cloudposture

package
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package cloudposture models vendor-neutral live cloud inventory and posture.

Index

Constants

View Source
const (
	RuleStoragePublic       = "cloud-storage-public"
	RuleComputePublic       = "cloud-compute-public"
	RuleIdentityWildcard    = "cloud-identity-wildcard"
	RuleIdentityUnusedAdmin = "cloud-identity-unused-privileged"
	RuleEncryptionDisabled  = "cloud-resource-encryption-disabled"
	RuleSensitivePublicPath = "cloud-network-sensitive-public-path"
	RuleIaCLiveDrift        = "cloud-iac-live-drift"
	ClassIaCLiveDrift       = "iac_live_drift"
)

Variables

This section is empty.

Functions

func DetectDrift

func DetectDrift(inv Inventory, expectations []Expectation) ([]PostureFinding, []CoverageIssue)

DetectDrift compares only explicit, matched control states.

func NormalizeRoot

func NormalizeRoot(provider Provider, root string) (string, string, error)

State is a three-valued observed control state. Unknown is never treated as secure. NormalizeRoot returns the provider-native root and its stable provider-qualified identity.

func ScopeKey

func ScopeKey(provider Provider, root string) (string, error)

ScopeKey returns the stable provider-qualified identity for one approved root.

Types

type CoverageIssue

type CoverageIssue struct {
	Provider Provider `json:"provider"`
	Scope    string   `json:"scope"`
	Category string   `json:"category"`
	Code     string   `json:"code"`
	Detail   string   `json:"detail,omitempty"`
}

CoverageIssue records why a scope or category could not be assessed completely.

type EvidenceReference

type EvidenceReference struct {
	ScopeKey string    `json:"scope_key"`
	ID       shared.ID `json:"id"`
	Hash     string    `json:"hash"`
}

type Expectation

type Expectation struct {
	Provider       Provider
	ScopeKey       string
	ResourceID     string
	Control        string
	State          State
	Source         string
	AnalysisID     shared.ID
	ArtifactDigest string
}

Expectation is one file-derived control expectation that can be joined to live state.

type Inventory

type Inventory struct {
	Provider      Provider
	ScopeKey      string
	Resources     []Resource
	Relationships []Relationship
	Complete      bool
}

Inventory is a bounded, normalized snapshot returned by a connector.

func (*Inventory) Sort

func (i *Inventory) Sort()

Sort makes connector output deterministic.

func (Inventory) Validate

func (i Inventory) Validate() error

Validate checks inventory identity and bounded-domain invariants.

type PostureFinding

type PostureFinding struct {
	RuleKey     string
	ScopeKey    string
	ResourceID  string
	Control     string
	Title       string
	Description string
	Severity    shared.Severity
	Class       string
}

PostureFinding is a provider-neutral rule match, converted to the standard Finding path by the use case.

func Evaluate

func Evaluate(inv Inventory) ([]PostureFinding, error)

Evaluate applies the high-confidence checks only to explicit provider facts.

type Provider

type Provider string

Provider identifies a supported cloud control plane.

const (
	ProviderAWS   Provider = "aws"
	ProviderAzure Provider = "azure"
	ProviderGCP   Provider = "gcp"
)

func (Provider) Valid

func (p Provider) Valid() bool

type Relationship

type Relationship struct {
	ScopeKey string
	FromID   string
	ToID     string
	Kind     asset.EdgeKind
}

Relationship is an observed relationship between normalized resources.

type Resource

type Resource struct {
	Provider       Provider
	ScopeKey       string
	AccountID      string
	ID             string
	Name           string
	Kind           asset.Kind
	ResourceType   string
	Region         string
	Public         State
	Encrypted      State
	Sensitive      bool
	PublicNetwork  State
	HighPrivilege  bool
	PolicyKnown    bool
	UnusedDays     int
	LastUseKnown   bool
	WildcardAction bool
	WildcardTarget bool
}

Resource is the SDK-free representation of one live cloud resource.

type Rule

type Rule struct {
	Key      string
	Title    string
	Category string
	Severity shared.Severity
}

Rule is a stable clean-room live posture check.

func Catalog

func Catalog() ([]Rule, error)

Catalog returns a validated, deterministic copy of the built-in rules.

func (Rule) Validate

func (r Rule) Validate() error

type Run

type Run struct {
	ID             shared.ID           `json:"id"`
	TenantID       shared.ID           `json:"-"`
	EngagementID   shared.ID           `json:"engagement_id"`
	Actor          string              `json:"actor"`
	Status         RunStatus           `json:"status"`
	Complete       bool                `json:"complete"`
	Assets         int                 `json:"assets"`
	Findings       int                 `json:"findings"`
	CoverageIssues []CoverageIssue     `json:"coverage_issues,omitempty"`
	ErrorCode      string              `json:"error_code,omitempty"`
	EvidenceRefs   []EvidenceReference `json:"evidence_refs,omitempty"`
	StartedAt      time.Time           `json:"started_at"`
	FinishedAt     *time.Time          `json:"finished_at,omitempty"`
}

Run is the durable, secret-free record returned by the CSPM API.

func (Run) Validate

func (r Run) Validate() error

type RunStatus

type RunStatus string

RunStatus is the durable CSPM execution lifecycle.

const (
	RunQueued    RunStatus = "queued"
	RunRunning   RunStatus = "running"
	RunSucceeded RunStatus = "succeeded"
	RunPartial   RunStatus = "partial"
	RunFailed    RunStatus = "failed"
	RunCancelled RunStatus = "cancelled"
)

func (RunStatus) Terminal

func (s RunStatus) Terminal() bool

func (RunStatus) Valid

func (s RunStatus) Valid() bool

type State

type State string
const (
	StateUnknown  State = "unknown"
	StateEnabled  State = "enabled"
	StateDisabled State = "disabled"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL