-
Notifications
You must be signed in to change notification settings - Fork 9.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Enhancement]: Add EKS Runtime monitoring to Guard Duty #32949
Comments
Community NoteVoting for Prioritization
Volunteering to Work on This Issue
|
As EKS Runtime Monitoring is an EKS add-on, I'm wondering if the deployment of the runtime agent would be done by using the existing That said, it would be helpful to have a bit of documentation on how to configure the monitoring agent, as it seems like there are at least a few config options and it would be good to have an example. Perhaps the config would sit under the |
The add-on needs to be enabled for the agent to gather events and send them to Guardduty but the Guardduty feature needs to be enabled nevertheless. Example CLI command:
|
No, that is something else. This is the org wide auto enablement of the deployment of that EKS addon and is a guardduty setting. You can of course manually deploy it, but that is not what we are talking about here. |
You will be able to use the upcoming resource "aws_guardduty_detector" "example" {
enable = true
}
resource "aws_guardduty_detector_feature" "example" {
detector_id = aws_guardduty_detector.example.id
name = "EKS_RUNTIME_MONITORING"
status = "ENABLED"
additional_configuration {
name = "EKS_ADDON_MANAGEMENT"
status = "ENABLED"
}
} |
This functionality has been released in v5.20.0 of the Terraform AWS Provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template. Thank you! |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. |
Description
Guard Duty now supports EKS Runtime monitoring, but it is not configurable in Terraform at the moment.
Affected Resource(s) and/or Data Source(s)
Potential Terraform Configuration
References
https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-eks-runtime-monitoring.html
Would you like to implement a fix?
None
The text was updated successfully, but these errors were encountered: