Skip to content

Roadmap v2 M4: versioned read-only Config conformance pack - #71

Merged
amitkarpe merged 2 commits into
mainfrom
g/issue-70-config-pack
Oct 1, 2026
Merged

amitkarpe merged 2 commits into
mainfrom
g/issue-70-config-pack

Conversation

@amitkarpe

Copy link
Copy Markdown
Owner

Roadmap v2 M4 / F4 — repository-only Config pack

Closes #70 after G's review and merge. Parent #62.

This PR defines awsops-home-readonly-v1, a six-rule AWS managed Config Conformance Pack target for lab-dev, lab-poc, lab-qa, and lab-sec in ap-southeast-1. The two accepted M3 controls remain the live dashboard/agent contract; four additional controls are planned only. No AWS pack or rule is deployed.

Read-only personal-LAB discovery confirmed the existing organization aggregator covers the four aliases in the requested Region, all eight source status rows were SUCCEEDED, and each alias still has only the two accepted controls. Home config2 remained READY/non-partial with 4 aliases, 8 checks, 2 controls, 1 read-only tool and 0 actions; stale Harness telemetry appeared DEGRADED as designed. The stable public login returned 200.

Validation: npm ci, npm run validate:pack (3/3 focused fail-closed tests), npm run lint, npm run build, existing cockpit tests (2/2), and git diff --check passed locally. CI/GitGuardian pending PR readback.

Hard stop: no live AWS write is authorized by this PR. G/Amit must separately record the exact #62 mutation gate before any future PutConformancePack or related IAM action.

@amitkarpe

Copy link
Copy Markdown
Owner Author

HANDOFF: CHATGPT — Roadmap v2 M4/F4 repository acceptance, Issue #70 / PR #71

Exact head: 91b76510e6606bdf7288d5809dc512f0da0abf0c on g/issue-70-config-pack, based on merged-M3 main 5ed00e33198914139b7f07ed0b3cac1edf07dda2. PR #71 is mergeable; CI test and GitGuardian PASS. No AWS resource was written.

Repo deliverable: integration/config_dashboard/conformance-pack/ contains awsops-home-readonly-v1.yaml, a versioned six-control manifest, and an offline validator. The validator requires exact scope/inventory, the accepted two-rule mapping to the live registry, AWS-owned managed rules only, and no parameters, custom rules, remediation, extra resources or model-selected actions. docs/current/CONFIG_PACK_M4.md is the public-safe deployment/rollback/readback packet. CONTEXT and ROADMAP now identify M3 as merged and M4 as repository-ready only.

Verified managed SourceIdentifiers (official AWS Config rule pages):

Control SourceIdentifier State
S3 bucket public access S3_BUCKET_LEVEL_PUBLIC_ACCESS_PROHIBITED Existing M3
S3 TLS-only S3_BUCKET_SSL_REQUESTS_ONLY Planned
S3 default encryption S3_BUCKET_SERVER_SIDE_ENCRYPTION_ENABLED Planned
Restricted SSH INCOMING_SSH_DISABLED Existing M3
Encrypted EBS volumes ENCRYPTED_VOLUMES Planned
EBS encryption by default EC2_EBS_ENCRYPTION_BY_DEFAULT Planned

Read-only discovery: the existing personal-LAB amit profile authenticated in ap-southeast-1; the organization-sourced Config aggregator includes that Region. All eight source-status rows were SUCCEEDED. Private bindings resolve the four approved aliases, and each alias has exactly the two accepted rule names in the aggregate readback. Other aggregate rows do not prove the four planned rules are present. Current Home config2 diagnostics are READY/non-partial for 4 aliases × 2 controls = 8 checks, with 1 read-only agent tool and 0 actions. Cockpit showed DEGRADED because Harness telemetry was stale, as designed; stable public /login returned 200.

Validation: npm ci, npm run validate:pack (3 focused fail-closed tests), npm run lint, npm run build, existing cockpit tests (2), git diff --check, and final-head CI/GitGuardian PASS. No AWS pack/rule or IAM change; no M3 live-registry expansion.

Complete Issue #62 seven-item gate packet for later owner authorization:

  1. Scope: only lab-dev, lab-poc, lab-qa, lab-sec in ap-southeast-1; privately reverify exact per-alias identity and active Config recorder before each write. Aggregator read access is not deployment authority.
  2. Operation: pack awsops-home-readonly-v1, version 1; proposed per-account CREATE using the reviewed YAML as TemplateBody. Exact existing content is a no-op; divergent v1 content stops for a new version, not an in-place update. No organization-wide API.
  3. Controls/canary: exactly the six identifiers above. Two duplicate existing organization-rule semantics until a separately reviewed transition; four are planned. No M5 canary resource/control is selected in this gate; M5 needs a separate exact authorization.
  4. Actions: propose scoped config:PutConformancePack, required config:TagResource, Config describe/compliance readback, and read-only iam:GetRole prerequisite check. AWS says PutConformancePack may create AWSServiceRoleForConfigConforms if absent; stop if absent for separate exact IAM authority. No PutConfigRule, remediation API, SSM, Organizations or broad IAM. See AWS API and IAM action reference.
  5. Rollback/retention: stage one alias at a time, preserve private before/after evidence and template digest, stop on failure/unknown. DeleteConformancePack would remove pack-owned rules/history and needs separate exact cleanup approval; never touch the M3 organization rules. Proposed review/TTL date 2026-12-31 and exact lifecycle tags need owner acceptance.
  6. Cost: usage-based Config and pack evaluations. Illustrative 1,200 pack evaluations/month across 4×6 at 50 each ≈ USD 1.20 at AWS's example USD 0.001 rate, excluding other Config/storage charges; verify Singapore rates and actual volume. Proposed incremental cap USD 10/month, with 24-hour/monthly readback; owner must approve the cap before any write. AWS pricing.
  7. Exclusions: no AWS write before the explicit gate; no remediation/SSM, IAM/OIDC/Organizations/network expansion, new public exposure, PROD/company, OLD demo, retained EC2, Lightsail, vagent, Issue M3C: trusted pause registration and isolated native canary acceptance #11/PR M3 canary: isolated normal authentication and native acceptance evidence #13, or deletion.

Decision for G: review/merge the repository proposal if accepted. The first live AWS write remains blocked until Amit records the full gate, including the cost/retention choices and service-linked-role preflight.

@amitkarpe
amitkarpe merged commit 22800ab into main Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Roadmap v2 M4: versioned four-account Config Conformance Pack

1 participant