diff --git a/checkov/terraform/checks/resource/azure/AKSEncryptionAtHostEnabled.py b/checkov/terraform/checks/resource/azure/AKSEncryptionAtHostEnabled.py index 95d3c81f280..0640780f851 100644 --- a/checkov/terraform/checks/resource/azure/AKSEncryptionAtHostEnabled.py +++ b/checkov/terraform/checks/resource/azure/AKSEncryptionAtHostEnabled.py @@ -1,4 +1,3 @@ - from checkov.common.models.enums import CheckCategories, CheckResult from checkov.terraform.checks.resource.base_resource_value_check import BaseResourceValueCheck @@ -18,8 +17,13 @@ def __init__(self) -> None: id = "CKV_AZURE_227" supported_resources = ("azurerm_kubernetes_cluster", "azurerm_kubernetes_cluster_node_pool") categories = (CheckCategories.KUBERNETES,) - super().__init__(name=name, id=id, categories=categories, supported_resources=supported_resources, - missing_block_result=CheckResult.FAILED) + super().__init__( + name=name, + id=id, + categories=categories, + supported_resources=supported_resources, + missing_block_result=CheckResult.FAILED, + ) def get_inspected_key(self) -> str: if self.entity_type == "azurerm_kubernetes_cluster": @@ -28,5 +32,4 @@ def get_inspected_key(self) -> str: return "enable_host_encryption" - check = AKSEncryptionAtHostEnabled() diff --git a/checkov/terraform/checks/resource/azure/AKSEphemeralOSDisks.py b/checkov/terraform/checks/resource/azure/AKSEphemeralOSDisks.py index 54487e7901d..e8af9392c4a 100644 --- a/checkov/terraform/checks/resource/azure/AKSEphemeralOSDisks.py +++ b/checkov/terraform/checks/resource/azure/AKSEphemeralOSDisks.py @@ -26,7 +26,7 @@ def __init__(self) -> None: def get_inspected_key(self) -> str: return "default_node_pool/[0]/os_disk_type" - + def get_expected_value(self) -> Any: return "Ephemeral" diff --git a/tests/terraform/checks/resource/azure/test_AKSEncryptionAtHostEnabled.py b/tests/terraform/checks/resource/azure/test_AKSEncryptionAtHostEnabled.py index af0255e90d5..479e1aaaeeb 100644 --- a/tests/terraform/checks/resource/azure/test_AKSEncryptionAtHostEnabled.py +++ b/tests/terraform/checks/resource/azure/test_AKSEncryptionAtHostEnabled.py @@ -22,15 +22,15 @@ def test(self): 'azurerm_kubernetes_cluster_node_pool.pass' } failing_resources = { - 'azurerm_kubernetes_cluster.fail', 'azurerm_kubernetes_cluster.fail1', - 'azurerm_kubernetes_cluster_node_pool.fail', + 'azurerm_kubernetes_cluster.fail2', 'azurerm_kubernetes_cluster_node_pool.fail1', + 'azurerm_kubernetes_cluster_node_pool.fail2', } skipped_resources = {} - passed_check_resources = set([c.resource for c in report.passed_checks]) - failed_check_resources = set([c.resource for c in report.failed_checks]) + passed_check_resources = {c.resource for c in report.passed_checks} + failed_check_resources = {c.resource for c in report.failed_checks} self.assertEqual(summary['passed'], len(passing_resources)) self.assertEqual(summary['failed'], len(failing_resources))