discovery

package
v2.0.0-ccit-pre2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 14, 2024 License: Apache-2.0 Imports: 33 Imported by: 0

README

Discovery Status

✅: Discovered
❌: Not Discovered
🚫: Not available

Compute
Expand
Function
Evidence Azure AWS
Compute ✅ ✅
RuntimeLanguage ✅ ❌
RuntimeVersion ✅ ❌
VirtualMachine
Evidence Azure AWS
Compute ✅ ✅
BlockStorage ✅ ✅
MalwareProtection ✅ ❌
BootLogging ✅ ✅
OSLogging ✅ ✅
AutomaticUpdates ✅ ❌
Compute
Evidence Azure AWS
Resource ✅ ✅
NetworkInterfaces ✅ ✅
ResourceLogging ✅
Backups ❌
Resource
Evidence Azure AWS
ID ✅ ✅
Name ✅ ✅
Type ✅ ✅
GeoLocation ✅ ✅
Labels ✅ ✅
OSLogging
Evidence Azure AWS
Auditing ✅ 🚫
SecurityFeature ✅ 🚫
Enabled ✅ ❌
LoggingService ✅ 🚫
RetentionPeriod ✅ 🚫
BootLogging
Evidence Azure AWS
Auditing ✅ 🚫
SecurityFeature ✅ 🚫
Enabled ✅ ❌
LoggingService ✅ 🚫
RetentionPeriod ✅ 🚫
ResourceLogging
Evidence Azure AWS
MonitoringLogDataEnabled ✅
SecurityAlertsEnabled ✅
BlockStorage
Evidence Azure AWS
Resource ✅ ✅
AtRestEncryption ✅ ✅
Immutability ✅ ❌
Backups ✅ ❌
ManagedKeyEncryption
Evidence Azure AWS
Enabled ✅ ❌
Algorithm ✅ ❌
CustomerKeyEncryption
Evidence Azure AWS
Enabled ✅ ❌
Algorithm ❌ ❌
KeyUrl ✅ ❌
Network
Expand
LoadBalancer
Evidence Azure AWS
Networkservice ✅ ❌
AccessRestriction ✅ ❌
HttpEndpoints ✅ ❌
Networkservices ✅ ❌
Urls ✅ ❌
Networkservice
Evidence Azure AWS
Networking ✅ ❌
Authenticity ✅ ❌
Compute ✅ ❌
TransportEncryption ✅ ❌
Ips ✅ ❌
Ports ✅ ❌
Networkinterfaces
Evidence Azure AWS
Networking ✅ ✅
Networkservice ❌ ❌
AccessRestriction partly ❌
Storage
Expand
ObjectStorage
Evidence Azure AWS
Storage ✅ ✅
PublicAccess ✅ ❌
Backups ✅
Storage
Evidence Azure AWS
Resource ✅ ✅
AtRestEncryption ✅ ✅
Immutability ✅ ❌
ResourceLogging ✅
Backups ✅
ObjectStorageService
Evidence Azure AWS
NetworkService ✅ ✅
HttpEndpoint ✅ ✅
Networkservice
Evidence Azure AWS
Networking ✅ ✅
Authenticity ❌ ❌
Compute ❌ ❌
TransportEncryption ✅ ✅
Ips ❌ ❌
Ports ❌ ❌
HttpEndpoint
Evidence Azure AWS
Url ✅ ✅
TransportEncryption ✅ ✅
FileStorage
Evidence Azure AWS
Storage ✅ ❌
Backups ❌
ManagedKeyEncryption
Evidence Azure AWS
Enabled ✅ ✅
Algorithm ✅ ✅
CustomerKeyEncryption
Evidence Azure AWS
Enabled ✅ ✅
Algorithm ❌ ❌
KeyUrl ✅ ✅
Database Storage
Evidence Azure AWS
Storage ✅ ❌
Parent ✅ ❌
Database Service
Evidence Azure AWS
NetworkService ✅ ❌
AnomalyDetection ✅ ❌
Networkservice
Evidence Azure AWS
Networking ✅ ✅
Authenticity ❌ ❌
Compute ❌ ❌
TransportEncryption ❌ ✅
Ips ❌ ❌
Ports ❌ ❌

Azure Backup

Expand

There are 2 different backup solutions for different resources

  • Backup Vaults and
  • Recovery Services Vault.
Resource Backup Vaults Recovery Services Vault
Azure Virtual Machine x
Azure Storage (Files) x
Azure Backup Agent x
Azure Backup Server x
DPM x
SQL in Azure VM x
SAP HANA in Azure VM x
Azure Storage (Blobs) x
Azure disks x
Azure Database for PostgreSQL servers x
Kubernetes Services x

Documentation

Index

Constants

View Source
const (
	ProviderAWS   = "aws"
	ProviderK8S   = "k8s"
	ProviderAzure = "azure"
	ProviderCSAF  = "csaf"
	ProviderCMC   = "cmc"
)
View Source
const (
	// DefaultAssessmentAddress specifies the default gRPC address of the assessment service.
	DefaultAssessmentAddress = "localhost:9090"
)

Variables

This section is empty.

Functions

func DefaultServiceSpec

func DefaultServiceSpec() launcher.ServiceSpec

DefaultServiceSpec returns a launcher.ServiceSpec for this Service with all necessary options retrieved from the config system.

func WithAdditionalDiscoverers

func WithAdditionalDiscoverers(discoverers []discovery.Discoverer) service.Option[*Service]

WithAdditionalDiscoverers is an option to add additional discoverers for discovering. Note: These are added in addition to the ones created by WithProviders.

func WithAssessmentAddress

func WithAssessmentAddress(target string, opts ...grpc.DialOption) service.Option[*Service]

WithAssessmentAddress is an option to configure the assessment service gRPC address.

func WithAuthorizationStrategy

func WithAuthorizationStrategy(authz service.AuthorizationStrategy) service.Option[*Service]

WithAuthorizationStrategy is an option that configures an authorization strategy to be used with this service.

func WithCertificationTargetID

func WithCertificationTargetID(ID string) service.Option[*Service]

WithCertificationTargetID is an option to configure the certification target ID for which resources will be discovered.

func WithDiscoveryInterval

func WithDiscoveryInterval(interval time.Duration) service.Option[*Service]

WithDiscoveryInterval is an option to set the discovery interval. If not set, the discovery is set to 5 minutes.

func WithEvidenceCollectorToolID

func WithEvidenceCollectorToolID(ID string) service.Option[*Service]

WithEvidenceCollectorToolID is an option to configure the collector tool ID that is used to discover resources.

func WithOAuth2Authorizer

func WithOAuth2Authorizer(config *clientcredentials.Config) service.Option[*Service]

WithOAuth2Authorizer is an option to use an OAuth 2.0 authorizer

func WithProviders

func WithProviders(providersList []string) service.Option[*Service]

WithProviders is an option to set providers for discovering

func WithStorage

func WithStorage(storage persistence.Storage) service.Option[*Service]

WithStorage is an option to set the storage. If not set, NewService will use inmemory storage.

Types

type DiscoveryEvent

type DiscoveryEvent struct {
	Type            DiscoveryEventType
	DiscovererName  string
	DiscoveredItems int
	Time            time.Time
}

DiscoveryEvent represents an event that is emitted if certain situations happen in the discoverer (defined by DiscoveryEventType). Examples would be the start or the end of the discovery. We will potentially expand this in the future.

type DiscoveryEventType

type DiscoveryEventType int

DiscoveryEventType defines the event types for DiscoveryEvent.

const (
	// DiscovererStart is emitted at the start of a discovery run.
	DiscovererStart DiscoveryEventType = iota
	// DiscovererFinished is emitted at the end of a discovery run.
	DiscovererFinished
)

type Service

type Service struct {
	discovery.UnimplementedDiscoveryServer
	discovery.UnimplementedExperimentalDiscoveryServer

	Events chan *DiscoveryEvent
	// contains filtered or unexported fields
}

Service is an implementation of the Clouditor Discovery service (plus its experimental extensions). It should not be used directly, but rather the NewService constructor should be used.

func NewService

func NewService(opts ...service.Option[*Service]) *Service

func (*Service) GetCertificationTargetId

func (svc *Service) GetCertificationTargetId() string

GetCertificationTargetId implements CertificationTargetRequest for this service. This is a little trick, so that we can call CheckAccess directly on the service. This is necessary because the discovery service itself is tied to a specific certification target ID, instead of the individual requests that are made against the service.

func (*Service) Init

func (svc *Service) Init()

func (*Service) ListGraphEdges

func (svc *Service) ListGraphEdges(ctx context.Context, req *discovery.ListGraphEdgesRequest) (res *discovery.ListGraphEdgesResponse, err error)

func (*Service) ListResources

func (svc *Service) ListResources(ctx context.Context, req *discovery.ListResourcesRequest) (res *discovery.ListResourcesResponse, err error)

func (*Service) Shutdown

func (svc *Service) Shutdown()

func (*Service) Start

Start starts discovery

func (*Service) StartDiscovery

func (svc *Service) StartDiscovery(discoverer discovery.Discoverer)

func (*Service) UpdateResource

func (svc *Service) UpdateResource(ctx context.Context, req *discovery.UpdateResourceRequest) (res *discovery.Resource, err error)

Directories

Path Synopsis
extra
cmc

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL