IAM whatever you say IAM
eng.lyft.com
eng.lyft.com
At the time Cartography support for GCP was lacking, so we just ingested Cloud Asset Inventory data in neo4j.
If you are on GCP I highly suggest using CAI as a backbone for IAM security controls: hands down the best service on the platform for security teams.
It might be time to revisit that decision now though: it would be neat to have your CAI ingestion logic in Cartography :-)
Pulling data from the APIs won’t scale and it’s the exact reason why we migrated off Forseti (forsetisecurity.org) , which we helped build in the first place.
Feel free to ping me if you want more details, my contact is in my profile.
- https://docs.aws.amazon.com/AmazonS3/latest/dev/using-iam-po...
- https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQS...
While you _can_ do it with the Azure REST API (and their various SDKs that leverage it), the easiest way to do it is via `az graph query` in the Azure CLI.
Here's the link to documentation describing how to do this since it's insanely hard to find: https://docs.microsoft.com/en-us/azure/governance/resource-g...
That said, Cartography looks awesome and is probably better to use anyway. Awesome stuff, Lyft!
You can encode entire policy DSLs in graphs, and I can foresee a graph replacement for UMA/XACML emerging organically. Add DLT concepts to it, and it's a huge deal, imo.
My new phrase when I write anything resembling complicated.
This seems wrong. I wouldn’t call changes in the Redshift admins list “data drift” and seems rather deterministic.
I can imagine buckets or nested buckets as rows, policies, groups or users as columns, just as one way of viewing it. Alternative graphing tools such as Sourcetrail for source code also come to mind, as a way to merge policy source code with a graph view, for example.
- https://www.marcolancini.it/2020/blog-mapping-moving-clouds-...
- https://www.marcolancini.it/2020/blog-tracking-moving-clouds...
Cartography has some good ideas in there. For our case I am looking an event-driven model where the graph is continually updated as the environment changes. Then i can hook those changes to do targeted analysis as needed. I know HN loves to poo on serverless but the event-driven approach would be quite compatible with that as well.
For me the biggest challenge with any of this is trying to map the native data models of the cloud provider to something that is compatible with the simplistic property support in most graph databases (including Neo4j). Things move too quickly to be constantly mapping the schema from provider to the graph, I'd much rather have a system where I can just plop the native content and iterate on that.