Commit 6210a7f
Mark Stemm
Secure beta changes (#41)
* Split sdc into monitor and common
First step towards adding support for sysdig secure in the python sdc
client--splitting existing api into common and monitor-only
halves.
The new terminology is that "sdc" refers to the common code for both
monitor and secure. _SdcCommon is the (private) base class that has
endpoints/methods common to both monitor and secure. SdMonClient is the
class that provides all sysdig monitor capabilities, inheriting from
_SdcCommon. SdSecureClient will implement sysdig secure.
Split all the methods into the two classes as follows based on endpoint:
Common endpoints:
- /api/user/me
- /api/token (and /api/token/<user>/<id>)
- /api/agents/connected
- /api/notificationChannels
- /api/history/timelines
- /api/data
- /api/events
- /api/sysdig
- /api/users
- /api/teams
- /api/user
- /api/agents/config
Monitor-only endpoints:
- /api/data/metrics
- /api/alerts
- /api/notifications
- /data/drilldownDashboardDescriptors.json
- /data/drilldownDashboards
- /ui/dashboards
- /api/groupConfigurations
- /api/agents/falco_rules
Add __init__.py changes so all 3 objects are imported.
Change __checkResponse so it's simply hidden instead of hidden + mangled
with the class name. Allows sharing in inherited classes.
* Add secure methods and tests.
Add methods
SdSecureClient.{get_set}_{user,system}_rules(new-rules-content). Set
actually only works for on-premise deployments. New examples
{get,set}_secure_{user,sytem}_falco_rules.py corespond to the
SdSecureClient methods.
Add new methods SdSecureClient.get_policy_events_{range,duration} to
fetch policy events. The API allows for an initial query based either on
duration or from/to. It returns a context dict containing the current
offset for pagination. That context can be provided to
get_more_policy_events() which increments the offset. The caller should
stop when the number of returned events is 0.
Also add a test script test/test_secure_apis.sh that can be used for
travis, and run that test script in travis. This script depends on a
staging account [email protected]. The API key and customer
id are passed to travis via environment variables.
The test script tests the following:
- Trying to set the system falco rules file. This will fail with a
405 (method not allowed) error, as this account is saas.
- Trying to get the system falco rules file. This is compared to a
known system rules file in test/sample-falco-rules.yaml.
- Trying to set and get the user falco rules file. This uses the date
as part of the rule name to ensure a fresh value is set/read.
- Starting an agent with the python-sdc-testing account and triggering
policy events, while checking for recent policy events. It should
eventually find some policy events.
Also, for consistency's sake switch to external env variables for all
keys--instead of using a mix of embedded and externally provided
environment variables for api keys/access keys, use externally provided
keys everywhere.
* Add methods to manage security policies
Add methods/example programs for limited management of security
policies:
- create default policies from corresponding system falco rules file
- list all policies
- delete all policies
Add tests to use these example programs in conjunction with the system
rules file for the python-sdc-testing staging account.
* Add sphinx docs
Add docs for all SdSecureClient methods. Also update the docs
specification to properly handle both the SdSecureClient and SdMonClient
objects (thanks @philrz!).
I was able to run "make docs" and browse the docs for both
objects. Shared methods for both objects are actually listed twice,
under each object. This seems ok for now as long as they're pulling docs
from a single location.
* Add ability to summarize policy events
Add the ability to summarize policy events by output string. This
removes any likely container information (xxx (id=yyy)) from output
strings, and then sorts by frequency descending.
New option --summarize controls whether to print summary or raw outputs,
and --limit allows you to print only the first <limit> entries.
* Make sure ssl_verify is honored for all methods.
Make sure the instance variable self.ssl_verify, which is set from the
environment variable SDC_SSL_VERIFY, is actually used for any call to
requests.
This is necessary to handle communicating with servers using self-signed
certificates.
* Add programs/methods to manipulate secure policies
Add methods and example programs to manipulate policies, specifically:
- Get a policy
- Add a policy
- Modify a policy
- Delete a policy
The methods all work on json objects so they are dependent on the data
format. But they allow for some scriptability.
* Add missing newline.
Summary output was all being printed on one line.
* Move to monitor/common
Was put under secure as a part of merge.
* call hidden unmangled checkResponse
Part of changes for secure/monitor split.1 parent 9d2bee3 commit 6210a7f
File tree
19 files changed
+1973
-830
lines changed- doc
- examples
- sdcclient
- test
19 files changed
+1973
-830
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
4 | | - | |
| 2 | + | |
| 3 | + | |
5 | 4 | | |
6 | 5 | | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
7 | 9 | | |
8 | 10 | | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
36 | 40 | | |
37 | 41 | | |
38 | 42 | | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
58 | | - | |
59 | | - | |
60 | | - | |
61 | | - | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
62 | 66 | | |
63 | 67 | | |
64 | 68 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
35 | | - | |
| 35 | + | |
36 | 36 | | |
37 | | - | |
| 37 | + | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
| 40 | + | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
| 45 | + | |
| 46 | + | |
45 | 47 | | |
46 | 48 | | |
47 | | - | |
48 | | - | |
| 49 | + | |
| 50 | + | |
49 | 51 | | |
50 | 52 | | |
51 | 53 | | |
52 | | - | |
| 54 | + | |
53 | 55 | | |
54 | 56 | | |
55 | 57 | | |
| |||
58 | 60 | | |
59 | 61 | | |
60 | 62 | | |
61 | | - | |
| 63 | + | |
62 | 64 | | |
63 | 65 | | |
64 | 66 | | |
| |||
68 | 70 | | |
69 | 71 | | |
70 | 72 | | |
71 | | - | |
| 73 | + | |
72 | 74 | | |
73 | 75 | | |
74 | 76 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
21 | 26 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
0 commit comments