Skip to content

Restrict MQ security group ingress to VPC CIDR in integration test#3884

Merged
licjun merged 3 commits intodevelopfrom
licjun/fix-policy-engine-risk
Feb 17, 2026
Merged

Restrict MQ security group ingress to VPC CIDR in integration test#3884
licjun merged 3 commits intodevelopfrom
licjun/fix-policy-engine-risk

Conversation

@licjun
Copy link
Contributor

@licjun licjun commented Feb 17, 2026

The MQSecurityGroup in function_with_mq_using_autogen_role.yaml and function_with_mq.yaml was allowing ingress from 0.0.0.0/0, triggering Policy Engine violations in test account.

Since this is an integration test that only validates CloudFormation resource creation (no actual MQ message sending), restrict ingress to the companion stack VPC CIDR (10.0.0.0/16) instead of the public internet.

This prevents security groups from being flagged in Policy Engine risk assessment.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@licjun licjun requested a review from a team as a code owner February 17, 2026 21:28
@licjun licjun merged commit dfc6b74 into develop Feb 17, 2026
7 checks passed
@licjun licjun deleted the licjun/fix-policy-engine-risk branch February 17, 2026 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Comments