mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-08-29 04:26:20 +00:00
* fix(security): restrict Neptune cookbook SG, add VPC flow logs, harden IaC scan suppressions
Addresses open GHAS code scanning alerts:
- Neptune cookbook stack (neptune-setup.yaml) no longer opens the Bolt/OpenCypher
port to 0.0.0.0/0; a required ClientCidr parameter must be supplied instead.
Updated 21_Amazon_Neptune_Store.ipynb deploy instructions to match.
- Added VPC Flow Logs (CloudWatch Logs + IAM role) to the same stack.
- Documented why an account-wide IAM password policy resource does not belong
in a disposable per-learner CFN stack, with a justified ts:skip.
- Added inline `checkov:skip` / `ts:skip` comments to the knowledge-explorer
Helm templates (deployment/service/configmap) as a second suppression path
for the CKV_K8S_21/AC_K8S_0086/AC_K8S_0080 false positives, since the prior
annotation-only suppression was not being honored by the scanner.
* docs(changelog): document the Neptune and Helm chart security scan fixes
* fix(security): correct flow-log IAM scope and ClientCidr regex from review
- FlowLogRole granted logs:CreateLogStream/PutLogEvents on the bare log
group ARN, but those actions apply to log streams, not the group itself;
scoped them to "${FlowLogGroup.Arn}:log-stream:*" instead and moved the
Describe* actions (which don't support group/stream-level resource
restriction) to Resource: "*", matching AWS's documented flow-log IAM
policy shape. Without this, flow log delivery could silently fail.
- ClientCidr's AllowedPattern only checked digit count (1-3 digits per
octet), so malformed values like 999.999.999.999/32 passed parameter
validation and would only fail later when CloudFormation tried to
create the security group rule. Tightened the regex to enforce valid
IPv4 octet ranges (0-255) and prefix lengths (0-32).
* fix(security): harden IAM policy in neptune-setup and standardize Helm chart scan suppressions
- neptune-setup.yaml: split FlowLogRole policy into account-level statement (CreateLogGroup, DescribeLogGroups, DescribeLogStreams with Resource: '*') and log-group-scoped statement (CreateLogStream, PutLogEvents with !GetAtt FlowLogGroup.Arn) per AWS VPC Flow Logs least-privilege documentation.
- deployment.yaml: remove unreliable file-header skip comments (# checkov:skip / # ts:skip) and replace with resource-level metadata.annotations (checkov.io/skip and runterrascan.io/skip). Update seccomp rule ID from CKV_K8S_28 to checkov's actual seccomp rule CKV_K8S_31 on both Deployment and pod-template metadata.
- configmap.yaml / service.yaml: remove stale # ts:skip=AC_K8S_0086 file-header comments and add runterrascan.io/skip resource-level metadata annotations for consistency across all chart templates.
- .checkov.yaml: update documentation to explain resource-level metadata.annotations and reference CKV_K8S_31.
---------
Co-authored-by: Sameer6305 <sskadam6305@gmail.com>
20 lines
1.2 KiB
YAML
20 lines
1.2 KiB
YAML
# Checkov configuration.
|
|
# Cloud Run false-positives (CKV_K8S_21/28/30) are suppressed via per-file
|
|
# inline checkov:skip comments in deploy/gcp/cloudrun-service.yaml rather than
|
|
# globally here, so future real Kubernetes manifests are not silently exempted.
|
|
#
|
|
# The knowledge-explorer Helm chart's unconditional templates (service.yaml,
|
|
# deployment.yaml, configmap.yaml) set metadata.namespace to .Release.Namespace,
|
|
# which is only bound at `helm install`/`helm template` time. Checkov's helm
|
|
# framework renders the chart without a namespace override, so it always
|
|
# resolves to "default" and trips CKV_K8S_21 even though the chart is
|
|
# namespace-agnostic by design. Suppressed via metadata annotations
|
|
# (checkov.io/skip1 / runterrascan.io/skip) on each resource's metadata.annotations,
|
|
# as both Checkov and Terrascan require K8s/Helm resource-level annotations
|
|
# rather than file-header comments.
|
|
# deployment.yaml additionally suppresses AC_K8S_0080 and CKV_K8S_31 (seccomp) via
|
|
# metadata.annotations on both the Deployment resource and the pod template:
|
|
# the seccomp profile is set correctly in values.yaml and only resolves once
|
|
# Helm actually renders `toYaml`, which static template scanning does not do.
|
|
skip-check: []
|