Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: update L1 CloudFormation resource definitions (#29606)
Updates the L1 CloudFormation resource definitions with the latest changes from `@aws-cdk/aws-service-spec` **L1 CloudFormation resource definition changes:** ``` ├[~] service aws-cloudwatch │ └ resources │ └[~] resource AWS::CloudWatch::AnomalyDetector │ └ types │ └[~] type SingleMetricAnomalyDetector │ └ properties │ └[+] AccountId: string ├[~] service aws-docdbelastic │ └ resources │ └[~] resource AWS::DocDBElastic::Cluster │ └ properties │ ├[+] BackupRetentionPeriod: integer │ ├[+] PreferredBackupWindow: string │ └[+] ShardInstanceCount: integer ├[~] service aws-elasticache │ └ resources │ └[~] resource AWS::ElastiCache::ParameterGroup │ └ attributes │ └[-] CacheParameterGroupName: string ├[~] service aws-entityresolution │ └ resources │ └[~] resource AWS::EntityResolution::IdMappingWorkflow │ ├ properties │ │ └ OutputSourceConfig: - Array<IdMappingWorkflowOutputSource> (required) │ │ + Array<IdMappingWorkflowOutputSource> │ └ types │ └[~] type IdMappingWorkflowInputSource │ └ properties │ ├ SchemaArn: - string (required) │ │ + string │ └[+] Type: string ├[~] service aws-iam │ └ resources │ └[~] resource AWS::IAM::ManagedPolicy │ └ properties │ └ Path: - string (immutable) │ + string (default="/", immutable) └[~] service aws-securityhub └ resources ├[-] resource AWS::SecurityHub::DelegatedAdmin │ ├ name: DelegatedAdmin │ │ cloudFormationType: AWS::SecurityHub::DelegatedAdmin │ │ documentation: The AWS::SecurityHub::DelegatedAdmin resource represents the AWS Security Hub delegated admin account in your organization. One delegated admin resource is allowed to create for the organization in each region in which you configure the AdminAccountId. │ ├ properties │ │ └AdminAccountId: string (required, immutable) │ └ attributes │ ├DelegatedAdminIdentifier: string │ └Status: string ├[-] resource AWS::SecurityHub::Insight │ ├ name: Insight │ │ cloudFormationType: AWS::SecurityHub::Insight │ │ documentation: Creates a custom insight in Security Hub. An insight is a consolidation of findings that relate to a security issue that requires attention or remediation. │ │ To group the related findings in the insight, use the `GroupByAttribute` . │ ├ properties │ │ ├Name: string (required) │ │ ├Filters: AwsSecurityFindingFilters (required) │ │ └GroupByAttribute: string (required) │ ├ attributes │ │ └InsightArn: string │ └ types │ ├type AwsSecurityFindingFilters │ │├ documentation: A collection of filters that are applied to all active findings aggregated by AWS Security Hub . │ ││ You can filter by up to ten finding attributes. For each attribute, you can provide up to 20 filter values. │ ││ name: AwsSecurityFindingFilters │ │└ properties │ │ ├ProductArn: Array<StringFilter> │ │ ├AwsAccountId: Array<StringFilter> │ │ ├AwsAccountName: Array<StringFilter> │ │ ├Id: Array<StringFilter> │ │ ├GeneratorId: Array<StringFilter> │ │ ├Type: Array<StringFilter> │ │ ├Region: Array<StringFilter> │ │ ├SeverityLabel: Array<StringFilter> │ │ ├Title: Array<StringFilter> │ │ ├Description: Array<StringFilter> │ │ ├RecommendationText: Array<StringFilter> │ │ ├SourceUrl: Array<StringFilter> │ │ ├ProductFields: Array<MapFilter> │ │ ├ProductName: Array<StringFilter> │ │ ├CompanyName: Array<StringFilter> │ │ ├UserDefinedFields: Array<MapFilter> │ │ ├MalwareName: Array<StringFilter> │ │ ├MalwareType: Array<StringFilter> │ │ ├MalwarePath: Array<StringFilter> │ │ ├MalwareState: Array<StringFilter> │ │ ├NetworkDirection: Array<StringFilter> │ │ ├NetworkProtocol: Array<StringFilter> │ │ ├NetworkSourceIpV4: Array<IpFilter> │ │ ├NetworkSourceIpV6: Array<IpFilter> │ │ ├NetworkSourceDomain: Array<StringFilter> │ │ ├NetworkSourceMac: Array<StringFilter> │ │ ├NetworkDestinationIpV4: Array<IpFilter> │ │ ├NetworkDestinationIpV6: Array<IpFilter> │ │ ├NetworkDestinationDomain: Array<StringFilter> │ │ ├ProcessName: Array<StringFilter> │ │ ├ProcessPath: Array<StringFilter> │ │ ├ThreatIntelIndicatorType: Array<StringFilter> │ │ ├ThreatIntelIndicatorValue: Array<StringFilter> │ │ ├ThreatIntelIndicatorCategory: Array<StringFilter> │ │ ├ThreatIntelIndicatorSource: Array<StringFilter> │ │ ├ThreatIntelIndicatorSourceUrl: Array<StringFilter> │ │ ├ResourceType: Array<StringFilter> │ │ ├ResourceId: Array<StringFilter> │ │ ├ResourcePartition: Array<StringFilter> │ │ ├ResourceRegion: Array<StringFilter> │ │ ├ResourceTags: Array<MapFilter> │ │ ├ResourceAwsEc2InstanceType: Array<StringFilter> │ │ ├ResourceAwsEc2InstanceImageId: Array<StringFilter> │ │ ├ResourceAwsEc2InstanceIpV4Addresses: Array<IpFilter> │ │ ├ResourceAwsEc2InstanceIpV6Addresses: Array<IpFilter> │ │ ├ResourceAwsEc2InstanceKeyName: Array<StringFilter> │ │ ├ResourceAwsEc2InstanceIamInstanceProfileArn: Array<StringFilter> │ │ ├ResourceAwsEc2InstanceVpcId: Array<StringFilter> │ │ ├ResourceAwsEc2InstanceSubnetId: Array<StringFilter> │ │ ├ResourceAwsS3BucketOwnerId: Array<StringFilter> │ │ ├ResourceAwsS3BucketOwnerName: Array<StringFilter> │ │ ├ResourceAwsIamAccessKeyStatus: Array<StringFilter> │ │ ├ResourceContainerName: Array<StringFilter> │ │ ├ResourceContainerImageId: Array<StringFilter> │ │ ├ResourceContainerImageName: Array<StringFilter> │ │ ├ResourceDetailsOther: Array<MapFilter> │ │ ├ComplianceStatus: Array<StringFilter> │ │ ├VerificationState: Array<StringFilter> │ │ ├WorkflowState: Array<StringFilter> │ │ ├WorkflowStatus: Array<StringFilter> │ │ ├RecordState: Array<StringFilter> │ │ ├RelatedFindingsProductArn: Array<StringFilter> │ │ ├RelatedFindingsId: Array<StringFilter> │ │ ├ResourceApplicationArn: Array<StringFilter> │ │ ├ResourceApplicationName: Array<StringFilter> │ │ ├NoteText: Array<StringFilter> │ │ ├NoteUpdatedBy: Array<StringFilter> │ │ ├Sample: Array<BooleanFilter> │ │ ├ComplianceAssociatedStandardsId: Array<StringFilter> │ │ ├ComplianceSecurityControlId: Array<StringFilter> │ │ ├ComplianceSecurityControlParametersName: Array<StringFilter> │ │ ├ComplianceSecurityControlParametersValue: Array<StringFilter> │ │ ├FindingProviderFieldsRelatedFindingsId: Array<StringFilter> │ │ ├FindingProviderFieldsRelatedFindingsProductArn: Array<StringFilter> │ │ ├FindingProviderFieldsSeverityLabel: Array<StringFilter> │ │ ├FindingProviderFieldsSeverityOriginal: Array<StringFilter> │ │ ├FindingProviderFieldsTypes: Array<StringFilter> │ │ ├ResourceAwsIamAccessKeyPrincipalName: Array<StringFilter> │ │ ├ResourceAwsIamUserUserName: Array<StringFilter> │ │ ├VulnerabilitiesExploitAvailable: Array<StringFilter> │ │ └VulnerabilitiesFixAvailable: Array<StringFilter> │ ├type StringFilter │ │├ documentation: A string filter for filtering AWS Security Hub findings. │ ││ name: StringFilter │ │└ properties │ │ ├Comparison: string (required) │ │ └Value: string (required) │ ├type MapFilter │ │├ documentation: A map filter for filtering AWS Security Hub findings. Each map filter provides the field to check for, the value to check for, and the comparison operator. │ ││ name: MapFilter │ │└ properties │ │ ├Comparison: string (required) │ │ ├Key: string (required) │ │ └Value: string (required) │ ├type IpFilter │ │├ documentation: The IP filter for querying findings. │ ││ name: IpFilter │ │└ properties │ │ └Cidr: string │ └type BooleanFilter │ ├ documentation: Boolean filter for querying findings. │ │ name: BooleanFilter │ └ properties │ └Value: boolean (required) └[-] resource AWS::SecurityHub::ProductSubscription ├ name: ProductSubscription │ cloudFormationType: AWS::SecurityHub::ProductSubscription │ documentation: The AWS::SecurityHub::ProductSubscription resource represents a subscription to a service that is allowed to generate findings for your Security Hub account. One product subscription resource is created for each product enabled. ├ properties │ └ProductArn: string (required, immutable) └ attributes └ProductSubscriptionArn: string ```
- Loading branch information