Documentation
¶
Overview ¶
Package controllers holds Draugr's built-in controllers (e.g. images, sast, opensource, dast), each orchestrating scanners for one security control.
See docs/ARCHITECTURE.md.
Index ¶
- func NewDAST() plugin.Controller
- func NewHeaders() plugin.Controller
- func NewIAC() plugin.Controller
- func NewImages() plugin.Controller
- func NewInfrastructure() plugin.Controller
- func NewLicenses() plugin.Controller
- func NewSAST() plugin.Controller
- func NewSCA() plugin.Controller
- func NewSecrets() plugin.Controller
- func NewTLS() plugin.Controller
- func SelectedScanners(model saga.Model, control string, defaults []string) map[string]bool
- func SeverityFloor(control string) sarif.Severity
- type DAST
- type Headers
- type IAC
- type Images
- type Infrastructure
- type Licenses
- type SAST
- type SCA
- type Secrets
- type TLS
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func NewDAST ¶ added in v0.28.0
func NewDAST() plugin.Controller
NewDAST returns the dast controller.
func NewHeaders ¶ added in v0.9.0
func NewHeaders() plugin.Controller
NewHeaders returns the headers controller.
func NewInfrastructure ¶ added in v0.45.0
func NewInfrastructure() plugin.Controller
NewInfrastructure returns the infrastructure controller.
func NewLicenses ¶ added in v0.43.0
func NewLicenses() plugin.Controller
NewLicenses returns the licenses controller.
func NewSAST ¶ added in v0.3.0
func NewSAST() plugin.Controller
NewSAST returns the sast controller.
func NewSecrets ¶ added in v0.2.0
func NewSecrets() plugin.Controller
NewSecrets returns the secrets controller.
func SelectedScanners ¶ added in v0.48.0
SelectedScanners returns the scanner names a control will actually run for this model — the union of the selection across every component.
This is what a control *requires*, as opposed to every scanner that could serve it. Those differ wherever a control has more than one scanner: `sast` demanding gosec from a project that never enabled it, or `infrastructure` demanding kube-bench and kubectl when the default reads the API and needs neither. Either way the report is a list of tools to go and install that the scan would not have used — and, worse, a missing one reads as a control that cannot run.
defaults must be the controller's own DefaultScanners, so the answer matches what Plan will do.
func SeverityFloor ¶ added in v0.5.0
SeverityFloor returns the minimum normalized severity for a control's findings, or an empty severity (no floor) when the control declares none. Used by prioritization when resolving a finding's severity.
Types ¶
type DAST ¶ added in v0.28.0
type DAST struct{}
DAST is the dynamic application security testing control. It plans one Nuclei scan per running host declared on a component and aggregates the findings. Complements the "headers" control: dast covers runtime issues (exposures, misconfigurations, info disclosure, outdated libraries) while headers owns HTTP security-header checks.
func (DAST) Aggregate ¶ added in v0.28.0
Aggregate merges the scan reports and summarizes findings by severity.
func (DAST) Info ¶ added in v0.28.0
func (DAST) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type Headers ¶ added in v0.9.0
type Headers struct{}
Headers is the HTTP security-header control. It plans one native header scan per host declared on a component and aggregates the findings. No external tool is required.
func (Headers) Aggregate ¶ added in v0.9.0
Aggregate merges the scan reports and summarizes findings by severity.
func (Headers) Info ¶ added in v0.9.0
func (Headers) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type IAC ¶ added in v0.4.0
type IAC struct{}
IAC is the Infrastructure-as-Code / misconfiguration control: it scans a component's repositories for insecure IaC (Terraform, Kubernetes manifests, Dockerfiles, …). It plans one scan per repository.
func (IAC) Aggregate ¶ added in v0.4.0
Aggregate merges the scan reports and summarizes findings by severity. Trivy reports per-check severity, so severity is taken as reported.
func (IAC) Info ¶ added in v0.4.0
func (IAC) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type Images ¶
type Images struct{}
Images is the container-image security control. It plans one Trivy scan per image in a component and aggregates the results.
func (Images) Info ¶
func (Images) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type Infrastructure ¶ added in v0.45.0
type Infrastructure struct{}
Infrastructure assesses the platform a component runs on against the CIS Kubernetes Benchmark.
Component-scoped rather than project-scoped, because that is where the Saga puts the data: `infrastructure:` is a list on a component, describing what that component runs on. Two components on the same cluster produce two jobs with the same target, which the engine collapses — so the shared case costs one scan, not two.
func (Infrastructure) Aggregate ¶ added in v0.45.0
func (Infrastructure) Aggregate(reports []sarif.Report) (plugin.ControlResult, error)
Aggregate merges the scan reports and summarizes findings by severity.
func (Infrastructure) Info ¶ added in v0.45.0
func (Infrastructure) Info() plugin.ControllerInfo
Info identifies the controller.
func (Infrastructure) Plan ¶ added in v0.45.0
Plan produces one scan job per Kubernetes infrastructure entry on the component.
Infrastructure of another kind is skipped rather than failed: a Saga may describe surfaces Draugr has no benchmark for, and refusing to plan the ones it does understand would make the descriptor less useful the more honestly it was written.
type Licenses ¶ added in v0.43.0
type Licenses struct{}
Licenses reports dependency licences that carry an obligation.
A separate control rather than part of `sca`, deliberately. Licence risk is not a vulnerability: the exposure is legal and commercial, the policy is owned by different people, and it changes on a different cadence. Keeping it separate is also what lets `config.gate.controls` hold it to its own threshold — "fail on a forbidden licence but only warn on a medium CVE" is a reasonable position that one shared threshold cannot express.
func (Licenses) Aggregate ¶ added in v0.43.0
Aggregate merges the scan reports and summarizes findings by severity.
func (Licenses) Info ¶ added in v0.43.0
func (Licenses) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type SAST ¶ added in v0.3.0
type SAST struct{}
SAST is the Static Application Security Testing control: it analyzes a component's own source code (not its dependencies) for security bugs. It plans one scan per repository, per selected scanner.
func (SAST) Aggregate ¶ added in v0.3.0
Aggregate merges the scan reports and summarizes findings by severity. Semgrep emits per-rule SARIF levels, so severity is taken as reported.
func (SAST) Info ¶ added in v0.3.0
func (SAST) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type SCA ¶
type SCA struct{}
SCA is the Software Composition Analysis control: dependency vulnerabilities (and, later, licenses) for a component's source repositories. It plans one scan per repository.
func (SCA) Info ¶
func (SCA) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type Secrets ¶ added in v0.2.0
type Secrets struct{}
Secrets is the secret-detection control: it scans a component's repositories for leaked credentials. Any detected secret is treated as an error — a leaked secret should fail the gate regardless of how the scanner rated it.
func (Secrets) Aggregate ¶ added in v0.2.0
Aggregate merges the scan reports and escalates every finding to error severity — a detected secret is always gate-failing.
func (Secrets) Info ¶ added in v0.2.0
func (Secrets) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).
type TLS ¶ added in v0.31.0
type TLS struct{}
TLS is the transport-security control. It plans one native TLS probe per host declared on a component and aggregates the findings. No external tool is required.
func (TLS) Aggregate ¶ added in v0.31.0
Aggregate merges the scan reports and summarizes findings by severity.
func (TLS) Info ¶ added in v0.31.0
func (TLS) Info() plugin.ControllerInfo
Info identifies the controller (component-scoped).