* feat(secrev): doc-drift Plane-1 Tier-1 checker (UNGATED)
Third Plane-1 checker on the Phase-0 shared substrate, mirroring
compliance-drift.sh / dependency-cve.sh conventions verbatim (set -euo pipefail,
sourced substrate, --canary/--dry-run/--no-api/--refresh/--targets, mode-600
reports under $REPORT_ROOT/doc-drift/<UTC-date>/, ALARM-only, finding.schema
spirit JSON, exit 0/2/3, dotgit->.git fixture trick).
Detects documentation drift deterministically (design §4 doc-drift row):
- readme-omits-component: README omits an existing major component in the tree
(top-level service dir, SAM/CDK stack, Lambda handler dir, openapi/docs spec)
- readme-stale-vs-code: README last-touch far older than newest code commit
(two-factor: >=DOC_DRIFT_STALE_DAYS AND >=DOC_DRIFT_STALE_COMMITS)
A repo with NO README is SKIPPED (compliance-drift owns readme-present; no
double-flag). Future Gemini large-context judge (§4) is an inert stub (maybe_judge),
off in canary/dry-run/offline.
Planted-drift fixture corpus + EXPECTED_DRIFT_COUNT=4, canary-asserted (exit 3 on
miss). shellcheck -x clean (only accepted SC1091 source-line info).
Does NOT touch checker_coordinator.sh, requirements.txt, or aws-posture.
Wiring/systemd is gated (PROVISIONING footer). Design refs §4, §7 Phase 3.
* feat(secrev): Phase-3 IAM artifacts for cross-review (aws-posture gated)
Authored FILES (not applied to AWS — provisioning gated behind the mandatory
GPT-4.1 IAM cross-review + Adam, design §7 B3) for the aws-posture checker's
read-only AWS identity. Decision D5: box stays read-only, auths via IAM Roles
Anywhere short-lived leaf certs from a new internal step-ca; NO long-lived AWS key.
- aws-posture-readonly-policy.json least-privilege read-only (ce:Get*,
cloudwatch:GetMetric*/DescribeAlarms, ec2/elb/rds:Describe*, lambda list +
GetFunctionConfiguration, s3:ListAllMyBuckets/GetBucketLocation). No write,
no iam:* mutation, no s3:GetObject/secrets/kms/logs data reads, no wildcard
actions. Resource:* only where AWS has no resource-level support.
- aws-posture-readonly-policy.rationale.md per-statement least-privilege rationale.
- aws-posture-trust-policy.json pins Roles Anywhere principal + leaf subject CN +
issuer CN + trust-anchor SourceArn (three conditions, all required).
- roles-anywhere-config.json trust anchor (pins step-ca root) + profile (1h session).
- step-ca-config-sketch.md internal CA config + systemd-timer leaf auto-renewal.
- CROSS-REVIEW-PACKET.md end-to-end trust model, blast radius, EXERCISED rollback,
reviewer scrutiny list.
Does NOT build aws-posture.sh, touch checker_coordinator.sh, or requirements.txt.
* fix(secrev): apply IAM cross-review FIXes
GPT-4.1 IAM cross-review 2026-06-18: APPROVE, no BLOCKs. Applied FIXes:
- trust policy: add aws:SourceAccount=328440206208 (confused-deputy guard)
alongside the existing aws:SourceArn trust-anchor pin
- readonly policy: remove ec2:DescribeImages (data minimization — AMIs are
not an idle-spend signal)
- aws:RequestedRegion NIT: deliberately SKIPPED — ce:* and s3:ListAllMyBuckets
are global-endpoint services a blanket region condition could DENY; rationale
recorded in aws-posture-readonly-policy.rationale.md
- rationale.md + CROSS-REVIEW-PACKET.md: record APPROVE + FIXes + NIT answers
(snapshots=account-owned idle signal; s3 list=names-only; no logs:* needed)
* feat(secrev): aws-posture checker (Tier-2, provisioning-gated)
Read-only Tier-2 idle/anomalous-spend + idle-resource posture checker for the
R720 agent-team (design D5 / §4 / §6.3 / §7 Phase 3). Mirrors the Tier-1 checker
conventions verbatim (flags --canary/--dry-run/--no-api/--targets, mode-600
report under $REPORT_ROOT/aws-posture/<date>/, ALARM-only, finding.schema.json
spirit, exit 0/2/3, shared substrate redact/post_slack_alarm).
Detectors (complement GuardDuty/SecurityHub/Config, do not replace):
- anomalous Cost Explorer deltas (ce get-anomalies, $-impact threshold)
- stopped EC2 still paying for attached EBS
- unattached EBS volumes
- unassociated Elastic IPs
- idle NAT gateways (≈0 bytes out)
- idle load balancers (0 healthy targets)
- idle RDS (0 connections over window)
Live AWS calls are PROVISIONING-GATED: they run ONLY when Roles Anywhere creds
are available (STS identity probe) AND not --no-api/--canary. With no creds or
--no-api/--canary the checker SKIPS live calls and notes them — NEVER alarms on
missing data (memory feedback_cloudwatch_alarms). Roles Anywhere/step-ca are not
stood up (IAM cross-review PASSED 2026-06-18; see security-review/iam/).
Offline canary: fixtures of mocked AWS responses (cost/describe-* JSON) under
fixtures/aws-posture/ + EXPECTED_FINDING_COUNT=7, asserted fully offline (no aws,
no network). Identical detector code runs online and offline. shellcheck-clean
(only accepted SC1091), chmod +x.
* fix(secrev): doc-drift fixture py ruff-clean (root CI runs check + format --check)
The repo-root CI lint runs both 'ruff check .' and 'ruff format --check .' over
all fixtures. Fixed E701 one-liners and ruff-formatted the sample-service .py
files (handlers/*, feature_*.py). Fixture content is irrelevant to doc-drift
(keys on file/dir presence + git staleness).
145 lines
5.6 KiB
Markdown
145 lines
5.6 KiB
Markdown
# step-ca config sketch — internal CA for aws-posture Roles Anywhere leaf certs
|
|
|
|
Design ref: `docs/r720-agent-team-design.md` §6.3 (step-ca + Roles Anywhere, D5) and §7 Phase 3.
|
|
|
|
**Not provisioned here.** This is the config + renewal approach for the GPT-4.1 cross-review.
|
|
step-ca is the small internal CA on the R720 box (Smallstep `step-ca`) whose **root** cert is
|
|
pinned as the Roles Anywhere trust anchor, and which issues a **short-lived leaf** that the box
|
|
presents to Roles Anywhere to obtain short-lived read-only STS credentials. **No long-lived AWS
|
|
key ever lands on the box** — the leaf self-expires and is auto-renewed by a systemd timer.
|
|
|
|
## Trust chain (one CA, one purpose)
|
|
|
|
```
|
|
step-ca ROOT (offline-ish, long-lived)
|
|
└── step-ca intermediate (the online signer)
|
|
└── leaf CN=r720-aws-posture (short-lived, ~24h, auto-renewed)
|
|
└── presented to AWS IAM Roles Anywhere trust anchor
|
|
└── AssumeRole -> r720-aws-posture-readonly (1h STS session)
|
|
```
|
|
|
|
The trust anchor pins the **root** cert (`roles-anywhere-config.json` → `sourceData
|
|
.x509CertificateData`). The role trust policy (`aws-posture-trust-policy.json`) additionally
|
|
pins the leaf **subject CN** (`r720-aws-posture`) and **issuer CN**, so only this CA's leaf with
|
|
this exact CN can assume the role.
|
|
|
|
## `ca.json` (sketch — the single-purpose provisioner)
|
|
|
|
```jsonc
|
|
{
|
|
"root": "/etc/step-ca/certs/root_ca.crt",
|
|
"crt": "/etc/step-ca/certs/intermediate_ca.crt",
|
|
"key": "/etc/step-ca/secrets/intermediate_ca_key",
|
|
"address": "127.0.0.1:8443", // localhost-only; the box is the sole client
|
|
"dnsNames": ["localhost", "r720.lan"],
|
|
"authority": {
|
|
"claims": {
|
|
"minTLSCertDuration": "5m",
|
|
"maxTLSCertDuration": "24h", // hard cap: leaves are short-lived
|
|
"defaultTLSCertDuration": "24h",
|
|
"disableRenewal": false
|
|
},
|
|
"provisioners": [
|
|
{
|
|
"type": "JWK",
|
|
"name": "aws-posture",
|
|
"key": { "use": "sig", "kty": "EC", "crv": "P-256", "alg": "ES256", "kid": "REPLACE", "x": "REPLACE", "y": "REPLACE" },
|
|
"encryptedKey": "REPLACE_WITH_ENCRYPTED_PROVISIONER_KEY",
|
|
"claims": {
|
|
"maxTLSCertDuration": "24h",
|
|
"defaultTLSCertDuration": "24h"
|
|
},
|
|
"options": {
|
|
"x509": {
|
|
// The provisioner only ever issues this one CN; templating keeps the
|
|
// subject/issuer fields the Roles Anywhere trust policy pins.
|
|
"templateData": { "CommonName": "r720-aws-posture" }
|
|
}
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
```
|
|
|
|
Root CA subject CN: **`Sea Haven Internal CA - R720 Roles Anywhere`** (matches the
|
|
`x509Issuer/CN` condition in `aws-posture-trust-policy.json`).
|
|
|
|
## Initial bootstrap (one-time, at provisioning)
|
|
|
|
```bash
|
|
step ca init \
|
|
--name "Sea Haven Internal CA - R720 Roles Anywhere" \
|
|
--dns localhost --dns r720.lan --address 127.0.0.1:8443 \
|
|
--provisioner aws-posture --deployment-type standalone
|
|
|
|
# Issue the first leaf the box will present to Roles Anywhere:
|
|
step ca certificate "r720-aws-posture" \
|
|
/etc/aws-posture/leaf.crt /etc/aws-posture/leaf.key \
|
|
--not-after 24h --provisioner aws-posture
|
|
```
|
|
|
|
`leaf.key` is mode 600, owned by the unattended service user; it never leaves the box.
|
|
|
|
## Auto-renewal — systemd timer (the leaf self-expires; the timer keeps it fresh)
|
|
|
|
`step-ca` ships `step ca renew`, which no-ops until the cert is within its renewal window.
|
|
|
|
`/etc/systemd/system/aws-posture-cert-renew.service`:
|
|
```ini
|
|
[Unit]
|
|
Description=Renew r720-aws-posture Roles Anywhere leaf certificate
|
|
After=network-online.target step-ca.service
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
User=aws-posture
|
|
# --expires-in: renew only when <8h of life remains; idempotent, safe to run hourly.
|
|
ExecStart=/usr/bin/step ca renew --force --expires-in 8h \
|
|
/etc/aws-posture/leaf.crt /etc/aws-posture/leaf.key
|
|
# step-ca renew rewrites the cert in place; aws_signing_helper reads it fresh each call,
|
|
# so no service reload is needed.
|
|
```
|
|
|
|
`/etc/systemd/system/aws-posture-cert-renew.timer`:
|
|
```ini
|
|
[Unit]
|
|
Description=Hourly renewal check for the aws-posture leaf cert
|
|
|
|
[Timer]
|
|
OnCalendar=hourly
|
|
RandomizedDelaySec=300
|
|
Persistent=true # catch up a renewal missed while the box was off
|
|
|
|
[Install]
|
|
WantedBy=timers.target
|
|
```
|
|
|
|
Hourly check + 8h renewal window + 24h cert = the leaf is always fresh and a missed window has
|
|
hours of slack. The timer mirrors the existing secrev launchd/systemd discipline.
|
|
|
|
## How aws-posture USES the leaf (no AWS key on disk)
|
|
|
|
aws-posture invokes AWS's `aws_signing_helper credential-process`, which signs the Roles
|
|
Anywhere request with the **leaf** and returns short-lived STS creds on stdout:
|
|
|
|
```ini
|
|
# ~/.aws/config (on the box)
|
|
[profile r720-aws-posture]
|
|
credential_process = /usr/local/bin/aws_signing_helper credential-process \
|
|
--certificate /etc/aws-posture/leaf.crt \
|
|
--private-key /etc/aws-posture/leaf.key \
|
|
--trust-anchor-arn arn:aws:rolesanywhere:us-east-1:328440206208:trust-anchor/REPLACE \
|
|
--profile-arn arn:aws:rolesanywhere:us-east-1:328440206208:profile/REPLACE \
|
|
--role-arn arn:aws:iam::328440206208:role/r720-aws-posture-readonly
|
|
```
|
|
|
|
The credentials live only in process memory for the 1h session duration; nothing long-lived is
|
|
written. This is **strictly stronger than the box's existing long-lived GitHub PAT** (design
|
|
§6.3): the AWS identity self-expires and rotates without operator action.
|
|
|
|
## Capacity note (design §6.5)
|
|
|
|
step-ca on a 4GB / 2 vCPU / 40GB box is negligible (a localhost signer + a tiny DB). Re-check
|
|
disk headroom after Phase 1 per §6.5; snapshot the Hyper-V VM before standing this up per
|
|
`feedback_ec2_replacement_snapshot`.
|