern: regexp.MustCompile(`^arn:aws:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}$`),
31+
}
32+
}
33+
34+
// Name returns the rule name
35+
func (r *AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule) Name() string {
36+
return "aws_ssoadmin_account_assignment_invalid_permission_set_arn"
37+
}
38+
39+
// Enabled returns whether the rule is enabled by default
40+
func (r *AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule) Enabled() bool {
41+
return true
42+
}
43+
44+
// Severity returns the rule severity
45+
func (r *AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule) Severity() string {
46+
return tflint.ERROR
47+
}
48+
49+
// Link returns the rule reference link
50+
func (r *AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule) Link() string {
51+
return ""
52+
}
53+
54+
// Check checks the pattern is valid
55+
func (r *AwsSsoadminAccountAssignmentInvalidPermissionSetArnRule) Check(runner tflint.Runner) error {
56+
log.Printf("[TRACE] Check `%s` rule", r.Name())
57+
58+
return runner.WalkResourceAttributes(r.resourceType, r.attributeName, func(attribute *hcl.Attribute) error {
59+
var val string
60+
err := runner.EvaluateExpr(attribute.Expr, &val, nil)
61+
62+
return runner.EnsureNoError(err, func() error {
63+
if len(val) > r.max {
64+
runner.EmitIssueOnExpr(
65+
r,
66+
"permission_set_arn must be 1224 characters or less",
67+
attribute.Expr,
68+
)
69+
}
70+
if len(val) < r.min {
71+
runner.EmitIssueOnExpr(
72+
r,
73+
"permission_set_arn must be 10 characters or higher",
74+
attribute.Expr,
75+
)
76+
}
77+
if !r.pattern.MatchString(val) {
78+
runner.EmitIssueOnExpr(
79+
r,
80+
fmt.Sprintf(`"%s" does not match valid pattern %s`, truncateLongMessage(val), `^arn:aws:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}$`),
81+
attribute.Expr,
82+
)
83+
}
84+
return nil
85+
})
86+
})
87+
}
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
// This file generated by `generator/`. DO NOT EDIT
2+
3+
package models
4+
5+
import (
6+
"fmt"
7+
"log"
8+
"regexp"
9+
10+
hcl "github.com/hashicorp/hcl/v2"
11+
"github.com/terraform-linters/tflint-plugin-sdk/tflint"
12+
)
13+
14+
// AwsSsoadminAccountAssignmentInvalidPrincipalIDRule checks the pattern is valid
15+
type AwsSsoadminAccountAssignmentInvalidPrincipalIDRule struct {
16+
resourceType string
17+
attributeName string
18+
max int
19+
min int
20+
pattern *regexp.Regexp
21+
}
22+
23+
// NewAwsSsoadminAccountAssignmentInvalidPrincipalIDRule returns new rule with default attributes
24+
func NewAwsSsoadminAccountAssignmentInvalidPrincipalIDRule() *AwsSsoadminAccountAssignmentInvalidPrincipalIDRule {
25+
return &AwsSsoadminAccountAssignmentInvalidPrincipalIDRule{
26+
resourceType: "aws_ssoadmin_account_assignment",
27+
attributeName: "principal_id",
28+
max: 47,
29+
min: 1,
30+
pattern: regexp.MustCompile(`^([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}$`),
31+
}
32+
}
33+
34+
// Name returns the rule name
35+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalIDRule) Name() string {
36+
return "aws_ssoadmin_account_assignment_invalid_principal_id"
37+
}
38+
39+
// Enabled returns whether the rule is enabled by default
40+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalIDRule) Enabled() bool {
41+
return true
42+
}
43+
44+
// Severity returns the rule severity
45+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalIDRule) Severity() string {
46+
return tflint.ERROR
47+
}
48+
49+
// Link returns the rule reference link
50+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalIDRule) Link() string {
51+
return ""
52+
}
53+
54+
// Check checks the pattern is valid
55+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalIDRule) Check(runner tflint.Runner) error {
56+
log.Printf("[TRACE] Check `%s` rule", r.Name())
57+
58+
return runner.WalkResourceAttributes(r.resourceType, r.attributeName, func(attribute *hcl.Attribute) error {
59+
var val string
60+
err := runner.EvaluateExpr(attribute.Expr, &val, nil)
61+
62+
return runner.EnsureNoError(err, func() error {
63+
if len(val) > r.max {
64+
runner.EmitIssueOnExpr(
65+
r,
66+
"principal_id must be 47 characters or less",
67+
attribute.Expr,
68+
)
69+
}
70+
if len(val) < r.min {
71+
runner.EmitIssueOnExpr(
72+
r,
73+
"principal_id must be 1 characters or higher",
74+
attribute.Expr,
75+
)
76+
}
77+
if !r.pattern.MatchString(val) {
78+
runner.EmitIssueOnExpr(
79+
r,
80+
fmt.Sprintf(`"%s" does not match valid pattern %s`, truncateLongMessage(val), `^([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}$`),
81+
attribute.Expr,
82+
)
83+
}
84+
return nil
85+
})
86+
})
87+
}
Lines changed: 77 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,77 @@
1+
// This file generated by `generator/`. DO NOT EDIT
2+
3+
package models
4+
5+
import (
6+
"fmt"
7+
"log"
8+
9+
hcl "github.com/hashicorp/hcl/v2"
10+
"github.com/terraform-linters/tflint-plugin-sdk/tflint"
11+
)
12+
13+
// AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule checks the pattern is valid
14+
type AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule struct {
15+
resourceType string
16+
attributeName string
17+
enum []string
18+
}
19+
20+
// NewAwsSsoadminAccountAssignmentInvalidPrincipalTypeRule returns new rule with default attributes
21+
func NewAwsSsoadminAccountAssignmentInvalidPrincipalTypeRule() *AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule {
22+
return &AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule{
23+
resourceType: "aws_ssoadmin_account_assignment",
24+
attributeName: "principal_type",
25+
enum: []string{
26+
"USER",
27+
"GROUP",
28+
},
29+
}
30+
}
31+
32+
// Name returns the rule name
33+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule) Name() string {
34+
return "aws_ssoadmin_account_assignment_invalid_principal_type"
35+
}
36+
37+
// Enabled returns whether the rule is enabled by default
38+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule) Enabled() bool {
39+
return true
40+
}
41+
42+
// Severity returns the rule severity
43+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule) Severity() string {
44+
return tflint.ERROR
45+
}
46+
47+
// Link returns the rule reference link
48+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule) Link() string {
49+
return ""
50+
}
51+
52+
// Check checks the pattern is valid
53+
func (r *AwsSsoadminAccountAssignmentInvalidPrincipalTypeRule) Check(runner tflint.Runner) error {
54+
log.Printf("[TRACE] Check `%s` rule", r.Name())
55+
56+
return runner.WalkResourceAttributes(r.resourceType, r.attributeName, func(attribute *hcl.Attribute) error {
57+
var val string
58+
err := runner.EvaluateExpr(attribute.Expr, &val, nil)
59+
60+
return runner.EnsureNoError(err, func() error {
61+
found := false
62+
for _, item := range r.enum {
63+
if item == val {
64+
found = true
65+
}
66+
}
67+
if !found {
68+
runner.EmitIssueOnExpr(
69+
r,
70+
fmt.Sprintf(`"%s" is an invalid value as principal_type`, truncateLongMessage(val)),
71+
attribute.Expr,
72+
)
73+
}
74+
return nil
75+
})
76+
})
77+
}

0 commit comments

Comments
 (0)