Repository navigation
chore: trigger release rebuild - #2165
Conversation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Dependency Review✅ No vulnerabilities or license issues found.Scanned FilesNone |
📝 WalkthroughWalkthroughDocumentation comment for the Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Suggested labels
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2165 +/- ##
==========================================
- Coverage 77.18% 77.16% -0.02%
==========================================
Files 951 951
Lines 90375 90375
==========================================
- Hits 69755 69740 -15
- Misses 16540 16554 +14
- Partials 4080 4081 +1
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
These changes were released in v1.209.0. |
|
These changes were released in v1.210.0-test.8. |
|
These changes were released in v1.210.0-test.10. |
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…ediation (#2282) * updates * updates * Implement AI security & compliance commands with AWS Security Hub integration Add `atmos ai security` and `atmos ai compliance` CLI commands with full AWS Security Hub integration, dual-path finding-to-component mapping (tag-based and heuristic), and multi-format report rendering (markdown/json/yaml/csv). Phase 1: Schema, CLI commands, report renderers, sentinel errors. Phase 2: AWS SDK clients (Security Hub, Resource Groups Tagging API), paginated finding fetcher with filters, batch tag-based mapping (Path A), naming convention and resource type heuristics (Path B), unit tests. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Register security AI tools: list_findings, describe_finding, compliance_report Phase 3: Register three new AI tools for the agent to use: - atmos_list_findings: Query Security Hub findings with severity/source/stack filters - atmos_describe_finding: Get detailed info about a specific finding by ID - atmos_compliance_report: Generate compliance posture reports for CIS/PCI/SOC2/HIPAA/NIST Tools are registered as read-only core tools in the AI tool registry, available in both chat and MCP modes. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Phase 4: Add caching, docs, tests, and multi-provider PRD update - Add findings cache with configurable TTL to reduce AWS API calls - Add report renderer tests (17 tests covering all formats) - Add Docusaurus docs for atmos ai security and compliance commands - Increase test coverage from 71% to 91% - Update PRD to support all 7 Atmos AI providers (not just Bedrock) - Position Bedrock for enterprise customers needing data residency Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Add AI-powered finding analysis with multi-provider support - Implement FindingAnalyzer that sends findings + component source to configured AI provider for root cause analysis and remediation - Parse AI response into structured Remediation (root cause, deploy command, risk level) - Integrate analyzer into security command (runs unless --no-ai is set) - Add ErrAISecurityAnalysisFailed sentinel error - Tests for analyzer, prompt building, response parsing (91.8% coverage) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Add atmos_analyze_finding AI tool for deep finding analysis - Register atmos_analyze_finding tool in AI tool system - Fetches finding by ID, maps to component, runs AI analysis - Returns root cause, remediation, deploy command, and risk level - Accepts optional component_source and stack_config for richer context Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Refactor security/compliance from atmos ai to atmos aws namespace Move security and compliance commands from `atmos ai` to `atmos aws` since they are AWS-specific and work without AI. AI analysis is now opt-in via the `--ai` flag (default: off) instead of opt-out via `--no-ai`. Key changes: - Move cmd/ai/security.go → cmd/aws/security.go - Move cmd/ai/compliance.go → cmd/aws/compliance.go - Move pkg/ai/security/ → pkg/aws/security/ - Move schema from ai.security → aws.security (AWSSecuritySettings) - Flip --no-ai flag to --ai (opt-in, default false) - Use error builder pattern for all error handling - Replace errors.Join with fmt.Errorf for order preservation - Add tests for parseOutputFormat, parseSource, parseSeverities, etc. - Add Docusaurus docs under cli/commands/aws/ and cli/configuration/aws/ - Update PRD to v0.3 with aws namespace and --ai flag - Update depguard to allow AWS SDK in pkg/aws/security/ Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Make --ai a global persistent flag and update PRD with implementation status Move --ai from a command-local flag on `atmos aws security` to a global persistent flag available to all commands. Register via GlobalOptionsBuilder with ATMOS_AI env var support. Update PRD to v0.4 with detailed completion status for all phases. Update global-flags.mdx documentation. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * updates * updates * updates * updates * updates * updates * updates * chore: trigger release rebuild (#2165) Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * updates * updates * fix: AWS security compliance — controls flag, total_controls, credential validation, tests 1. Wire up --controls flag in compliance command — parses comma-separated control IDs, filters report, recalculates score. 2. Fix compliance total_controls — was set to failing count (score always 0%). Now uses DescribeStandardsControls API with graceful fallback. 3. Add AWS credential validation — early STS GetCallerIdentity check before pipeline starts. Clear error with actionable hints. 4. Add 30+ new tests — all testable functions at 100% coverage. Covers: flag parsing, error sentinels, validation, report building, control filtering, shorthand aliases. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: add Atmos Auth identity integration to AWS security commands Add `identity` field to `AWSSecuritySettings` schema and `--identity`/`-i` CLI flag to both `atmos aws security analyze` and `atmos aws compliance report`. When set, credentials are resolved through the Atmos Auth provider chain (SSO → role assumption → isolated credentials), targeting the delegated admin account where Security Hub aggregates all findings. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * test: add coverage for auth context, client cache, and identity field - AWS client cache: newAWSClientCache, WithAuthContext, empty maps - resolveAuthContext: empty identity (nil), non-empty with no auth config (error) - Schema: identity field read/write, empty default - Coverage: WithAuthContext 100%, resolveAuthContext 73%, pkg/aws/security 90.1% Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: add default region to AWS security config Add `region` field to AWSSecuritySettings for Security Hub aggregation region. Precedence: --region CLI flag > config region > default (us-east-1). Combined with `identity`, users configure once in atmos.yaml: aws: security: identity: "security-readonly" # Which account region: "us-east-2" # Which region No extra flags needed for subsequent queries. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: update PRD config example and flags table with identity and region Add identity and region fields to the main Configuration section example. Add --identity flag to CLI flags table. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: structured remediation schema and AI skill for consistent output Two changes ensuring consistent, reproducible AI analysis across all providers: 1. Formalized Remediation schema — added Steps, References fields, changed StackChanges to string. Every output follows the same structure. 2. Created atmos-aws-security agent skill — embedded as system prompt via go:embed. Instructs AI to use exact section headers that map directly to Remediation struct fields. Parser handles both structured and legacy formats via extractFirstMatch fallback. Refactored for complexity compliance: - parseRemediationResponse uses extractFirstMatch helper (17 → 8 complexity) - parseListItems/extractListItem replace parseNumberedList/parseReferenceList - Named constants for magic numbers New tests: skill prompt embedding, parseListItems (6 cases), structured format parsing, fallback format parsing, JSON round-trip. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: add data pipeline and schema diagram to security PRD Shows the complete flow: AWS APIs → Finding → ComponentMapping → Remediation → Report → ReportRenderer (4 formats). Explains behavior with and without --ai flag, and how the skill prompt ensures consistent AI output. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: render all Remediation schema fields in Markdown and CSV output Markdown now renders: root cause, numbered steps, code changes (diff format), stack changes, deploy command, risk level, and references. Falls back to Description when no structured fields are populated. CSV now includes root_cause, deploy_command, risk_level columns. Refactored for complexity: extracted renderSteps, renderCodeChanges, renderReferences helpers. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: multi-turn tool-aware AI analysis for security findings API providers now use SendMessageWithSystemPromptAndTools with the full Atmos tool registry. The AI can call atmos_describe_component, read_component_file, read_stack_file, etc. to gather context before generating remediation. Tool loop runs up to 10 iterations. CLI providers automatically fall back to single-prompt mode when SendMessageWithSystemPromptAndTools returns ErrCLIProviderToolsNotSupported. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: add aws-security-compliance example Minimal example showing atmos aws security analyze and compliance report configuration with Atmos Auth, tag mapping, and optional AI remediation. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: add identity and region to AWS security website docs Updated 3 files: - cli/configuration/aws/security.mdx: identity and region in Quick Start, Full Configuration, and Settings Reference - cli/commands/aws/security/analyze.mdx: --identity flag, updated config example - cli/commands/aws/compliance/report.mdx: --identity flag, updated config example Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: add blog post and roadmap for AWS security & compliance Blog post covers: finding analysis, code mapping, AI remediation, compliance reports, auth integration, output formats. Roadmap: 5 shipped milestones added to aws-security initiative (84% progress). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: remove duplicate ai flag registration causing panic registerAIFlags was called twice in NewGlobalOptionsBuilder — once at line 41 and again at line 44 (copy-paste error). Both ai and skill flags were registered twice, causing a panic on startup. Removed the first duplicate call, keeping the single registration in its logical position after performance flags. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: render security/compliance Markdown output with colors When format is Markdown and output is stdout, pipe through ui.Markdown() for themed rendering with colors. File output remains raw Markdown. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: use configured tag names in unmapped findings message, colored Markdown - Unmapped findings message now uses tag names from aws.security.tag_mapping config instead of hardcoded "atmos:*" - Markdown output to stdout rendered with colors via ui.Markdown() - File output remains raw Markdown Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add Mapped By field, lower naming convention confidence to low - Add "Mapped By" field to Markdown output showing how the mapping was determined (tag, naming-convention, resource-type) - Lower naming convention confidence from medium to low — the heuristic of taking the last hyphen-separated segment as the component name is unreliable for multi-word components (e.g., "origin" from "example-static-app-origin") - Note: 0 exact (tag-based) mappings suggests the tag API is queried in the wrong account (security account vs resource account). This is a known limitation to fix in a follow-up. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: update PRD with production testing findings and known limitations Items 27-31: colored output, Mapped By field, configurable tag names, naming convention confidence fix, duplicate flag fix. Known limitations from InSpatial production testing: - Cross-account tag lookup (0 exact matches) - Naming convention unreliable for multi-word components - --ai flag not working from security command context Updated remaining work with specific fixes needed. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: extract resource tags from Security Hub findings, show in reports Security Hub ASFF findings include Resources[].Tags with all resource tags. This eliminates the need for cross-account Tagging API calls. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: context tags mapping strategy for reliable component extraction New heuristic (confidence: high, method: "context-tags") that uses Cloud Posse context tags (Namespace, Tenant, Environment, Stage, Name) to reconstruct the naming prefix and extract the component name. Example: Name=ins-plat-use2-dev-example-static-app-origin with context tags → component=example-static-app-origin, stack=plat-use2-dev. Mapping priority: finding-tag (exact) → tag-api (exact) → context-tags (high) → naming-convention (low) → resource-type (low). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: account mapping, ECR repo extraction, duplicate grouping 1. Account-level findings (AWS::::Account:ID) map to account names via configurable account_map in aws.security config. 2. ECR repository findings extract repo/image name as component. 3. Duplicate findings (same title) grouped in Markdown output with affected resources table instead of repeated entries. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: show tags in grouped findings, add Mapped By column Grouped findings now show: - Mapped By column in the resource table - Collapsible Resource Tags section (<details>) for findings with tags - AI analysis only processes mapped findings (unmapped skipped) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: add --no-group flag to disable finding grouping By default, duplicate findings (same title) are grouped in Markdown output. Use --no-group to show each finding individually with full details and tags — useful for AI pipelines and detailed analysis. Usage: atmos aws security analyze --no-group atmos aws security analyze --no-group --format json --file findings.json Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: add --no-group flag, account_map to example and website docs - Example: add account_map, --no-group usage - Security analyze docs: add --no-group flag, account_map in config - Security config reference: add account_map to settings and config example Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: exclude display-only fields from JSON/YAML output TagMapping and GroupFindings are display-only settings used by the Markdown renderer. Changed to json:"-" yaml:"-" to prevent leaking. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: filter by stack/component AFTER mapping, not at AWS API level Security Hub has no concept of Atmos stacks. The --stack and --component flags now filter findings after mapping via tags or heuristics. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: increase default max-findings from 50 to 500 50 was too low for multi-account orgs — with post-mapping filtering, we need to fetch enough findings to cover all accounts before filtering by stack/component. AI cost is controlled separately (only mapped findings are sent to AI). Users can still override with --max-findings. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: ECR repo mapper resolves stack from account map ECR findings had empty stack because mapByECRRepo only extracted the component name. Now uses the account_map to resolve the finding's account ID to an account/stack name. Before: component=monitor-nats, stack="" (395 findings) After: component=monitor-nats, stack="core-artifacts" Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: resource-type mapper resolves stack from account map Same fix as ECR repo mapper — use account_map to set the stack name from the finding's account ID. Fixes the last empty-stack finding (AwsEc2Instance in core-auto). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: always show message when no findings match filters Previously the "no findings" message only showed for Markdown format. Now shows for all formats (JSON, YAML, CSV) so the user knows no report was written. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: use ui.Info/Success/Warning instead of hardcoded icons Replace all hardcoded emoji icons (🔍, ✅, 🗺️, 🤖, 📊) with the ui layer functions that handle theming automatically: - ui.Info() for status messages - ui.Success() for completion messages - ui.Warning() for warnings - ui.Successf()/ui.Infof() for formatted messages Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: update PRD with production testing results and mapping accuracy Items 40-42: max-findings 500, account map for ECR/resource-type, themed UI. Production results: 97.2% mapping accuracy (486/500), 5 mapping methods, stack/component filtering verified across multiple stacks. Replaced Known Limitations with Production Testing Results table showing exact counts per method and verified filter scenarios. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: AI analysis improvements — dedup, retry, color fix, docs - Deduplicate findings before AI analysis: same title+component+stack share remediation (4 identical findings → 1 API call) - Retry with exponential backoff on transient AI errors (529/429/5xx) using pkg/retry: 3 attempts, 2s initial delay, 15s max, 30% jitter - Increase default timeout to 300s when --ai is used (multi-turn tool analysis with retries needs more time) - Fix glamour color profile: add explicit WithColorProfile to renderMarkdown() for consistent colored output - Update PRD to v0.8 with items 43-47 and production AI test results - Update blog post and example README with full AI analysis showcase (findings breakdown, anomaly detection, remediation, risk assessment) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: broken links to eks update-kubeconfig command Fix 3 broken links pointing to /cli/commands/aws/eks-update-kubeconfig (flat path) → /cli/commands/aws/eks/update-kubeconfig (correct nested path). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: compliance report framework filter, control counting, and table - Fix framework filter: use PREFIX with full standard ID paths including type prefix (ruleset/ or standards/) since CONTAINS is not supported - Replace deprecated DescribeStandardsControls with ListSecurityControlDefinitions (works in delegated admin mode) - Remove empty Component/Remediation columns from compliance table - Extract repeated framework name strings to constants (linter fix) - Add compliance report examples (with and without --ai) to docs Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: docs consistency — max_findings default, source values, severity format - Fix max_findings default from 50 to 500 in config docs and example YAML - Add missing source values (macie, access-analyzer, all) to analyze docs - Clarify severity is case-insensitive with default critical,high - Fix PRD tag names from underscores to colons (atmos:stack, atmos:component) - Simplify PRD to v1.0 (problem/solution/implementation/results structure) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add language tag to unlabeled code fence in agent skill Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * [autofix.ci] apply automated fixes * fix: address CodeRabbit review — compliance dedup, cache safety, global flags - Fix compliance dedup: use SecurityControlID (e.g., EC2.18) instead of ComplianceStandard (framework ID) as dedup key - Fix cache key: add Framework, Stack, Component; add nil guard - Fix cache safety: copy slices on get/set to prevent mutation - Fix global flags: parse BasePath in security and compliance commands - Fix --framework flag: wire into QueryOptions for security analyze - Fix CSV flush: check cw.Error() after Flush() in both renderers - Fix auth region fallback: check authContext.Region before us-east-1 - Fix resolveAuthContext: nil guard, Profile validation, extract helper - Fix INFORMATIONAL: include in summary table severity loops - Fix Bedrock PRD: qualify data residency and compliance claims - Fix PRD: strategy count 5→7, tag names use colons - Fix roadmap: add pr:2282 to milestones, remove duplicate entries - Fix CLI markdown: use $ prompt style per convention - Document --ai flag for compliance report with examples - Improve tests: table-driven auth, assert element contents, tool calls - Update compliance examples with 35/42 (83%) production results Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: CodeRabbit review round 2 — coverage, global flags, rendering fixes - Fix global config flags: pass Config, ConfigPath, Profile to InitCliConfig (not just BasePath) in both security and compliance commands - Fix resolveAuthContext: check empty identity before nil config - Fix AI analyzer warning: show visible ui.Warning instead of silent debug log - Fix reportTarget: handle component-only case ("All Stacks / vpc") - Fix grouped markdown: render remediation for grouped findings - Fix NIST description: "NIST 800-53" not "NIST CSF" in compliance docs - Improve test coverage: 45 new tests across credentials, renderer, fetcher, and mapper — pkg/aws/security/ coverage 85.5% → 91.8% Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * test: consolidate reportTarget component-only case into table-driven test Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * updates * refactor: move security/compliance to subpackages, inline auth, Organizations API Code organization: - Move cmd/aws/security.go → cmd/aws/security/ subpackage (EKS/ECR pattern) - Move cmd/aws/compliance.go → cmd/aws/compliance/ subpackage - Delete cmd/aws/credentials.go — inline auth directly in each command - Delete cmd/aws/common/ — no shared cmd-level packages needed - Move skill_prompt.md → pkg/aws/security/markdown/ - Move ParseOutputFormat to pkg/aws/security/types.go (next to OutputFormat type) Authentication: - Inline authenticateAndResolveAWS() in each command — calls auth.CreateAndAuthenticateManagerWithAtmosConfig() directly, reads AuthContext.AWS (same pattern as S3 backend) - Move ValidateAWSCredentials to pkg/aws/identity/identity.go (next to GetCallerIdentity) - Use narrow stackInfoProvider interface for extractAWSAuthContext AWS Organizations API: - Add OrganizationsAPI interface and client for account name lookup - resolveAccountName checks config account_map first (no API call), then falls back to DescribeAccount API, caches results - Update example atmos.yaml and config docs — account_map is now optional Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: CodeRabbit review — ErrorIs, context threading, perf.Track, tests - Use require.ErrorIs instead of assert.True(errors.Is(...)) in types_test - Thread context.Context through resolveAccountName → lookupAccountName and all caller methods (mapByAccountID, mapByECRRepo, mapByResourceType) - Add perf.Track to MapFinding public method - Strengthen Args test to actually invoke Args() validator - Add analyzer tests: direct tool call loop, error path, CLI fallback, nil tool result handling Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: friendly errors for missing AWS services, reduce example README - Add wrapAWSServiceError() that detects Security Hub not enabled, access denied, and connection errors — provides actionable hints instead of raw AWS SDK error messages - Add ValidateAWSCredentials tests via mockable getCallerIdentityFn - Reduce example README from 302 to 119 lines — condensed output examples while keeping all 4 scenarios - Add wrapAWSServiceError tests for all error patterns Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: rename ErrAISecurity → ErrAWSSecurity, remove AWS from error message Address Erik's review: - Remove "AWS" from ErrAWSSecurityNotEnabled message text - Rename all ErrAISecurity* → ErrAWSSecurity* error sentinels (45 refs across 14 files) since these are AWS-specific errors Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Summary
Test plan
test.ymlworkflow runs on mergeSummary by CodeRabbit