.snykfile in the directory where you launch the
snyk iac describecommand, typically the root of your IaC repo.
resource_idis a wildcard to exclude all resources of a given type
resource_idis a wildcard to ignore a drift on given field for a given type and
pathcan also contain wildcards.
.snykpolicy file also supports negation of rules. This allows you to ignore everything except certain types. In this example, only S3 buckets will not be ignored:
snyk iac describeignores this resource.
snyk iac update-exclude-policy --help.
.snykpolicy file, adding all the detected drifts to it, in order to ignore them all.