credential-sweep

command
v0.10.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 3, 2026 License: MPL-2.0 Imports: 14 Imported by: 0

Documentation

Overview

Command credential-sweep is issue #431's measurement: a provider-wide sweep for identity.CredentialMaterial's shape, so the credential exclusion class stops being a set of precedents someone happened to notice and becomes a number recomputed from the pinned schema.

identity.CredentialMaterial (internal/live/identity/located.go) is the rule: any attribute the provider marks Sensitive and does not also mark Deprecated, anywhere in a resource type's schema - nested blocks and nested attribute objects included. It already gates two live decisions (LocatedType's record-located route, and internal/live/projection's residue classifier), each over its own narrow population. This sweeps every resource type hashicorp/aws 6.59.0 ships, so a type neither route has looked at yet is not silently outside the count.

For every hit it records what is already known about the type, read from the artifacts and tables this fork already maintains - never re-classified here, since a second implementation of "is this type admitted" would drift from the first:

  • admitted: a row in internal/live/identity.DefaultTable, and, when so, whether the ratified identity's own components ever name the flagged attribute (identity_uses_sensitive_attr) - the same question ruling 5 (issue #365 population 2, commit 361e0da9ab) asked of the markerless population, asked here of the whole roster: a type whose recorded identity never touches the sensitive attribute is not excluded by admitting it, whatever the schema sweep alone would suggest.
  • rejected: a key in tools/row-gen/rejected.json, and its reason's first 200 characters - the veto set the schema-first table route already consults, whatever the veto's actual ground is.
  • markerless: a member of internal/live/identity.MarkerlessTypes, the record-located route's own population.
  • taggable / importable: live/survey-full.json's own signals, so a type with an ownership marker or with no route to admission at all reads as what it already is without a second schema read.

Disposing each hit - genuinely credential material, or a false positive the rule catches for an unrelated reason - is prose, not data, and lives in the issue and the PR that measured it, not in this tool or its artifact. This writes the measurement; it rules on nothing.

Usage, from anywhere in the checkout:

go run ./tools/credential-sweep

Needs network for the provider download (or a warm TF_PLUGIN_CACHE_DIR) and a terraform binary on PATH (-init-bin overrides), the same requirement tools/survey-gen states for the identical acquisition.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL