amazonka-fms-2.0: Amazon Firewall Management Service SDK.
Copyright(c) 2013-2023 Brendan Hay
LicenseMozilla Public License, v. 2.0.
MaintainerBrendan Hay
Stabilityauto-generated
Portabilitynon-portable (GHC extensions)
Safe HaskellSafe-Inferred
LanguageHaskell2010

Amazonka.FMS.Types.ResourceViolation

Description

 
Synopsis

Documentation

data ResourceViolation Source #

Violation detail based on resource type.

See: newResourceViolation smart constructor.

Constructors

ResourceViolation' 

Fields

Instances

Instances details
FromJSON ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

Generic ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

Associated Types

type Rep ResourceViolation :: Type -> Type #

Read ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

Show ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

NFData ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

Methods

rnf :: ResourceViolation -> () #

Eq ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

Hashable ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

type Rep ResourceViolation Source # 
Instance details

Defined in Amazonka.FMS.Types.ResourceViolation

type Rep ResourceViolation = D1 ('MetaData "ResourceViolation" "Amazonka.FMS.Types.ResourceViolation" "amazonka-fms-2.0-351knTjuYAjE9GRQTo0ohx" 'False) (C1 ('MetaCons "ResourceViolation'" 'PrefixI 'True) ((((S1 ('MetaSel ('Just "awsEc2InstanceViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe AwsEc2InstanceViolation)) :*: S1 ('MetaSel ('Just "awsEc2NetworkInterfaceViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe AwsEc2NetworkInterfaceViolation))) :*: (S1 ('MetaSel ('Just "awsVPCSecurityGroupViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe AwsVPCSecurityGroupViolation)) :*: (S1 ('MetaSel ('Just "dnsDuplicateRuleGroupViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe DnsDuplicateRuleGroupViolation)) :*: S1 ('MetaSel ('Just "dnsRuleGroupLimitExceededViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe DnsRuleGroupLimitExceededViolation))))) :*: ((S1 ('MetaSel ('Just "dnsRuleGroupPriorityConflictViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe DnsRuleGroupPriorityConflictViolation)) :*: (S1 ('MetaSel ('Just "firewallSubnetIsOutOfScopeViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe FirewallSubnetIsOutOfScopeViolation)) :*: S1 ('MetaSel ('Just "firewallSubnetMissingVPCEndpointViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe FirewallSubnetMissingVPCEndpointViolation)))) :*: (S1 ('MetaSel ('Just "networkFirewallBlackHoleRouteDetectedViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallBlackHoleRouteDetectedViolation)) :*: (S1 ('MetaSel ('Just "networkFirewallInternetTrafficNotInspectedViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallInternetTrafficNotInspectedViolation)) :*: S1 ('MetaSel ('Just "networkFirewallInvalidRouteConfigurationViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallInvalidRouteConfigurationViolation)))))) :*: (((S1 ('MetaSel ('Just "networkFirewallMissingExpectedRTViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallMissingExpectedRTViolation)) :*: (S1 ('MetaSel ('Just "networkFirewallMissingExpectedRoutesViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallMissingExpectedRoutesViolation)) :*: S1 ('MetaSel ('Just "networkFirewallMissingFirewallViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallMissingFirewallViolation)))) :*: (S1 ('MetaSel ('Just "networkFirewallMissingSubnetViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallMissingSubnetViolation)) :*: (S1 ('MetaSel ('Just "networkFirewallPolicyModifiedViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallPolicyModifiedViolation)) :*: S1 ('MetaSel ('Just "networkFirewallUnexpectedFirewallRoutesViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallUnexpectedFirewallRoutesViolation))))) :*: ((S1 ('MetaSel ('Just "networkFirewallUnexpectedGatewayRoutesViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe NetworkFirewallUnexpectedGatewayRoutesViolation)) :*: (S1 ('MetaSel ('Just "possibleRemediationActions") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe PossibleRemediationActions)) :*: S1 ('MetaSel ('Just "routeHasOutOfScopeEndpointViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe RouteHasOutOfScopeEndpointViolation)))) :*: (S1 ('MetaSel ('Just "thirdPartyFirewallMissingExpectedRouteTableViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe ThirdPartyFirewallMissingExpectedRouteTableViolation)) :*: (S1 ('MetaSel ('Just "thirdPartyFirewallMissingFirewallViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe ThirdPartyFirewallMissingFirewallViolation)) :*: S1 ('MetaSel ('Just "thirdPartyFirewallMissingSubnetViolation") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe ThirdPartyFirewallMissingSubnetViolation))))))))

newResourceViolation :: ResourceViolation Source #

Create a value of ResourceViolation with all optional fields omitted.

Use generic-lens or optics to modify other optional fields.

The following record fields are available, with the corresponding lenses provided for backwards compatibility:

$sel:awsEc2InstanceViolation:ResourceViolation', resourceViolation_awsEc2InstanceViolation - Violation detail for an EC2 instance.

$sel:awsEc2NetworkInterfaceViolation:ResourceViolation', resourceViolation_awsEc2NetworkInterfaceViolation - Violation detail for a network interface.

$sel:awsVPCSecurityGroupViolation:ResourceViolation', resourceViolation_awsVPCSecurityGroupViolation - Violation detail for security groups.

$sel:dnsDuplicateRuleGroupViolation:ResourceViolation', resourceViolation_dnsDuplicateRuleGroupViolation - Violation detail for a DNS Firewall policy that indicates that a rule group that Firewall Manager tried to associate with a VPC is already associated with the VPC and can't be associated again.

$sel:dnsRuleGroupLimitExceededViolation:ResourceViolation', resourceViolation_dnsRuleGroupLimitExceededViolation - Violation detail for a DNS Firewall policy that indicates that the VPC reached the limit for associated DNS Firewall rule groups. Firewall Manager tried to associate another rule group with the VPC and failed.

$sel:dnsRuleGroupPriorityConflictViolation:ResourceViolation', resourceViolation_dnsRuleGroupPriorityConflictViolation - Violation detail for a DNS Firewall policy that indicates that a rule group that Firewall Manager tried to associate with a VPC has the same priority as a rule group that's already associated.

$sel:firewallSubnetIsOutOfScopeViolation:ResourceViolation', resourceViolation_firewallSubnetIsOutOfScopeViolation - Contains details about the firewall subnet that violates the policy scope.

$sel:firewallSubnetMissingVPCEndpointViolation:ResourceViolation', resourceViolation_firewallSubnetMissingVPCEndpointViolation - The violation details for a third-party firewall's VPC endpoint subnet that was deleted.

$sel:networkFirewallBlackHoleRouteDetectedViolation:ResourceViolation', resourceViolation_networkFirewallBlackHoleRouteDetectedViolation - Undocumented member.

$sel:networkFirewallInternetTrafficNotInspectedViolation:ResourceViolation', resourceViolation_networkFirewallInternetTrafficNotInspectedViolation - Violation detail for the subnet for which internet traffic hasn't been inspected.

$sel:networkFirewallInvalidRouteConfigurationViolation:ResourceViolation', resourceViolation_networkFirewallInvalidRouteConfigurationViolation - The route configuration is invalid.

$sel:networkFirewallMissingExpectedRTViolation:ResourceViolation', resourceViolation_networkFirewallMissingExpectedRTViolation - Violation detail for an Network Firewall policy that indicates that a subnet is not associated with the expected Firewall Manager managed route table.

$sel:networkFirewallMissingExpectedRoutesViolation:ResourceViolation', resourceViolation_networkFirewallMissingExpectedRoutesViolation - Expected routes are missing from Network Firewall.

$sel:networkFirewallMissingFirewallViolation:ResourceViolation', resourceViolation_networkFirewallMissingFirewallViolation - Violation detail for an Network Firewall policy that indicates that a subnet has no Firewall Manager managed firewall in its VPC.

$sel:networkFirewallMissingSubnetViolation:ResourceViolation', resourceViolation_networkFirewallMissingSubnetViolation - Violation detail for an Network Firewall policy that indicates that an Availability Zone is missing the expected Firewall Manager managed subnet.

$sel:networkFirewallPolicyModifiedViolation:ResourceViolation', resourceViolation_networkFirewallPolicyModifiedViolation - Violation detail for an Network Firewall policy that indicates that a firewall policy in an individual account has been modified in a way that makes it noncompliant. For example, the individual account owner might have deleted a rule group, changed the priority of a stateless rule group, or changed a policy default action.

$sel:networkFirewallUnexpectedFirewallRoutesViolation:ResourceViolation', resourceViolation_networkFirewallUnexpectedFirewallRoutesViolation - There's an unexpected firewall route.

$sel:networkFirewallUnexpectedGatewayRoutesViolation:ResourceViolation', resourceViolation_networkFirewallUnexpectedGatewayRoutesViolation - There's an unexpected gateway route.

$sel:possibleRemediationActions:ResourceViolation', resourceViolation_possibleRemediationActions - A list of possible remediation action lists. Each individual possible remediation action is a list of individual remediation actions.

$sel:routeHasOutOfScopeEndpointViolation:ResourceViolation', resourceViolation_routeHasOutOfScopeEndpointViolation - Contains details about the route endpoint that violates the policy scope.

$sel:thirdPartyFirewallMissingExpectedRouteTableViolation:ResourceViolation', resourceViolation_thirdPartyFirewallMissingExpectedRouteTableViolation - The violation details for a third-party firewall that has the Firewall Manager managed route table that was associated with the third-party firewall has been deleted.

$sel:thirdPartyFirewallMissingFirewallViolation:ResourceViolation', resourceViolation_thirdPartyFirewallMissingFirewallViolation - The violation details for a third-party firewall that's been deleted.

$sel:thirdPartyFirewallMissingSubnetViolation:ResourceViolation', resourceViolation_thirdPartyFirewallMissingSubnetViolation - The violation details for a third-party firewall's subnet that's been deleted.

resourceViolation_dnsDuplicateRuleGroupViolation :: Lens' ResourceViolation (Maybe DnsDuplicateRuleGroupViolation) Source #

Violation detail for a DNS Firewall policy that indicates that a rule group that Firewall Manager tried to associate with a VPC is already associated with the VPC and can't be associated again.

resourceViolation_dnsRuleGroupLimitExceededViolation :: Lens' ResourceViolation (Maybe DnsRuleGroupLimitExceededViolation) Source #

Violation detail for a DNS Firewall policy that indicates that the VPC reached the limit for associated DNS Firewall rule groups. Firewall Manager tried to associate another rule group with the VPC and failed.

resourceViolation_dnsRuleGroupPriorityConflictViolation :: Lens' ResourceViolation (Maybe DnsRuleGroupPriorityConflictViolation) Source #

Violation detail for a DNS Firewall policy that indicates that a rule group that Firewall Manager tried to associate with a VPC has the same priority as a rule group that's already associated.

resourceViolation_firewallSubnetIsOutOfScopeViolation :: Lens' ResourceViolation (Maybe FirewallSubnetIsOutOfScopeViolation) Source #

Contains details about the firewall subnet that violates the policy scope.

resourceViolation_firewallSubnetMissingVPCEndpointViolation :: Lens' ResourceViolation (Maybe FirewallSubnetMissingVPCEndpointViolation) Source #

The violation details for a third-party firewall's VPC endpoint subnet that was deleted.

resourceViolation_networkFirewallMissingExpectedRTViolation :: Lens' ResourceViolation (Maybe NetworkFirewallMissingExpectedRTViolation) Source #

Violation detail for an Network Firewall policy that indicates that a subnet is not associated with the expected Firewall Manager managed route table.

resourceViolation_networkFirewallMissingFirewallViolation :: Lens' ResourceViolation (Maybe NetworkFirewallMissingFirewallViolation) Source #

Violation detail for an Network Firewall policy that indicates that a subnet has no Firewall Manager managed firewall in its VPC.

resourceViolation_networkFirewallMissingSubnetViolation :: Lens' ResourceViolation (Maybe NetworkFirewallMissingSubnetViolation) Source #

Violation detail for an Network Firewall policy that indicates that an Availability Zone is missing the expected Firewall Manager managed subnet.

resourceViolation_networkFirewallPolicyModifiedViolation :: Lens' ResourceViolation (Maybe NetworkFirewallPolicyModifiedViolation) Source #

Violation detail for an Network Firewall policy that indicates that a firewall policy in an individual account has been modified in a way that makes it noncompliant. For example, the individual account owner might have deleted a rule group, changed the priority of a stateless rule group, or changed a policy default action.

resourceViolation_possibleRemediationActions :: Lens' ResourceViolation (Maybe PossibleRemediationActions) Source #

A list of possible remediation action lists. Each individual possible remediation action is a list of individual remediation actions.

resourceViolation_routeHasOutOfScopeEndpointViolation :: Lens' ResourceViolation (Maybe RouteHasOutOfScopeEndpointViolation) Source #

Contains details about the route endpoint that violates the policy scope.

resourceViolation_thirdPartyFirewallMissingExpectedRouteTableViolation :: Lens' ResourceViolation (Maybe ThirdPartyFirewallMissingExpectedRouteTableViolation) Source #

The violation details for a third-party firewall that has the Firewall Manager managed route table that was associated with the third-party firewall has been deleted.

resourceViolation_thirdPartyFirewallMissingSubnetViolation :: Lens' ResourceViolation (Maybe ThirdPartyFirewallMissingSubnetViolation) Source #

The violation details for a third-party firewall's subnet that's been deleted.