This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/iam/README.md
Adam Moussa a9bccf33d0 feat(secrev): aws-posture checker (Tier-2, provisioning-gated)
Read-only Tier-2 idle/anomalous-spend + idle-resource posture checker for the
R720 agent-team (design D5 / §4 / §6.3 / §7 Phase 3). Mirrors the Tier-1 checker
conventions verbatim (flags --canary/--dry-run/--no-api/--targets, mode-600
report under $REPORT_ROOT/aws-posture/<date>/, ALARM-only, finding.schema.json
spirit, exit 0/2/3, shared substrate redact/post_slack_alarm).

Detectors (complement GuardDuty/SecurityHub/Config, do not replace):
- anomalous Cost Explorer deltas (ce get-anomalies, $-impact threshold)
- stopped EC2 still paying for attached EBS
- unattached EBS volumes
- unassociated Elastic IPs
- idle NAT gateways (≈0 bytes out)
- idle load balancers (0 healthy targets)
- idle RDS (0 connections over window)

Live AWS calls are PROVISIONING-GATED: they run ONLY when Roles Anywhere creds
are available (STS identity probe) AND not --no-api/--canary. With no creds or
--no-api/--canary the checker SKIPS live calls and notes them — NEVER alarms on
missing data (memory feedback_cloudwatch_alarms). Roles Anywhere/step-ca are not
stood up (IAM cross-review PASSED 2026-06-18; see security-review/iam/).

Offline canary: fixtures of mocked AWS responses (cost/describe-* JSON) under
fixtures/aws-posture/ + EXPECTED_FINDING_COUNT=7, asserted fully offline (no aws,
no network). Identical detector code runs online and offline. shellcheck-clean
(only accepted SC1091), chmod +x.
2026-06-18 16:18:11 -04:00

30 lines
2.1 KiB
Markdown

# security-review/iam/ — Phase-3 IAM artifacts (authored for cross-review, NOT applied)
These are the IAM / Roles Anywhere / step-ca artifacts for the R720 agent-team **aws-posture**
checker (design `docs/r720-agent-team-design.md` D5 / §4 / §6.3 / §7 Phase 3).
**Nothing here is applied to AWS.** They are FILES for the mandatory GPT-4.1 IAM cross-review.
**Cross-review status (2026-06-18): APPROVE, no BLOCKs.** FIXes applied — `aws:SourceAccount`
added to the trust policy; `ec2:DescribeImages` removed from the permission policy (see
`CROSS-REVIEW-PACKET.md` header + `aws-posture-readonly-policy.rationale.md`). The review passing
**unblocked building** `../checkers/aws-posture.sh` (built in this Phase-3 change set). That
checker stays **PROVISIONING-GATED**: it makes NO AWS call until step-ca + the Roles Anywhere
trust anchor + this role are stood up. Provisioning happens only after the review is recorded
(design §7, B3) — and a VM snapshot is taken first per `feedback_ec2_replacement_snapshot`.
Decision (D5): the box stays **read-only** and authenticates to AWS via **Roles Anywhere**
short-lived leaf certs issued by a new internal **step-ca** — **no long-lived AWS key on the
box**.
| File | Purpose |
|---|---|
| `CROSS-REVIEW-PACKET.md` | **Start here.** End-to-end trust model, least-privilege rationale, blast radius, exercised rollback, and the specific items for the reviewer. |
| `aws-posture-readonly-policy.json` | Least-privilege read-only permission policy (valid, applyable IAM JSON). |
| `aws-posture-readonly-policy.rationale.md` | Statement-by-statement rationale (IAM JSON can't carry comments). |
| `aws-posture-trust-policy.json` | Role trust policy — pins Roles Anywhere + the leaf subject/issuer CN + trust-anchor ARN. |
| `roles-anywhere-config.json` | Trust-anchor (pins step-ca root) + profile (1h session) config. |
| `step-ca-config-sketch.md` | Internal CA config + systemd-timer auto-renewal of the short-lived leaf. |
Per global instructions this IAM change also requires the GPT-4.1 cross-family review via
`orchestrator/run.py`; this directory is that review's input.