Documentation
¶
Overview ¶
Package cloudposture models vendor-neutral live cloud inventory and posture.
Index ¶
- Constants
- func DetectDrift(inv Inventory, expectations []Expectation) ([]PostureFinding, []CoverageIssue)
- func NormalizeRoot(provider Provider, root string) (string, string, error)
- func ScopeKey(provider Provider, root string) (string, error)
- type CoverageIssue
- type EvidenceReference
- type Expectation
- type Inventory
- type PostureFinding
- type Provider
- type Relationship
- type Resource
- type Rule
- type Run
- type RunStatus
- type State
Constants ¶
const ( RuleStoragePublic = "cloud-storage-public" RuleComputePublic = "cloud-compute-public" RuleIdentityWildcard = "cloud-identity-wildcard" RuleIdentityUnusedAdmin = "cloud-identity-unused-privileged" RuleEncryptionDisabled = "cloud-resource-encryption-disabled" RuleSensitivePublicPath = "cloud-network-sensitive-public-path" RuleIaCLiveDrift = "cloud-iac-live-drift" ClassIaCLiveDrift = "iac_live_drift" )
Variables ¶
This section is empty.
Functions ¶
func DetectDrift ¶
func DetectDrift(inv Inventory, expectations []Expectation) ([]PostureFinding, []CoverageIssue)
DetectDrift compares only explicit, matched control states.
func NormalizeRoot ¶
State is a three-valued observed control state. Unknown is never treated as secure. NormalizeRoot returns the provider-native root and its stable provider-qualified identity.
Types ¶
type CoverageIssue ¶
type CoverageIssue struct {
Provider Provider `json:"provider"`
Scope string `json:"scope"`
Category string `json:"category"`
Code string `json:"code"`
Detail string `json:"detail,omitempty"`
}
CoverageIssue records why a scope or category could not be assessed completely.
type EvidenceReference ¶
type Expectation ¶
type Expectation struct {
Provider Provider
ScopeKey string
ResourceID string
Control string
State State
Source string
AnalysisID shared.ID
ArtifactDigest string
}
Expectation is one file-derived control expectation that can be joined to live state.
type Inventory ¶
type Inventory struct {
Provider Provider
ScopeKey string
Resources []Resource
Relationships []Relationship
Complete bool
}
Inventory is a bounded, normalized snapshot returned by a connector.
type PostureFinding ¶
type PostureFinding struct {
RuleKey string
ScopeKey string
ResourceID string
Control string
Title string
Description string
Severity shared.Severity
Class string
}
PostureFinding is a provider-neutral rule match, converted to the standard Finding path by the use case.
func Evaluate ¶
func Evaluate(inv Inventory) ([]PostureFinding, error)
Evaluate applies the high-confidence checks only to explicit provider facts.
type Relationship ¶
Relationship is an observed relationship between normalized resources.
type Resource ¶
type Resource struct {
Provider Provider
ScopeKey string
AccountID string
ID string
Name string
Kind asset.Kind
ResourceType string
Region string
Public State
Encrypted State
Sensitive bool
PublicNetwork State
HighPrivilege bool
PolicyKnown bool
UnusedDays int
LastUseKnown bool
WildcardAction bool
WildcardTarget bool
}
Resource is the SDK-free representation of one live cloud resource.
type Rule ¶
Rule is a stable clean-room live posture check.
type Run ¶
type Run struct {
ID shared.ID `json:"id"`
TenantID shared.ID `json:"-"`
EngagementID shared.ID `json:"engagement_id"`
Actor string `json:"actor"`
Status RunStatus `json:"status"`
Complete bool `json:"complete"`
Assets int `json:"assets"`
Findings int `json:"findings"`
CoverageIssues []CoverageIssue `json:"coverage_issues,omitempty"`
ErrorCode string `json:"error_code,omitempty"`
EvidenceRefs []EvidenceReference `json:"evidence_refs,omitempty"`
StartedAt time.Time `json:"started_at"`
FinishedAt *time.Time `json:"finished_at,omitempty"`
}
Run is the durable, secret-free record returned by the CSPM API.