forked from widdix/aws-cf-templates
-
Notifications
You must be signed in to change notification settings - Fork 0
/
zone-dnssec.yaml
101 lines (101 loc) · 3.63 KB
/
zone-dnssec.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
---
# Copyright 2018 widdix GmbH
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
AWSTemplateFormatVersion: '2010-09-09'
Description: 'VPC: DNSSEC for public DNS zone (us-east-1 only!), a cloudonaut.io template'
Metadata:
'AWS::CloudFormation::Interface':
ParameterGroups:
- Label:
default: 'Parent Stacks'
Parameters:
- ParentZoneStack
- ParentKmsKeyStack
- ParentAlertStack
Parameters:
ParentZoneStack:
Description: 'Stack name of parent zone stack based on vpc/zone-*.yaml template.'
Type: String
ParentKmsKeyStack:
Description: 'Stack name of parent KMS key stack based on security/kms-key.yaml template (ignored when DBSnapshotIdentifier is set, value used from snapshot).'
Type: String
ParentAlertStack:
Description: 'Optional but recommended stack name of parent alert stack based on operations/alert.yaml template.'
Type: String
Default: ''
Conditions:
HasAlertTopic: !Not [!Equals [!Ref ParentAlertStack, '']]
Resources:
KeySigningKey:
Type: 'AWS::Route53::KeySigningKey'
Properties:
HostedZoneId: {'Fn::ImportValue': !Sub '${ParentZoneStack}-HostedZoneId'}
KeyManagementServiceArn: {'Fn::ImportValue': !Sub '${ParentKmsKeyStack}-KeyArn'}
Name: 'ksk_01'
Status: 'ACTIVE'
DNSSEC:
DependsOn: [KeySigningKey]
Type: 'AWS::Route53::DNSSEC'
Properties:
HostedZoneId: {'Fn::ImportValue': !Sub '${ParentZoneStack}-HostedZoneId'}
DNSSECInternalFailureAlarm:
Condition: HasAlertTopic
Type: 'AWS::CloudWatch::Alarm'
Properties:
AlarmActions:
- {'Fn::ImportValue': !Sub '${ParentAlertStack}-TopicARN'}
AlarmDescription: 'Hosted zone is in an INTERNAL_FAILURE state.'
ComparisonOperator: GreaterThanThreshold
Dimensions:
- Name: HostedZoneId
Value: {'Fn::ImportValue': !Sub '${ParentZoneStack}-HostedZoneId'}
EvaluationPeriods: 1
MetricName: DNSSECInternalFailure
Namespace: 'AWS/Route53'
OKActions:
- {'Fn::ImportValue': !Sub '${ParentAlertStack}-TopicARN'}
Period: 60
Statistic: Sum
Threshold: 0
TreatMissingData: notBreaching
DNSSECKeySigningKeysNeedingActionAlarm:
Condition: HasAlertTopic
Type: 'AWS::CloudWatch::Alarm'
Properties:
AlarmActions:
- {'Fn::ImportValue': !Sub '${ParentAlertStack}-TopicARN'}
AlarmDescription: 'One or multiple key signing keys (KSKs) are in ACTION_NEEDED state due to KMS failure.'
ComparisonOperator: GreaterThanThreshold
Dimensions:
- Name: HostedZoneId
Value: {'Fn::ImportValue': !Sub '${ParentZoneStack}-HostedZoneId'}
EvaluationPeriods: 1
MetricName: DNSSECKeySigningKeysNeedingAction
Namespace: 'AWS/Route53'
OKActions:
- {'Fn::ImportValue': !Sub '${ParentAlertStack}-TopicARN'}
Period: 60
Statistic: Sum
Threshold: 0
TreatMissingData: notBreaching
Outputs:
TemplateID:
Description: 'cloudonaut.io template id.'
Value: 'vpc/zone-dnssec'
TemplateVersion:
Description: 'cloudonaut.io template version.'
Value: '__VERSION__'
StackName:
Description: 'Stack name.'
Value: !Sub '${AWS::StackName}'