mirror of
https://github.com/kubescape/kubescape.git
synced 2026-04-15 06:58:11 +00:00
+18









David Wertenteil
GitHub
Vlad Klokun
Moshe-Rappaport-CA
Moshe Rappaport
Om Raut
Kamal Nayan
Chirag Arora
shm12
Amir Malka
Krishna Agarwal
Saswata Senapati
Rahul Singh
deepuyadav004
kartik
Rounak-28
pwnb0y
Ben Hirschberg
Saptarshi Sarkar
Rahul Surwade
Suhas Gumma
TarangVerma
avikittu
satyam kale
Aditya Pratap Singh
Ashray Shetty
Anubhav Gupta
Meyazhagan
eb16440ba6
* Fix issue for scanning list obj * Fix go mod in httphandler pkg * Broken links fix in roadmap.md Planning, backlog, and wishlist links were not taking to the required section. * override infoMap only if it's not nil * improved icon of kubescape in readme * Support scanning several files * gramatical improvements * docs(readme): Star → star * Fix issues according to review * Handle with issues caused by updating opa-utils * Fix scanning ListObj following reviews * Update core/pkg/resourcehandler/filesloader.go Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> * Update completion.go * Added fixed control input * update go.mod * Print chart name log when fail to generate * Change formatting to %s * Added resource prioritization information, raw resource will be sent on the result object * Merging typo fixes from master (#772) * greetings * Update aws.sh simplified the comment * typo: In the title and h1 element Their was a typo in index.html file. * punctuation changes * docs : added gitpod badge in readme.md * fixed typos * some grammar mistake is corrected inPULL_REQUEST_TEMPLATE.md file * Updated README.md file Added link to CONTRIBUTING.md file in a line in README. * Added link to code of conduct file I have added link to the code of conduct file and fixed some problems in the Readme file. * Fixed readme * Added alpine tag Adding alpine tag instead of latest and removing repeating commands * roadmap.md file is modified * Automatically Close "Typo" labelled Issue * build.py is modified * modified PR template * Fixed some typos in feature_request.md "." at the end of the headings were missing and all the text were in same line. Now this gives a clear and concise view of the texts. * fixed the typo in docs/index.html Found and fixed typo in the 'alt' attribute of img tag * Update PULL_REQUEST_TEMPLATE.md Co-authored-by: Krishna Agarwal <dmkrishna.agarwal@gmail.com> Co-authored-by: Saswata Senapati <74651639+saswat16@users.noreply.github.com> Co-authored-by: Rahul Singh <110548934+rahuldhirendersingh@users.noreply.github.com> Co-authored-by: deepuyadav004 <deepuyadavze@gmail.com> Co-authored-by: kartik <97971066+kartikgajjar7@users.noreply.github.com> Co-authored-by: Rounak-28 <95576871+Rounak-28@users.noreply.github.com> Co-authored-by: pwnb0y <vickykr07@yahoo.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> Co-authored-by: Saptarshi Sarkar <saptarshi.programmer@gmail.com> Co-authored-by: Rahul Surwade <93492791+RahulSurwade08@users.noreply.github.com> Co-authored-by: Suhas Gumma <43647369+suhasgumma@users.noreply.github.com> Co-authored-by: Kamal Nayan <95926324+legendarykamal@users.noreply.github.com> Co-authored-by: TarangVerma <90996971+TarangVerma@users.noreply.github.com> Co-authored-by: avikittu <65793296+avikittu@users.noreply.github.com> * update logger version * update logger version (#773) * Fixed: Kubescape fails to authenticate remote private Github repo (#721) * grammar error fixer in CONTRIBUTING.md * scanning private git repository is available * giturl to gitapi * NO TOKEN error functionality added * Used GetToken method of giturl.IGitAPPI for auth Co-authored-by: satyam kale <satyamkale271@gmail.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> * bump opa-utils to 181 * Option to force enable color output (closes #560) (#767) * Option to force enable color output (closes #560) (cherry picked from commit 4f951781ee8dd6bb451ac7d159787f47e4b07379) * Update go.mod * update scanner image * Update host scanner image (#774) * update logger version * update scanner image * remove windows exe extension * Remove windows extension build (#775) * update logger version * update scanner image * remove windows exe extension * commened out prioritization logic * Edit Junit output (#802) * Edit Junit output * Update go sum * Following review * update AdoptClusterName * Print line separator only if some controls failed (#813) * removed the extra 'download' word from the example (#810) it was confusing to understand the download command because there was an extra 'download' mentioned * Prioritization (#815) * removed commented out code * Added attack tracks information to prioritization algorithm * bump opa-utils * go mod tidy * go mod tidy * CR changes * Issue 613 cluster name (#783) * added --clusterName flag (#613) Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> * update flag name to --cluster-name Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> * Per 307 fail on severity counters (#831) * feat: fail on exceeding severity thresholds (#830) - Add support for severity counters - Add support for CLI flags that set severity thresholds - Terminate Kubescape with an exit code 1 if scan results exceed the severity thresholds * Update opa-utils pkg version Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> * Fix merge conflict * typo in .gitignore file (#833) * remove unsupported installation method * fixed welcome message * fixed merge * fixed attack tracks loading logic Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> Co-authored-by: Moshe-Rappaport-CA <moshep@armosec.io> Co-authored-by: Moshe Rappaport <89577611+Moshe-Rappaport-CA@users.noreply.github.com> Co-authored-by: Om Raut <33827410+om2137@users.noreply.github.com> Co-authored-by: Kamal Nayan <95926324+legendarykamal@users.noreply.github.com> Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> Co-authored-by: Chirag Arora <84070677+Chirag8023@users.noreply.github.com> Co-authored-by: shm12 <shmuelb@armosec.io> Co-authored-by: Amir Malka <amirm@armosec.io> Co-authored-by: Krishna Agarwal <dmkrishna.agarwal@gmail.com> Co-authored-by: Saswata Senapati <74651639+saswat16@users.noreply.github.com> Co-authored-by: Rahul Singh <110548934+rahuldhirendersingh@users.noreply.github.com> Co-authored-by: deepuyadav004 <deepuyadavze@gmail.com> Co-authored-by: kartik <97971066+kartikgajjar7@users.noreply.github.com> Co-authored-by: Rounak-28 <95576871+Rounak-28@users.noreply.github.com> Co-authored-by: pwnb0y <vickykr07@yahoo.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> Co-authored-by: Saptarshi Sarkar <saptarshi.programmer@gmail.com> Co-authored-by: Rahul Surwade <93492791+RahulSurwade08@users.noreply.github.com> Co-authored-by: Suhas Gumma <43647369+suhasgumma@users.noreply.github.com> Co-authored-by: TarangVerma <90996971+TarangVerma@users.noreply.github.com> Co-authored-by: avikittu <65793296+avikittu@users.noreply.github.com> Co-authored-by: satyam kale <satyamkale271@gmail.com> Co-authored-by: Aditya Pratap Singh <adityapratapsingh51@gmail.com> Co-authored-by: Ashray Shetty <ashrayshetty1999@gmail.com> Co-authored-by: Anubhav Gupta <mail.anubhav06@gmail.com> Co-authored-by: Meyazhagan <meyazhagan.ofcl@gmail.com>
230 lines
7.6 KiB
Go
230 lines
7.6 KiB
Go
package opaprocessor
|
|
|
|
import (
|
|
logger "github.com/kubescape/go-logger"
|
|
"github.com/kubescape/kubescape/v2/core/cautils"
|
|
|
|
"github.com/kubescape/k8s-interface/k8sinterface"
|
|
"github.com/kubescape/k8s-interface/workloadinterface"
|
|
"github.com/kubescape/opa-utils/reporthandling"
|
|
"github.com/kubescape/opa-utils/reporthandling/apis"
|
|
"github.com/kubescape/opa-utils/reporthandling/results/v1/reportsummary"
|
|
resources "github.com/kubescape/opa-utils/resources"
|
|
)
|
|
|
|
// updateResults updates the results objects and report objects. This is a critical function - DO NOT CHANGE
|
|
//
|
|
// The function:
|
|
// - removes sensible data
|
|
// - adds exceptions
|
|
// - summarizes results
|
|
func (opap *OPAProcessor) updateResults() {
|
|
|
|
// remove data from all objects
|
|
for i := range opap.AllResources {
|
|
removeData(opap.AllResources[i])
|
|
}
|
|
|
|
// set exceptions
|
|
for i := range opap.ResourcesResult {
|
|
|
|
t := opap.ResourcesResult[i]
|
|
|
|
// first set exceptions
|
|
if resource, ok := opap.AllResources[i]; ok {
|
|
t.SetExceptions(resource, opap.Exceptions, cautils.ClusterName)
|
|
}
|
|
|
|
// summarize the resources
|
|
opap.Report.AppendResourceResultToSummary(&t)
|
|
|
|
// Add score
|
|
// TODO
|
|
|
|
// save changes
|
|
opap.ResourcesResult[i] = t
|
|
}
|
|
|
|
// set result summary
|
|
// map control to error
|
|
controlToInfoMap := mapControlToInfo(opap.ResourceToControlsMap, opap.InfoMap, opap.Report.SummaryDetails.Controls)
|
|
opap.Report.SummaryDetails.InitResourcesSummary(controlToInfoMap)
|
|
}
|
|
|
|
func mapControlToInfo(mapResourceToControls map[string][]string, infoMap map[string]apis.StatusInfo, controlSummary reportsummary.ControlSummaries) map[string]apis.StatusInfo {
|
|
controlToInfoMap := make(map[string]apis.StatusInfo)
|
|
for resource, statusInfo := range infoMap {
|
|
controlIDs := mapResourceToControls[resource]
|
|
for _, controlID := range controlIDs {
|
|
ctrl := controlSummary.GetControl(reportsummary.EControlCriteriaID, controlID)
|
|
if ctrl != nil {
|
|
resources := ctrl.NumberOfResources()
|
|
// Check that there are no K8s resources too
|
|
if isEmptyResources(resources) {
|
|
controlToInfoMap[controlID] = statusInfo
|
|
}
|
|
}
|
|
|
|
}
|
|
}
|
|
return controlToInfoMap
|
|
}
|
|
|
|
func isEmptyResources(counters reportsummary.ICounters) bool {
|
|
return counters.Failed() == 0 && counters.Excluded() == 0 && counters.Passed() == 0
|
|
}
|
|
|
|
func getAllSupportedObjects(k8sResources *cautils.K8SResources, ksResources *cautils.KSResources, allResources map[string]workloadinterface.IMetadata, rule *reporthandling.PolicyRule) []workloadinterface.IMetadata {
|
|
k8sObjects := []workloadinterface.IMetadata{}
|
|
k8sObjects = append(k8sObjects, getKubernetesObjects(k8sResources, allResources, rule.Match)...)
|
|
k8sObjects = append(k8sObjects, getKSObjects(ksResources, allResources, rule.DynamicMatch)...)
|
|
return k8sObjects
|
|
}
|
|
|
|
func getKSObjects(k8sResources *cautils.KSResources, allResources map[string]workloadinterface.IMetadata, match []reporthandling.RuleMatchObjects) []workloadinterface.IMetadata {
|
|
k8sObjects := []workloadinterface.IMetadata{}
|
|
|
|
for m := range match {
|
|
for _, groups := range match[m].APIGroups {
|
|
for _, version := range match[m].APIVersions {
|
|
for _, resource := range match[m].Resources {
|
|
groupResources := k8sinterface.ResourceGroupToString(groups, version, resource)
|
|
for _, groupResource := range groupResources {
|
|
if k8sObj, ok := (*k8sResources)[groupResource]; ok {
|
|
// if k8sObj == nil {
|
|
// logger.L().Debug(fmt.Sprintf("resource '%s' is nil, probably failed to pull the resource", groupResource))
|
|
// }
|
|
for i := range k8sObj {
|
|
k8sObjects = append(k8sObjects, allResources[k8sObj[i]])
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
return filterOutChildResources(k8sObjects, match)
|
|
}
|
|
|
|
func getKubernetesObjects(k8sResources *cautils.K8SResources, allResources map[string]workloadinterface.IMetadata, match []reporthandling.RuleMatchObjects) []workloadinterface.IMetadata {
|
|
k8sObjects := []workloadinterface.IMetadata{}
|
|
|
|
for m := range match {
|
|
for _, groups := range match[m].APIGroups {
|
|
for _, version := range match[m].APIVersions {
|
|
for _, resource := range match[m].Resources {
|
|
groupResources := k8sinterface.ResourceGroupToString(groups, version, resource)
|
|
for _, groupResource := range groupResources {
|
|
if k8sObj, ok := (*k8sResources)[groupResource]; ok {
|
|
if k8sObj == nil {
|
|
// logger.L().Debug("skipping", helpers.String("resource", groupResource))
|
|
}
|
|
for i := range k8sObj {
|
|
k8sObjects = append(k8sObjects, allResources[k8sObj[i]])
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
return filterOutChildResources(k8sObjects, match)
|
|
}
|
|
|
|
// filterOutChildResources filter out child resources if the parent resource is in the list
|
|
func filterOutChildResources(objects []workloadinterface.IMetadata, match []reporthandling.RuleMatchObjects) []workloadinterface.IMetadata {
|
|
response := []workloadinterface.IMetadata{}
|
|
owners := []string{}
|
|
for m := range match {
|
|
for i := range match[m].Resources {
|
|
owners = append(owners, match[m].Resources[i])
|
|
}
|
|
}
|
|
for i := range objects {
|
|
if !k8sinterface.IsTypeWorkload(objects[i].GetObject()) {
|
|
response = append(response, objects[i])
|
|
continue
|
|
}
|
|
w := workloadinterface.NewWorkloadObj(objects[i].GetObject())
|
|
ownerReferences, err := w.GetOwnerReferences()
|
|
if err != nil || len(ownerReferences) == 0 {
|
|
response = append(response, w)
|
|
} else if !k8sinterface.IsStringInSlice(owners, ownerReferences[0].Kind) {
|
|
response = append(response, w)
|
|
}
|
|
}
|
|
return response
|
|
}
|
|
func getRuleDependencies() (map[string]string, error) {
|
|
modules := resources.LoadRegoModules()
|
|
if len(modules) == 0 {
|
|
logger.L().Warning("failed to load rule dependencies")
|
|
}
|
|
return modules, nil
|
|
}
|
|
|
|
func removeData(obj workloadinterface.IMetadata) {
|
|
if !k8sinterface.IsTypeWorkload(obj.GetObject()) {
|
|
return // remove data only from kubernetes objects
|
|
}
|
|
workload := workloadinterface.NewWorkloadObj(obj.GetObject())
|
|
switch workload.GetKind() {
|
|
case "Secret":
|
|
removeSecretData(workload)
|
|
case "ConfigMap":
|
|
removeConfigMapData(workload)
|
|
default:
|
|
removePodData(workload)
|
|
}
|
|
}
|
|
|
|
func removeConfigMapData(workload workloadinterface.IWorkload) {
|
|
workload.RemoveAnnotation("kubectl.kubernetes.io/last-applied-configuration")
|
|
workloadinterface.RemoveFromMap(workload.GetObject(), "metadata", "managedFields")
|
|
overrideSensitiveData(workload)
|
|
}
|
|
|
|
func overrideSensitiveData(workload workloadinterface.IWorkload) {
|
|
dataInterface, ok := workloadinterface.InspectMap(workload.GetObject(), "data")
|
|
if ok {
|
|
data, ok := dataInterface.(map[string]interface{})
|
|
if ok {
|
|
for key := range data {
|
|
workloadinterface.SetInMap(workload.GetObject(), []string{"data"}, key, "XXXXXX")
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
func removeSecretData(workload workloadinterface.IWorkload) {
|
|
workload.RemoveAnnotation("kubectl.kubernetes.io/last-applied-configuration")
|
|
workloadinterface.RemoveFromMap(workload.GetObject(), "metadata", "managedFields")
|
|
overrideSensitiveData(workload)
|
|
}
|
|
func removePodData(workload workloadinterface.IWorkload) {
|
|
workload.RemoveAnnotation("kubectl.kubernetes.io/last-applied-configuration")
|
|
workloadinterface.RemoveFromMap(workload.GetObject(), "metadata", "managedFields")
|
|
workloadinterface.RemoveFromMap(workload.GetObject(), "status")
|
|
|
|
containers, err := workload.GetContainers()
|
|
if err != nil || len(containers) == 0 {
|
|
return
|
|
}
|
|
for i := range containers {
|
|
for j := range containers[i].Env {
|
|
containers[i].Env[j].Value = "XXXXXX"
|
|
}
|
|
}
|
|
workloadinterface.SetInMap(workload.GetObject(), workloadinterface.PodSpec(workload.GetKind()), "containers", containers)
|
|
}
|
|
|
|
func ruleData(rule *reporthandling.PolicyRule) string {
|
|
return rule.Rule
|
|
}
|
|
|
|
func ruleEnumeratorData(rule *reporthandling.PolicyRule) string {
|
|
return rule.ResourceEnumerator
|
|
}
|