-
Notifications
You must be signed in to change notification settings - Fork 1
docs: add Kosli Capture Managed Service page #380
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
193060c
0d7fb53
7afa53c
b6dd574
6e1d5c5
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,73 @@ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| --- | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| title: "Kosli Capture Managed Service" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| sidebarTitle: "Kosli Capture" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| description: "Learn how the Kosli Capture Managed Service snapshots your cloud environments from Kosli's infrastructure, with no software to install." | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| tag: "ALPHA" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| --- | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| <Warning> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture is still in active development. Its capabilities and configuration format may change, and onboarding is done together with Kosli's Customer Success team. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| </Warning> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture is a managed service that runs on Kosli's infrastructure and connects to your cloud platform to observe the resources deployed there. You grant Kosli Capture a set of permissions, and it uses them to run a `kosli snapshot` every few minutes against the infrastructure you have allowed it to scan. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli also supports reporting from your own cloud accounts by running the Kosli CLI on a schedule. Kosli Capture inverts this, with Kosli running the regular [snapshots](/getting_started/environments) so there is no software for you to install. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
gsavage marked this conversation as resolved.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## Overview | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture connects to your cloud accounts using permissions that you manage. You configure Kosli Capture by providing a few details describing what you want to be in scope, and Kosli Capture uses the permissions to regularly reach into your estate and record snapshots, sending the data into your Kosli organization. Kosli Capture is architected to be driven by your tagging scheme; it examines the tags on your infrastructure and uses them to determine how to structure the snapshots, and how to build the environments within Kosli. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| There are several benefits to this this architecture: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Suggestion — duplicated word, and the bullets use semicolon terminators. "to this this architecture" has a doubled "this". Also, the two bullets end in
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| * the only infrastructure you need to manage is an IAM role; you do not need to install or execute any additional software in your cloud estate; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| * Kosli Capture leverages your existing tagging scheme, so as your infrastructure evolves, Kosli Capture will automatically discover the snapshots it needs to take. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+20
to
+23
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Suggestion — doubled word, and these two bullets are punctuated unlike every other list on the pages. "to this this architecture" has a doubled "this". The bullets also start lowercase and terminate with
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## Security | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| The security of your cloud infrastructure is the primary driver behind the internal architecture of the Kosli Capture managed service. Kosli Capture runs as a shared, autoscaled service, but each job runs under a role that is scoped to one customer | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+25
to
+27
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Suggestion — this section duplicates the dedicated security page without linking to it.
A single forward pointer at the end of this section, e.g. "For the IAM role, trust policy and full permission list, see Kosli Capture security." — the security page has no link back to the overview either, so the pair is currently only navigable via the sidebar. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| * A Kosli Capture worker picks up a job for your organization and assumes a Kosli-side role that exists only for your organization. Only that role is permitted to call AssumeRole into A's account with A's ExternalId. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| * When the job finishes, those credentials are discarded. A worker holding credentials for your cloud account has no path to anyone else's account. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| * The trust policy's ExternalId lives in Parameter Store and is readable only by the Kosli-side role for your organization. The shared task role cannot read any customer's ExternalId. Separation is enforced by IAM, not by application code. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Catpure does not hold any customer data, it is near-stateless with the only thing it keeps is your configuration data. Snapshots taken by Kosli Catpure are immediately sent to Kosli through the same ingest path as your existing pipelines. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+27
to
+33
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Critical — this section still refers to an unnamed "customer A". Line 29 reads "Only that role is permitted to call AssumeRole into A's account with A's ExternalId." Nothing on the page defines "A" — it's carried over from an internal design document where customers were labelled A and B. A reader hits an unresolvable pronoun in the one section they are most likely to forward to their security team. Three more defects in the same block:
Suggested change
(The suggestion also unifies on "external ID", which is the form used on lines 71–73 and on the security page.)
Comment on lines
+27
to
+33
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — this section still refers to an unnamed "customer A". Line 29 reads "Only that role is permitted to call AssumeRole into A's account with A's ExternalId." Nothing on the page defines "A" — it reads as a leftover from an internal design document where customers were labelled A and B. This is the one section a reader is most likely to forward to their own security team, and it contains an unresolvable pronoun. Two more defects in the same block: line 27 has no closing full stop ("...scoped to one customer"), and line 33 is a comma splice ("...customer data, it is near-stateless...") whose second clause also doesn't parse ("with the only thing it keeps is your configuration data").
Suggested change
(The suggestion also unifies on "external ID", the form used on lines 71–73 and on the security page.) |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## Hands-off operation | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture has been designed to operate with no on-going support from you. Once the initial security permissions have been created, Kosli capture will continue to operate in a headless mode. Monitoring, maintenance and rotation of API keys is all handed automatically. As your cloud infrastructure changes over time, Kosli capture will continue to find resources according to your tagging scheme without you needing to do anything; your application teams do not need to take any action in order to onboard their products and services into Kosli. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — this over-claims against the tag-driven model the page is built on, plus two word-level defects. "your application teams do not need to take any action in order to onboard their products and services into Kosli" contradicts lines 18, 23 and 57, which all say routing is driven by your tagging scheme. An untagged new service can't be routed into an environment — so the action app teams do need to take is tagging their resources to the scheme. Saying that is more useful than claiming zero action, and it's exactly what a platform team needs to pass on. Also on this line: "rotation of API keys is all handed automatically" → "handled", and "Kosli capture" is lowercase twice (capitalized everywhere else on the page). Neither is caught by
Suggested change
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — the closing clause over-claims against the tag-driven model this page is built on. "your application teams do not need to take any action in order to onboard their products and services into Kosli" contradicts lines 18, 23 and 57, which all say routing is driven by your tagging scheme. An untagged new service cannot be routed into an environment, so the action app teams do need to take is tagging their resources to the scheme. Stating that is more useful than claiming zero action — it is exactly the instruction a platform team needs to pass on, and it is the one thing that will generate support tickets if left unsaid.
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## Setup | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Getting started with Kosli Capture involves three stages: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| <Steps> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| <Step title="Prepare your environment"> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Create an IAM role in your AWS account specifically for Kosli Capture. Kosli provides a CloudFormation template to simplify this process. The template requires a shared secret, which Kosli provides to you during onboarding. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — the CloudFormation template is the one artifact the reader has to get hold of, and it's still not linked. It's named four times across the two pages (here, line 64, and If the URL is public, link it here and on the security page. If it isn't public yet, say that explicitly ("Kosli provides the template during onboarding") so the reader stops looking. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| </Step> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| <Step title="Write the configuration document"> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Working with Kosli's Customer Success team, author a configuration document that shows how your cloud resources should be mapped to Kosli environments. This configuration document is loaded into Kosli. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| </Step> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| <Step title="Enable Kosli Capture"> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli enables Kosli Capture for your Kosli org, and the regular snapshots appear in Kosli. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| </Step> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| </Steps> | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## Finding resources | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture finds all supported resources within your AWS accounts, and examines the tags on those resources to determine which Kosli environment should hold the snapshots. Kosli Capture will create physical environments for you. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture can filter out resources based on your tags. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| As your cloud environment evolves, such as the addition of new ECS clusters or the retirement of existing Lambdas, Kosli Capture automatically detects the changes. Because Kosli Capture creates physical environments as needed, when your infrastructure changes, Kosli will keep up. No changes to the configuration created during the initial setup are required. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — environment auto-creation is now stated twice. Line 38 ends with "Kosli Capture will create physical environments for you", and this sentence repeats it four lines later ("Because Kosli Capture creates physical environments as needed..."). The claim only needs to land once; here the useful new information is that evolving infrastructure is handled without reconfiguration.
Suggested change
If you take this, drop the trailing sentence on line 38 ("Kosli Capture will create physical environments for you.") so the claim appears once, in the paragraph that explains why it matters.
Comment on lines
+57
to
+61
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — environment auto-creation is still stated twice. Line 38 ends with "Kosli Capture will create physical environments for you", and line 42 repeats it ("Because Kosli Capture creates physical environments as needed, when your infrastructure changes, Kosli will keep up"). The second sentence in line 42 is also circular — it restates the claim as the reason for itself. Fold the capability into the paragraph that explains why it matters, and drop it from line 38:
Suggested change
Comment on lines
+57
to
+61
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — environment auto-creation is still claimed twice, and the second one is circular. Line 38 ends with "Kosli Capture will create physical environments for you", then line 42 says "Because Kosli Capture creates physical environments as needed, when your infrastructure changes, Kosli will keep up" — which restates the claim as the reason for itself. The genuinely new information in that paragraph is that evolving infrastructure needs no reconfiguration; folding the auto-creation into it lands the claim once, in the place where it matters.
Suggested change
Comment on lines
+57
to
+61
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — "all supported resources" is now undefined anywhere on the site, and auto-creation is claimed twice. The
So a reader evaluating Kosli Capture has to reverse-engineer the supported resource types from an IAM policy two pages away. One sentence naming them ("Kosli Capture currently snapshots ECS services and Lambda functions") restores what the removed section provided, and keeps this page in sync when S3 or EKS lands. Separately, environment auto-creation is stated on line 57 ("Kosli Capture will create physical environments for you") and again on line 61 ("Because Kosli Capture creates physical environments as needed, when your infrastructure changes, Kosli will keep up") — the second is circular, restating the claim as its own reason. Folding it into the evolution paragraph lands it once, where it matters.
Suggested change
Comment on lines
+57
to
+61
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — "all supported resources" is no longer defined anywhere on the site. 7afa53c removed the
So a reader evaluating Kosli Capture has to reverse-engineer the supported resource types from an IAM policy on another page. One sentence naming them restores what the removed section provided, and gives you an obvious place to update when S3 or EKS lands. Separately, environment auto-creation is claimed twice — line 57 ("Kosli Capture will create physical environments for you") and again on line 61 ("Because Kosli Capture creates physical environments as needed, when your infrastructure changes, Kosli will keep up"), where it is restated as its own reason. Folding it into the evolution paragraph lands it once, in the place where it matters.
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## Multiple AWS accounts | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture can operate across multiple AWS regions and accounts, allowing you to snapshot development, QA, pre-production, and production workloads with the same configuration document. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## IAM permissions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| For Kosli Capture to snapshot your environment, you must grant a set of read-only permissions. Kosli's CloudFormation template lists these. The permissions are typically "Describe" or "List" permissions. The [Kosli Capture Security](/administration/kosli_capture/security) page provides a deep-diver into the structure of the permissions needed. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| The IAM role created in your environment includes a trust policy that allows Kosli Capture to assume the role. The trust policy limits access to the AWS account in which Kosli Capture is running. Furthermore, the trust policy includes an external ID that acts as a shared secret between Kosli and you, so that only access from Kosli Capture is permitted. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| The external ID (shared secret) is securely stored with Kosli Capture. Kosli's internal IAM permissions ensure that the secret can only be accessed by the specific instance of Kosli Capture worker that is operating for you. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+67
to
+73
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — with the pages now split, this section and 6e1d5c5 gave Kosli Capture its own folder with Worth deciding what each page owns. A reasonable split: the overview says what access is needed and why it is safe in two or three sentences, and the security page owns the mechanism. Right now the only link between them is buried at the end of line 69, and Two things on line 69 itself: "deep-diver" should be "deep dive", and there is a double space before "The".
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,100 @@ | ||||||||||||||||||||||||||||||||||||||||||||||||
| --- | ||||||||||||||||||||||||||||||||||||||||||||||||
| title: Kosli Capture - Security | ||||||||||||||||||||||||||||||||||||||||||||||||
| sidebarTitle: Security | ||||||||||||||||||||||||||||||||||||||||||||||||
| description: "Learn about the security of Kosli Capture" | ||||||||||||||||||||||||||||||||||||||||||||||||
| tag: "ALPHA" | ||||||||||||||||||||||||||||||||||||||||||||||||
| --- | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| <Warning> | ||||||||||||||||||||||||||||||||||||||||||||||||
| Kosli Capture is still in active development. Its capabilities and configuration format may change, and onboarding is done together with Kosli's Customer Success team. | ||||||||||||||||||||||||||||||||||||||||||||||||
| </Warning> | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| ## Kosli capture permissions | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| The Kosli Capture managed service uses the public AWS, GCP and Azure APIs to extract information about your cloud environments. In order to do this, you need to provide Kosli with an IAM role that allows access to these APIs. The role is created and owned by you. Kosli publishes a CloudFormation template, for use in AWS, showing the permissions needed. The template is publicly accessible and can be used directly within an `aws cloudformation create-stack` call. | ||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — GCP and Azure are claimed here but nowhere else, and "supported resources" is now undefined. This sentence says Kosli Capture "uses the public AWS, GCP and Azure APIs", but the rest of this page is AWS-only (IAM role, CloudFormation, ECS/Lambda/S3 statements), and This got worse when the "Current status" section was dropped from Suggest scoping this sentence to what exists today and naming the supported resource types on the main page (or restoring a short scope statement there).
Suggested change
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — GCP and Azure are claimed only here, and the "publicly accessible" template still has no URL. Two problems in one sentence:
Suggested change
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — GCP and Azure are claimed only here, and the "publicly accessible" template still has no URL. Two problems in one sentence:
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| ### Assume role | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| The IAM role defined within the CloudFormation template includes an "assume role" policy granting permission from Kosli. This appears as: | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| ``` | ||||||||||||||||||||||||||||||||||||||||||||||||
| KosliCaptureAccessRole: | ||||||||||||||||||||||||||||||||||||||||||||||||
| Type: AWS::IAM::Role | ||||||||||||||||||||||||||||||||||||||||||||||||
| Properties: | ||||||||||||||||||||||||||||||||||||||||||||||||
| RoleName: !Ref RoleName | ||||||||||||||||||||||||||||||||||||||||||||||||
| Description: >- | ||||||||||||||||||||||||||||||||||||||||||||||||
| Read-only access for Kosli Capture SDLC compliance evidence collection. | ||||||||||||||||||||||||||||||||||||||||||||||||
| Managed by CloudFormation; do not edit in place. | ||||||||||||||||||||||||||||||||||||||||||||||||
| MaxSessionDuration: 3600 | ||||||||||||||||||||||||||||||||||||||||||||||||
| AssumeRolePolicyDocument: | ||||||||||||||||||||||||||||||||||||||||||||||||
| Version: "2012-10-17" | ||||||||||||||||||||||||||||||||||||||||||||||||
| Statement: | ||||||||||||||||||||||||||||||||||||||||||||||||
| - Sid: AllowKosliToAssumeWithExternalId | ||||||||||||||||||||||||||||||||||||||||||||||||
| Effect: Allow | ||||||||||||||||||||||||||||||||||||||||||||||||
| Principal: | ||||||||||||||||||||||||||||||||||||||||||||||||
| AWS: !Ref TrustedPrincipalArn | ||||||||||||||||||||||||||||||||||||||||||||||||
| Action: sts:AssumeRole | ||||||||||||||||||||||||||||||||||||||||||||||||
| Condition: | ||||||||||||||||||||||||||||||||||||||||||||||||
| StringEquals: | ||||||||||||||||||||||||||||||||||||||||||||||||
| sts:ExternalId: !Ref ExternalId | ||||||||||||||||||||||||||||||||||||||||||||||||
| ``` | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| ### All permissions needed | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| The IAM role defined within the Cloudformation template includes a number of IAM policy statements, granting read-only access to some AWS APIs. The statements are: | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| ``` | ||||||||||||||||||||||||||||||||||||||||||||||||
| Statement: | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| # How Capture finds what to snapshot. Discovery lists the ECS | ||||||||||||||||||||||||||||||||||||||||||||||||
| # clusters in the account and reads each cluster's tags from the | ||||||||||||||||||||||||||||||||||||||||||||||||
| # same DescribeClusters call; those tags are what decide which | ||||||||||||||||||||||||||||||||||||||||||||||||
| # Kosli environment a cluster is reported into. Without | ||||||||||||||||||||||||||||||||||||||||||||||||
| # ListClusters and DescribeClusters a role created from this | ||||||||||||||||||||||||||||||||||||||||||||||||
| # template cannot run discovery at all. | ||||||||||||||||||||||||||||||||||||||||||||||||
| # | ||||||||||||||||||||||||||||||||||||||||||||||||
| # Worth knowing for a security review: these are inventory calls | ||||||||||||||||||||||||||||||||||||||||||||||||
| # and none of them returns application data. DescribeTaskDefinition | ||||||||||||||||||||||||||||||||||||||||||||||||
| # is the widest - a task definition holds the container image, the | ||||||||||||||||||||||||||||||||||||||||||||||||
| # command, and any environment variables written into the | ||||||||||||||||||||||||||||||||||||||||||||||||
| # definition itself in plain text. Values injected from Secrets | ||||||||||||||||||||||||||||||||||||||||||||||||
| # Manager or Parameter Store are named there rather than resolved, | ||||||||||||||||||||||||||||||||||||||||||||||||
| # so what comes back is the reference and not the secret. | ||||||||||||||||||||||||||||||||||||||||||||||||
| - Sid: EcsInventory | ||||||||||||||||||||||||||||||||||||||||||||||||
| Effect: Allow | ||||||||||||||||||||||||||||||||||||||||||||||||
| Action: | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:DescribeCapacityProviders | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:DescribeClusters | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:DescribeContainerInstances | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:DescribeServices | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:DescribeTaskDefinition | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:DescribeTasks | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:ListClusters | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:ListContainerInstances | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:ListServices | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:ListTagsForResource | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:ListTaskDefinitionFamilies | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:ListTaskDefinitions | ||||||||||||||||||||||||||||||||||||||||||||||||
| - ecs:ListTasks | ||||||||||||||||||||||||||||||||||||||||||||||||
| Resource: "*" | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| - Sid: LambdaInventory | ||||||||||||||||||||||||||||||||||||||||||||||||
| Effect: Allow | ||||||||||||||||||||||||||||||||||||||||||||||||
| Action: | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:GetFunctionConfiguration | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:GetPolicy | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:ListAliases | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:ListFunctions | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:ListTags | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:ListVersionsByFunction | ||||||||||||||||||||||||||||||||||||||||||||||||
| Resource: "*" | ||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
| # lambda:GetFunction returns a pre-signed URL to the deployment | ||||||||||||||||||||||||||||||||||||||||||||||||
| # package. That is source-code access, so it is denied outright. | ||||||||||||||||||||||||||||||||||||||||||||||||
| - Sid: NeverDownloadFunctionCode | ||||||||||||||||||||||||||||||||||||||||||||||||
| Effect: Deny | ||||||||||||||||||||||||||||||||||||||||||||||||
| Action: | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:GetFunction | ||||||||||||||||||||||||||||||||||||||||||||||||
| - lambda:GetLayerVersion | ||||||||||||||||||||||||||||||||||||||||||||||||
| Resource: "*" | ||||||||||||||||||||||||||||||||||||||||||||||||
| ```` | ||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Suggestion — closing fence has four backticks, and neither code block declares a language. The four-backtick close does still terminate the block under CommonMark, so it renders — but it's a stray character, and neither block (line 20 and line 46) tags a language, so both lose syntax highlighting on what is otherwise a page of YAML. Change
Suggested change
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Improvement — stray fourth backtick, and the S3 removal left the block's framing stale. The closing fence is More substantively: b6dd574 removed the Neither code block declares a language, so both lose highlighting on what is otherwise a page of YAML — change
Suggested change
Comment on lines
+92
to
+100
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Suggestion — the S3 removal left this deny unexplained, and the closing fence has four backticks. b6dd574 removed the Also, line 100 closes with
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||||
Uh oh!
There was an error while loading. Please reload this page.