AWS EKS Terraform module
Upstream version 21.24.1
7 controls from PCI DSS v4.0 requirements
Terraform Module Source
pcidss.compliance.tf/terraform-aws-modules/eks/awsCloudWatch log groups should have retention period of at least 365 days
cloudwatch_log_group_retention_period_3653.2.1
Framework requirement
EC2 launch templates should not assign public IPs to network interfaces
ec2_launch_template_not_publicly_accessible1.4.5
Framework requirement
EKS clusters should have control plane audit logging enabled
eks_cluster_control_plane_audit_logging_enabled5.3.4
Framework requirement
EKS clusters endpoint public access should be restricted
eks_cluster_endpoint_public_access_restricted1.2.8
Framework requirement
EKS clusters should be configured to have kubernetes secrets encrypted using KMS
eks_cluster_secrets_encrypted3.5.1
Framework requirement
Log groups should have encryption at rest enabled
log_group_encryption_at_rest_enabled3.5.1
Framework requirement
VPC Security groups should only allow unrestricted incoming traffic for authorized ports
vpc_security_group_allows_ingress_authorized_ports1.3.2
Framework requirement