Aws Tls Policy Approved
terraform.aws-tls-policy-approved
Requires every TLS-terminating resource to negotiate using a policy on the
approved list: ALB/NLB listener ssl_policy, CloudFront
minimum_protocol_version, and API Gateway custom-domain security_policy.
Complements aws-elb-https-only, which asserts the listener is encrypted but
not which protocol versions and ciphers it will accept. Configure the set
via approved_tls_policies; skipped when none are configured, because the
approved suite is the organisation's cryptographic standard and there is no
safe default to assume on its behalf. A resource that terminates TLS but
names no policy fails, since the negotiated suite is then whatever the
provider defaults to.
Compatible Integrations
This guardrail works with the following integrations. Click to see how to use Aws Tls Policy Approved with each collector.
Enable This Guardrail
Add the parent policy to your lunar-config.yml to enable this guardrail.
policies:
- uses: github://earthly/lunar-lib/policies/terraform@v1.0.5
include: [aws-tls-policy-approved]
# with: ...
How This Guardrail Works
This guardrail is part of the Terraform Guardrails policy. It evaluates data collected by integrations and produces a pass/fail check with actionable feedback.
When enabled, this check runs automatically on every PR and in AI coding workflows, providing real-time enforcement of your engineering standards.
Learn How Lunar Works →Configuration Options
These inputs can be configured in your lunar-config.yml to customize
how the parent policy (and this guardrail) behaves.
| Input | Required | Default | Description |
|---|---|---|---|
required_backend_types
|
Required | — | Comma-separated list of approved backend types (empty = any remote backend) |
min_provider_versions
|
Optional |
{}
|
JSON object mapping provider names to minimum versions (e.g., {"aws": "5.0", "random": "3.0"}) |
ssh_port
|
Optional |
22
|
TCP port treated as SSH for the public-ingress check |
postgres_port
|
Optional |
5432
|
TCP port treated as PostgreSQL for the public-ingress check |
eks_required_log_types
|
Optional |
api,audit,authenticator,controllerManager,scheduler
|
Comma-separated EKS control-plane log types that must be enabled |
require_cloudtrail_cloudwatch
|
Optional |
true
|
Whether CloudTrail must also deliver logs to CloudWatch Logs (true/false) |
extra_admin_ports
|
Required | — | Additional comma-separated TCP ports to treat as sensitive for the public admin-ports check |
min_password_length
|
Optional |
14
|
Minimum IAM account password length required by aws-iam-password-min-length |
approved_tls_policies
|
Required | — | Comma-separated list of approved TLS policy names, checked by aws-tls-policy-approved against ALB/NLB `ssl_policy`, CloudFront `minimum_protocol_version` and API Gateway `security_policy`. Empty (the default) skips the check. |
Terraform Guardrails
This guardrail is part of the Terraform Guardrails policy, which includes 38 guardrails for deployment and infrastructure.
Ready to Automate Your Standards?
See how Lunar can turn your AGENTS.md, engineering wiki, compliance docs, or postmortem action items into automated guardrails with our 200+ built-in guardrails.