Files
prowler/providers/aws/services/efs/efs_service.py
Nacho Rivera c87327bb77 feat(EFS): Service and checks (#1469)
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com>
Co-authored-by: sergargar <sergio@verica.io>
2022-11-14 15:05:41 +01:00

94 lines
3.1 KiB
Python

import threading
from dataclasses import dataclass
from lib.logger import logger
from providers.aws.aws_provider import generate_regional_clients
################### EFS
class EFS:
def __init__(self, audit_info):
self.service = "efs"
self.session = audit_info.audit_session
self.regional_clients = generate_regional_clients(self.service, audit_info)
self.filesystems = []
self.__threading_call__(self.__describe_file_systems__)
self.__describe_file_system_policies__()
def __get_session__(self):
return self.session
def __threading_call__(self, call):
threads = []
for regional_client in self.regional_clients.values():
threads.append(threading.Thread(target=call, args=(regional_client,)))
for t in threads:
t.start()
for t in threads:
t.join()
def __describe_file_systems__(self, regional_client):
logger.info("EFS - Describing file systems...")
try:
describe_efs_paginator = regional_client.get_paginator(
"describe_file_systems"
)
for page in describe_efs_paginator.paginate():
for efs in page["FileSystems"]:
self.filesystems.append(
FileSystem(
id=efs["FileSystemId"],
region=regional_client.region,
policy=None,
backup_policy=None,
encrypted=efs["Encrypted"],
)
)
except Exception as error:
logger.error(
f"{regional_client.region} -- {error.__class__.__name__}[{error.__traceback__.tb_lineno}]: {error}"
)
def __describe_file_system_policies__(self):
logger.info("EFS - Describing file system policies...")
try:
for filesystem in self.filesystems:
for region, client in self.regional_clients.items():
if filesystem.region == region:
filesystem.backup_policy = client.describe_backup_policy(
FileSystemId=filesystem.id
)["BackupPolicy"]["Status"]
fs_policy = client.describe_file_system_policy(
FileSystemId=filesystem.id
)
if "Policy" in fs_policy:
filesystem.policy = fs_policy["Policy"]
except Exception as error:
logger.error(
f"{client.region} -- {error.__class__.__name__}[{error.__traceback__.tb_lineno}]: {error}"
)
@dataclass
class FileSystem:
id: str
region: str
policy: dict
backup_policy: str
encrypted: bool
def __init__(
self,
id,
region,
policy,
backup_policy,
encrypted,
):
self.id = id
self.region = region
self.policy = policy
self.backup_policy = backup_policy
self.encrypted = encrypted