This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/iam
Adam Moussa 94ed6ea224
feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19)
* feat(secrev): doc-drift Plane-1 Tier-1 checker (UNGATED)

Third Plane-1 checker on the Phase-0 shared substrate, mirroring
compliance-drift.sh / dependency-cve.sh conventions verbatim (set -euo pipefail,
sourced substrate, --canary/--dry-run/--no-api/--refresh/--targets, mode-600
reports under $REPORT_ROOT/doc-drift/<UTC-date>/, ALARM-only, finding.schema
spirit JSON, exit 0/2/3, dotgit->.git fixture trick).

Detects documentation drift deterministically (design §4 doc-drift row):
  - readme-omits-component: README omits an existing major component in the tree
    (top-level service dir, SAM/CDK stack, Lambda handler dir, openapi/docs spec)
  - readme-stale-vs-code: README last-touch far older than newest code commit
    (two-factor: >=DOC_DRIFT_STALE_DAYS AND >=DOC_DRIFT_STALE_COMMITS)
A repo with NO README is SKIPPED (compliance-drift owns readme-present; no
double-flag). Future Gemini large-context judge (§4) is an inert stub (maybe_judge),
off in canary/dry-run/offline.

Planted-drift fixture corpus + EXPECTED_DRIFT_COUNT=4, canary-asserted (exit 3 on
miss). shellcheck -x clean (only accepted SC1091 source-line info).

Does NOT touch checker_coordinator.sh, requirements.txt, or aws-posture.
Wiring/systemd is gated (PROVISIONING footer). Design refs §4, §7 Phase 3.

* feat(secrev): Phase-3 IAM artifacts for cross-review (aws-posture gated)

Authored FILES (not applied to AWS — provisioning gated behind the mandatory
GPT-4.1 IAM cross-review + Adam, design §7 B3) for the aws-posture checker's
read-only AWS identity. Decision D5: box stays read-only, auths via IAM Roles
Anywhere short-lived leaf certs from a new internal step-ca; NO long-lived AWS key.

  - aws-posture-readonly-policy.json  least-privilege read-only (ce:Get*,
      cloudwatch:GetMetric*/DescribeAlarms, ec2/elb/rds:Describe*, lambda list +
      GetFunctionConfiguration, s3:ListAllMyBuckets/GetBucketLocation). No write,
      no iam:* mutation, no s3:GetObject/secrets/kms/logs data reads, no wildcard
      actions. Resource:* only where AWS has no resource-level support.
  - aws-posture-readonly-policy.rationale.md  per-statement least-privilege rationale.
  - aws-posture-trust-policy.json  pins Roles Anywhere principal + leaf subject CN +
      issuer CN + trust-anchor SourceArn (three conditions, all required).
  - roles-anywhere-config.json  trust anchor (pins step-ca root) + profile (1h session).
  - step-ca-config-sketch.md  internal CA config + systemd-timer leaf auto-renewal.
  - CROSS-REVIEW-PACKET.md  end-to-end trust model, blast radius, EXERCISED rollback,
      reviewer scrutiny list.

Does NOT build aws-posture.sh, touch checker_coordinator.sh, or requirements.txt.

* fix(secrev): apply IAM cross-review FIXes

GPT-4.1 IAM cross-review 2026-06-18: APPROVE, no BLOCKs. Applied FIXes:
- trust policy: add aws:SourceAccount=328440206208 (confused-deputy guard)
  alongside the existing aws:SourceArn trust-anchor pin
- readonly policy: remove ec2:DescribeImages (data minimization — AMIs are
  not an idle-spend signal)
- aws:RequestedRegion NIT: deliberately SKIPPED — ce:* and s3:ListAllMyBuckets
  are global-endpoint services a blanket region condition could DENY; rationale
  recorded in aws-posture-readonly-policy.rationale.md
- rationale.md + CROSS-REVIEW-PACKET.md: record APPROVE + FIXes + NIT answers
  (snapshots=account-owned idle signal; s3 list=names-only; no logs:* needed)

* feat(secrev): aws-posture checker (Tier-2, provisioning-gated)

Read-only Tier-2 idle/anomalous-spend + idle-resource posture checker for the
R720 agent-team (design D5 / §4 / §6.3 / §7 Phase 3). Mirrors the Tier-1 checker
conventions verbatim (flags --canary/--dry-run/--no-api/--targets, mode-600
report under $REPORT_ROOT/aws-posture/<date>/, ALARM-only, finding.schema.json
spirit, exit 0/2/3, shared substrate redact/post_slack_alarm).

Detectors (complement GuardDuty/SecurityHub/Config, do not replace):
- anomalous Cost Explorer deltas (ce get-anomalies, $-impact threshold)
- stopped EC2 still paying for attached EBS
- unattached EBS volumes
- unassociated Elastic IPs
- idle NAT gateways (≈0 bytes out)
- idle load balancers (0 healthy targets)
- idle RDS (0 connections over window)

Live AWS calls are PROVISIONING-GATED: they run ONLY when Roles Anywhere creds
are available (STS identity probe) AND not --no-api/--canary. With no creds or
--no-api/--canary the checker SKIPS live calls and notes them — NEVER alarms on
missing data (memory feedback_cloudwatch_alarms). Roles Anywhere/step-ca are not
stood up (IAM cross-review PASSED 2026-06-18; see security-review/iam/).

Offline canary: fixtures of mocked AWS responses (cost/describe-* JSON) under
fixtures/aws-posture/ + EXPECTED_FINDING_COUNT=7, asserted fully offline (no aws,
no network). Identical detector code runs online and offline. shellcheck-clean
(only accepted SC1091), chmod +x.

* fix(secrev): doc-drift fixture py ruff-clean (root CI runs check + format --check)

The repo-root CI lint runs both 'ruff check .' and 'ruff format --check .' over
all fixtures. Fixed E701 one-liners and ruff-formatted the sample-service .py
files (handlers/*, feature_*.py). Fixture content is irrelevant to doc-drift
(keys on file/dir presence + git staleness).
2026-06-18 16:25:40 -04:00
..
aws-posture-readonly-policy.json feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
aws-posture-readonly-policy.rationale.md feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
aws-posture-trust-policy.json feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
CROSS-REVIEW-PACKET.md feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
README.md feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
roles-anywhere-config.json feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
step-ca-config-sketch.md feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00

security-review/iam/ — Phase-3 IAM artifacts (authored for cross-review, NOT applied)

These are the IAM / Roles Anywhere / step-ca artifacts for the R720 agent-team aws-posture checker (design docs/r720-agent-team-design.md D5 / §4 / §6.3 / §7 Phase 3).

Nothing here is applied to AWS. They are FILES for the mandatory GPT-4.1 IAM cross-review.

Cross-review status (2026-06-18): APPROVE, no BLOCKs. FIXes applied — aws:SourceAccount added to the trust policy; ec2:DescribeImages removed from the permission policy (see CROSS-REVIEW-PACKET.md header + aws-posture-readonly-policy.rationale.md). The review passing unblocked building ../checkers/aws-posture.sh (built in this Phase-3 change set). That checker stays PROVISIONING-GATED: it makes NO AWS call until step-ca + the Roles Anywhere trust anchor + this role are stood up. Provisioning happens only after the review is recorded (design §7, B3) — and a VM snapshot is taken first per feedback_ec2_replacement_snapshot.

Decision (D5): the box stays read-only and authenticates to AWS via Roles Anywhere short-lived leaf certs issued by a new internal step-ca — no long-lived AWS key on the box.

File Purpose
CROSS-REVIEW-PACKET.md Start here. End-to-end trust model, least-privilege rationale, blast radius, exercised rollback, and the specific items for the reviewer.
aws-posture-readonly-policy.json Least-privilege read-only permission policy (valid, applyable IAM JSON).
aws-posture-readonly-policy.rationale.md Statement-by-statement rationale (IAM JSON can't carry comments).
aws-posture-trust-policy.json Role trust policy — pins Roles Anywhere + the leaf subject/issuer CN + trust-anchor ARN.
roles-anywhere-config.json Trust-anchor (pins step-ca root) + profile (1h session) config.
step-ca-config-sketch.md Internal CA config + systemd-timer auto-renewal of the short-lived leaf.

Per global instructions this IAM change also requires the GPT-4.1 cross-family review via orchestrator/run.py; this directory is that review's input.