Detect and scan all active (opted-in) regions if no region list is provided - #164
Merged
Merged
Conversation
Contributor
|
@rbclark thank you so much for the PR! @m-pizarro can you please review this when you get a chance? |
Contributor
@tyler-dunkel I've been reviewing and doing some tests. It looks good to me. Thanks you @rbclark for it! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes/solution
There are multiple regions in AWS that are opt in and not enabled by default. Attempting to scan these regions just slows things down. This adds an active region check which runs when no region list is provided. This also updates the init script to not create an entry at all for 'regions' in the config file if the user doesn't select any regions (which causes the region detection code to run).
Testing
I have run this locally against a test account after removing the region configuration from my config file and can verify that non-opted-in regions were not scanned.
Notes and considerations
After these changes it didn't really make sense to setup the regions at the global level, so I moved them to a per-account level.
There is one completely different approach I could've taken here, I could've made this code automatically filter out any regions that the user may have enabled that are not opted into. If desired I can update these changes to use that approach instead.
Dependencies
N/A