29 lines
626 B
Plaintext

include::../description.adoc[]
include::../ask-yourself.adoc[]
include::../recommended.adoc[]
== Sensitive Code Example
For https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue[aws_sqs_queue]:
----
resource "aws_sqs_queue" "queue" { # Sensitive, encryption disabled by default
name = "sqs-unencrypted"
}
----
== Compliant Solution
For https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue[aws_sqs_queue]:
----
resource "aws_sqs_queue" "queue" {
name = "sqs-encrypted"
kms_master_key_id = aws_kms_key.enc_key.key_id
}
----
include::../see.adoc[]