Skip to content

feat(cloudfront): detect Standard Logging v2 via CloudWatch Log Delivery - #10090

Merged
HugoPBrito merged 10 commits into
prowler-cloud:masterfrom
mcrolly:fix/cloudfront-logging-v2-10004
Mar 25, 2026
Merged

HugoPBrito merged 10 commits into
prowler-cloud:masterfrom
mcrolly:fix/cloudfront-logging-v2-10004

Conversation

@mcrolly

@mcrolly mcrolly commented Feb 16, 2026 •

Copy link
Copy Markdown
Contributor

Context

Fix #10004

CloudFront distributions using Standard Logging v2 (CloudWatch Log Delivery) are incorrectly flagged as having logging disabled. This is the current AWS-recommended logging method, configurable directly from the AWS Console.

Description

The cloudfront_distributions_logging_enabled check only evaluated legacy Standard Logging (S3) and Real-time logging, missing Standard Logging v2 which uses CloudWatch Logs delivery sources (logs:DescribeDeliverySources).

Changes:

  • Service (cloudfront_service.py): Added _get_log_delivery_sources() method that queries logs:DescribeDeliverySources and matches resourceArn to CloudFront distribution ARNs
  • Model: Added logging_v2_enabled: bool field to Distribution
  • Check: Updated to pass when any of the three logging methods is configured
  • Tests: Added v2 logging test cases, updated service test mock
  • CHANGELOG: Added entry under Fixed in 5.19.0

Steps to review

  1. Review _get_log_delivery_sources() in cloudfront_service.py — uses paginated logs:DescribeDeliverySources to detect v2 logging
  2. Verify the check logic now covers all three logging paths
  3. Run tests: pytest -xvs tests/providers/aws/services/cloudfront/

Checklist

SDK/CLI

  • Are there new checks included in this PR? No
    • No new permissions needed — logs:DescribeDeliverySources is read-only

License

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Fixes prowler-cloud#10004

The cloudfront_distributions_logging_enabled check only evaluated legacy
Standard Logging (S3) and Real-time logging, missing Standard Logging v2
which is configured via CloudWatch Logs delivery sources.

Changes:
- Add _get_log_delivery_sources() to CloudFront service to query
  logs:DescribeDeliverySources and match resourceArns to distributions
- Add logging_v2_enabled field to Distribution model
- Update check to pass when any logging method is configured
- Add unit tests for v2 logging scenarios
@mcrolly
mcrolly requested review from a team February 16, 2026 19:05
@github-actions github-actions Bot added provider/aws Issues/PRs related with the AWS provider community Opened by the Community labels Feb 16, 2026
@github-actions

github-actions Bot commented Feb 16, 2026 •

Copy link
Copy Markdown
Contributor

✅ Conflict Markers Resolved

All conflict markers have been successfully resolved in this pull request.

@jfagoagas jfagoagas added the status/waiting-for-revision Waiting for maintainer's revision label Mar 9, 2026
@codecov

codecov Bot commented Mar 9, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.45455% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 6.51%. Comparing base (aa36417) to head (72ba644).
⚠️ Report is 8 commits behind head on master.

❗ There is a different number of reports uploaded between BASE (aa36417) and HEAD (72ba644). Click for more details.

HEAD has 1 upload less than BASE
Flag BASE (aa36417) HEAD (72ba644)
api 1 0
Additional details and impacted files
@@             Coverage Diff             @@
##           master   #10090       +/-   ##
===========================================
- Coverage   93.42%    6.51%   -86.91%     
===========================================
  Files         219      834      +615     
  Lines       30698    23759     -6939     
===========================================
- Hits        28679     1549    -27130     
- Misses       2019    22210    +20191     
Flag Coverage Δ
api ?
prowler-py3.10-aws 6.51% <95.45%> (?)
prowler-py3.11-aws 6.51% <95.45%> (?)
prowler-py3.12-aws 6.51% <95.45%> (?)
prowler-py3.9-aws 6.51% <95.45%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
prowler 6.51% <95.45%> (∅)
api ∅ <ø> (∅)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jfagoagas jfagoagas self-assigned this Mar 23, 2026
@jfagoagas

Copy link
Copy Markdown
Member

Hi @mcrolly apologies for the delay. I'm going to review changes and will make some edits if needed. Thanks!

@jfagoagas jfagoagas changed the title fix(cloudfront): detect Standard Logging v2 via CloudWatch Log Delivery feat(cloudfront): detect Standard Logging v2 via CloudWatch Log Delivery Mar 23, 2026
@HugoPBrito
HugoPBrito merged commit 833f377 into prowler-cloud:master Mar 25, 2026
33 of 36 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community Opened by the Community metadata-review provider/aws Issues/PRs related with the AWS provider status/waiting-for-revision Waiting for maintainer's revision

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CloudFront logging check does not detect Standard Logging (v2) via CloudWatch Log Delivery

3 participants