mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-09-30 08:03:17 +00:00
Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced.
38 lines
2.3 KiB
JSON
38 lines
2.3 KiB
JSON
{
|
|
"_comment": "Reviewer-facing config describing the IAM Roles Anywhere trust-anchor + profile to be created. NOT applied — provisioning is gated behind the GPT-4.1 cross-review + Adam. Values prefixed REPLACE_WITH_* are filled in at provisioning time. Region us-east-1, account 328440206208.",
|
|
|
|
"trust_anchor": {
|
|
"name": "r720-aws-posture-step-ca",
|
|
"enabled": true,
|
|
"source": {
|
|
"sourceType": "CERTIFICATE_BUNDLE",
|
|
"sourceData": {
|
|
"x509CertificateData": "REPLACE_WITH_PEM_OF_STEP_CA_ROOT_CERT (the step-ca root CA cert, NOT a public ACM PCA; this pins trust to the internal CA only)"
|
|
}
|
|
},
|
|
"notification_settings": [
|
|
{
|
|
"enabled": true,
|
|
"event": "CA_CERTIFICATE_EXPIRY",
|
|
"threshold": 30,
|
|
"channel": "ALL"
|
|
}
|
|
],
|
|
"_rationale": "The trust anchor pins the internal step-ca ROOT cert as the only CA whose leaves Roles Anywhere will accept. Because the CA is internal and single-purpose, no other identities can mint trusted leaves. CA-expiry notifications are on so the anchor cannot silently go stale."
|
|
},
|
|
|
|
"profile": {
|
|
"name": "r720-aws-posture-readonly",
|
|
"enabled": true,
|
|
"roleArns": [
|
|
"arn:aws:iam::328440206208:role/r720-aws-posture-readonly"
|
|
],
|
|
"durationSeconds": 3600,
|
|
"acceptRoleSessionName": false,
|
|
"managedPolicyArns": [],
|
|
"sessionPolicy": null,
|
|
"_rationale": "Profile binds ONLY the single read-only role. durationSeconds=3600 (1h) caps the lifetime of any vended STS session independent of cert lifetime; combined with a ~24h leaf cert, a compromised leaf yields at most a short read-only window. No extra managed policies; no session-policy widening."
|
|
},
|
|
|
|
"_binding_note": "The role's trust policy (aws-posture-trust-policy.json) additionally pins aws:PrincipalTag/x509Subject/CN = 'r720-aws-posture' AND aws:PrincipalTag/x509Issuer/CN, and ArnEquals on aws:SourceArn = this trust anchor. So three independent conditions must all hold for AssumeRole to succeed: (1) the call comes via Roles Anywhere, (2) from THIS trust anchor, (3) presenting a leaf whose subject CN and issuer CN match. Roles Anywhere maps x509 subject/issuer fields into aws:PrincipalTag/x509Subject/* and aws:PrincipalTag/x509Issuer/* session tags, which is what the trust policy keys on."
|
|
}
|