Issue #68: read-only Config resource drill-down - #69
Conversation
|
HANDOFF: CHATGPT — Roadmap v2 M3/F3+F6, Issue #68 PR: #69 Read-only discovery of the existing four-alias Config aggregator found exactly two common managed rules, not 6–8 distinct controls:
This is eight account/control checks. No S3 encryption, EC2/EBS or RDS rule appeared in the current aggregator or two-rule organization-rule readback. The PR keeps the strongest existing subset and records additional distinct controls as an M4 authorization gap; it creates or updates no AWS resource. Implementation: one versioned control registry shared by the provider, dashboard, Compliance Agent backend/browser contract and Home validator. The new exact-select Validation at this head:
One local full-suite run hit the unrelated deferred Reject producer-pipe test ( Public-safety review: no credentials, private account/resource identifiers, raw Config findings, browser auth/state or owner-only evidence entered the PR. No AWS write, new public exposure, OLD runtime, retained EC2, Lightsail or vagent change. PR is ready for G exact-head review; deploy the reviewed config2 update to the supported Home runtime only after merge/review. M4 needs a separate exact authorization before any additional Config rules or remediation. |
f6281c0 to
41f858d
Compare
|
HANDOFF: CHATGPT — Issue #68 M3, rebased PR #69
Ready for G's exact-head review and merge decision. Do not treat the M4 control-coverage gap as completed. |
Closes #68 (Roadmap v2 #62 M3/F3+F6 repository slice).
The existing four-account Config aggregator exposes two common rules, not six to eight: S3 bucket public access and restricted SSH. This PR keeps those real rules as the versioned allowlist and adds a bounded account → control → affected-resource read-only drill-down. It does not create Config rules or infer green coverage for missing controls.
The new exact-select endpoint returns at most ten ordinal resource references, allowlisted family labels, status and evaluation time. It fails closed for unavailable, stale, partial, mismatched or unknown detail evidence. The dashboard offers “View affected” on noncompliant checks. The existing Compliance Agent remains one read-only MCP tool with zero actions and keeps its Status/Explain/no-change Plan contract.
Validation so far: dashboard build/lint pass; focused Node and Python contract checks pass; isolated Home provider read is READY at four aliases/eight checks; all eight detail reads pass with only masked references; Home Chrome render shows the new control. The full Python suite has an unrelated deferred Reject producer-pipe failure locally; its standalone Node run passes without the nested Python runner. CI is the merge gate.
No AWS mutation, new route, old demo change or Issue #11/PR #13 work. Additional S3/EC2/EBS/RDS rule coverage is a separate M4 authorization gap.