Skip to content

Commit

Permalink
DMZ Tagging: Support multiple tags, move to panther_config
Browse files Browse the repository at this point in the history
  • Loading branch information
jof committed Dec 12, 2023
1 parent 2f53632 commit ff915d0
Show file tree
Hide file tree
Showing 4 changed files with 32 additions and 9 deletions.
13 changes: 6 additions & 7 deletions global_helpers/panther_base_helpers.py
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
from functools import reduce
from ipaddress import ip_address, ip_network
from typing import Any, List, Optional, Sequence, Union
from panther_config import config

# # # # # # # # # # # # # #
# Exceptions #
Expand Down Expand Up @@ -59,23 +60,21 @@ def is_dmz_cidr(ip_range):
return any(ip_network(ip_range).overlaps(dmz_network) for dmz_network in DMZ_NETWORKS)


DMZ_TAG_KEY = "environment"
DMZ_TAG_VALUE = "dmz"


# Defaults to False to assume something is not a DMZ if it is not tagged
def is_dmz_tags(resource):
def is_dmz_tags(resource, dmz_tags):
"""This function determines whether a given resource is tagged as existing in a DMZ."""
if resource["Tags"] is None:
return False
return resource["Tags"].get(DMZ_TAG_KEY) == DMZ_TAG_VALUE
for key, value in dmz_tags:
if resource["Tags"].get(key) == value:
return True
return False


# Function variables here so that implementation details of these functions can be changed without
# having to rename the function in all locations its used, or having an outdated name on the actual
# function being used, etc.
IN_PCI_SCOPE = in_pci_scope_tags
IS_DMZ = is_dmz_tags

# # # # # # # # # # # # # #
# GSuite Helpers #
Expand Down
7 changes: 7 additions & 0 deletions global_helpers/panther_config_defaults.py
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,10 @@
MS_EXCHANGE_ALLOWED_FORWARDING_DESTINATION_DOMAINS = ORGANIZATION_DOMAINS
MS_EXCHANGE_ALLOWED_FORWARDING_DESTINATION_EMAILS = ["postmaster@" + ORGANIZATION_DOMAINS[0]]
TELEPORT_ORGANIZATION_DOMAINS = ORGANIZATION_DOMAINS

# Key/value pairs of tags used to denote resources that are intentionally exposed
DMZ_TAGS = set(
[
("environment", "dmz"),
]
)
Original file line number Diff line number Diff line change
@@ -1,6 +1,11 @@
import json
from ipaddress import ip_network
from unittest.mock import MagicMock

from panther_base_helpers import IS_DMZ
from panther_base_helpers import is_dmz_tags
from panther_config import config

DMZ_TAGS = config.DMZ_TAGS


def policy(resource):
Expand All @@ -9,7 +14,10 @@ def policy(resource):
return True

# DMZ security groups can have inbound permissions from the internet
if IS_DMZ(resource):
global DMZ_TAGS
if isinstance(DMZ_TAGS, MagicMock):
DMZ_TAGS = set([tuple(kv) for kv in json.loads(DMZ_TAGS())])
if is_dmz_tags(resource, DMZ_TAGS):
return True

for permission in resource["IpPermissions"]:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@ Tests:
-
Name: DMZ Security Group Does Allows Public Access
ExpectedResult: true
Mocks:
- objectName: DMZ_TAGS
returnValue: '[["environment", "dmz"]]'
Resource:
{
"Description": "example VPC security group",
Expand Down Expand Up @@ -88,6 +91,9 @@ Tests:
-
Name: Non DMZ Security Group Allows Public Access
ExpectedResult: false
Mocks:
- objectName: DMZ_TAGS
returnValue: '[["environment", "dmz"]]'
Resource:
{
"Description": "example VPC security group",
Expand Down Expand Up @@ -151,6 +157,9 @@ Tests:
-
Name: Non DMZ Security Group Does Not Allow Public Access
ExpectedResult: true
Mocks:
- objectName: DMZ_TAGS
returnValue: '[["environment", "dmz"]]'
Resource:
{
"Description": "example VPC security group",
Expand Down

0 comments on commit ff915d0

Please sign in to comment.