------------------------------------------------------------ cdk.out/EkycInfraStack.template.json ------------------------------------------------------------------------------------------------------------------------ | WARN W68 | | Resource: ["ekycapiekycdataapic8938b7df4d45f02729def30bb8a7d9970465a1792DeploymentB9033C4F6a6d1363d407849f80ce7ed24aece408"] | Line Numbers: [2663] | | AWS::ApiGateway::Deployment resources should be associated with an AWS::ApiGateway::UsagePlan.  ------------------------------------------------------------ | WARN W69 | | Resource: ["ekycapiekycdataapic8938b7df4d45f02729def30bb8a7d9970465a1792DeploymentStageprod9353301D", "ekycapidevstage7E0AD487", "ekycapiteststage8991420A", "ekycapiuatstage19B4A1DC"] | Line Numbers: [2682, 3098, 3113, 3128] | | AWS::ApiGateway::Stage should have the AccessLogSetting property defined. ------------------------------------------------------------ | WARN W64 | | Resource: ["ekycapiekycdataapic8938b7df4d45f02729def30bb8a7d9970465a1792DeploymentStageprod9353301D"] | Line Numbers: [2682] | | AWS::ApiGateway::Stage resources should be associated with an AWS::ApiGateway::UsagePlan.  ------------------------------------------------------------ | WARN W10 | | Resource: ["webappjswebdistributionCFDistribution59824C8A", "swaggerswaggerdistributionCFDistributionDC90E2C9"] | Line Numbers: [932, 3437] | | CloudFront Distribution should enable access logging ------------------------------------------------------------ | WARN W70 | | Resource: ["webappjswebdistributionCFDistribution59824C8A", "swaggerswaggerdistributionCFDistributionDC90E2C9"] | Line Numbers: [932, 3437] | | Cloudfront should use minimum protocol version TLS 1.2 ------------------------------------------------------------ | WARN W78 | | Resource: ["storageSessions515A5702", "storageDataRequestsF5098A37", "storageTrainingJobs6DCD8424", "storageVerificationHistoryB8330F3D"] | Line Numbers: [695, 725, 755, 799] | | DynamoDB table should have backup enabled, should be set using PointInTimeRecoveryEnabled ------------------------------------------------------------ | WARN W12 | | Resource: ["CustomCDKBucketDeployment8693BB64968944B69AAFB0CC9EB8756CServiceRoleDefaultPolicy88902FDF", "identityGroundTruthRoleDefaultPolicy53477035", "ekycapiekycproxyhandlerServiceRoleDefaultPolicy9E8CBCB6"] | Line Numbers: [1150, 1769, 2195] | | IAM policy should not allow * resource ------------------------------------------------------------ | WARN W58 | | Resource: ["CustomS3AutoDeleteObjectsCustomResourceProviderHandler9D90184F", "CustomCDKBucketDeployment8693BB64968944B69AAFB0CC9EB8756C81C01536", "ekycapiekycproxyhandlerD9FA9D66", "eventtriggersgroundtrutheventchangehandler82C23C83", "eventtriggerscheckdatasethandler4A0254CA"] | Line Numbers: [850, 1399, 2413, 3729, 3932] | | Lambda functions require permission to write CloudWatch Logs ------------------------------------------------------------ | WARN W89 | | Resource: ["CustomS3AutoDeleteObjectsCustomResourceProviderHandler9D90184F", "CustomCDKBucketDeployment8693BB64968944B69AAFB0CC9EB8756C81C01536", "ekycapiekycproxyhandlerD9FA9D66", "eventtriggersgroundtrutheventchangehandler82C23C83", "eventtriggerscheckdatasethandler4A0254CA"] | Line Numbers: [850, 1399, 2413, 3729, 3932] | | Lambda functions should be deployed inside a VPC ------------------------------------------------------------ | WARN W92 | | Resource: ["CustomS3AutoDeleteObjectsCustomResourceProviderHandler9D90184F", "CustomCDKBucketDeployment8693BB64968944B69AAFB0CC9EB8756C81C01536", "ekycapiekycproxyhandlerD9FA9D66", "eventtriggersgroundtrutheventchangehandler82C23C83", "eventtriggerscheckdatasethandler4A0254CA"] | Line Numbers: [850, 1399, 2413, 3729, 3932] | | Lambda functions should define ReservedConcurrentExecutions to reserve simultaneous executions ------------------------------------------------------------ | WARN W28 | | Resource: ["ekycapiEkycAPIkeyCBC50C4E"] | Line Numbers: [3143] | | Resource found with an explicit name, this disallows updates that require replacement of this resource ------------------------------------------------------------ | WARN W35 | | Resource: ["storagedeployBucketB61B3C55", "storagestorageBucketB86286FA", "storageswaggerBucketC75FADBA", "storagetrainingBucketF044F5ED", "storageuihostingbucketB2F58A5E"] | Line Numbers: [4, 105, 232, 397, 517] | | S3 Bucket should have access logging configured ------------------------------------------------------------ | WARN W41 | | Resource: ["storageuihostingbucketB2F58A5E"] | Line Numbers: [517] | | S3 Bucket should have encryption option set ------------------------------------------------------------ | WARN W76 | | Resource: ["CustomCDKBucketDeployment8693BB64968944B69AAFB0CC9EB8756CServiceRoleDefaultPolicy88902FDF", "ekycapiekycproxyhandlerServiceRoleDefaultPolicy9E8CBCB6"] | Line Numbers: [1150, 2195] | | SPCM for IAM policy document is higher than 25 ------------------------------------------------------------ | WARN W47 | | Resource: ["topicsekycapprovaltopic27D1BBB1", "topicsekyclabellingtopic0A3A8A49"] | Line Numbers: [1853, 1904] | | SNS Topic should specify KmsMasterKeyId property Failures count: 0 Warnings count: 43