Sign inSign up

manheim/manheim-cloudmapper

By manheim

•Updated over 5 years ago

Manheim's Cloudmapper Docker image

Image
1

5.2K

manheim/manheim-cloudmapper repository overview

⁠manheim-cloudmapper

TravisCI build badge

Docker Hub Build Status

Manheim's Cloudmapper Docker image

This project provides a Docker image for managing Manheim's cloudmapper automation. This project/repository is intended to be used (via the generated Docker image) alongside a terraform module which runs the Docker image in AWS ECS on a schedulued cycle.

For documentation on the upstream cloudmapper project, please see https://github.com/duo-labs/cloudmapper⁠

⁠Introduction and Goals

Cloudmapper is a tool designed to help analyze AWS environments. Cloudmapper contains a public command which is used to find public hosts and port ranges. (More details here⁠.). The purpose of this repository is to run Cloudmapper remotely (on AWS) and use the public command to find any AWS resources which have publicly accessible ports. Alerts will then be generated and sent to PagerDuty.

⁠Main Components

PagerDuty Alert: A PagerDuty alert will be generated when a public port is found that is not listed in the OK_PORTS environment varbiable. (See Installation and Usage section)

AWS SES Email: An SES (simple email service) email is generated and sent to AWS account owners with the cloudmapper audit findings. These findings contain the public port information as well as AWS account specific information (resource counts, audit findings, etc.). This feature is disabled by default and requires AWS SES setup to function properly.

⁠Installation and Usage

WARNING: This project is NOT a Python package, this is a Docker image which contains cloudmapper code from duo-labs⁠ as well as custom python code to support PagerDuty Alerting and AWS SES notifications.

To use the docker image, execute a docker run command on the manheim/manheim-cloudmapper image. Environment varaibles are required for the docker container to execute. The recommended way to set the environment variables is with the --env-file flag.

docker run --env-file <env_file> manheim/manheim-cloudmapper:<tag>

env-file example:

S3_BUCKET=aws-account-us-east-1-cloudmapper
ACCOUNT=aws-account
DATADOG_API_KEY=abc123456
...

Environment Varaibles

NameDescriptionExample
S3_BUCKETAWS S3 bucket name where config.json file for cloudmapper is expected. This json file contains AWS account information for the cloudmapper run.mybucket
ACCOUNTName of AWS account where Cloudmapper will be runningaws-company-prod
DATADOG_API_KEYDatadog API key, for sending metricsabc123...
PD_SERVICE_KEYPagerDuty Service Key (Events V1 integration) for alerting on critical thresholds crossedxyz890...
OK_PORTSA list of acceptable publicly accessible ports in string format80,443
AWS_REGIONAWS Region from which SES will send emailsus-east-1
SES_ENABLEDstring to enable/disable email notification via SES.true
SES_SENDEREmail address of SES sender[email protected]⁠
SES_RECIPIENTEmail address of SES recipient[email protected]⁠

AWS Authentication:
In addition to the environment variables above, the Docker container requires access to the AWS account in which cloudmapper will be run. Any method of boto3 AWS authentication⁠ is supported (environment varaibles, ~/.aws/credentials, ~/.aws/config, etc.)

When using environment varaibles, the following AWS Environment varaibles can be set in the env-file:

AWS_SESSION_TOKEN
AWS_DEFAULT_REGION
AWS_SECRET_ACCESS_KEY
AWS_ACCESS_KEY_ID

The following privilieges are required for the IAM user running cloudmapper:
arn:aws:iam::aws:policy/SecurityAudit
arn:aws:iam::aws:policy/job-function/ViewOnlyAccess

Tag summary

Content type

Image

Digest

Size

541.9 MB

Last updated

over 6 years ago

docker pull manheim/manheim-cloudmapper