Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feature(deadline): Enable logging for DocDB #37

Merged
merged 3 commits into from
Aug 10, 2020
Merged

Conversation

kozlove-aws
Copy link
Contributor

@kozlove-aws kozlove-aws commented Aug 6, 2020

This fix DocDB part of the issue discovered during the security audit

Was added class that can be used if customer want to switch audit log.

Description of how audit log can be enabled is here

In repository constructor was added databaseAuditLogging parameter and according to value of this parameter enable audit logging for DocDB cluster.

Also was added example code in kitchen sink.

Was enabled parameter audit_logs and added audit to enableCloudwatchLogsExports construct option.

Testing

Was deployed kitchen sink with this changes and checked that CloudWatch logs enabled
image

Checking CloudWatch that audit log group was created and messages appeared.

Copy link
Contributor

@ddneilson ddneilson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We use CDK construct for DocumentDB so we only can fix it in our example.

I do not believe this statement. Anything that can be done in the application code can be done in the Repository. The ask, for the Repository, is to design an interface (similar to what Dave did for the ALB) that allows a customer to tell the Repository to enable audit logging when/if the Repository creates a DocDB database for the customer (i.e. if it's not being provided one).

Especially since the thinking is to remove the kitchen sink example from the repo once we have a solid set of official samples in place.

@jericht jericht self-requested a review August 6, 2020 15:41
* For more information about audit logging in DocumentDB, see: https://docs.aws.amazon.com/documentdb/latest/developerguide/event-auditing.html
*
*/
export class DocumentDbClusterWithLogs extends DatabaseCluster {
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ideally we should upstream these changes to the DatabaseCluster class in CDK so we can simply add a new property for the audit logging stuff (e.g. auditLogging?: AuditLoggingProps). If we are short on time though, this will have to do for now. Thoughts @ddneilson ?

@kozlove-aws kozlove-aws force-pushed the docdb_audit_log branch 3 times, most recently from 70d30ca to af7afdc Compare August 6, 2020 22:17
Copy link
Contributor

@jericht jericht left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just the comment on the parameter group descriptions then this looks good to me.

jericht
jericht previously approved these changes Aug 7, 2020
Copy link
Contributor

@jericht jericht left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

Copy link
Contributor

@grbartel grbartel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have 2 more comments for this one:

  1. The merge request title needs to be updated since you are adding a feature to the Repository not adding to the example
  2. This MR requires Tests for the new functionality that was added to the Repository.

@kozlove-aws kozlove-aws changed the title chore: Enable logging for DocDB example chore: Enable logging for DocDB Aug 7, 2020
@kozlove-aws kozlove-aws changed the title chore: Enable logging for DocDB feature(deadline): Enable logging for DocDB Aug 7, 2020
ddneilson
ddneilson previously approved these changes Aug 10, 2020
expectCDK(stack).to(haveResourceLike('AWS::DocDB::DBInstance', {
AutoMinorVersionUpgrade: true,
}));
});

test('audit log is disabled when it required', () => {
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This test title is kind of awkward. Can we instead have it be something along the lines of

Disabling Audit logging removes parameters

Copy link
Contributor Author

@kozlove-aws kozlove-aws Aug 10, 2020

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is not actually remove parameters, it switching audit log off.
What about Disabling Audit logging does not enable audit logging?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Compared to the default it is removing the parameters to switch of auditing.

But sure your naming should work.

@ddneilson ddneilson merged commit 00367f2 into mainline Aug 10, 2020
@ddneilson ddneilson deleted the docdb_audit_log branch August 27, 2020 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants