Skip to content

Issue #68: read-only Config resource drill-down - #69

Merged
amitkarpe merged 1 commit into
mainfrom
g/issue-68-readonly-controls
Sep 29, 2026
Merged

amitkarpe merged 1 commit into
mainfrom
g/issue-68-readonly-controls

Conversation

@amitkarpe

Copy link
Copy Markdown
Owner

Closes #68 (Roadmap v2 #62 M3/F3+F6 repository slice).

The existing four-account Config aggregator exposes two common rules, not six to eight: S3 bucket public access and restricted SSH. This PR keeps those real rules as the versioned allowlist and adds a bounded account → control → affected-resource read-only drill-down. It does not create Config rules or infer green coverage for missing controls.

The new exact-select endpoint returns at most ten ordinal resource references, allowlisted family labels, status and evaluation time. It fails closed for unavailable, stale, partial, mismatched or unknown detail evidence. The dashboard offers “View affected” on noncompliant checks. The existing Compliance Agent remains one read-only MCP tool with zero actions and keeps its Status/Explain/no-change Plan contract.

Validation so far: dashboard build/lint pass; focused Node and Python contract checks pass; isolated Home provider read is READY at four aliases/eight checks; all eight detail reads pass with only masked references; Home Chrome render shows the new control. The full Python suite has an unrelated deferred Reject producer-pipe failure locally; its standalone Node run passes without the nested Python runner. CI is the merge gate.

No AWS mutation, new route, old demo change or Issue #11/PR #13 work. Additional S3/EC2/EBS/RDS rule coverage is a separate M4 authorization gap.

@amitkarpe

Copy link
Copy Markdown
Owner Author

HANDOFF: CHATGPT — Roadmap v2 M3/F3+F6, Issue #68

PR: #69
Branch: g/issue-68-readonly-controls
Exact head/base: f6281c05cbc0ac86888d5d0a85fd770bd795f036 / cca4b1dec354e9b92347b150594d3dd145044a55

Read-only discovery of the existing four-alias Config aggregator found exactly two common managed rules, not 6–8 distinct controls:

LAB alias Existing controls Resource families
lab-dev s3-bucket-level-public-access-prohibited, restricted-ssh S3 bucket, security group
lab-poc same two S3 bucket, security group
lab-qa same two S3 bucket, security group
lab-sec same two S3 bucket, security group

This is eight account/control checks. No S3 encryption, EC2/EBS or RDS rule appeared in the current aggregator or two-rule organization-rule readback. The PR keeps the strongest existing subset and records additional distinct controls as an M4 authorization gap; it creates or updates no AWS resource.

Implementation: one versioned control registry shared by the provider, dashboard, Compliance Agent backend/browser contract and Home validator. The new exact-select GET /api/resources supports account → control → affected-resource drill-down, at most ten rows, ordinal masked references, allowlisted family labels and evaluation times. Unknown selections, partial/missing aggregate evidence, mismatched detail evidence and detail evaluations older than 30 days fail closed. The UI shows a read-only “View affected” control only for noncompliant checks; no raw account/resource IDs, ARNs, annotations or private findings are returned. Status/Explain/no-change Plan semantics remain 4 × 2 from the same normalized evidence. The Compliance Agent remains one read-only MCP tool and zero actions.

Validation at this head:

  • Dashboard npm ci, build and lint PASS locally and in an isolated Home source/build.
  • Focused Python browser/prompt/Home contract checks PASS (20); focused Node cockpit/detail checks PASS (2), including masked output, mismatched response and stale failure.
  • Isolated Home config2 provider READY: four aliases, eight checks; all eight exact detail reads PASS with only masked references. Home headless Chrome rendered the dashboard and “View affected” control. Accepted running services and the M1 public route were unchanged.
  • Canonical NEW sec2 browser acceptance from a clean Home checkout at this exact head: Status, Explain and no-change Plan 3/3 PASS, exact evidence/render binding, 3/3 Archive readbacks, one tool, zero actions. The exact-head home_demo.py validate then PASS.
  • GitHub test CI and GitGuardian: PASS on this head.

One local full-suite run hit the unrelated deferred Reject producer-pipe test (AWSOPS_PAUSE_NOT_READY); its standalone Node run passed without the nested runner. The PR's GitHub CI suite passed. No Issue #11/PR #13 code or live Reject flow was changed or run.

Public-safety review: no credentials, private account/resource identifiers, raw Config findings, browser auth/state or owner-only evidence entered the PR. No AWS write, new public exposure, OLD runtime, retained EC2, Lightsail or vagent change. PR is ready for G exact-head review; deploy the reviewed config2 update to the supported Home runtime only after merge/review. M4 needs a separate exact authorization before any additional Config rules or remediation.

@amitkarpe
amitkarpe force-pushed the g/issue-68-readonly-controls branch from f6281c0 to 41f858d Compare September 29, 2026 03:04
@amitkarpe

Copy link
Copy Markdown
Owner Author

HANDOFF: CHATGPT — Issue #68 M3, rebased PR #69

  • Exact PR head: 41f858dae5bbbc0b39ec703bd562d77dad140b39 on g/issue-68-readonly-controls; parent is current main cb31b6ce8e4d6b9cfb135b9f02a0088e09003f0d. Same PR, one rebased M3 commit. PR is mergeable; no replacement PR.
  • Rebase resolution: reconciled only CONTEXT.md and ROADMAP.md. M1 merged Tailscale lifecycle/docs and M2 merged cockpit/Harness telemetry remain present. The NEW stable HTTPS /login readback returned 200. Home cockpit was visibly DEGRADED with stale Harness telemetry before the browser invocation and READY with fresh telemetry afterward; one MCP tool, zero actions.
  • Actual provider truth: four LAB aliases currently expose only the two common managed rules for S3 bucket public access and restricted SSH (8 account/control checks). The fixed registry, normalized read contract and bounded account/control drill-down retain this honest scope. Eight live detail reads passed with at most ten masked resource-* references per response; no raw account/resource identifiers or private Config fields were emitted. Missing/stale/partial evidence remains fail-closed.
  • Exact-head checks: dashboard npm run build and npm run lint PASS; focused cockpit tests 2/2 PASS; focused Python/browser/Home contracts 22/22 PASS; git diff --check PASS. GitHub test and GitGuardian Security Checks PASS at this head.
  • Home acceptance at this exact head: canonical browser Status, Explain and no-change Plan PASS 3/3 via the stable route, with persisted/tool/rendered binding, three Archive readbacks, one read-only tool and zero actions. A separate Home loopback browser run also passed 3/3 and archived 3/3. python3 scripts/home_demo.py validate --browser-evidence <owner-private evidence directory> PASS: 4 aliases, 8 checks, 2 controls, 1 tool, 0 actions, 3 prompts, 3 archived. The first route browser attempt had a transient runtime block before creating any conversation; the diagnostic retry and separate loopback run passed without code or auth changes.
  • M4 gap: the requested 6–8 distinct controls do not exist in the current four-alias Config evidence. Any new Config rule or Conformance Pack requires the separate Issue Roadmap v2: demo-ready multi-account compliance and governed remediation #62 AWS mutation gate; PR Issue #68: read-only Config resource drill-down #69 does not create rules or claim green coverage for absent controls.
  • Safety: AWS calls were read-only. No new public route, OLD demo, retained EC2, Lightsail/vagent, IAM/network, Issue M3C: trusted pause registration and isolated native canary acceptance #11/PR M3 canary: isolated normal authentication and native acceptance evidence #13, remediation or model-facing AWS tool was changed. No private identifiers or auth state were published.

Ready for G's exact-head review and merge decision. Do not treat the M4 control-coverage gap as completed.

@amitkarpe
amitkarpe merged commit 5ed00e3 into main Sep 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Roadmap v2 M3: 6-8 read-only controls and safe resource drill-down

1 participant