{"id":18524545,"url":"https://github.com/stelligent/cfn-nag-service","last_synced_at":"2025-08-08T17:22:55.062Z","repository":{"id":40525009,"uuid":"190651284","full_name":"stelligent/cfn-nag-service","owner":"stelligent","description":"Exposes cfn-nag as a service through a Lambda/APIGW or Docker image","archived":false,"fork":false,"pushed_at":"2023-03-16T02:38:45.000Z","size":61,"stargazers_count":3,"open_issues_count":18,"forks_count":1,"subscribers_count":5,"default_branch":"master","last_synced_at":"2025-03-24T05:34:43.458Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/stelligent.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-06-06T21:20:36.000Z","updated_at":"2024-01-23T10:37:02.000Z","dependencies_parsed_at":"2024-11-06T17:56:55.785Z","dependency_job_id":null,"html_url":"https://github.com/stelligent/cfn-nag-service","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stelligent%2Fcfn-nag-service","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stelligent%2Fcfn-nag-service/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stelligent%2Fcfn-nag-service/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stelligent%2Fcfn-nag-service/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/stelligent","download_url":"https://codeload.github.com/stelligent/cfn-nag-service/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248040088,"owners_count":21037813,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-06T17:42:22.555Z","updated_at":"2025-04-09T12:30:52.818Z","avatar_url":"https://github.com/stelligent.png","language":"Ruby","funding_links":[],"categories":[],"sub_categories":[],"readme":"## CfnNagService\n\nThis repository contains the automation code required to deploy https://github.com/stelligent/cfn_nag as either an API Gateway endpoint\nor as a Docker container.\n\n### Endpoints\n\nEach request expects a CloudFormation template in either JSON or YAML.\n\n#### /scan\n\nThis endpoint returns a similar response that you would see if you just ran `cfn_nag` from the command line.\n\nResponse example:\n\n```\n{\n    \"failure_count\": 1,\n    \"violations\": [\n        {\n            \"id\": \"W35\",\n            \"type\": \"WARN\",\n            \"message\": \"S3 Bucket should have access logging configured\",\n            \"logical_resource_ids\": [\n                \"S3Bucket\"\n            ],\n            \"line_numbers\": [\n                5\n            ]\n        },\n        {\n            \"id\": \"F14\",\n            \"type\": \"FAIL\",\n            \"message\": \"S3 Bucket should not have a public read-write acl\",\n            \"logical_resource_ids\": [\n                \"S3Bucket\"\n            ],\n            \"line_numbers\": [\n                5\n            ]\n        }\n    ]\n}\n```\n\n#### /signed_scan\n\nThis endpoint will provide a digital signature so you can verify the authenticity of the results. \n\nResponse example:\n\n```\n{\n    \"results\": {\n        \"failure_count\": 1,\n        \"violations\": [\n            {\n                \"id\": \"W35\",\n                \"type\": \"WARN\",\n                \"message\": \"S3 Bucket should have access logging configured\",\n                \"logical_resource_ids\": [\n                    \"S3Bucket\"\n                ],\n                \"line_numbers\": [\n                    5\n                ]\n            },\n            {\n                \"id\": \"F14\",\n                \"type\": \"FAIL\",\n                \"message\": \"S3 Bucket should not have a public read-write acl\",\n                \"logical_resource_ids\": [\n                    \"S3Bucket\"\n                ],\n                \"line_numbers\": [\n                    5\n                ]\n            }\n        ]\n    },\n    \"encoded_results\": \"FGSDFSDFW.....\",\n    \"signature\": \"eKlzShFty5tCC/zXo3Cf7L0E0yCxdXejS7dAYauBc2s9eBoCfs9Lmd2AQcGR\\nEwrSUzr43s+bUjqy/5Sum1JcCQ==\\n\"\n}\n```\n\nThe encoded_results are strict Base64 encoded of the original template body, the results/violations and the list of rules applied.\nWhen verifying the payload, verify the signature of the encoded_results as Base64 (i.e. don't decode the encoded_results\nbefore verifying)\n\n#### /status\n\nThis endpoint just provides a 200 HTTP response and a simple message to let you know the endpoint is up.\n\n#### Variations Between Lambda/Docker\n\nThe API exposed by the Docker endpoint is cfn_nag/v1/*\n\n### Verifying Signatures\n\nWhen using the /signed_scan endpoint you can use the libsodium library to verify the signatures. An example ruby implementation is provided.\n\n```\n$ ./scripts/verify_signature.rb\nEnter Base64 encoded signature:\n2nW3Y/2U/HyLy7KZvyfBgtZfz3spYI6ppYHL4rt0+pu/C7DjC/nLcTrEGiROkoVsV3TBLctgwtruHg502uxuBQ==\nEnter Base64 encoded verification key\n...\nEnter in Base64 encoded results\neyJmYWlsdXJlX2NvdW50IjoxLCJ2aW9sYXRpb25zIjpbeyJpZCI6IlczNSIsInR5cGUiOiJXQVJOIiwibWVzc2FnZSI6IlMzIEJ1Y2tldCBzaG91bGQgaGF2ZSBhY2Nlc3MgbG9nZ2luZyBjb25maWd1cmVkIiwibG9naWNhbF9yZXNvdXJjZV9pZHMiOlsiUzNCdWNrZXQiXSwibGluZV9udW1iZXJzIjpbNV19LHsiaWQiOiJGMTQiLCJ0eXBlIjoiRkFJTCIsIm1lc3NhZ2UiOiJTMyBCdWNrZXQgc2hvdWxkIG5vdCBoYXZlIGEgcHVibGljIHJlYWQtd3JpdGUgYWNsIiwibG9naWNhbF9yZXNvdXJjZV9pZHMiOlsiUzNCdWNrZXQiXSwibGluZV9udW1iZXJzIjpbNV19XX0=\nSignature is valid!\n```\n\n### Deployment\n\nTo deploy the Lambda, run `scripts/deploy_sam.sh` and consult the outputs for the endpoints\n\nTo deploy the Docker container locally:\n\ndocker build .\ndocker run -p 4567:4567 -e 'private_key_override=...base64 signing_key...' -e use_https=self ...image_id...\n\nThen hit https://localhost:4567/cfn_nag/v1/status\n\n### HTTPS\nThe docker image observes env var use_https to determine whether to enable SSL.\n\nnone means http\nself means https with a self-signed cert generated by the web container\ncert means a certificate of your own choosing that you must generate and map it.  for example:\n-e use_https=cert -e cert_public_path=/certs/cert.pem -e cert_private_path=/certs/key.pem -v ~/certs:/certs\n\n#### Testing - Under development\n\n```\nfile=~/git/cfn_nag/spec/test_templates/json/elasticsearch/elasticsearch_domain_with_explicit_name.json\ncurl -d \"{\\\"template_body\\\": \\\"`base64 $file`\\\"}\" -H \"Content-Type: application/json\" -X POST https://ycabffgus6.execute-api.us-east-1.amazonaws.com/Prod/scan/\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstelligent%2Fcfn-nag-service","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fstelligent%2Fcfn-nag-service","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstelligent%2Fcfn-nag-service/lists"}