Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Cloud AutoDiscovery MVP #1894

Copy link
Copy link
Closed
Closed
Copy link
@o1oo11oo

Description

@o1oo11oo
Issue body actions

➹ New Feature implementation request

Is your feature request related to a problem?

Automatically detecting changes in infrastructure currently only works for services/containers deployed to kubernetes using the autodiscovery. External resources, directly hosted by cloud providers, cannot be detected.

Describe the solution you'd like

The secureCodeBox should add a cloud autodiscovery to enable monitoring cloud providers for changes. Because a general solution for multiple cloud providers at once seems inconvenient, AWS is a good first step.

Describe alternatives you've considered

Additional context

Steps to take:

  • Design a possible high level architecture
  • Implement change detection and AWS monitoring
  • Implement kubernetes updates
  • AWS state tracking for only one scan per image used
  • Basic unit and integration tests (using envtest)
  • Project structure (Dockerfile, Helm chart)
  • AWS access from Docker container
  • Configurable ScanType for ScheduledScans
  • Combine autodiscovery with SBOM workflow

Steps excluded from the scope of the MVP:

  • Implement AWS state synchronization and initial sync
  • Local message buffer and reordering (EventBridge does not guarantee order)
  • K8s health check endpoint
  • Scans in different namespace
  • Proper retry and requeuing for requests that resulted in k8s errors

Metadata

Metadata

Assignees

Type

No type

Projects

Status

Done
Show more project fields

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    Morty Proxy This is a proxified and sanitized view of the page, visit original site.