🔐 IAM (Global)

🛡️ IAM Compliance Findings

4

Total IAM Users

4

Users Without MFA

2

Access Keys >90 Days Old

0

Users with Admin Access

👥 IAM Users
User Name MFA Enabled Access Key ID Key Status Key Created
vegastars_staging_cms_nginx_s3_gatewayNo---
vegastars_staging_ecs_deployNoAKIAQCFFYI73RQ6CXHBMActive2025-08-29
vegastars_staging_s3uploadNoAKIAQCFFYI73Y3AWQYQGActive2025-08-29
vegastars_staging_sqsNo---

📍 Region: eu-west-2

🌐 VPCs & Subnets
Name VPC ID CIDR Block State Tenancy Tags
aws-controltower-VPC vpc-0e533e6ec57b55bb4 172.31.0.0/16 available default aws:cloudformation:stack-name=StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32aws:cloudformation:stack-id=arn:aws:cloudformation:eu-west-2:004642588663:stack/StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32/fe619890-2bd6-11f0-a89b-06099fe648afaws:cloudformation:logical-id=VPC
Subnets
Name Subnet ID VPC ID CIDR Block AZ Available IPs Public IP on Launch Tags
aws-controltower-PrivateSubnet1A subnet-0c6a4b4c3900f365a vpc-0e533e6ec57b55bb4 172.31.64.0/20 eu-west-2a 4091 No aws:cloudformation:logical-id=PrivateSubnet1Aaws:cloudformation:stack-name=StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32aws:cloudformation:stack-id=arn:aws:cloudformation:eu-west-2:004642588663:stack/StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32/fe619890-2bd6-11f0-a89b-06099fe648afNetwork=Private
aws-controltower-PrivateSubnet3A subnet-0b0b72fe05f46f609 vpc-0e533e6ec57b55bb4 172.31.80.0/20 eu-west-2c 4091 No aws:cloudformation:stack-name=StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32Network=Privateaws:cloudformation:stack-id=arn:aws:cloudformation:eu-west-2:004642588663:stack/StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32/fe619890-2bd6-11f0-a89b-06099fe648afaws:cloudformation:logical-id=PrivateSubnet3A
aws-controltower-PrivateSubnet2A subnet-0180b0e7d9621b0f8 vpc-0e533e6ec57b55bb4 172.31.32.0/20 eu-west-2b 4091 No Network=Privateaws:cloudformation:stack-id=arn:aws:cloudformation:eu-west-2:004642588663:stack/StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32/fe619890-2bd6-11f0-a89b-06099fe648afaws:cloudformation:logical-id=PrivateSubnet2Aaws:cloudformation:stack-name=StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32
Lambda Functions
Function Name Runtime Memory Timeout VPC Last Modified Tags
aws-controltower-NotificationForwarder python3.13 128 MB 60s No VPC 2025-08-21 aws:cloudformation:logical-id=ForwardSnsNotificationaws:cloudformation:stack-id=arn:aws:cloudformation:eu-west-2:004642588663:stack/StackSet-AWSControlTowerBP-BASELINE-CLOUDWATCH-b98dc7ff-77c1-4c16-8941-06428e11e808/84c19440-2bd6-11f0-8cbb-067cb2bf19b1aws:cloudformation:stack-name=StackSet-AWSControlTowerBP-BASELINE-CLOUDWATCH-b98dc7ff-77c1-4c16-8941-06428e11e808
📋 CloudWatch Log Groups
Total Log Groups: 2
Without Retention Policy: 0
Log Group Name Retention (Days) Stored Size
/aws/lambda/aws-controltower-NotificationForwarder 14 0 B
StackSet-AWSControlTowerBP-VPC-ACCOUNT-FACTORY-V1-281cb42c-86a3-46c3-a93f-d2797ae0fb32-VPCFlowLogsLogGroup-SJRbPNe8TZ4j 90 0 B
🛡️ Compliance Findings
Network & Security (Section 5.2)

0

Open Security Groups (0.0.0.0/0)

0

EC2 Without IMDSv2

Yes

CloudTrail Enabled

Data Protection (Section 5.4)

0

Unencrypted EBS Volumes

0

Unencrypted RDS

0

SQS Without Encryption

Logging & Monitoring (Section 5.3)

0

Log Groups (No Retention)

RDS Standards (Section 7)

0

Public RDS Instances

0

RDS Without Multi-AZ

0

RDS Without Backups

Lambda Standards (Section 7)

0

Lambda Default Timeout (3s)

1

Lambda Without DLQ

SQS Standards (Section 7)

0

SQS Without DLQ

ECS Standards (Section 7)

0

Plaintext Env Vars

0

Privileged Containers

📍 Region: ap-east-1

🌐 VPCs & Subnets
Name VPC ID CIDR Block State Tenancy Tags
vegastars-staging-vpc vpc-05affcf55cc0c3910 10.10.0.0/16 available default Customer=vegastarsEnvironment=stagingmap-migrated=migS0EK6JMBZC
Subnets
Name Subnet ID VPC ID CIDR Block AZ Available IPs Public IP on Launch Tags
vegastars-staging-private-subnet-1 subnet-0251a64cb95799483 vpc-05affcf55cc0c3910 10.10.1.0/24 ap-east-1a 246 No Customer=vegastarsEnvironment=stagingmap-migrated=migS0EK6JMBZC
vegastars-staging-private-subnet-2 subnet-0c0e9638b2f82b2d8 vpc-05affcf55cc0c3910 10.10.3.0/24 ap-east-1b 247 No map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastars
vegastars-staging-public-subnet-2 subnet-05f88b9fb16c2f6c3 vpc-05affcf55cc0c3910 10.10.4.0/24 ap-east-1b 247 No Customer=vegastarsmap-migrated=migS0EK6JMBZCEnvironment=staging
vegastars-staging-public-subnet-1 subnet-0485f874b0ed5430a vpc-05affcf55cc0c3910 10.10.2.0/24 ap-east-1a 246 No map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastars
🖥️ EC2 Instances
Name Instance ID Type State Public IP Private IP VPC Security Groups AMI Key Pair IAM Profile EBS Volumes IMDSv2 Tags
vegastars_staging_bastion_host i-01e4df7127883286d c5a.xlarge stopped 16.163.49.90 10.10.2.116 vpc-05affcf55cc0c3910 sg-008663f41bbb0eda0 ami-0c815d298114f624e vegastars_staging_Aug2025 vegastars_staging_SSMInstanceProfile 1 required map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastars
vegastars_staging_mongodb_cms i-0c63b822645027f2a t3.medium stopped - 10.10.1.68 vpc-05affcf55cc0c3910 sg-0e3b6c93bbc18121e ami-00d77e4c9718c184f vegastars_staging_Aug2025 vegastars_staging_SSMInstanceProfile 1 optional map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
💾 EBS Volumes
Name Volume ID Size (GiB) Type State Encrypted IOPS Attached Instance Device AZ Tags
vegastars_staging_mongodb_cms_volume vol-0c7f60948bffc996a 50 gp3 in-use No 3000 i-0c63b822645027f2a /dev/sda1 ap-east-1a Environment=stagingCustomer=vegastarsmap-migrated=migS0EK6JMBZC
vegastars_staging_bastion_host_volume vol-012c64a7495140408 50 gp3 in-use No 3000 i-01e4df7127883286d /dev/sda1 ap-east-1a Customer=vegastarsmap-migrated=migS0EK6JMBZCEnvironment=staging
🐳 ECS Clusters
Cluster Name Status Running Tasks Pending Tasks Active Services Container Instances
vegastars-staging-callback-fargate-ecs-cluster ACTIVE 0 0 1 0
vegastars-staging-api-callback-ecs-cluster ACTIVE 0 0 0 0
vegastars-staging-queue-ecs-cluster ACTIVE 0 0 1 0
vegastars-staging-api-fargate-ecs-cluster ACTIVE 0 0 1 0
vegastars-staging-game-proxy-v2-fargate-ecs-cluster ACTIVE 1 0 1 0
vegastars-staging-fe-bo-cms-cdn-websocket-cronjob-ecs-cluster ACTIVE 0 0 6 0
vegastars-staging-game-proxy-fargate-ecs-cluster ACTIVE 0 0 1 0
⚙️ ECS Services
Service Name Status Desired Running Launch Type Task Definition Load Balancers Security Groups
vegastars-staging-game-proxy-v2-service ACTIVE 1 1 FARGATE vegastars-staging-game-proxy-v2-fargate-task-definitions:19 1 target groups sg-0e3b6c93bbc18121e
vegastars-staging-callback-service ACTIVE 0 0 FARGATE vegastars-staging-callback-fargate-task-definitions:1 1 target groups sg-0e3b6c93bbc18121e
vegastars-staging-game-proxy-service ACTIVE 0 0 FARGATE vegastars-staging-game-proxy-fargate-task-definitions:2 1 target groups sg-0e3b6c93bbc18121e
vegastars-staging-api-service ACTIVE 0 0 FARGATE vegastars-staging-api-fargate-task-definitions:1 1 target groups sg-0e3b6c93bbc18121e
vegastars-staging-bo-service ACTIVE 0 0 EC2 vegastars-staging-bo-task-definitions:1 1 target groups
vegastars-staging-cms-service ACTIVE 0 0 EC2 vegastars-staging-cms-task-definitions:3 2 target groups
vegastars-staging-fe-service ACTIVE 0 0 EC2 vegastars-staging-fe-task-definitions:3 1 target groups
vegastars-staging-cronjob-service ACTIVE 0 0 EC2 vegastars-staging-cronjob-task-definitions:1 0 target groups
vegastars-staging-websocket-services ACTIVE 0 0 EC2 vegastars-staging-websocket-task-definitions:1 3 target groups
vegastars-staging-cdn-cms-service ACTIVE 0 0 EC2 vegastars-staging-cdn-cms-task-definitions:1 1 target groups
vegastars-staging-queue-worker-service ACTIVE 0 0 EC2 vegastars-staging-queue-worker-task-definitions:1 0 target groups
📋 ECS Task Definitions (Active)
Family Rev CPU Memory Containers Task Role Privileged Env Vars Secrets Log Config
vegastars-staging-api-fargate-task-definitions 1 512 1024 3 Yes No 4 0 No logs
vegastars-staging-bo-task-definitions 1 - - 3 No No 4 0 No logs
vegastars-staging-callback-fargate-task-definitions 1 512 1024 3 Yes No 4 0 No logs
vegastars-staging-cdn-cms-task-definitions 1 - - 1 No No 0 0 No logs
vegastars-staging-cms-task-definitions 3 - - 2 No No 1 0 No logs
vegastars-staging-cronjob-task-definitions 1 - - 3 No No 4 0 No logs
vegastars-staging-fe-task-definitions 3 - - 2 No No 1 0 No logs
vegastars-staging-game-proxy-fargate-task-definitions 2 2048 4096 2 Yes No 1 0 No logs
vegastars-staging-game-proxy-v2-fargate-task-definitions 19 2048 4096 3 Yes No 1 0 No logs
vegastars-staging-queue-worker-task-definitions 1 - - 3 No No 4 0 No logs
vegastars-staging-websocket-task-definitions 1 - - 2 No No 0 0 No logs, json-file
Container Configuration Detail

⚠️ Plaintext environment variables should be avoided for sensitive data. Use Secrets Manager or SSM Parameter Store. log_router containers are excluded.

Task Definition Container Image Log Config Plaintext Env Vars Secrets (SSM/SM)
vegastars-staging-api-fargate-task-definitions:1 terragon-api 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-api:4d9762d-38-develop No logs None -
vegastars-staging-api-fargate-task-definitions:1 filebeat 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0 No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-api-fargate-task-definitions:1 filebeat-integration 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0-integration No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-bo-task-definitions:1 terragon-bo 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-bo:4d9762d-38-develop No logs None -
vegastars-staging-bo-task-definitions:1 filebeat 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0 No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-bo-task-definitions:1 filebeat-integration 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0-integration No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-callback-fargate-task-definitions:1 terragon-callback 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-callback:4d9762d-38-develop No logs None -
vegastars-staging-callback-fargate-task-definitions:1 filebeat 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0 No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-callback-fargate-task-definitions:1 filebeat-integration 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0-integration No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-cdn-cms-task-definitions:1 nginx-s3-gateway 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-nginx-base:s3-gateway-1.0 No logs None -
vegastars-staging-cms-task-definitions:3 nginx-cms 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-nginx-base:3.0 No logs NGINX_DEFAULT_CONF_FILE -
vegastars-staging-cms-task-definitions:3 terragon-cms 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-cms:e5923cc-4-develop No logs None -
vegastars-staging-cronjob-task-definitions:1 queue-worker 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-queue-worker:4d9762d-38-develop No logs None -
vegastars-staging-cronjob-task-definitions:1 filebeat 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0 No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-cronjob-task-definitions:1 filebeat-integration 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0-integration No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-fe-task-definitions:3 nginx-fe 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-nginx-base:3.0 No logs NGINX_DEFAULT_CONF_FILE -
vegastars-staging-fe-task-definitions:3 app 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-fe:e786bef-17319383167-release-1.10.3 No logs None -
vegastars-staging-game-proxy-fargate-task-definitions:2 nginx 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-nginx-base:3.0-game-proxy-v2 No logs None -
vegastars-staging-game-proxy-fargate-task-definitions:2 proxy 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-game-proxy:d5f72c6-16-main No logs NODE_ENV -
vegastars-staging-game-proxy-v2-fargate-task-definitions:19 nginx 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-nginx-base:3.0-game-proxy-v2 No logs None -
vegastars-staging-game-proxy-v2-fargate-task-definitions:19 proxy 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-game-proxy:a48543b-45-release-safari-fix No logs NODE_ENV -
vegastars-staging-game-proxy-v2-fargate-task-definitions:19 epoxy-server 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastar-staging-docker-base:epoxy-server-2.0.0 No logs None -
vegastars-staging-queue-worker-task-definitions:1 queue-worker 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-queue-worker:4d9762d-38-develop No logs None -
vegastars-staging-queue-worker-task-definitions:1 filebeat 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0 No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-queue-worker-task-definitions:1 filebeat-integration 004642588663.dkr.ecr.ap-east-1.amazonaws.com/filebeat:3.0-integration No logs GRAYLOG_HOSTGRAYLOG_LISTEN_PORT -
vegastars-staging-websocket-task-definitions:1 nginx-websocket 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-nginx-base:3.0 No logs None -
vegastars-staging-websocket-task-definitions:1 app 004642588663.dkr.ecr.ap-east-1.amazonaws.com/vegastars-staging-soketi:1.0-16-debian json-file None -
🗄️ RDS Instances
DB Identifier Engine Class Status Storage Encrypted Multi-AZ Public Backup Delete Prot. Tags
vegastars-staging-aurora-primary-cluster-instance-0 aurora-mysql 8.0.mysql_aurora.3.08.2 db.t4g.medium available 1 GiB Yes No No 7d No map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastarsName=vegastars-staging-database-writer
Lambda Functions
Function Name Runtime Memory Timeout VPC Last Modified Tags
vegastars-staging-change-proxy-ip python3.13 128 MB 30s No VPC 2026-01-15 Customer=vegastarsEnvironment=stagingmap-migrated=migS0EK6JMBZC
📨 SQS Queues
Total Queues: 19
Without Encryption: 19
Without DLQ: 19
Queue Name Type Encrypted DLQ Configured Visibility Timeout Messages Tags
accumulate_bonus_programs_ref_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
accumulate_bonus_programs_referral_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
accumulate_bonus_programs_settle_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
accumulate_bonus_programs_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
broadcast_balance_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
broadcast_recent_rewards_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
compliance_actions_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
compliances_vegastars_staging.fifo FIFO No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
crm_high_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
crm_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
game_logs_vegastars_staging.fifo FIFO No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
kafka_failed_message_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
player_flagged_computing_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
player_tracking_session_computing_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
segments_computing_vegastars_staging.fifo FIFO No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
segments_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
segments_vegastars_staging.fifo FIFO No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
tournaments_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
wagering_requirements_vegastars_staging Standard No No 300s 0 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
🔑 Secrets Manager
Total Secrets: 3
Without Rotation: 3
Secret Name Description KMS Key Rotation Last Rotated Last Accessed Tags
vegastars-staging-rds-admin-password - secretsmanager Disabled - 2026-01-15 map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastars
vegastars-staging-redshift-admin-password - secretsmanager Disabled - 2026-01-15 map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastars
vegastars-staging-other-credentials - secretsmanager Disabled - 2026-01-15 map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastars
📱 AWS Amplify Apps
App Name App ID Platform Repository Default Domain Production Branch Branches Created Tags
vegastars-frontend d1ckiyvnd6l8ns WEB_COMPUTE https://github.com/bwgservices/vegastars-frontend d1ckiyvnd6l8ns.amplifyapp.com - 1 2026-01-12 -
Amplify Branches
App Name Branch Name Stage Framework Auto Build Basic Auth Total Jobs
vegastars-frontend release-staging NONE - Yes No 0
📋 CloudWatch Log Groups
Total Log Groups: 10
Without Retention Policy: 4
Log Group Name Retention (Days) Stored Size
/aws/amplify/d1ckiyvnd6l8ns Never Expire 0 B
/aws/lambda/vegastars-staging-change-proxy-ip 30 0 B
/aws/rds/cluster/vegastars-staging-primary-cluster/error Never Expire 129.18 MB
/aws/rds/cluster/vegastars-staging-primary-cluster/slowquery Never Expire 825.19 MB
/ecs/vegastars-staging-api 365 0 B
/ecs/vegastars-staging-callback 365 0 B
/ecs/vegastars-staging-game-proxy 365 0 B
/ecs/vegastars-staging-game-proxy-v2 365 4.32 KB
RDSOSMetrics 30 66.16 MB
vegastars-staging-backend-redis-slowlog Never Expire 0 B
⚖️ Application & Network Load Balancers
Name Type Scheme State DNS Name VPC AZs Listeners Target Groups Tags
vegastars-staging-other-ecs-alb APPLICATION internet-facing active vegastars-staging-other-ecs-alb-2113333005.ap-east-1.elb.amazonaws.com vpc-05affcf55cc0c3910 2 HTTP:80, HTTPS:443 11 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
vegastars-staging-api-cb-ecs-alb APPLICATION internet-facing active vegastars-staging-api-cb-ecs-alb-1451829908.ap-east-1.elb.amazonaws.com vpc-05affcf55cc0c3910 2 HTTPS:443, HTTP:80 2 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
vegastars-staging-ecs-int-alb APPLICATION internal active internal-vegastars-staging-ecs-int-alb-2105877725.ap-east-1.elb.amazonaws.com vpc-05affcf55cc0c3910 2 HTTP:80, HTTPS:443 2 map-migrated=migS0EK6JMBZCCustomer=vegastarsEnvironment=staging
Target Groups
Load Balancer Target Group Name Protocol Port Target Type Health Check
vegastars-staging-other-ecs-alb vegastars-staging-bo-tg-443 HTTPS 440 instance HTTPS:/player/api/v1/ping
vegastars-staging-other-ecs-alb vegastars-staging-cdn-cms-tg-449 HTTPS 449 instance HTTPS:/health
vegastars-staging-other-ecs-alb vegastars-staging-cms-tg-444 HTTPS 444 instance HTTPS:/
vegastars-staging-other-ecs-alb vegastars-staging-elk-tg-443 HTTPS 443 instance HTTPS:/
vegastars-staging-other-ecs-alb vegastars-staging-fe-tg-443 HTTPS 443 instance HTTPS:/robots.txt
vegastars-staging-other-ecs-alb vegastars-staging-game-px-tg-443 HTTPS 443 ip HTTPS:/health
vegastars-staging-other-ecs-alb vegastars-staging-gpx-v2-tg-443 HTTPS 443 ip HTTPS:/healthz
vegastars-staging-other-ecs-alb vegastars-staging-graylog-tg-443 HTTPS 443 instance HTTPS:/
vegastars-staging-other-ecs-alb vegastars-staging-intglog-tg-443 HTTPS 443 instance HTTPS:/
vegastars-staging-other-ecs-alb vegastars-staging-ws-tg-6002 HTTPS 6002 instance HTTPS:/
vegastars-staging-other-ecs-alb vegastars-staging-ws-tg-9601 HTTP 9601 instance HTTP:/
vegastars-staging-api-cb-ecs-alb vegastars-staging-api-fg-tg-441 HTTPS 441 ip HTTPS:/robots.txt
vegastars-staging-api-cb-ecs-alb vegastars-staging-cb-fg-tg-443 HTTPS 443 ip HTTPS:/player/api/v1/ping
vegastars-staging-ecs-int-alb vegastars-staging-cms-int-444 HTTPS 444 instance HTTPS:/
vegastars-staging-ecs-int-alb vegastars-staging-ws-int-tg-6002 HTTPS 6002 instance HTTPS:/
🔐 Security Groups (In Use)
Name Group ID VPC Used By Inbound Ports Outbound Ports Open to Internet Tags
vegastars-staging-allow-local-port-3306 sg-0255907f915f5bb2c vpc-05affcf55cc0c3910 RDS(1) tcp:3306 All No Customer=vegastarsEnvironment=stagingmap-migrated=migS0EK6JMBZC
vegastars-staging-allow-ssh sg-008663f41bbb0eda0 vpc-05affcf55cc0c3910 EC2(1) tcp:22 All No Environment=stagingmap-migrated=migS0EK6JMBZCCustomer=vegastars
vegastars-staging-allow-local sg-0e3b6c93bbc18121e vpc-05affcf55cc0c3910 APPLICATION(1), EC2(1), ECS(4) All All No Environment=stagingCustomer=vegastarsmap-migrated=migS0EK6JMBZC
vegastars-staging-allow-http-https sg-0442b119388a99f09 vpc-05affcf55cc0c3910 APPLICATION(2) tcp:443, tcp:80 All Yes map-migrated=migS0EK6JMBZCEnvironment=stagingCustomer=vegastars
Security Group Rules Detail
Security Group Direction Protocol Port Range Source/Destination
vegastars-staging-allow-local-port-3306 sg-0255907f915f5bb2c Inbound tcp 3306 10.10.3.0/24, 10.10.1.0/24, 10.10.2.116/32
vegastars-staging-allow-ssh sg-008663f41bbb0eda0 Inbound tcp 22 93.36.220.74/32, 92.251.112.229/32, 43.218.68.91/32, 3.108.12.97/32, 38.54.33.217/32, 115.78.100.17/32, 119.93.179.143/32, 14.161.16.211/32, 115.79.29.29/32, 118.69.133.85/32
vegastars-staging-allow-local sg-0e3b6c93bbc18121e Inbound All All 10.10.3.0/24, 10.10.4.0/24, 10.10.1.0/24, 10.10.2.0/24
vegastars-staging-allow-http-https sg-0442b119388a99f09 Inbound tcp 80 0.0.0.0/0
vegastars-staging-allow-http-https sg-0442b119388a99f09 Inbound tcp 443 0.0.0.0/0
vegastars-staging-allow-local-port-3306 sg-0255907f915f5bb2c Outbound All All 0.0.0.0/0
vegastars-staging-allow-ssh sg-008663f41bbb0eda0 Outbound All All 0.0.0.0/0
vegastars-staging-allow-local sg-0e3b6c93bbc18121e Outbound All All 0.0.0.0/0
vegastars-staging-allow-http-https sg-0442b119388a99f09 Outbound All All 0.0.0.0/0
🛡️ Compliance Findings
Network & Security (Section 5.2)

1

Open Security Groups (0.0.0.0/0)

1

EC2 Without IMDSv2

Yes

CloudTrail Enabled

Data Protection (Section 5.4)

2

Unencrypted EBS Volumes

0

Unencrypted RDS

19

SQS Without Encryption

Logging & Monitoring (Section 5.3)

4

Log Groups (No Retention)

RDS Standards (Section 7)

0

Public RDS Instances

1

RDS Without Multi-AZ

0

RDS Without Backups

Lambda Standards (Section 7)

0

Lambda Default Timeout (3s)

1

Lambda Without DLQ

SQS Standards (Section 7)

19

SQS Without DLQ

ECS Standards (Section 7)

24

Plaintext Env Vars

0

Privileged Containers