# C7n Community Meeting Minutes # September 13th 2022 :::info - **URL:** meet.google.com/mii-evqh-esh - **Date:** September 13th, 2022 (2:00 PM (ET) / 11:00 PM (PT) / 6PM (UTC)) - **[Timezone Converter (Click me)](https://www.timeanddate.com/worldclock/converter.html?iso=20220621T180000&p1=263&p2=224&p3=136&p4=37&p5=367&p6=438&p7=248&p8=22)** - **Agenda** 1. Intros `10m` 1. Agenda Items `20m` 1. PR Party `30m` - **Meeting Contact:** Jorge: <jorge@stacklet.io> - **Video Archive and Transcripts**: https://mtngs.io/cloud-custodian/community-meetings/ ::: [![Video Recording](https://img.youtube.com/vi/7Ghds99cbvs/0.jpg)](https://youtu.be/7Ghds99cbvs) ## Agenda Item - Intros, etc. - Governance Updates - See this [GitHub issue](https://github.com/cloud-custodian/cloud-custodian/issues/7149) for the latest draft revisions. - Governance as Code day CFPs are technically closed but we can try to do another track if we get more submissions! - https://github.com/orgs/cloud-custodian/discussions/7625 - [CFP Form](https://docs.google.com/forms/d/e/1FAIpQLSfUf5bB0k-XZRH_IXUnCQxIX1nxHI0dxrSxOXUMBhMNtUh0lQ/viewform) - [Registration](https://hopin.com/events/governance-as-code-day-with-cloud-custodian-hosted-by-stacklet-2022?hss_channel=tw-1242918094160498699) - We're testing Slack! Join us: - [Invite page](https://communityinviter.com/apps/cloud-custodian/c7n-chat) - PRs incoming to update project link - Still working on an archive solution, more to follow next week - [wwitzel3] - https://github.com/cloud-custodian/tfparse - A python extension for parsing and evaluating terraform using defsec. - [sonny] - K8s provider update - See [#7697](https://github.com/cloud-custodian/cloud-custodian/pull/7697) - Image signing update - [aj/jorge/sonny] - Changelog discussion - Contributor guide skeleton ## Weekly Stats | | Opened this week| Closed this week| |--|---|-----| |Issues| 9 | 10| |PR's| 27 | 30| | | | |--|--| | New stars | 192| | New forks | 54| ## PR's Opened * :boom: [#7706](https://github.com/cloud-custodian/cloud-custodian/pull/7706): Add FMS WAFv2 support for alb, cloudfront * :boom: [#7729](https://github.com/cloud-custodian/cloud-custodian/pull/7729): Aws.rds.cluster.paragroup.filter * :boom: [#7696](https://github.com/cloud-custodian/cloud-custodian/pull/7696) * [#7744](https://github.com/cloud-custodian/cloud-custodian/pull/7744): Added Instance Metadata Tags action * [#7743](https://github.com/cloud-custodian/cloud-custodian/pull/7743): releng - aws - ec2 tag - fix test * :boom: [#7740](https://github.com/cloud-custodian/cloud-custodian/pull/7740): Fixing a bug in the filter_resources code * :boom: [#7739](https://github.com/cloud-custodian/cloud-custodian/pull/7739): core - filters - add value-list filter * [#7737](https://github.com/cloud-custodian/cloud-custodian/pull/7737): gcp - build - query fix & resource_map cleanup * :boom: [#7735](https://github.com/cloud-custodian/cloud-custodian/pull/7735): c7n_tencentcloud - tests - support vcr for flight recording * [#7734](https://github.com/cloud-custodian/cloud-custodian/pull/7734): releng - ci - gcp/azure ft * [#7733](https://github.com/cloud-custodian/cloud-custodian/pull/7733): releng - ci - add AWS functional tests to github actions, fix FTs * [#7732](https://github.com/cloud-custodian/cloud-custodian/pull/7732): ci - add functional tests * [#7727](https://github.com/cloud-custodian/cloud-custodian/pull/7727): core - add directory loader * [#7726](https://github.com/cloud-custodian/cloud-custodian/pull/7726): releng - fix docker ci if statement for publishing * [#7725](https://github.com/cloud-custodian/cloud-custodian/pull/7725): aws - eks - add kms filter * [#7724](https://github.com/cloud-custodian/cloud-custodian/pull/7724): releng - github actions - use setup-python native poetry caching * [#7723](https://github.com/cloud-custodian/cloud-custodian/pull/7723): feat: add main unittest and support retry, paged query, adding tags * [#7722](https://github.com/cloud-custodian/cloud-custodian/pull/7722): AWS - Lambda added new action 'set-xray-tracing' * [#7721](https://github.com/cloud-custodian/cloud-custodian/pull/7721): offhour - support GCP resources with escaped label * [#7720](https://github.com/cloud-custodian/cloud-custodian/pull/7720): aws - dynamodb - add consecutive daily snapshot count filter * [#7718](https://github.com/cloud-custodian/cloud-custodian/pull/7718): chore - update license headers across files * [#7715](https://github.com/cloud-custodian/cloud-custodian/pull/7715): releng - fix for dockerfile after poetry update * [#7714](https://github.com/cloud-custodian/cloud-custodian/pull/7714): aws - augment resources with model data * [#7712](https://github.com/cloud-custodian/cloud-custodian/pull/7712): releng - fix docker build action * [#7711](https://github.com/cloud-custodian/cloud-custodian/pull/7711): core - use cache context manager uniformly - resolves value-from cache err * [#7709](https://github.com/cloud-custodian/cloud-custodian/pull/7709): Adding kms-key-filter for secrets manager * [#7708](https://github.com/cloud-custodian/cloud-custodian/pull/7708): azure, gcp - add data to notify action * [#7707](https://github.com/cloud-custodian/cloud-custodian/pull/7707): Adding kms-key-gilter for secrets manager ## PR's Closed * [#7743](https://github.com/cloud-custodian/cloud-custodian/pull/7743): releng - aws - ec2 tag - fix test * [#7740](https://github.com/cloud-custodian/cloud-custodian/pull/7740): Fixing a bug in the filter_resources code * [#7737](https://github.com/cloud-custodian/cloud-custodian/pull/7737): gcp - build - query fix & resource_map cleanup * [#7735](https://github.com/cloud-custodian/cloud-custodian/pull/7735): c7n_tencentcloud - tests - support vcr for flight recording * [#7734](https://github.com/cloud-custodian/cloud-custodian/pull/7734): releng - ci - gcp/azure ft * [#7733](https://github.com/cloud-custodian/cloud-custodian/pull/7733): releng - ci - add AWS functional tests to github actions, fix FTs * [#7732](https://github.com/cloud-custodian/cloud-custodian/pull/7732): ci - add functional tests * [#7727](https://github.com/cloud-custodian/cloud-custodian/pull/7727): core - add directory loader * [#7726](https://github.com/cloud-custodian/cloud-custodian/pull/7726): releng - fix docker ci if statement for publishing * [#7725](https://github.com/cloud-custodian/cloud-custodian/pull/7725): aws - eks - add kms filter * [#7723](https://github.com/cloud-custodian/cloud-custodian/pull/7723): feat: add main unittest and support retry, paged query, adding tags * [#7721](https://github.com/cloud-custodian/cloud-custodian/pull/7721): offhour - support GCP resources with escaped label * [#7718](https://github.com/cloud-custodian/cloud-custodian/pull/7718): chore - update license headers across files * [#7715](https://github.com/cloud-custodian/cloud-custodian/pull/7715): releng - fix for dockerfile after poetry update * [#7714](https://github.com/cloud-custodian/cloud-custodian/pull/7714): aws - augment resources with model data * [#7712](https://github.com/cloud-custodian/cloud-custodian/pull/7712): releng - fix docker build action * [#7711](https://github.com/cloud-custodian/cloud-custodian/pull/7711): core - use cache context manager uniformly - resolves value-from cache err * [#7709](https://github.com/cloud-custodian/cloud-custodian/pull/7709): Adding kms-key-filter for secrets manager * [#7708](https://github.com/cloud-custodian/cloud-custodian/pull/7708): azure, gcp - add data to notify action * [#7707](https://github.com/cloud-custodian/cloud-custodian/pull/7707): Adding kms-key-gilter for secrets manager * [#7705](https://github.com/cloud-custodian/cloud-custodian/pull/7705): aws - ecr - add metrics filter for ECR * [#7698](https://github.com/cloud-custodian/cloud-custodian/pull/7698): Add FMS WAFv2 support for alb, cloudfront * [#7688](https://github.com/cloud-custodian/cloud-custodian/pull/7688): feat: init skeleton for tencentcloud * :boom: [#7682](https://github.com/cloud-custodian/cloud-custodian/pull/7682): aws - output - try to determine bucket region without a client * [#7674](https://github.com/cloud-custodian/cloud-custodian/pull/7674): Added mark-for-op action and marked-for-op filter for FIS * [#7666](https://github.com/cloud-custodian/cloud-custodian/pull/7666): aws - kms - more cross account condition keys * [#7652](https://github.com/cloud-custodian/cloud-custodian/pull/7652): feat: add lambda handler as parameter #7635 * [#7618](https://github.com/cloud-custodian/cloud-custodian/pull/7618): Aws.rds.cluster.paragroup.filter * [#7574](https://github.com/cloud-custodian/cloud-custodian/pull/7574): aws - apigw waf - fix for #7573 and cloudtrail mode support for apigw * [#7532](https://github.com/cloud-custodian/cloud-custodian/pull/7532): Interpolate universal tags #6821 ## Issues Opened * [#7745](https://github.com/cloud-custodian/cloud-custodian/issues/7745): delete action on the secrets manager resource for the resource policy * [#7741](https://github.com/cloud-custodian/cloud-custodian/issues/7741): Bug in tags.py filter_resources methods * :boom: [#7738](https://github.com/cloud-custodian/cloud-custodian/issues/7738): Kubernetes Provider Roadmap * [#7736](https://github.com/cloud-custodian/cloud-custodian/issues/7736): Support CIDR math for Azure network security group ingress/egress filters * [#7731](https://github.com/cloud-custodian/cloud-custodian/issues/7731): Security Groups used by ECS and that are attached via SDK are detected as unused by c7n * [#7728](https://github.com/cloud-custodian/cloud-custodian/issues/7728): test case `test_value_from_sqlkv` failed * [#7719](https://github.com/cloud-custodian/cloud-custodian/issues/7719): Add kms filter for AWS EKS resource * [#7717](https://github.com/cloud-custodian/cloud-custodian/issues/7717): ECR Public Repositories * [#7710](https://github.com/cloud-custodian/cloud-custodian/issues/7710): Instructions on updating C7n, C7n-org, c7n-mailer in the Custodian Docs ## Issues Closed * [#7728](https://github.com/cloud-custodian/cloud-custodian/issues/7728): test case `test_value_from_sqlkv` failed * [#7719](https://github.com/cloud-custodian/cloud-custodian/issues/7719): Add kms filter for AWS EKS resource * [#7703](https://github.com/cloud-custodian/cloud-custodian/issues/7703): Elasticache metrics * [#7694](https://github.com/cloud-custodian/cloud-custodian/issues/7694): Add ECR metrics filter support * [#7693](https://github.com/cloud-custodian/cloud-custodian/issues/7693): sqlkvcache errors when using `value_from` * [#7690](https://github.com/cloud-custodian/cloud-custodian/issues/7690): Add Glue Connections tagging filter and action * [#7665](https://github.com/cloud-custodian/cloud-custodian/issues/7665): Add KMS condition key handlers for cross-account filter * [#7656](https://github.com/cloud-custodian/cloud-custodian/issues/7656): Cloud custodian v0.9.18.0 is not able to find our policy file in the container * [#7573](https://github.com/cloud-custodian/cloud-custodian/issues/7573): APIGateway resources returned are tuples * [#6821](https://github.com/cloud-custodian/cloud-custodian/issues/6821): AWS: Add interpolation to the kms-key tag a