Built-in scenario

aws/sample_aws_plan.json

Mixed AWS Plan Demo

Analyzed sample_aws_plan.json with 23 normalized resources and 9 trust boundaries.

Analyze another plan

Active findings

15

Analysis gaps

0

Trust boundaries

9

Resources

23

Observations

0
High 4
Medium 10
Low 1

Analysis coverage

Audit trail for this run

Terraform resources 24
Unsupported 1
Enabled rules 104
Unresolved refs 0

Sensitive resource labels are assumptions based on resource class. tfSTRIDE does not assess stored data contents from the plan.

Resource coverage

Provider resources considered
24
Normalized resources
23
  • aws_cloudwatch_log_group1

Rule coverage

Registered rules
104
Disabled rules
0
  • aws-public-compute-broad-ingress1
  • aws-public-alb-waf-missing1
  • aws-rds-cloudwatch-log-exports-missing1
  • aws-s3-public-access1
  • aws-workload-kms-vpc-endpoint-missing1
  • aws-workload-s3-vpc-endpoint-missing1
  • aws-vpc-flow-logs-not-configured1
  • aws-database-permissive-ingress1
  • aws-missing-tier-segmentation1
  • aws-iam-wildcard-permissions2
  • aws-iam-privileged-role-assignment1
  • aws-workload-role-sensitive-permissions1
  • aws-role-trust-expansion1
  • aws-role-trust-missing-narrowing1

Analysis gaps

Unassessed operation paths

No operation gaps were reported by the 5 analysis families that ran. This does not establish complete authorization coverage.

Findings

Severity bands

High

4

Database is reachable from overly permissive sources

aws-database-permissive-ingress

aws_db_instance.app is a sensitive data store, but database is not marked directly internet reachable, but its security groups allow internet-origin ingress, and database trusts security groups attached to internet-exposed workloads. That weakens the expected separation between the workload tier and the data tier.

Category
Information Disclosure
Boundary
workload-to-data-store:aws_instance.app->aws_db_instance.app
Resources
aws_db_instance.app, aws_security_group.db
Evidence
  • security group rules: aws_security_group.db ingress tcp 5432 from 0.0.0.0/0 (Postgres from internet); aws_security_group.db ingress tcp 5432 from sg-app-001 (Postgres from public app tier)
  • network path: database is not marked directly internet reachable, but its security groups allow internet-origin ingress; database trusts security groups attached to internet-exposed workloads; aws_security_group.db allows sg-app-001 attached to aws_instance.app, aws_lb.web
  • subnet posture: aws_instance.app sits in public subnet aws_subnet.public_app with an internet route; aws_lb.web sits in public subnet aws_subnet.public_app with an internet route

IAM role has privileged assignment posture

aws-iam-privileged-role-assignment

aws_iam_role.workload has deterministic privileged IAM assignment posture: compute-admin, data-admin, iam-admin, key-admin, privilege-escalation. If this role is attached to a workload or assumable by a control-plane principal, those privileges increase blast radius.

Category
Elevation of Privilege
Boundary
not-applicable
Resources
aws_iam_role.workload, aws_iam_policy.admin_like
Evidence
  • iam role: address=aws_iam_role.workload; type=aws_iam_role; arn=arn:aws:iam::111122223333:role/workload-role; identifier=workload-role
  • privileged access: grant_1=categories=[data-admin, key-admin, privilege-escalation]; scope=account; confidence=high; grant_2=categories=[compute-admin, iam-admin]; scope=account; confidence=high
  • privilege categories: compute-admin; data-admin; iam-admin; key-admin; privilege-escalation
  • permission patterns: s3:*; iam:PassRole; sts:AssumeRole; ec2:*; iam:*
  • grant scopes: scope_kind=account; scope_value=*
  • grant confidence: high
  • attached policies: attached_policy_arn=arn:aws:iam::111122223333:policy/admin-like; attached_policy_address=aws_iam_policy.admin_like
  • inline policy sources: inline_policy_name=workload-inline

Private data tier directly trusts the public application tier

aws-missing-tier-segmentation

aws_db_instance.app accepts traffic from security groups attached to internet-facing workloads. A compromise of the public tier can therefore move laterally into the private data tier.

Category
Tampering
Boundary
workload-to-data-store:aws_instance.app->aws_db_instance.app
Resources
aws_db_instance.app, aws_instance.app, aws_lb.web, aws_security_group.db
Evidence
  • security group rules: aws_security_group.db ingress tcp 5432 from sg-app-001 (Postgres from public app tier)
  • network path: aws_security_group.db allows sg-app-001 attached to aws_instance.app, aws_lb.web
  • subnet posture: aws_instance.app sits in public subnet aws_subnet.public_app with an internet route; aws_lb.web sits in public subnet aws_subnet.public_app with an internet route

Workload role carries sensitive permissions

aws-workload-role-sensitive-permissions

aws_lambda_function.processor inherits sensitive privileges from aws_iam_role.workload, including iam:PassRole, kms:Decrypt, s3:*, sts:AssumeRole. If the workload is compromised, those credentials can be reused for privilege escalation, data access, or role chaining.

Category
Elevation of Privilege
Boundary
admin-to-workload-plane:aws_iam_role.workload->aws_lambda_function.processor
Resources
aws_lambda_function.processor, aws_iam_role.workload
Evidence
  • iam actions: iam:PassRole; kms:Decrypt; s3:*; sts:AssumeRole
  • policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]

Medium

10

Cross-account or broad role trust lacks narrowing conditions

aws-role-trust-missing-narrowing

aws_iam_role.workload trusts arn:aws:iam::999988887777:root without supported narrowing conditions such as `sts:ExternalId`, `aws:SourceArn`, or `aws:SourceAccount`. That leaves the assume-role path dependent on the trusted principal match alone.

Category
Elevation of Privilege
Boundary
cross-account-or-role-access:arn:aws:iam::999988887777:root->aws_iam_role.workload
Resources
aws_iam_role.workload
Evidence
  • trust principals: arn:aws:iam::999988887777:root
  • trust scope: principal is foreign account root 999988887777
  • target account resolution: state=resolved; account_id=111122223333; partition=aws; evidence=aws_iam_role.workload.arn = arn:aws:iam::111122223333:role/workload-role
  • trust narrowing: supported narrowing conditions present: false; supported narrowing condition keys: none

IAM policy grants wildcard privileges

aws-iam-wildcard-permissions

aws_iam_role.workload contains allow statements with wildcard actions or resources. That makes the resulting access difficult to reason about and expands blast radius.

Category
Elevation of Privilege
Boundary
not-applicable
Resources
aws_iam_role.workload
Evidence
  • iam actions: ec2:*; iam:*; s3:*
  • iam resources: *
  • policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]; Allow actions=[ec2:*, iam:*] resources=[*]

IAM policy grants wildcard privileges

aws-iam-wildcard-permissions

aws_iam_policy.admin_like contains allow statements with wildcard actions or resources. That makes the resulting access difficult to reason about and expands blast radius.

Category
Elevation of Privilege
Boundary
not-applicable
Resources
aws_iam_policy.admin_like
Evidence
  • iam actions: ec2:*; iam:*
  • iam resources: *
  • policy statements: Allow actions=[ec2:*, iam:*] resources=[*]

Internet-exposed compute service permits overly broad ingress

aws-public-compute-broad-ingress

aws_instance.app is reachable from the internet and at least one attached security group allows administrative access or all ports from 0.0.0.0/0. That broad ingress raises the chance of unauthenticated probing and credential attacks.

Category
Spoofing
Boundary
internet-to-service:internet->aws_instance.app
Resources
aws_instance.app, aws_security_group.app
Evidence
  • security group rules: aws_security_group.app ingress tcp 22 from 0.0.0.0/0 (SSH from internet)
  • public exposure reasons: instance has a public IP path and attached security groups allow internet ingress
  • subnet posture: aws_instance.app sits in public subnet aws_subnet.public_app with an internet route

Object storage is publicly accessible

aws-s3-public-access

aws_s3_bucket.assets appears to be public through ACLs or bucket policy. Public object access is a common source of unintended data disclosure.

Category
Information Disclosure
Boundary
internet-to-service:internet->aws_s3_bucket.assets
Resources
aws_s3_bucket.assets
Evidence
  • public exposure reasons: bucket ACL `public-read` grants public access; bucket policy allows anonymous access

Public Application Load Balancer is not associated with a WAF Web ACL

aws-public-alb-waf-missing

aws_lb.web is an internet-facing Application Load Balancer, but the Terraform plan does not show a deterministic AWS WAFv2 Web ACL association targeting it. Public edge traffic can reach the ALB without a modeled WAF or edge protection policy.

Category
Tampering
Boundary
not-applicable
Resources
aws_lb.web
Evidence
  • target load balancer: address=aws_lb.web; type=aws_lb; arn=arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456; load_balancer_type=application; public_exposure=true; load balancer is internet-facing and attached security groups allow internet ingress
  • waf association coverage: target_resource_arn=arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456; resolved_web_acl_association_count=0; modeled_web_acl_association_count=0

Role trust relationship expands blast radius

aws-role-trust-expansion

aws_iam_role.workload can be assumed by arn:aws:iam::999988887777:root. Broad or foreign-account trust relationships increase the chance that compromise in one identity domain spills into another.

Category
Elevation of Privilege
Boundary
cross-account-or-role-access:arn:aws:iam::999988887777:root->aws_iam_role.workload
Resources
aws_iam_role.workload
Evidence
  • trust principals: arn:aws:iam::999988887777:root
  • target account resolution: state=resolved; account_id=111122223333; partition=aws; evidence=aws_iam_role.workload.arn = arn:aws:iam::111122223333:role/workload-role
  • trust path: trust principal belongs to foreign account 999988887777

VPC Flow Logs are not configured for a modeled VPC

aws-vpc-flow-logs-not-configured

aws_vpc.main does not have a resolved aws_flow_log targeting the VPC in this Terraform plan. Network traffic metadata for incident response, threat hunting, and segmentation review may be unavailable unless Flow Logs are configured elsewhere.

Category
Repudiation
Boundary
not-applicable
Resources
aws_vpc.main
Evidence
  • target vpc: address=aws_vpc.main; type=aws_vpc; identifier=vpc-00000001; cidr_block=10.0.0.0/16
  • flow log coverage: target_vpc_id=vpc-00000001; resolved_vpc_flow_log_count=0; aws_flow_log resources are not modeled

Workload uses KMS without a VPC endpoint

aws-workload-kms-vpc-endpoint-missing

aws_lambda_function.processor runs in VPC `vpc-00000001` and inherits KMS cryptographic key access from aws_iam_role.workload, but the Terraform plan does not show a KMS interface VPC endpoint for that VPC. Calls to the sensitive service may therefore depend on public AWS service endpoints, NAT, or another egress path.

Category
Information Disclosure
Boundary
not-applicable
Resources
aws_lambda_function.processor, aws_iam_role.workload
Evidence
  • target workload: address=aws_lambda_function.processor; type=aws_lambda_function; vpc_id=vpc-00000001; subnet_ids=[subnet-private-001]; security_group_ids=[sg-app-001]
  • sensitive service dependency: service=kms; role=aws_iam_role.workload; actions=[kms:Decrypt]; resources=[*]
  • vpc endpoint coverage: vpc_id=vpc-00000001; service=kms; expected_endpoint_type=interface; vpc_endpoint_coverage=missing
  • policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]

Workload uses S3 without a VPC endpoint

aws-workload-s3-vpc-endpoint-missing

aws_lambda_function.processor runs in VPC `vpc-00000001` and inherits S3 data-plane permissions from aws_iam_role.workload, but the Terraform plan does not show an S3 VPC endpoint for that VPC. S3 access may therefore depend on public AWS service endpoints, NAT, or another egress path; this does not imply the bucket itself is public.

Category
Information Disclosure
Boundary
not-applicable
Resources
aws_lambda_function.processor, aws_iam_role.workload
Evidence
  • target workload: address=aws_lambda_function.processor; type=aws_lambda_function; vpc_id=vpc-00000001; subnet_ids=[subnet-private-001]; security_group_ids=[sg-app-001]
  • sensitive service dependency: service=s3; role=aws_iam_role.workload; actions=[s3:*]; resources=[*]
  • vpc endpoint coverage: vpc_id=vpc-00000001; service=s3; expected_endpoint_type=gateway_or_interface; vpc_endpoint_coverage=missing
  • policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]

Low

1

RDS database does not export engine CloudWatch logs

aws-rds-cloudwatch-log-exports-missing

aws_db_instance.app (engine `postgres`) does not export any of the baseline CloudWatch Logs expected for its engine family (postgresql). Without these log exports the database lacks the basic observability posture needed to investigate errors, slow queries, and audit activity from CloudWatch.

Category
Repudiation
Boundary
not-applicable
Resources
aws_db_instance.app
Evidence
  • target resource: address=aws_db_instance.app; type=aws_db_instance; identifier=db-001; engine=postgres
  • log export posture: enabled_cloudwatch_logs_exports=[]; expected_log_exports=['postgresql']; engine-family baseline log exports are absent

Observations

Controls and mitigating signals

No observations were recorded for this plan.

Trust boundaries

Crossings that drive the model

Source
aws_iam_role.workload
Relationship
admin-to-workload-plane
Destination
aws_lambda_function.processor

Rationale: The workload inherits permissions from the attached identity. This attachment does not establish authority to modify or operate the workload.

Source
arn:aws:iam::999988887777:root
Relationship
cross-account-or-role-access
Destination
aws_iam_role.workload

Rationale: A foreign AWS account can cross into this role's trust boundary.

Source
Internet
Relationship
internet-to-service
Destination
aws_instance.app

Rationale: The resource is directly reachable or intentionally exposed to unauthenticated network clients.

Source
Internet
Relationship
internet-to-service
Destination
aws_lb.web

Rationale: The resource is directly reachable or intentionally exposed to unauthenticated network clients.

Source
Internet
Relationship
internet-to-service
Destination
aws_s3_bucket.assets

Rationale: The resource is directly reachable or intentionally exposed to unauthenticated network clients.

Source
aws_subnet.public_app
Relationship
public-subnet-to-private-subnet
Destination
aws_subnet.private_data

Rationale: VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation.

Source
aws_instance.app
Relationship
workload-to-data-store
Destination
aws_db_instance.app

Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.

Source
aws_lambda_function.processor
Relationship
workload-to-data-store
Destination
aws_db_instance.app

Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.

Source
aws_lambda_function.processor
Relationship
workload-to-data-store
Destination
aws_s3_bucket.assets

Rationale: Application or function workloads cross into a higher-sensitivity data plane when their attached role allows S3 actions such as s3:*.

Raw outputs

Stable contract and markdown

JSON report
{
  "kind": "tfstride-report",
  "version": "1.3",
  "tool": {
    "name": "tfstride",
    "version": "0.5.0"
  },
  "title": "Mixed AWS Plan Demo",
  "analyzed_file": "sample_aws_plan.json",
  "analyzed_path": "sample_aws_plan.json",
  "summary": {
    "normalized_resources": 23,
    "unsupported_resources": 1,
    "trust_boundaries": 9,
    "active_findings": 15,
    "total_findings": 15,
    "suppressed_findings": 0,
    "baselined_findings": 0,
    "severity_counts": {
      "high": 4,
      "medium": 10,
      "low": 1
    }
  },
  "filtering": {
    "total_findings": 15,
    "active_findings": 15,
    "suppressed_findings": 0,
    "baselined_findings": 0,
    "suppressions_path": null,
    "baseline_path": null
  },
  "analysis_coverage": {
    "resources": {
      "total_resources": 24,
      "provider_resources": 24,
      "normalized_resources": 23,
      "unsupported_resources": 1,
      "plan_time_unknown_resources": 0,
      "unsupported_resource_types": {
        "aws_cloudwatch_log_group": 1
      }
    },
    "rules": {
      "registered_rule_count": 104,
      "enabled_rules": [
        "aws-public-compute-broad-ingress",
        "aws-lambda-public-invocation",
        "aws-load-balancer-http-public-listener",
        "aws-load-balancer-listener-tls-certificate-missing",
        "aws-load-balancer-listener-ssl-policy-weak-or-unknown",
        "aws-public-alb-waf-missing",
        "aws-cloudfront-viewer-http-allowed",
        "aws-cloudfront-viewer-tls-policy-weak-or-unknown",
        "aws-cloudfront-access-logging-not-configured",
        "aws-public-cloudfront-waf-missing",
        "aws-api-gateway-cors-permissive",
        "aws-public-api-gateway-waf-missing",
        "aws-api-gateway-public-route-authorization-none",
        "aws-api-gateway-stage-access-logs-missing",
        "aws-cloudtrail-multi-region-disabled",
        "aws-cloudtrail-log-file-validation-disabled",
        "aws-cloudtrail-management-events-disabled",
        "aws-cloudtrail-data-events-not-modeled",
        "aws-cloudtrail-insight-selectors-missing",
        "aws-guardduty-detector-disabled-or-missing",
        "aws-securityhub-account-missing",
        "aws-config-recorder-disabled-or-missing",
        "aws-config-delivery-channel-missing",
        "aws-access-analyzer-not-configured",
        "aws-macie-not-enabled-for-sensitive-storage",
        "aws-rds-storage-encryption-disabled",
        "aws-rds-public-endpoint-enabled",
        "aws-rds-backup-retention-insufficient",
        "aws-rds-deletion-protection-disabled",
        "aws-rds-customer-managed-kms-key-missing",
        "aws-rds-multi-az-disabled",
        "aws-rds-performance-insights-disabled",
        "aws-rds-cloudwatch-log-exports-missing",
        "aws-rds-iam-auth-disabled",
        "aws-dynamodb-customer-managed-kms-key-missing",
        "aws-dynamodb-point-in-time-recovery-disabled-or-unknown",
        "aws-dynamodb-deletion-protection-disabled-or-unknown",
        "aws-s3-public-access",
        "aws-s3-customer-managed-encryption-missing",
        "aws-s3-versioning-disabled",
        "aws-s3-object-lock-retention-missing",
        "aws-s3-lifecycle-noncurrent-retention-insufficient",
        "aws-ecr-image-tag-mutability-enabled",
        "aws-ecr-customer-managed-encryption-missing",
        "aws-ecr-repository-scanning-disabled",
        "aws-workload-image-not-digest-pinned",
        "aws-workload-ecr-mutable-tag",
        "aws-workload-can-modify-image-repository",
        "aws-ecs-sensitive-environment-value-inline",
        "aws-ecs-secret-access-blast-radius",
        "aws-public-ecs-secret-access",
        "aws-public-ecs-secret-tampering",
        "aws-public-ecs-secret-disruption",
        "aws-public-ecs-cloudtrail-disruption",
        "aws-public-ecs-s3-mutation-access",
        "aws-public-ecs-s3-object-disruption",
        "aws-public-ecs-s3-bucket-topology-disruption",
        "aws-public-ecs-dynamodb-mutation-access",
        "aws-public-ecs-dynamodb-item-disruption",
        "aws-public-ecs-dynamodb-table-topology-disruption",
        "aws-public-ecs-dynamodb-read-access",
        "aws-public-ecs-kms-decrypt-access",
        "aws-public-ecs-kms-signing-access",
        "aws-public-ecs-kms-key-disruption",
        "aws-public-ecs-kms-authorization-delegation",
        "aws-public-ecs-messaging-mutation-access",
        "aws-public-ecs-sqs-message-disruption",
        "aws-public-ecs-messaging-topology-disruption",
        "aws-public-ecs-sqs-receive-access",
        "aws-sns-customer-managed-encryption-missing",
        "aws-sqs-customer-managed-encryption-missing",
        "aws-sqs-message-retention-insufficient",
        "aws-sqs-dead-letter-queue-not-configured",
        "aws-secretsmanager-customer-managed-kms-key-missing",
        "aws-secretsmanager-recovery-window-too-short",
        "aws-secretsmanager-rotation-not-configured-or-too-long",
        "aws-kms-key-rotation-disabled-or-unknown",
        "aws-kms-key-deletion-window-too-short",
        "aws-kms-key-policy-lockout-safety-check-bypassed",
        "aws-kms-grant-broad-authorization",
        "aws-workload-secretsmanager-vpc-endpoint-missing",
        "aws-workload-kms-vpc-endpoint-missing",
        "aws-workload-s3-vpc-endpoint-missing",
        "aws-vpc-endpoint-policy-broad-access",
        "aws-vpc-flow-logs-not-configured",
        "aws-vpc-flow-log-traffic-type-incomplete",
        "aws-vpc-flow-log-destination-missing",
        "aws-eks-api-endpoint-public-unrestricted",
        "aws-eks-private-endpoint-not-enabled",
        "aws-eks-secrets-encryption-not-configured",
        "aws-eks-control-plane-logging-incomplete",
        "aws-eks-authentication-mode-weak-or-unknown",
        "aws-eks-vpc-cni-network-policy-not-enabled",
        "aws-database-permissive-ingress",
        "aws-missing-tier-segmentation",
        "aws-sensitive-resource-policy-external-access",
        "aws-service-resource-policy-external-access",
        "aws-iam-wildcard-permissions",
        "aws-iam-privileged-role-assignment",
        "aws-workload-role-sensitive-permissions",
        "aws-private-data-transitive-exposure",
        "aws-control-plane-sensitive-workload-chain",
        "aws-role-trust-expansion",
        "aws-role-trust-missing-narrowing"
      ],
      "disabled_rules": [],
      "severity_overrides": {},
      "finding_counts_by_rule": {
        "aws-public-compute-broad-ingress": 1,
        "aws-lambda-public-invocation": 0,
        "aws-load-balancer-http-public-listener": 0,
        "aws-load-balancer-listener-tls-certificate-missing": 0,
        "aws-load-balancer-listener-ssl-policy-weak-or-unknown": 0,
        "aws-public-alb-waf-missing": 1,
        "aws-cloudfront-viewer-http-allowed": 0,
        "aws-cloudfront-viewer-tls-policy-weak-or-unknown": 0,
        "aws-cloudfront-access-logging-not-configured": 0,
        "aws-public-cloudfront-waf-missing": 0,
        "aws-api-gateway-cors-permissive": 0,
        "aws-public-api-gateway-waf-missing": 0,
        "aws-api-gateway-public-route-authorization-none": 0,
        "aws-api-gateway-stage-access-logs-missing": 0,
        "aws-cloudtrail-multi-region-disabled": 0,
        "aws-cloudtrail-log-file-validation-disabled": 0,
        "aws-cloudtrail-management-events-disabled": 0,
        "aws-cloudtrail-data-events-not-modeled": 0,
        "aws-cloudtrail-insight-selectors-missing": 0,
        "aws-guardduty-detector-disabled-or-missing": 0,
        "aws-securityhub-account-missing": 0,
        "aws-config-recorder-disabled-or-missing": 0,
        "aws-config-delivery-channel-missing": 0,
        "aws-access-analyzer-not-configured": 0,
        "aws-macie-not-enabled-for-sensitive-storage": 0,
        "aws-rds-storage-encryption-disabled": 0,
        "aws-rds-public-endpoint-enabled": 0,
        "aws-rds-backup-retention-insufficient": 0,
        "aws-rds-deletion-protection-disabled": 0,
        "aws-rds-customer-managed-kms-key-missing": 0,
        "aws-rds-multi-az-disabled": 0,
        "aws-rds-performance-insights-disabled": 0,
        "aws-rds-cloudwatch-log-exports-missing": 1,
        "aws-rds-iam-auth-disabled": 0,
        "aws-dynamodb-customer-managed-kms-key-missing": 0,
        "aws-dynamodb-point-in-time-recovery-disabled-or-unknown": 0,
        "aws-dynamodb-deletion-protection-disabled-or-unknown": 0,
        "aws-s3-public-access": 1,
        "aws-s3-customer-managed-encryption-missing": 0,
        "aws-s3-versioning-disabled": 0,
        "aws-s3-object-lock-retention-missing": 0,
        "aws-s3-lifecycle-noncurrent-retention-insufficient": 0,
        "aws-ecr-image-tag-mutability-enabled": 0,
        "aws-ecr-customer-managed-encryption-missing": 0,
        "aws-ecr-repository-scanning-disabled": 0,
        "aws-workload-image-not-digest-pinned": 0,
        "aws-workload-ecr-mutable-tag": 0,
        "aws-workload-can-modify-image-repository": 0,
        "aws-ecs-sensitive-environment-value-inline": 0,
        "aws-ecs-secret-access-blast-radius": 0,
        "aws-public-ecs-secret-access": 0,
        "aws-public-ecs-secret-tampering": 0,
        "aws-public-ecs-secret-disruption": 0,
        "aws-public-ecs-cloudtrail-disruption": 0,
        "aws-public-ecs-s3-mutation-access": 0,
        "aws-public-ecs-s3-object-disruption": 0,
        "aws-public-ecs-s3-bucket-topology-disruption": 0,
        "aws-public-ecs-dynamodb-mutation-access": 0,
        "aws-public-ecs-dynamodb-item-disruption": 0,
        "aws-public-ecs-dynamodb-table-topology-disruption": 0,
        "aws-public-ecs-dynamodb-read-access": 0,
        "aws-public-ecs-kms-decrypt-access": 0,
        "aws-public-ecs-kms-signing-access": 0,
        "aws-public-ecs-kms-key-disruption": 0,
        "aws-public-ecs-kms-authorization-delegation": 0,
        "aws-public-ecs-messaging-mutation-access": 0,
        "aws-public-ecs-sqs-message-disruption": 0,
        "aws-public-ecs-messaging-topology-disruption": 0,
        "aws-public-ecs-sqs-receive-access": 0,
        "aws-sns-customer-managed-encryption-missing": 0,
        "aws-sqs-customer-managed-encryption-missing": 0,
        "aws-sqs-message-retention-insufficient": 0,
        "aws-sqs-dead-letter-queue-not-configured": 0,
        "aws-secretsmanager-customer-managed-kms-key-missing": 0,
        "aws-secretsmanager-recovery-window-too-short": 0,
        "aws-secretsmanager-rotation-not-configured-or-too-long": 0,
        "aws-kms-key-rotation-disabled-or-unknown": 0,
        "aws-kms-key-deletion-window-too-short": 0,
        "aws-kms-key-policy-lockout-safety-check-bypassed": 0,
        "aws-kms-grant-broad-authorization": 0,
        "aws-workload-secretsmanager-vpc-endpoint-missing": 0,
        "aws-workload-kms-vpc-endpoint-missing": 1,
        "aws-workload-s3-vpc-endpoint-missing": 1,
        "aws-vpc-endpoint-policy-broad-access": 0,
        "aws-vpc-flow-logs-not-configured": 1,
        "aws-vpc-flow-log-traffic-type-incomplete": 0,
        "aws-vpc-flow-log-destination-missing": 0,
        "aws-eks-api-endpoint-public-unrestricted": 0,
        "aws-eks-private-endpoint-not-enabled": 0,
        "aws-eks-secrets-encryption-not-configured": 0,
        "aws-eks-control-plane-logging-incomplete": 0,
        "aws-eks-authentication-mode-weak-or-unknown": 0,
        "aws-eks-vpc-cni-network-policy-not-enabled": 0,
        "aws-database-permissive-ingress": 1,
        "aws-missing-tier-segmentation": 1,
        "aws-sensitive-resource-policy-external-access": 0,
        "aws-service-resource-policy-external-access": 0,
        "aws-iam-wildcard-permissions": 2,
        "aws-iam-privileged-role-assignment": 1,
        "aws-workload-role-sensitive-permissions": 1,
        "aws-private-data-transitive-exposure": 0,
        "aws-control-plane-sensitive-workload-chain": 0,
        "aws-role-trust-expansion": 1,
        "aws-role-trust-missing-narrowing": 1
      }
    },
    "references": {
      "unresolved_reference_count": 0,
      "symbolically_resolved_relationships": 0,
      "ambiguous_symbolic_relationships": 0,
      "unresolved_symbolic_relationships": 0,
      "unsupported_symbolic_relationships": 0,
      "unresolved_references": []
    }
  },
  "operation_gaps": {
    "reporting_families": [
      {
        "provider": "aws",
        "name": "ecs_s3_access"
      },
      {
        "provider": "aws",
        "name": "ecs_s3_bucket_topology"
      },
      {
        "provider": "aws",
        "name": "ecs_s3_mutation"
      },
      {
        "provider": "aws",
        "name": "ecs_s3_object_deletion"
      },
      {
        "provider": "aws",
        "name": "ecs_s3_protected_data"
      }
    ],
    "records": []
  },
  "resource_sensitivity": {
    "basis": "resource_class_assumption",
    "data_contents_state": "not_assessed",
    "explanation": "Sensitive resource labels are assumptions based on resource class. tfSTRIDE does not assess stored data contents from the plan."
  },
  "inventory": {
    "provider": "aws",
    "unsupported_resources": [
      "aws_cloudwatch_log_group.processor"
    ],
    "metadata": {
      "primary_account_id": "111122223333",
      "supported_resource_types": [
        "aws_accessanalyzer_analyzer",
        "aws_api_gateway_authorizer",
        "aws_api_gateway_method",
        "aws_api_gateway_rest_api",
        "aws_api_gateway_stage",
        "aws_apigatewayv2_api",
        "aws_apigatewayv2_route",
        "aws_apigatewayv2_stage",
        "aws_caller_identity",
        "aws_cloudfront_distribution",
        "aws_cloudtrail",
        "aws_config_configuration_recorder",
        "aws_config_configuration_recorder_status",
        "aws_config_delivery_channel",
        "aws_db_instance",
        "aws_dynamodb_resource_policy",
        "aws_dynamodb_table",
        "aws_ecr_registry_scanning_configuration",
        "aws_ecr_repository",
        "aws_ecs_cluster",
        "aws_ecs_service",
        "aws_ecs_task_definition",
        "aws_eks_addon",
        "aws_eks_cluster",
        "aws_flow_log",
        "aws_guardduty_detector",
        "aws_iam_instance_profile",
        "aws_iam_openid_connect_provider",
        "aws_iam_policy",
        "aws_iam_role",
        "aws_iam_role_policy",
        "aws_iam_role_policy_attachment",
        "aws_instance",
        "aws_internet_gateway",
        "aws_kms_alias",
        "aws_kms_grant",
        "aws_kms_key",
        "aws_kms_key_policy",
        "aws_lambda_function",
        "aws_lambda_function_url",
        "aws_lambda_permission",
        "aws_lb",
        "aws_lb_listener",
        "aws_lb_listener_rule",
        "aws_lb_target_group",
        "aws_macie2_account",
        "aws_nat_gateway",
        "aws_route_table",
        "aws_route_table_association",
        "aws_s3_bucket",
        "aws_s3_bucket_lifecycle_configuration",
        "aws_s3_bucket_object_lock_configuration",
        "aws_s3_bucket_policy",
        "aws_s3_bucket_public_access_block",
        "aws_s3_bucket_server_side_encryption_configuration",
        "aws_s3_bucket_versioning",
        "aws_secretsmanager_secret",
        "aws_secretsmanager_secret_policy",
        "aws_secretsmanager_secret_rotation",
        "aws_security_group",
        "aws_security_group_rule",
        "aws_securityhub_account",
        "aws_sns_topic",
        "aws_sqs_queue",
        "aws_sqs_queue_redrive_policy",
        "aws_subnet",
        "aws_vpc",
        "aws_vpc_endpoint",
        "aws_wafv2_web_acl",
        "aws_wafv2_web_acl_association"
      ],
      "total_input_resources": 24,
      "provider_resource_count": 24,
      "normalized_resource_count": 23,
      "unsupported_resource_types": {
        "aws_cloudwatch_log_group": 1
      }
    },
    "resources": [
      {
        "address": "aws_db_instance.app",
        "provider": "aws",
        "resource_type": "aws_db_instance",
        "name": "app",
        "category": "data",
        "identifier": "db-001",
        "arn": "arn:aws:rds:us-east-1:111122223333:db:customer-db",
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [
          "sg-db-001"
        ],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "sensitive",
        "metadata": {
          "engine": "postgres",
          "rds_publicly_accessible_state": "disabled",
          "rds_backup_retention_period": 14,
          "rds_deletion_protection_state": "enabled",
          "rds_multi_az_state": "unknown",
          "rds_kms_key_id": "arn:aws:kms:us-east-1:222233334444:key/rds",
          "rds_performance_insights_enabled_state": "unknown",
          "rds_enabled_cloudwatch_logs_exports": [],
          "rds_iam_database_authentication_enabled_state": "unknown",
          "rds_posture_uncertainties": [],
          "db_subnet_group_name": "private-data",
          "publicly_accessible": false,
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "storage_encrypted": true,
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [
            {
              "field": "arn",
              "value": "arn:aws:rds:us-east-1:111122223333:db:customer-db",
              "state": "known"
            }
          ],
          "kms_encryption_dependencies": [
            {
              "dependent_address": "aws_db_instance.app",
              "dependent_resource_type": "aws_db_instance",
              "dependency_source_address": "aws_db_instance.app",
              "dependency_source_type": "aws_db_instance",
              "configuration_path": [
                "kms_key_id"
              ],
              "configured_key_reference": "arn:aws:kms:us-east-1:222233334444:key/rds",
              "reference_provenance": "planned_value",
              "reference_kind": "key_arn",
              "resolution_state": "unresolved",
              "encryption_ownership_state": "customer_managed",
              "candidate_targets": [],
              "key_address": null,
              "key_arn": null,
              "key_id": null,
              "alias_address": null,
              "alias_name": null,
              "alias_arn": null,
              "key_origin": null,
              "multi_region_state": null,
              "posture_uncertainties": [
                "KMS reference arn:aws:kms:us-east-1:222233334444:key/rds does not resolve to a modeled key or alias"
              ]
            }
          ],
          "kms_encryption_dependency_uncertainties": [
            "aws_db_instance.app: KMS reference arn:aws:kms:us-east-1:222233334444:key/rds does not resolve to a modeled key or alias"
          ],
          "public_access_configured": false,
          "internet_ingress": true,
          "internet_ingress_capable": true,
          "internet_ingress_reasons": [
            "aws_security_group.db ingress tcp 5432 from 0.0.0.0/0 (Postgres from internet)"
          ],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_iam_policy.admin_like",
        "provider": "aws",
        "resource_type": "aws_iam_policy",
        "name": "admin_like",
        "category": "iam",
        "identifier": "admin-like",
        "arn": "arn:aws:iam::111122223333:policy/admin-like",
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [
          {
            "effect": "Allow",
            "actions": [
              "ec2:*",
              "iam:*"
            ],
            "resources": [
              "*"
            ],
            "principals": [],
            "principal_entries": [],
            "conditions": []
          }
        ],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "policy_document": {
            "Version": "2012-10-17",
            "Statement": [
              {
                "Effect": "Allow",
                "Action": [
                  "ec2:*",
                  "iam:*"
                ],
                "Resource": "*"
              }
            ]
          },
          "iam_policy_completeness_state": "complete",
          "iam_policy_posture_uncertainties": [],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [
            {
              "field": "arn",
              "value": "arn:aws:iam::111122223333:policy/admin-like",
              "state": "known"
            }
          ],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_iam_role.workload",
        "provider": "aws",
        "resource_type": "aws_iam_role",
        "name": "workload",
        "category": "iam",
        "identifier": "workload-role",
        "arn": "arn:aws:iam::111122223333:role/workload-role",
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [
          {
            "effect": "Allow",
            "actions": [
              "s3:*",
              "kms:Decrypt",
              "iam:PassRole",
              "sts:AssumeRole"
            ],
            "resources": [
              "*"
            ],
            "principals": [],
            "principal_entries": [],
            "conditions": []
          },
          {
            "effect": "Allow",
            "actions": [
              "ec2:*",
              "iam:*"
            ],
            "resources": [
              "*"
            ],
            "principals": [],
            "principal_entries": [],
            "conditions": []
          }
        ],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "assume_role_policy": {
            "Version": "2012-10-17",
            "Statement": [
              {
                "Effect": "Allow",
                "Action": "sts:AssumeRole",
                "Principal": {
                  "Service": "lambda.amazonaws.com"
                }
              },
              {
                "Effect": "Allow",
                "Action": "sts:AssumeRole",
                "Principal": {
                  "AWS": "arn:aws:iam::999988887777:root"
                }
              }
            ]
          },
          "trust_principals": [
            "arn:aws:iam::999988887777:root",
            "lambda.amazonaws.com"
          ],
          "trust_statements": [
            {
              "principals": [
                "lambda.amazonaws.com"
              ],
              "principal_entries": [
                {
                  "kind": "Service",
                  "value": "lambda.amazonaws.com"
                }
              ],
              "narrowing_condition_keys": [],
              "narrowing_conditions": [],
              "has_narrowing_conditions": false
            },
            {
              "principals": [
                "arn:aws:iam::999988887777:root"
              ],
              "principal_entries": [
                {
                  "kind": "AWS",
                  "value": "arn:aws:iam::999988887777:root"
                }
              ],
              "narrowing_condition_keys": [],
              "narrowing_conditions": [],
              "has_narrowing_conditions": false
            }
          ],
          "inline_policy_names": [
            "workload-inline"
          ],
          "iam_policy_completeness_state": "complete",
          "iam_policy_posture_uncertainties": [],
          "iam_permissions_boundary_state": "not_configured",
          "iam_permissions_boundary_uncertainties": [],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [
            {
              "field": "arn",
              "value": "arn:aws:iam::111122223333:role/workload-role",
              "state": "known"
            }
          ],
          "iam_role_policy_inputs": {
            "inline_statement_count": 1,
            "completeness_state": "complete",
            "posture_uncertainties": [],
            "inline_policy_names": [
              "workload-inline"
            ],
            "merged_statements": [
              {
                "effect": "Allow",
                "actions": [
                  "ec2:*",
                  "iam:*"
                ],
                "resources": [
                  "*"
                ],
                "principals": [],
                "principal_entries": [],
                "conditions": []
              }
            ]
          },
          "attached_policy_arns": [
            "arn:aws:iam::111122223333:policy/admin-like"
          ],
          "attached_policy_addresses": [
            "aws_iam_policy.admin_like"
          ],
          "privileged_access_grants": [
            {
              "provider": "aws",
              "principal_type": "role",
              "principal_identifier": "arn:aws:iam::111122223333:role/workload-role",
              "principal_display_name": "aws_iam_role.workload",
              "principal_source_address": "aws_iam_role.workload",
              "scope_kind": "account",
              "scope_value": "*",
              "scope_source_address": null,
              "privilege_categories": [
                "data-admin",
                "key-admin",
                "privilege-escalation"
              ],
              "confidence": "high",
              "assignment_source_address": "aws_iam_role.workload",
              "role_name": "workload-role",
              "role_id": "arn:aws:iam::111122223333:role/workload-role",
              "permission_patterns": [
                "s3:*",
                "iam:PassRole",
                "sts:AssumeRole"
              ],
              "evidence": [
                "action=s3:*",
                "action=kms:Decrypt",
                "action=iam:PassRole",
                "action=sts:AssumeRole",
                "resource=*"
              ],
              "uncertainties": []
            },
            {
              "provider": "aws",
              "principal_type": "role",
              "principal_identifier": "arn:aws:iam::111122223333:role/workload-role",
              "principal_display_name": "aws_iam_role.workload",
              "principal_source_address": "aws_iam_role.workload",
              "scope_kind": "account",
              "scope_value": "*",
              "scope_source_address": null,
              "privilege_categories": [
                "compute-admin",
                "iam-admin"
              ],
              "confidence": "high",
              "assignment_source_address": "aws_iam_role.workload",
              "role_name": "workload-role",
              "role_id": "arn:aws:iam::111122223333:role/workload-role",
              "permission_patterns": [
                "ec2:*",
                "iam:*"
              ],
              "evidence": [
                "action=ec2:*",
                "action=iam:*",
                "resource=*"
              ],
              "uncertainties": []
            }
          ],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_iam_role_policy_attachment.workload_admin_like",
        "provider": "aws",
        "resource_type": "aws_iam_role_policy_attachment",
        "name": "workload_admin_like",
        "category": "iam",
        "identifier": "workload-admin-like",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "role": "workload-role",
          "policy_arn": "arn:aws:iam::111122223333:policy/admin-like",
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_instance.app",
        "provider": "aws",
        "resource_type": "aws_instance",
        "name": "app",
        "category": "compute",
        "identifier": "i-001",
        "arn": "arn:aws:ec2:us-east-1:111122223333:instance/i-001",
        "vpc_id": "vpc-00000001",
        "subnet_ids": [
          "subnet-public-001"
        ],
        "security_group_ids": [
          "sg-app-001"
        ],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": true,
        "public_exposure": true,
        "data_sensitivity": "standard",
        "metadata": {
          "ami": "ami-1234567890",
          "instance_type": "t3.micro",
          "associate_public_ip_address": true,
          "iam_instance_profile": null,
          "tags": {
            "Tier": "app"
          },
          "public_access_reasons": [
            "instance requests an associated public IP address"
          ],
          "public_exposure_reasons": [
            "instance has a public IP path and attached security groups allow internet ingress"
          ],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [
            {
              "field": "arn",
              "value": "arn:aws:ec2:us-east-1:111122223333:instance/i-001",
              "state": "known"
            }
          ],
          "public_access_configured": true,
          "internet_ingress": true,
          "internet_ingress_capable": true,
          "internet_ingress_reasons": [
            "aws_security_group.app ingress tcp 22 from 0.0.0.0/0 (SSH from internet)",
            "aws_security_group.app ingress tcp 8080 from 0.0.0.0/0 (App port from internet)"
          ],
          "in_public_subnet": true,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": true
        }
      },
      {
        "address": "aws_internet_gateway.main",
        "provider": "aws",
        "resource_type": "aws_internet_gateway",
        "name": "main",
        "category": "network",
        "identifier": "igw-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_lambda_function.processor",
        "provider": "aws",
        "resource_type": "aws_lambda_function",
        "name": "processor",
        "category": "compute",
        "identifier": "processor",
        "arn": "arn:aws:lambda:us-east-1:111122223333:function:processor",
        "vpc_id": "vpc-00000001",
        "subnet_ids": [
          "subnet-private-001"
        ],
        "security_group_ids": [
          "sg-app-001"
        ],
        "attached_role_arns": [
          "arn:aws:iam::111122223333:role/workload-role"
        ],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "runtime": "python3.12",
          "handler": "handler.main",
          "vpc_enabled": true,
          "container_image_references": [],
          "container_image_posture_uncertainties": [],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [
            {
              "field": "arn",
              "value": "arn:aws:lambda:us-east-1:111122223333:function:processor",
              "state": "known"
            }
          ],
          "ecr_write_paths": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": true,
          "internet_ingress_capable": true,
          "internet_ingress_reasons": [
            "aws_security_group.app ingress tcp 22 from 0.0.0.0/0 (SSH from internet)",
            "aws_security_group.app ingress tcp 8080 from 0.0.0.0/0 (App port from internet)"
          ],
          "in_public_subnet": false,
          "has_nat_gateway_egress": true,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_lb.web",
        "provider": "aws",
        "resource_type": "aws_lb",
        "name": "web",
        "category": "edge",
        "identifier": "alb-001",
        "arn": "arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456",
        "vpc_id": "vpc-00000001",
        "subnet_ids": [
          "subnet-public-001"
        ],
        "security_group_ids": [
          "sg-app-001"
        ],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": true,
        "public_exposure": true,
        "data_sensitivity": "standard",
        "metadata": {
          "internal": false,
          "load_balancer_type": "application",
          "load_balancer_ip_address_type": "ipv4",
          "network_attachments": {
            "security_groups": [
              "sg-app-001"
            ],
            "security_groups_complete": true,
            "security_group_path": [
              "security_groups"
            ],
            "subnets": [
              "subnet-public-001"
            ],
            "subnets_complete": true,
            "subnet_path": [
              "subnets"
            ]
          },
          "public_access_reasons": [
            "load balancer is configured as internet-facing"
          ],
          "public_exposure_reasons": [
            "load balancer is internet-facing and attached security groups allow internet ingress"
          ],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [
            {
              "field": "arn",
              "value": "arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456",
              "state": "known"
            }
          ],
          "public_access_configured": true,
          "internet_ingress": true,
          "internet_ingress_capable": true,
          "internet_ingress_reasons": [
            "aws_security_group.app ingress tcp 22 from 0.0.0.0/0 (SSH from internet)",
            "aws_security_group.app ingress tcp 8080 from 0.0.0.0/0 (App port from internet)"
          ],
          "in_public_subnet": true,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": true
        }
      },
      {
        "address": "aws_nat_gateway.main",
        "provider": "aws",
        "resource_type": "aws_nat_gateway",
        "name": "main",
        "category": "network",
        "identifier": "nat-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [
          "subnet-public-001"
        ],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "allocation_id": "eipalloc-001",
          "connectivity_type": "public",
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": true,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_route_table.private",
        "provider": "aws",
        "resource_type": "aws_route_table",
        "name": "private",
        "category": "network",
        "identifier": "rtb-private-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "routes": [
            {
              "cidr_block": "0.0.0.0/0",
              "nat_gateway_id": "nat-001"
            }
          ],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_route_table.public",
        "provider": "aws",
        "resource_type": "aws_route_table",
        "name": "public",
        "category": "network",
        "identifier": "rtb-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "routes": [
            {
              "cidr_block": "0.0.0.0/0",
              "gateway_id": "igw-001"
            }
          ],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_route_table_association.private_data",
        "provider": "aws",
        "resource_type": "aws_route_table_association",
        "name": "private_data",
        "category": "network",
        "identifier": "rtassoc-private-001",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "route_table_id": "rtb-private-001",
          "subnet_id": "subnet-private-001",
          "gateway_id": null,
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_route_table_association.public_app",
        "provider": "aws",
        "resource_type": "aws_route_table_association",
        "name": "public_app",
        "category": "network",
        "identifier": "rtassoc-public-001",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "route_table_id": "rtb-001",
          "subnet_id": "subnet-public-001",
          "gateway_id": null,
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_s3_bucket.assets",
        "provider": "aws",
        "resource_type": "aws_s3_bucket",
        "name": "assets",
        "category": "data",
        "identifier": "customer-assets",
        "arn": "arn:aws:s3:::customer-assets",
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [
          {
            "effect": "Allow",
            "actions": [
              "s3:GetObject"
            ],
            "resources": [
              "arn:aws:s3:::customer-assets/*"
            ],
            "principals": [
              "*"
            ],
            "principal_entries": [
              {
                "kind": "unknown",
                "value": "*"
              }
            ],
            "conditions": []
          }
        ],
        "public_access_configured": true,
        "public_exposure": true,
        "data_sensitivity": "sensitive",
        "metadata": {
          "bucket": "customer-assets",
          "acl": "public-read",
          "policy_document": {
            "Version": "2012-10-17",
            "Statement": [
              {
                "Effect": "Allow",
                "Principal": "*",
                "Action": [
                  "s3:GetObject"
                ],
                "Resource": "arn:aws:s3:::customer-assets/*"
              }
            ]
          },
          "s3_bucket_policy_state": "configured",
          "s3_bucket_policy_completeness_state": "complete",
          "s3_bucket_policy_uncertainties": [],
          "public_access_reasons": [
            "bucket ACL `public-read` grants public access",
            "bucket policy allows anonymous access"
          ],
          "public_exposure_reasons": [
            "bucket ACL `public-read` grants public access",
            "bucket policy allows anonymous access"
          ],
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [
            {
              "field": "arn",
              "value": "arn:aws:s3:::customer-assets",
              "state": "known"
            }
          ],
          "kms_encryption_dependencies": [],
          "kms_encryption_dependency_uncertainties": [],
          "public_access_configured": true,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": true
        }
      },
      {
        "address": "aws_security_group.app",
        "provider": "aws",
        "resource_type": "aws_security_group",
        "name": "app",
        "category": "network",
        "identifier": "sg-app-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [
          {
            "direction": "egress",
            "protocol": "-1",
            "from_port": 0,
            "to_port": 0,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": null
          },
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 22,
            "to_port": 22,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": "SSH from internet"
          },
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 8080,
            "to_port": 8080,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": "App port from internet"
          }
        ],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "security_group_traffic_rules": [
            {
              "path": [
                "egress",
                0
              ],
              "rule_direction": "egress",
              "protocol": "all",
              "from_port": 0,
              "to_port": 0,
              "cidr_blocks": [
                "0.0.0.0/0"
              ],
              "ipv6_cidr_blocks": [],
              "security_groups": [],
              "security_group_path": [
                "egress",
                0,
                "security_groups"
              ],
              "self": null,
              "selectors_complete": true
            }
          ],
          "security_group_traffic_rules_known": true,
          "description": "Public application tier",
          "group_name": "app-sg",
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "standalone_rule_addresses": [
            "aws_security_group_rule.app_ssh_from_internet",
            "aws_security_group_rule.app_http_from_internet"
          ],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_security_group.db",
        "provider": "aws",
        "resource_type": "aws_security_group",
        "name": "db",
        "category": "network",
        "identifier": "sg-db-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [
          {
            "direction": "egress",
            "protocol": "-1",
            "from_port": 0,
            "to_port": 0,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": null
          },
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 5432,
            "to_port": 5432,
            "cidr_blocks": [],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [
              "sg-app-001"
            ],
            "description": "Postgres from public app tier"
          },
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 5432,
            "to_port": 5432,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": "Postgres from internet"
          }
        ],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "security_group_traffic_rules": [
            {
              "path": [
                "egress",
                0
              ],
              "rule_direction": "egress",
              "protocol": "all",
              "from_port": 0,
              "to_port": 0,
              "cidr_blocks": [
                "0.0.0.0/0"
              ],
              "ipv6_cidr_blocks": [],
              "security_groups": [],
              "security_group_path": [
                "egress",
                0,
                "security_groups"
              ],
              "self": null,
              "selectors_complete": true
            }
          ],
          "security_group_traffic_rules_known": true,
          "description": "Database tier",
          "group_name": "db-sg",
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "standalone_rule_addresses": [
            "aws_security_group_rule.db_from_public_app",
            "aws_security_group_rule.db_from_internet"
          ],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_security_group_rule.app_http_from_internet",
        "provider": "aws",
        "resource_type": "aws_security_group_rule",
        "name": "app_http_from_internet",
        "category": "network",
        "identifier": "sgrule-app-http-001",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 8080,
            "to_port": 8080,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": "App port from internet"
          }
        ],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "security_group_id": "sg-app-001",
          "security_group_traffic_rules": [
            {
              "path": [],
              "rule_direction": "ingress",
              "protocol": "tcp",
              "from_port": 8080,
              "to_port": 8080,
              "cidr_blocks": [
                "0.0.0.0/0"
              ],
              "ipv6_cidr_blocks": [],
              "security_groups": [],
              "security_group_path": [
                "source_security_group_id"
              ],
              "self": null,
              "selectors_complete": true
            }
          ],
          "security_group_traffic_rules_known": true,
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_security_group_rule.app_ssh_from_internet",
        "provider": "aws",
        "resource_type": "aws_security_group_rule",
        "name": "app_ssh_from_internet",
        "category": "network",
        "identifier": "sgrule-app-ssh-001",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 22,
            "to_port": 22,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": "SSH from internet"
          }
        ],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "security_group_id": "sg-app-001",
          "security_group_traffic_rules": [
            {
              "path": [],
              "rule_direction": "ingress",
              "protocol": "tcp",
              "from_port": 22,
              "to_port": 22,
              "cidr_blocks": [
                "0.0.0.0/0"
              ],
              "ipv6_cidr_blocks": [],
              "security_groups": [],
              "security_group_path": [
                "source_security_group_id"
              ],
              "self": null,
              "selectors_complete": true
            }
          ],
          "security_group_traffic_rules_known": true,
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_security_group_rule.db_from_internet",
        "provider": "aws",
        "resource_type": "aws_security_group_rule",
        "name": "db_from_internet",
        "category": "network",
        "identifier": "sgrule-db-public-001",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 5432,
            "to_port": 5432,
            "cidr_blocks": [
              "0.0.0.0/0"
            ],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [],
            "description": "Postgres from internet"
          }
        ],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "security_group_id": "sg-db-001",
          "security_group_traffic_rules": [
            {
              "path": [],
              "rule_direction": "ingress",
              "protocol": "tcp",
              "from_port": 5432,
              "to_port": 5432,
              "cidr_blocks": [
                "0.0.0.0/0"
              ],
              "ipv6_cidr_blocks": [],
              "security_groups": [],
              "security_group_path": [
                "source_security_group_id"
              ],
              "self": null,
              "selectors_complete": true
            }
          ],
          "security_group_traffic_rules_known": true,
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_security_group_rule.db_from_public_app",
        "provider": "aws",
        "resource_type": "aws_security_group_rule",
        "name": "db_from_public_app",
        "category": "network",
        "identifier": "sgrule-db-app-001",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [
          {
            "direction": "ingress",
            "protocol": "tcp",
            "from_port": 5432,
            "to_port": 5432,
            "cidr_blocks": [],
            "ipv6_cidr_blocks": [],
            "referenced_security_group_ids": [
              "sg-app-001"
            ],
            "description": "Postgres from public app tier"
          }
        ],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "security_group_id": "sg-db-001",
          "security_group_traffic_rules": [
            {
              "path": [],
              "rule_direction": "ingress",
              "protocol": "tcp",
              "from_port": 5432,
              "to_port": 5432,
              "cidr_blocks": [],
              "ipv6_cidr_blocks": [],
              "security_groups": [
                "sg-app-001"
              ],
              "security_group_path": [
                "source_security_group_id"
              ],
              "self": null,
              "selectors_complete": true
            }
          ],
          "security_group_traffic_rules_known": true,
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_subnet.private_data",
        "provider": "aws",
        "resource_type": "aws_subnet",
        "name": "private_data",
        "category": "network",
        "identifier": "subnet-private-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "cidr_block": "10.0.2.0/24",
          "availability_zone": "us-east-1a",
          "map_public_ip_on_launch": false,
          "tags": {
            "Tier": "private"
          },
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "is_public_subnet": false,
          "route_table_ids": [
            "rtb-private-001"
          ],
          "has_public_route": false,
          "has_nat_gateway_egress": true,
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_subnet.public_app",
        "provider": "aws",
        "resource_type": "aws_subnet",
        "name": "public_app",
        "category": "network",
        "identifier": "subnet-public-001",
        "arn": null,
        "vpc_id": "vpc-00000001",
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "cidr_block": "10.0.1.0/24",
          "availability_zone": "us-east-1a",
          "map_public_ip_on_launch": true,
          "tags": {
            "Tier": "public"
          },
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "is_public_subnet": true,
          "route_table_ids": [
            "rtb-001"
          ],
          "has_public_route": true,
          "has_nat_gateway_egress": false,
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "direct_internet_reachable": false
        }
      },
      {
        "address": "aws_vpc.main",
        "provider": "aws",
        "resource_type": "aws_vpc",
        "name": "main",
        "category": "network",
        "identifier": "vpc-00000001",
        "arn": null,
        "vpc_id": null,
        "subnet_ids": [],
        "security_group_ids": [],
        "attached_role_arns": [],
        "network_rules": [],
        "policy_statements": [],
        "public_access_configured": false,
        "public_exposure": false,
        "data_sensitivity": "standard",
        "metadata": {
          "cidr_block": "10.0.0.0/16",
          "tags": {
            "Name": "main"
          },
          "account_identity_source_mode": "managed",
          "account_identity_arn_inputs": [],
          "public_access_reasons": [],
          "public_exposure_reasons": [],
          "public_access_configured": false,
          "internet_ingress": false,
          "internet_ingress_capable": false,
          "internet_ingress_reasons": [],
          "in_public_subnet": false,
          "has_nat_gateway_egress": false,
          "direct_internet_reachable": false
        }
      }
    ]
  },
  "trust_boundaries": [
    {
      "identifier": "admin-to-workload-plane:aws_iam_role.workload->aws_lambda_function.processor",
      "boundary_type": "admin-to-workload-plane",
      "source": "aws_iam_role.workload",
      "target": "aws_lambda_function.processor",
      "description": "aws_lambda_function.processor uses aws_iam_role.workload as its runtime identity.",
      "rationale": "The workload inherits permissions from the attached identity. This attachment does not establish authority to modify or operate the workload."
    },
    {
      "identifier": "cross-account-or-role-access:arn:aws:iam::999988887777:root->aws_iam_role.workload",
      "boundary_type": "cross-account-or-role-access",
      "source": "arn:aws:iam::999988887777:root",
      "target": "aws_iam_role.workload",
      "description": "aws_iam_role.workload trusts arn:aws:iam::999988887777:root.",
      "rationale": "A foreign AWS account can cross into this role's trust boundary."
    },
    {
      "identifier": "internet-to-service:internet->aws_instance.app",
      "boundary_type": "internet-to-service",
      "source": "internet",
      "target": "aws_instance.app",
      "description": "Traffic can cross from the public internet to aws_instance.app.",
      "rationale": "The resource is directly reachable or intentionally exposed to unauthenticated network clients."
    },
    {
      "identifier": "internet-to-service:internet->aws_lb.web",
      "boundary_type": "internet-to-service",
      "source": "internet",
      "target": "aws_lb.web",
      "description": "Traffic can cross from the public internet to aws_lb.web.",
      "rationale": "The resource is directly reachable or intentionally exposed to unauthenticated network clients."
    },
    {
      "identifier": "internet-to-service:internet->aws_s3_bucket.assets",
      "boundary_type": "internet-to-service",
      "source": "internet",
      "target": "aws_s3_bucket.assets",
      "description": "Traffic can cross from the public internet to aws_s3_bucket.assets.",
      "rationale": "The resource is directly reachable or intentionally exposed to unauthenticated network clients."
    },
    {
      "identifier": "public-subnet-to-private-subnet:aws_subnet.public_app->aws_subnet.private_data",
      "boundary_type": "public-subnet-to-private-subnet",
      "source": "aws_subnet.public_app",
      "target": "aws_subnet.private_data",
      "description": "aws_subnet.public_app and aws_subnet.private_data occupy separate trust zones in the same network.",
      "rationale": "VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation."
    },
    {
      "identifier": "workload-to-data-store:aws_instance.app->aws_db_instance.app",
      "boundary_type": "workload-to-data-store",
      "source": "aws_instance.app",
      "target": "aws_db_instance.app",
      "description": "aws_instance.app can interact with aws_db_instance.app.",
      "rationale": "Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group."
    },
    {
      "identifier": "workload-to-data-store:aws_lambda_function.processor->aws_db_instance.app",
      "boundary_type": "workload-to-data-store",
      "source": "aws_lambda_function.processor",
      "target": "aws_db_instance.app",
      "description": "aws_lambda_function.processor can interact with aws_db_instance.app.",
      "rationale": "Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group."
    },
    {
      "identifier": "workload-to-data-store:aws_lambda_function.processor->aws_s3_bucket.assets",
      "boundary_type": "workload-to-data-store",
      "source": "aws_lambda_function.processor",
      "target": "aws_s3_bucket.assets",
      "description": "aws_lambda_function.processor can interact with aws_s3_bucket.assets.",
      "rationale": "Application or function workloads cross into a higher-sensitivity data plane when their attached role allows S3 actions such as s3:*."
    }
  ],
  "findings": [
    {
      "fingerprint": "sha256:301c930adaf56db8305981e5cfc288a207b5e0bd78719293a23dee5898951de1",
      "title": "Database is reachable from overly permissive sources",
      "rule_id": "aws-database-permissive-ingress",
      "category": "Information Disclosure",
      "severity": "high",
      "affected_resources": [
        "aws_db_instance.app",
        "aws_security_group.db"
      ],
      "trust_boundary_id": "workload-to-data-store:aws_instance.app->aws_db_instance.app",
      "rationale": "aws_db_instance.app is a sensitive data store, but database is not marked directly internet reachable, but its security groups allow internet-origin ingress, and database trusts security groups attached to internet-exposed workloads. That weakens the expected separation between the workload tier and the data tier.",
      "recommended_mitigation": "Keep databases off public paths, allow ingress only from narrowly scoped application security groups, and enforce authentication plus encryption independently of network policy.",
      "evidence": [
        {
          "key": "security_group_rules",
          "values": [
            "aws_security_group.db ingress tcp 5432 from 0.0.0.0/0 (Postgres from internet)",
            "aws_security_group.db ingress tcp 5432 from sg-app-001 (Postgres from public app tier)"
          ]
        },
        {
          "key": "network_path",
          "values": [
            "database is not marked directly internet reachable, but its security groups allow internet-origin ingress",
            "database trusts security groups attached to internet-exposed workloads",
            "aws_security_group.db allows sg-app-001 attached to aws_instance.app, aws_lb.web"
          ]
        },
        {
          "key": "subnet_posture",
          "values": [
            "aws_instance.app sits in public subnet aws_subnet.public_app with an internet route",
            "aws_lb.web sits in public subnet aws_subnet.public_app with an internet route"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 2,
        "privilege_breadth": 0,
        "data_sensitivity": 2,
        "lateral_movement": 1,
        "blast_radius": 1,
        "final_score": 6,
        "severity": "high",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:2ef25eba0c55969e963f0d28ec610d7ffb0995e104e83bf9ee974c09085d6920",
      "title": "IAM role has privileged assignment posture",
      "rule_id": "aws-iam-privileged-role-assignment",
      "category": "Elevation of Privilege",
      "severity": "high",
      "affected_resources": [
        "aws_iam_role.workload",
        "aws_iam_policy.admin_like"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_iam_role.workload has deterministic privileged IAM assignment posture: compute-admin, data-admin, iam-admin, key-admin, privilege-escalation. If this role is attached to a workload or assumable by a control-plane principal, those privileges increase blast radius.",
      "recommended_mitigation": "Review high-impact IAM role permissions, split administrative and runtime duties, scope resources to named ARNs, and avoid attaching broad IAM, role-passing, secrets, KMS, data, network, or audit administration permissions to general workload roles.",
      "evidence": [
        {
          "key": "iam_role",
          "values": [
            "address=aws_iam_role.workload",
            "type=aws_iam_role",
            "arn=arn:aws:iam::111122223333:role/workload-role",
            "identifier=workload-role"
          ]
        },
        {
          "key": "privileged_access",
          "values": [
            "grant_1=categories=[data-admin, key-admin, privilege-escalation]; scope=account; confidence=high",
            "grant_2=categories=[compute-admin, iam-admin]; scope=account; confidence=high"
          ]
        },
        {
          "key": "privilege_categories",
          "values": [
            "compute-admin",
            "data-admin",
            "iam-admin",
            "key-admin",
            "privilege-escalation"
          ]
        },
        {
          "key": "permission_patterns",
          "values": [
            "s3:*",
            "iam:PassRole",
            "sts:AssumeRole",
            "ec2:*",
            "iam:*"
          ]
        },
        {
          "key": "grant_scopes",
          "values": [
            "scope_kind=account; scope_value=*"
          ]
        },
        {
          "key": "grant_confidence",
          "values": [
            "high"
          ]
        },
        {
          "key": "attached_policies",
          "values": [
            "attached_policy_arn=arn:aws:iam::111122223333:policy/admin-like",
            "attached_policy_address=aws_iam_policy.admin_like"
          ]
        },
        {
          "key": "inline_policy_sources",
          "values": [
            "inline_policy_name=workload-inline"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 3,
        "data_sensitivity": 2,
        "lateral_movement": 2,
        "blast_radius": 3,
        "final_score": 10,
        "severity": "high",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:ad47040d6b7b6da7d9b260531e6cb85076300aea4f92c3c5e5c06b4b6204e9d0",
      "title": "Private data tier directly trusts the public application tier",
      "rule_id": "aws-missing-tier-segmentation",
      "category": "Tampering",
      "severity": "high",
      "affected_resources": [
        "aws_db_instance.app",
        "aws_instance.app",
        "aws_lb.web",
        "aws_security_group.db"
      ],
      "trust_boundary_id": "workload-to-data-store:aws_instance.app->aws_db_instance.app",
      "rationale": "aws_db_instance.app accepts traffic from security groups attached to internet-facing workloads. A compromise of the public tier can therefore move laterally into the private data tier.",
      "recommended_mitigation": "Introduce tighter tier segmentation with dedicated security groups, narrow ingress to specific services and ports, and keep the data tier reachable only through controlled application paths.",
      "evidence": [
        {
          "key": "security_group_rules",
          "values": [
            "aws_security_group.db ingress tcp 5432 from sg-app-001 (Postgres from public app tier)"
          ]
        },
        {
          "key": "network_path",
          "values": [
            "aws_security_group.db allows sg-app-001 attached to aws_instance.app, aws_lb.web"
          ]
        },
        {
          "key": "subnet_posture",
          "values": [
            "aws_instance.app sits in public subnet aws_subnet.public_app with an internet route",
            "aws_lb.web sits in public subnet aws_subnet.public_app with an internet route"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 2,
        "privilege_breadth": 0,
        "data_sensitivity": 2,
        "lateral_movement": 2,
        "blast_radius": 1,
        "final_score": 7,
        "severity": "high",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:72510a8d78162a2b31898329fe752971dac4b15c29eb560500b80ba698b16120",
      "title": "Workload role carries sensitive permissions",
      "rule_id": "aws-workload-role-sensitive-permissions",
      "category": "Elevation of Privilege",
      "severity": "high",
      "affected_resources": [
        "aws_lambda_function.processor",
        "aws_iam_role.workload"
      ],
      "trust_boundary_id": "admin-to-workload-plane:aws_iam_role.workload->aws_lambda_function.processor",
      "rationale": "aws_lambda_function.processor inherits sensitive privileges from aws_iam_role.workload, including iam:PassRole, kms:Decrypt, s3:*, sts:AssumeRole. If the workload is compromised, those credentials can be reused for privilege escalation, data access, or role chaining.",
      "recommended_mitigation": "Split high-privilege actions into separate roles, scope permissions to named resources, and remove role-passing or cross-role permissions from general application identities.",
      "evidence": [
        {
          "key": "iam_actions",
          "values": [
            "iam:PassRole",
            "kms:Decrypt",
            "s3:*",
            "sts:AssumeRole"
          ]
        },
        {
          "key": "policy_statements",
          "values": [
            "Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 2,
        "data_sensitivity": 1,
        "lateral_movement": 1,
        "blast_radius": 2,
        "final_score": 6,
        "severity": "high",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:5e031c625ec463cffb27faa6d5858fbcbee334a8a56cea29b7fc4028d2fc7c4d",
      "title": "Cross-account or broad role trust lacks narrowing conditions",
      "rule_id": "aws-role-trust-missing-narrowing",
      "category": "Elevation of Privilege",
      "severity": "medium",
      "affected_resources": [
        "aws_iam_role.workload"
      ],
      "trust_boundary_id": "cross-account-or-role-access:arn:aws:iam::999988887777:root->aws_iam_role.workload",
      "rationale": "aws_iam_role.workload trusts arn:aws:iam::999988887777:root without supported narrowing conditions such as `sts:ExternalId`, `aws:SourceArn`, or `aws:SourceAccount`. That leaves the assume-role path dependent on the trusted principal match alone.",
      "recommended_mitigation": "Keep the trusted principal as specific as possible and add supported assume-role conditions such as `ExternalId`, `SourceArn`, `SourceAccount`, `SAML:aud`, or provider-specific OIDC `aud` and `sub` checks when crossing accounts or trusting broad or federated principals.",
      "evidence": [
        {
          "key": "trust_principals",
          "values": [
            "arn:aws:iam::999988887777:root"
          ]
        },
        {
          "key": "trust_scope",
          "values": [
            "principal is foreign account root 999988887777"
          ]
        },
        {
          "key": "target_account_resolution",
          "values": [
            "state=resolved",
            "account_id=111122223333",
            "partition=aws",
            "evidence=aws_iam_role.workload.arn = arn:aws:iam::111122223333:role/workload-role"
          ]
        },
        {
          "key": "trust_narrowing",
          "values": [
            "supported narrowing conditions present: false",
            "supported narrowing condition keys: none"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 2,
        "data_sensitivity": 0,
        "lateral_movement": 1,
        "blast_radius": 2,
        "final_score": 5,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:a4073fcb001c86b6aa113375d6e64b5fa3f4e8e4f75189fd18c31712209d8786",
      "title": "IAM policy grants wildcard privileges",
      "rule_id": "aws-iam-wildcard-permissions",
      "category": "Elevation of Privilege",
      "severity": "medium",
      "affected_resources": [
        "aws_iam_role.workload"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_iam_role.workload contains allow statements with wildcard actions or resources. That makes the resulting access difficult to reason about and expands blast radius.",
      "recommended_mitigation": "Replace wildcard actions and resources with narrowly scoped permissions tied to the exact services, APIs, and ARNs required by the workload.",
      "evidence": [
        {
          "key": "iam_actions",
          "values": [
            "ec2:*",
            "iam:*",
            "s3:*"
          ]
        },
        {
          "key": "iam_resources",
          "values": [
            "*"
          ]
        },
        {
          "key": "policy_statements",
          "values": [
            "Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]",
            "Allow actions=[ec2:*, iam:*] resources=[*]"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 2,
        "data_sensitivity": 0,
        "lateral_movement": 1,
        "blast_radius": 2,
        "final_score": 5,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:71b5e5c5fe134d3fb9a78dfeea85c7bc76adcf129c6850f68e7903e91e15dcb6",
      "title": "IAM policy grants wildcard privileges",
      "rule_id": "aws-iam-wildcard-permissions",
      "category": "Elevation of Privilege",
      "severity": "medium",
      "affected_resources": [
        "aws_iam_policy.admin_like"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_iam_policy.admin_like contains allow statements with wildcard actions or resources. That makes the resulting access difficult to reason about and expands blast radius.",
      "recommended_mitigation": "Replace wildcard actions and resources with narrowly scoped permissions tied to the exact services, APIs, and ARNs required by the workload.",
      "evidence": [
        {
          "key": "iam_actions",
          "values": [
            "ec2:*",
            "iam:*"
          ]
        },
        {
          "key": "iam_resources",
          "values": [
            "*"
          ]
        },
        {
          "key": "policy_statements",
          "values": [
            "Allow actions=[ec2:*, iam:*] resources=[*]"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 2,
        "data_sensitivity": 0,
        "lateral_movement": 1,
        "blast_radius": 2,
        "final_score": 5,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:a813f866f70c3723cbf6b309829f87a9aeaec2171c8a2fa704307d5230663c42",
      "title": "Internet-exposed compute service permits overly broad ingress",
      "rule_id": "aws-public-compute-broad-ingress",
      "category": "Spoofing",
      "severity": "medium",
      "affected_resources": [
        "aws_instance.app",
        "aws_security_group.app"
      ],
      "trust_boundary_id": "internet-to-service:internet->aws_instance.app",
      "rationale": "aws_instance.app is reachable from the internet and at least one attached security group allows administrative access or all ports from 0.0.0.0/0. That broad ingress raises the chance of unauthenticated probing and credential attacks.",
      "recommended_mitigation": "Restrict ingress to expected client ports, remove direct administrative exposure, and place management access behind a controlled bastion, VPN, or SSM Session Manager.",
      "evidence": [
        {
          "key": "security_group_rules",
          "values": [
            "aws_security_group.app ingress tcp 22 from 0.0.0.0/0 (SSH from internet)"
          ]
        },
        {
          "key": "public_exposure_reasons",
          "values": [
            "instance has a public IP path and attached security groups allow internet ingress"
          ]
        },
        {
          "key": "subnet_posture",
          "values": [
            "aws_instance.app sits in public subnet aws_subnet.public_app with an internet route"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 2,
        "privilege_breadth": 0,
        "data_sensitivity": 0,
        "lateral_movement": 1,
        "blast_radius": 1,
        "final_score": 4,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:d22d3154af323df338d9e2592b1be16eaa6da2956113e6177b7e932c2898a9e4",
      "title": "Object storage is publicly accessible",
      "rule_id": "aws-s3-public-access",
      "category": "Information Disclosure",
      "severity": "medium",
      "affected_resources": [
        "aws_s3_bucket.assets"
      ],
      "trust_boundary_id": "internet-to-service:internet->aws_s3_bucket.assets",
      "rationale": "aws_s3_bucket.assets appears to be public through ACLs or bucket policy. Public object access is a common source of unintended data disclosure.",
      "recommended_mitigation": "Remove public ACL or bucket policy access, enable an S3 public access block, and serve content through a controlled CDN or origin access pattern when public distribution is required.",
      "evidence": [
        {
          "key": "public_exposure_reasons",
          "values": [
            "bucket ACL `public-read` grants public access",
            "bucket policy allows anonymous access"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 2,
        "privilege_breadth": 0,
        "data_sensitivity": 2,
        "lateral_movement": 0,
        "blast_radius": 1,
        "final_score": 5,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:7764e4c5514d2c0f6130714b1c5bb65fd64fb857cf3124a77d42b7d718d0ac33",
      "title": "Public Application Load Balancer is not associated with a WAF Web ACL",
      "rule_id": "aws-public-alb-waf-missing",
      "category": "Tampering",
      "severity": "medium",
      "affected_resources": [
        "aws_lb.web"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_lb.web is an internet-facing Application Load Balancer, but the Terraform plan does not show a deterministic AWS WAFv2 Web ACL association targeting it. Public edge traffic can reach the ALB without a modeled WAF or edge protection policy.",
      "recommended_mitigation": "Associate an AWS WAFv2 Web ACL with internet-facing Application Load Balancers and keep the association modeled in Terraform so public edge protection is reviewable before deployment.",
      "evidence": [
        {
          "key": "target_load_balancer",
          "values": [
            "address=aws_lb.web",
            "type=aws_lb",
            "arn=arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456",
            "load_balancer_type=application",
            "public_exposure=true",
            "load balancer is internet-facing and attached security groups allow internet ingress"
          ]
        },
        {
          "key": "waf_association_coverage",
          "values": [
            "target_resource_arn=arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456",
            "resolved_web_acl_association_count=0",
            "modeled_web_acl_association_count=0"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 2,
        "privilege_breadth": 0,
        "data_sensitivity": 0,
        "lateral_movement": 1,
        "blast_radius": 1,
        "final_score": 4,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:d02adcd0cc25ba815513c31afa125040a7ced498660a8bc43d2b08aeca00daff",
      "title": "Role trust relationship expands blast radius",
      "rule_id": "aws-role-trust-expansion",
      "category": "Elevation of Privilege",
      "severity": "medium",
      "affected_resources": [
        "aws_iam_role.workload"
      ],
      "trust_boundary_id": "cross-account-or-role-access:arn:aws:iam::999988887777:root->aws_iam_role.workload",
      "rationale": "aws_iam_role.workload can be assumed by arn:aws:iam::999988887777:root. Broad or foreign-account trust relationships increase the chance that compromise in one identity domain spills into another.",
      "recommended_mitigation": "Limit trust policies to the exact service principals or roles required, prefer role ARNs over account root where possible, and add conditions such as `ExternalId`, source ARN, SAML audience, or OIDC audience and subject checks.",
      "evidence": [
        {
          "key": "trust_principals",
          "values": [
            "arn:aws:iam::999988887777:root"
          ]
        },
        {
          "key": "target_account_resolution",
          "values": [
            "state=resolved",
            "account_id=111122223333",
            "partition=aws",
            "evidence=aws_iam_role.workload.arn = arn:aws:iam::111122223333:role/workload-role"
          ]
        },
        {
          "key": "trust_path",
          "values": [
            "trust principal belongs to foreign account 999988887777"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 1,
        "data_sensitivity": 0,
        "lateral_movement": 2,
        "blast_radius": 2,
        "final_score": 5,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:c2dad77f15c57ff9b288847015b64eb1504039f1eeae0aa0312b748ec4410f40",
      "title": "VPC Flow Logs are not configured for a modeled VPC",
      "rule_id": "aws-vpc-flow-logs-not-configured",
      "category": "Repudiation",
      "severity": "medium",
      "affected_resources": [
        "aws_vpc.main"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_vpc.main does not have a resolved aws_flow_log targeting the VPC in this Terraform plan. Network traffic metadata for incident response, threat hunting, and segmentation review may be unavailable unless Flow Logs are configured elsewhere.",
      "recommended_mitigation": "Enable VPC Flow Logs for production VPCs, route them to a retained CloudWatch Logs, S3, or Firehose destination, and manage Flow Log resources in Terraform so network telemetry posture is reviewable.",
      "evidence": [
        {
          "key": "target_vpc",
          "values": [
            "address=aws_vpc.main",
            "type=aws_vpc",
            "identifier=vpc-00000001",
            "cidr_block=10.0.0.0/16"
          ]
        },
        {
          "key": "flow_log_coverage",
          "values": [
            "target_vpc_id=vpc-00000001",
            "resolved_vpc_flow_log_count=0",
            "aws_flow_log resources are not modeled"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 0,
        "data_sensitivity": 0,
        "lateral_movement": 1,
        "blast_radius": 2,
        "final_score": 3,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:ecfa669cf5a1a8e4d830df4a95cbe64fc6b28c492699a989b49c529d55aad4bc",
      "title": "Workload uses KMS without a VPC endpoint",
      "rule_id": "aws-workload-kms-vpc-endpoint-missing",
      "category": "Information Disclosure",
      "severity": "medium",
      "affected_resources": [
        "aws_lambda_function.processor",
        "aws_iam_role.workload"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_lambda_function.processor runs in VPC `vpc-00000001` and inherits KMS cryptographic key access from aws_iam_role.workload, but the Terraform plan does not show a KMS interface VPC endpoint for that VPC. Calls to the sensitive service may therefore depend on public AWS service endpoints, NAT, or another egress path.",
      "recommended_mitigation": "Add a KMS interface VPC endpoint with private DNS enabled for VPC workloads that perform key operations, and narrow endpoint policies where possible.",
      "evidence": [
        {
          "key": "target_workload",
          "values": [
            "address=aws_lambda_function.processor",
            "type=aws_lambda_function",
            "vpc_id=vpc-00000001",
            "subnet_ids=[subnet-private-001]",
            "security_group_ids=[sg-app-001]"
          ]
        },
        {
          "key": "sensitive_service_dependency",
          "values": [
            "service=kms",
            "role=aws_iam_role.workload",
            "actions=[kms:Decrypt]",
            "resources=[*]"
          ]
        },
        {
          "key": "vpc_endpoint_coverage",
          "values": [
            "vpc_id=vpc-00000001",
            "service=kms",
            "expected_endpoint_type=interface",
            "vpc_endpoint_coverage=missing"
          ]
        },
        {
          "key": "policy_statements",
          "values": [
            "Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 1,
        "data_sensitivity": 1,
        "lateral_movement": 1,
        "blast_radius": 1,
        "final_score": 4,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:c8c0123dab1ec20cd7076d79f31e87909bac0834230e0eb68ce28e8dae222383",
      "title": "Workload uses S3 without a VPC endpoint",
      "rule_id": "aws-workload-s3-vpc-endpoint-missing",
      "category": "Information Disclosure",
      "severity": "medium",
      "affected_resources": [
        "aws_lambda_function.processor",
        "aws_iam_role.workload"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_lambda_function.processor runs in VPC `vpc-00000001` and inherits S3 data-plane permissions from aws_iam_role.workload, but the Terraform plan does not show an S3 VPC endpoint for that VPC. S3 access may therefore depend on public AWS service endpoints, NAT, or another egress path; this does not imply the bucket itself is public.",
      "recommended_mitigation": "Add an S3 gateway or interface VPC endpoint for VPC workloads that access S3, route expected private subnets through it, and use endpoint policies where possible.",
      "evidence": [
        {
          "key": "target_workload",
          "values": [
            "address=aws_lambda_function.processor",
            "type=aws_lambda_function",
            "vpc_id=vpc-00000001",
            "subnet_ids=[subnet-private-001]",
            "security_group_ids=[sg-app-001]"
          ]
        },
        {
          "key": "sensitive_service_dependency",
          "values": [
            "service=s3",
            "role=aws_iam_role.workload",
            "actions=[s3:*]",
            "resources=[*]"
          ]
        },
        {
          "key": "vpc_endpoint_coverage",
          "values": [
            "vpc_id=vpc-00000001",
            "service=s3",
            "expected_endpoint_type=gateway_or_interface",
            "vpc_endpoint_coverage=missing"
          ]
        },
        {
          "key": "policy_statements",
          "values": [
            "Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 1,
        "data_sensitivity": 1,
        "lateral_movement": 1,
        "blast_radius": 1,
        "final_score": 4,
        "severity": "medium",
        "computed_severity": null
      }
    },
    {
      "fingerprint": "sha256:ff9a1b4b0b11630f912c75371010b2df22e43179e7a2112f290cdf09014ab55e",
      "title": "RDS database does not export engine CloudWatch logs",
      "rule_id": "aws-rds-cloudwatch-log-exports-missing",
      "category": "Repudiation",
      "severity": "low",
      "affected_resources": [
        "aws_db_instance.app"
      ],
      "trust_boundary_id": null,
      "rationale": "aws_db_instance.app (engine `postgres`) does not export any of the baseline CloudWatch Logs expected for its engine family (postgresql). Without these log exports the database lacks the basic observability posture needed to investigate errors, slow queries, and audit activity from CloudWatch.",
      "recommended_mitigation": "Enable the CloudWatch Logs exports expected for the RDS engine family (for example `postgresql` for PostgreSQL, `error` and `slowquery` for MySQL/MariaDB) so errors, slow queries, and audit activity are captured for investigation.",
      "evidence": [
        {
          "key": "target_resource",
          "values": [
            "address=aws_db_instance.app",
            "type=aws_db_instance",
            "identifier=db-001",
            "engine=postgres"
          ]
        },
        {
          "key": "log_export_posture",
          "values": [
            "enabled_cloudwatch_logs_exports=[]",
            "expected_log_exports=['postgresql']",
            "engine-family baseline log exports are absent"
          ]
        }
      ],
      "severity_reasoning": {
        "internet_exposure": 0,
        "privilege_breadth": 0,
        "data_sensitivity": 1,
        "lateral_movement": 0,
        "blast_radius": 1,
        "final_score": 2,
        "severity": "low",
        "computed_severity": null
      }
    }
  ],
  "suppressed_findings": [],
  "baselined_findings": [],
  "observations": [],
  "limitations": [
    "AWS support is intentionally limited to a curated v1 resource set rather than the full Terraform AWS provider.",
    "Subnet public/private classification prefers explicit route table associations and NAT or internet routes when present, but it does not model main-route-table inheritance or every routing edge case.",
    "IAM analysis resolves inline role policies, customer-managed role-policy attachments, and EC2 instance profiles present in the plan, but it does not expand AWS-managed policy documents that are not materialized in Terraform state.",
    "Resource-policy analysis focuses on explicit policy documents and Lambda permission resources present in the plan; it does not model every service-specific condition key or every downstream runtime authorization path.",
    "The engine reasons over Terraform planned values only and does not validate runtime drift, runtime audit evidence, or post-deployment control-plane activity."
  ]
}
Markdown report
# Mixed AWS Plan Demo

- Analyzed file: `sample_aws_plan.json`
- Provider: `aws`
- Normalized resources: `23`
- Unsupported resources: `1`

## Summary

This run identified **9 trust boundaries** and **15 findings** across **23 normalized resources**.

- High severity findings: `4`
- Medium severity findings: `10`
- Low severity findings: `1`

## Analysis Coverage

- Terraform resources seen: `24`
- Provider resources considered: `24`
- Normalized resources: `23`
- Unsupported resources: `1`
- Resources with plan-time unknown values: `0`
- Registered provider rules (AWS): `104`
- Enabled provider rules (AWS): `104`
- Disabled rules: `0`
- Severity overrides: `0`
- Configuration-reference resolution: `0 symbolic`, `0 ambiguous`, `0 unresolved`, `0 unsupported`
- Recorded unresolved modeled references: `0`
- Unsupported resource types:
  - `aws_cloudwatch_log_group`: `1`
- Findings by rule:
  - `aws-public-compute-broad-ingress`: `1`
  - `aws-public-alb-waf-missing`: `1`
  - `aws-rds-cloudwatch-log-exports-missing`: `1`
  - `aws-s3-public-access`: `1`
  - `aws-workload-kms-vpc-endpoint-missing`: `1`
  - `aws-workload-s3-vpc-endpoint-missing`: `1`
  - `aws-vpc-flow-logs-not-configured`: `1`
  - `aws-database-permissive-ingress`: `1`
  - `aws-missing-tier-segmentation`: `1`
  - `aws-iam-wildcard-permissions`: `2`
  - `aws-iam-privileged-role-assignment`: `1`
  - `aws-workload-role-sensitive-permissions`: `1`
  - `aws-role-trust-expansion`: `1`
  - `aws-role-trust-missing-narrowing`: `1`

Sensitive resource labels are assumptions based on resource class. tfSTRIDE does not assess stored data contents from the plan.

## Discovered Trust Boundaries

### `internet-to-service`

- Source: `internet`
- Target: `aws_lb.web`
- Description: Traffic can cross from the public internet to aws_lb.web.
- Rationale: The resource is directly reachable or intentionally exposed to unauthenticated network clients.

### `internet-to-service`

- Source: `internet`
- Target: `aws_instance.app`
- Description: Traffic can cross from the public internet to aws_instance.app.
- Rationale: The resource is directly reachable or intentionally exposed to unauthenticated network clients.

### `internet-to-service`

- Source: `internet`
- Target: `aws_s3_bucket.assets`
- Description: Traffic can cross from the public internet to aws_s3_bucket.assets.
- Rationale: The resource is directly reachable or intentionally exposed to unauthenticated network clients.

### `public-subnet-to-private-subnet`

- Source: `aws_subnet.public_app`
- Target: `aws_subnet.private_data`
- Description: aws_subnet.public_app and aws_subnet.private_data occupy separate trust zones in the same network.
- Rationale: VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation.

### `workload-to-data-store`

- Source: `aws_instance.app`
- Target: `aws_db_instance.app`
- Description: aws_instance.app can interact with aws_db_instance.app.
- Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.

### `workload-to-data-store`

- Source: `aws_lambda_function.processor`
- Target: `aws_db_instance.app`
- Description: aws_lambda_function.processor can interact with aws_db_instance.app.
- Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.

### `workload-to-data-store`

- Source: `aws_lambda_function.processor`
- Target: `aws_s3_bucket.assets`
- Description: aws_lambda_function.processor can interact with aws_s3_bucket.assets.
- Rationale: Application or function workloads cross into a higher-sensitivity data plane when their attached role allows S3 actions such as s3:*.

### `admin-to-workload-plane`

- Source: `aws_iam_role.workload`
- Target: `aws_lambda_function.processor`
- Description: aws_lambda_function.processor uses aws_iam_role.workload as its runtime identity.
- Rationale: The workload inherits permissions from the attached identity. This attachment does not establish authority to modify or operate the workload.

### `cross-account-or-role-access`

- Source: `arn:aws:iam::999988887777:root`
- Target: `aws_iam_role.workload`
- Description: aws_iam_role.workload trusts arn:aws:iam::999988887777:root.
- Rationale: A foreign AWS account can cross into this role's trust boundary.

## Findings

### High

#### Database is reachable from overly permissive sources

- STRIDE category: Information Disclosure
- Affected resources: `aws_db_instance.app`, `aws_security_group.db`
- Trust boundary: `workload-to-data-store:aws_instance.app->aws_db_instance.app`
- Severity reasoning: internet_exposure +2, privilege_breadth +0, data_sensitivity +2, lateral_movement +1, blast_radius +1, final_score 6 => high
- Rationale: aws_db_instance.app is a sensitive data store, but database is not marked directly internet reachable, but its security groups allow internet-origin ingress, and database trusts security groups attached to internet-exposed workloads. That weakens the expected separation between the workload tier and the data tier.
- Recommended mitigation: Keep databases off public paths, allow ingress only from narrowly scoped application security groups, and enforce authentication plus encryption independently of network policy.
- Evidence:
  - security group rules: aws_security_group.db ingress tcp 5432 from 0.0.0.0/0 (Postgres from internet); aws_security_group.db ingress tcp 5432 from sg-app-001 (Postgres from public app tier)
  - network path: database is not marked directly internet reachable, but its security groups allow internet-origin ingress; database trusts security groups attached to internet-exposed workloads; aws_security_group.db allows sg-app-001 attached to aws_instance.app, aws_lb.web
  - subnet posture: aws_instance.app sits in public subnet aws_subnet.public_app with an internet route; aws_lb.web sits in public subnet aws_subnet.public_app with an internet route

#### IAM role has privileged assignment posture

- STRIDE category: Elevation of Privilege
- Affected resources: `aws_iam_role.workload`, `aws_iam_policy.admin_like`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +0, privilege_breadth +3, data_sensitivity +2, lateral_movement +2, blast_radius +3, final_score 10 => high
- Rationale: aws_iam_role.workload has deterministic privileged IAM assignment posture: compute-admin, data-admin, iam-admin, key-admin, privilege-escalation. If this role is attached to a workload or assumable by a control-plane principal, those privileges increase blast radius.
- Recommended mitigation: Review high-impact IAM role permissions, split administrative and runtime duties, scope resources to named ARNs, and avoid attaching broad IAM, role-passing, secrets, KMS, data, network, or audit administration permissions to general workload roles.
- Evidence:
  - iam role: address=aws_iam_role.workload; type=aws_iam_role; arn=arn:aws:iam::111122223333:role/workload-role; identifier=workload-role
  - privileged access: grant_1=categories=[data-admin, key-admin, privilege-escalation]; scope=account; confidence=high; grant_2=categories=[compute-admin, iam-admin]; scope=account; confidence=high
  - privilege categories: compute-admin; data-admin; iam-admin; key-admin; privilege-escalation
  - permission patterns: s3:*; iam:PassRole; sts:AssumeRole; ec2:*; iam:*
  - grant scopes: scope_kind=account; scope_value=*
  - grant confidence: high
  - attached policies: attached_policy_arn=arn:aws:iam::111122223333:policy/admin-like; attached_policy_address=aws_iam_policy.admin_like
  - inline policy sources: inline_policy_name=workload-inline

#### Private data tier directly trusts the public application tier

- STRIDE category: Tampering
- Affected resources: `aws_db_instance.app`, `aws_instance.app`, `aws_lb.web`, `aws_security_group.db`
- Trust boundary: `workload-to-data-store:aws_instance.app->aws_db_instance.app`
- Severity reasoning: internet_exposure +2, privilege_breadth +0, data_sensitivity +2, lateral_movement +2, blast_radius +1, final_score 7 => high
- Rationale: aws_db_instance.app accepts traffic from security groups attached to internet-facing workloads. A compromise of the public tier can therefore move laterally into the private data tier.
- Recommended mitigation: Introduce tighter tier segmentation with dedicated security groups, narrow ingress to specific services and ports, and keep the data tier reachable only through controlled application paths.
- Evidence:
  - security group rules: aws_security_group.db ingress tcp 5432 from sg-app-001 (Postgres from public app tier)
  - network path: aws_security_group.db allows sg-app-001 attached to aws_instance.app, aws_lb.web
  - subnet posture: aws_instance.app sits in public subnet aws_subnet.public_app with an internet route; aws_lb.web sits in public subnet aws_subnet.public_app with an internet route

#### Workload role carries sensitive permissions

- STRIDE category: Elevation of Privilege
- Affected resources: `aws_lambda_function.processor`, `aws_iam_role.workload`
- Trust boundary: `admin-to-workload-plane:aws_iam_role.workload->aws_lambda_function.processor`
- Severity reasoning: internet_exposure +0, privilege_breadth +2, data_sensitivity +1, lateral_movement +1, blast_radius +2, final_score 6 => high
- Rationale: aws_lambda_function.processor inherits sensitive privileges from aws_iam_role.workload, including iam:PassRole, kms:Decrypt, s3:*, sts:AssumeRole. If the workload is compromised, those credentials can be reused for privilege escalation, data access, or role chaining.
- Recommended mitigation: Split high-privilege actions into separate roles, scope permissions to named resources, and remove role-passing or cross-role permissions from general application identities.
- Evidence:
  - iam actions: iam:PassRole; kms:Decrypt; s3:*; sts:AssumeRole
  - policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]

### Medium

#### Cross-account or broad role trust lacks narrowing conditions

- STRIDE category: Elevation of Privilege
- Affected resources: `aws_iam_role.workload`
- Trust boundary: `cross-account-or-role-access:arn:aws:iam::999988887777:root->aws_iam_role.workload`
- Severity reasoning: internet_exposure +0, privilege_breadth +2, data_sensitivity +0, lateral_movement +1, blast_radius +2, final_score 5 => medium
- Rationale: aws_iam_role.workload trusts arn:aws:iam::999988887777:root without supported narrowing conditions such as `sts:ExternalId`, `aws:SourceArn`, or `aws:SourceAccount`. That leaves the assume-role path dependent on the trusted principal match alone.
- Recommended mitigation: Keep the trusted principal as specific as possible and add supported assume-role conditions such as `ExternalId`, `SourceArn`, `SourceAccount`, `SAML:aud`, or provider-specific OIDC `aud` and `sub` checks when crossing accounts or trusting broad or federated principals.
- Evidence:
  - trust principals: arn:aws:iam::999988887777:root
  - trust scope: principal is foreign account root 999988887777
  - target account resolution: state=resolved; account_id=111122223333; partition=aws; evidence=aws_iam_role.workload.arn = arn:aws:iam::111122223333:role/workload-role
  - trust narrowing: supported narrowing conditions present: false; supported narrowing condition keys: none

#### IAM policy grants wildcard privileges

- STRIDE category: Elevation of Privilege
- Affected resources: `aws_iam_role.workload`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +0, privilege_breadth +2, data_sensitivity +0, lateral_movement +1, blast_radius +2, final_score 5 => medium
- Rationale: aws_iam_role.workload contains allow statements with wildcard actions or resources. That makes the resulting access difficult to reason about and expands blast radius.
- Recommended mitigation: Replace wildcard actions and resources with narrowly scoped permissions tied to the exact services, APIs, and ARNs required by the workload.
- Evidence:
  - iam actions: ec2:*; iam:*; s3:*
  - iam resources: *
  - policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]; Allow actions=[ec2:*, iam:*] resources=[*]

#### IAM policy grants wildcard privileges

- STRIDE category: Elevation of Privilege
- Affected resources: `aws_iam_policy.admin_like`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +0, privilege_breadth +2, data_sensitivity +0, lateral_movement +1, blast_radius +2, final_score 5 => medium
- Rationale: aws_iam_policy.admin_like contains allow statements with wildcard actions or resources. That makes the resulting access difficult to reason about and expands blast radius.
- Recommended mitigation: Replace wildcard actions and resources with narrowly scoped permissions tied to the exact services, APIs, and ARNs required by the workload.
- Evidence:
  - iam actions: ec2:*; iam:*
  - iam resources: *
  - policy statements: Allow actions=[ec2:*, iam:*] resources=[*]

#### Internet-exposed compute service permits overly broad ingress

- STRIDE category: Spoofing
- Affected resources: `aws_instance.app`, `aws_security_group.app`
- Trust boundary: `internet-to-service:internet->aws_instance.app`
- Severity reasoning: internet_exposure +2, privilege_breadth +0, data_sensitivity +0, lateral_movement +1, blast_radius +1, final_score 4 => medium
- Rationale: aws_instance.app is reachable from the internet and at least one attached security group allows administrative access or all ports from 0.0.0.0/0. That broad ingress raises the chance of unauthenticated probing and credential attacks.
- Recommended mitigation: Restrict ingress to expected client ports, remove direct administrative exposure, and place management access behind a controlled bastion, VPN, or SSM Session Manager.
- Evidence:
  - security group rules: aws_security_group.app ingress tcp 22 from 0.0.0.0/0 (SSH from internet)
  - public exposure reasons: instance has a public IP path and attached security groups allow internet ingress
  - subnet posture: aws_instance.app sits in public subnet aws_subnet.public_app with an internet route

#### Object storage is publicly accessible

- STRIDE category: Information Disclosure
- Affected resources: `aws_s3_bucket.assets`
- Trust boundary: `internet-to-service:internet->aws_s3_bucket.assets`
- Severity reasoning: internet_exposure +2, privilege_breadth +0, data_sensitivity +2, lateral_movement +0, blast_radius +1, final_score 5 => medium
- Rationale: aws_s3_bucket.assets appears to be public through ACLs or bucket policy. Public object access is a common source of unintended data disclosure.
- Recommended mitigation: Remove public ACL or bucket policy access, enable an S3 public access block, and serve content through a controlled CDN or origin access pattern when public distribution is required.
- Evidence:
  - public exposure reasons: bucket ACL `public-read` grants public access; bucket policy allows anonymous access

#### Public Application Load Balancer is not associated with a WAF Web ACL

- STRIDE category: Tampering
- Affected resources: `aws_lb.web`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +2, privilege_breadth +0, data_sensitivity +0, lateral_movement +1, blast_radius +1, final_score 4 => medium
- Rationale: aws_lb.web is an internet-facing Application Load Balancer, but the Terraform plan does not show a deterministic AWS WAFv2 Web ACL association targeting it. Public edge traffic can reach the ALB without a modeled WAF or edge protection policy.
- Recommended mitigation: Associate an AWS WAFv2 Web ACL with internet-facing Application Load Balancers and keep the association modeled in Terraform so public edge protection is reviewable before deployment.
- Evidence:
  - target load balancer: address=aws_lb.web; type=aws_lb; arn=arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456; load_balancer_type=application; public_exposure=true; load balancer is internet-facing and attached security groups allow internet ingress
  - waf association coverage: target_resource_arn=arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/web/123456; resolved_web_acl_association_count=0; modeled_web_acl_association_count=0

#### Role trust relationship expands blast radius

- STRIDE category: Elevation of Privilege
- Affected resources: `aws_iam_role.workload`
- Trust boundary: `cross-account-or-role-access:arn:aws:iam::999988887777:root->aws_iam_role.workload`
- Severity reasoning: internet_exposure +0, privilege_breadth +1, data_sensitivity +0, lateral_movement +2, blast_radius +2, final_score 5 => medium
- Rationale: aws_iam_role.workload can be assumed by arn:aws:iam::999988887777:root. Broad or foreign-account trust relationships increase the chance that compromise in one identity domain spills into another.
- Recommended mitigation: Limit trust policies to the exact service principals or roles required, prefer role ARNs over account root where possible, and add conditions such as `ExternalId`, source ARN, SAML audience, or OIDC audience and subject checks.
- Evidence:
  - trust principals: arn:aws:iam::999988887777:root
  - target account resolution: state=resolved; account_id=111122223333; partition=aws; evidence=aws_iam_role.workload.arn = arn:aws:iam::111122223333:role/workload-role
  - trust path: trust principal belongs to foreign account 999988887777

#### VPC Flow Logs are not configured for a modeled VPC

- STRIDE category: Repudiation
- Affected resources: `aws_vpc.main`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +0, privilege_breadth +0, data_sensitivity +0, lateral_movement +1, blast_radius +2, final_score 3 => medium
- Rationale: aws_vpc.main does not have a resolved aws_flow_log targeting the VPC in this Terraform plan. Network traffic metadata for incident response, threat hunting, and segmentation review may be unavailable unless Flow Logs are configured elsewhere.
- Recommended mitigation: Enable VPC Flow Logs for production VPCs, route them to a retained CloudWatch Logs, S3, or Firehose destination, and manage Flow Log resources in Terraform so network telemetry posture is reviewable.
- Evidence:
  - target vpc: address=aws_vpc.main; type=aws_vpc; identifier=vpc-00000001; cidr_block=10.0.0.0/16
  - flow log coverage: target_vpc_id=vpc-00000001; resolved_vpc_flow_log_count=0; aws_flow_log resources are not modeled

#### Workload uses KMS without a VPC endpoint

- STRIDE category: Information Disclosure
- Affected resources: `aws_lambda_function.processor`, `aws_iam_role.workload`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +0, privilege_breadth +1, data_sensitivity +1, lateral_movement +1, blast_radius +1, final_score 4 => medium
- Rationale: aws_lambda_function.processor runs in VPC `vpc-00000001` and inherits KMS cryptographic key access from aws_iam_role.workload, but the Terraform plan does not show a KMS interface VPC endpoint for that VPC. Calls to the sensitive service may therefore depend on public AWS service endpoints, NAT, or another egress path.
- Recommended mitigation: Add a KMS interface VPC endpoint with private DNS enabled for VPC workloads that perform key operations, and narrow endpoint policies where possible.
- Evidence:
  - target workload: address=aws_lambda_function.processor; type=aws_lambda_function; vpc_id=vpc-00000001; subnet_ids=[subnet-private-001]; security_group_ids=[sg-app-001]
  - sensitive service dependency: service=kms; role=aws_iam_role.workload; actions=[kms:Decrypt]; resources=[*]
  - vpc endpoint coverage: vpc_id=vpc-00000001; service=kms; expected_endpoint_type=interface; vpc_endpoint_coverage=missing
  - policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]

#### Workload uses S3 without a VPC endpoint

- STRIDE category: Information Disclosure
- Affected resources: `aws_lambda_function.processor`, `aws_iam_role.workload`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +0, privilege_breadth +1, data_sensitivity +1, lateral_movement +1, blast_radius +1, final_score 4 => medium
- Rationale: aws_lambda_function.processor runs in VPC `vpc-00000001` and inherits S3 data-plane permissions from aws_iam_role.workload, but the Terraform plan does not show an S3 VPC endpoint for that VPC. S3 access may therefore depend on public AWS service endpoints, NAT, or another egress path; this does not imply the bucket itself is public.
- Recommended mitigation: Add an S3 gateway or interface VPC endpoint for VPC workloads that access S3, route expected private subnets through it, and use endpoint policies where possible.
- Evidence:
  - target workload: address=aws_lambda_function.processor; type=aws_lambda_function; vpc_id=vpc-00000001; subnet_ids=[subnet-private-001]; security_group_ids=[sg-app-001]
  - sensitive service dependency: service=s3; role=aws_iam_role.workload; actions=[s3:*]; resources=[*]
  - vpc endpoint coverage: vpc_id=vpc-00000001; service=s3; expected_endpoint_type=gateway_or_interface; vpc_endpoint_coverage=missing
  - policy statements: Allow actions=[s3:*, kms:Decrypt, iam:PassRole, sts:AssumeRole] resources=[*]

### Low

#### RDS database does not export engine CloudWatch logs

- STRIDE category: Repudiation
- Affected resources: `aws_db_instance.app`
- Trust boundary: `not-applicable`
- Severity reasoning: internet_exposure +0, privilege_breadth +0, data_sensitivity +1, lateral_movement +0, blast_radius +1, final_score 2 => low
- Rationale: aws_db_instance.app (engine `postgres`) does not export any of the baseline CloudWatch Logs expected for its engine family (postgresql). Without these log exports the database lacks the basic observability posture needed to investigate errors, slow queries, and audit activity from CloudWatch.
- Recommended mitigation: Enable the CloudWatch Logs exports expected for the RDS engine family (for example `postgresql` for PostgreSQL, `error` and `slowquery` for MySQL/MariaDB) so errors, slow queries, and audit activity are captured for investigation.
- Evidence:
  - target resource: address=aws_db_instance.app; type=aws_db_instance; identifier=db-001; engine=postgres
  - log export posture: enabled_cloudwatch_logs_exports=[]; expected_log_exports=['postgresql']; engine-family baseline log exports are absent

## Limitations / Unsupported Resources

- AWS support is intentionally limited to a curated v1 resource set rather than the full Terraform AWS provider.
- Subnet public/private classification prefers explicit route table associations and NAT or internet routes when present, but it does not model main-route-table inheritance or every routing edge case.
- IAM analysis resolves inline role policies, customer-managed role-policy attachments, and EC2 instance profiles present in the plan, but it does not expand AWS-managed policy documents that are not materialized in Terraform state.
- Resource-policy analysis focuses on explicit policy documents and Lambda permission resources present in the plan; it does not model every service-specific condition key or every downstream runtime authorization path.
- The engine reasons over Terraform planned values only and does not validate runtime drift, runtime audit evidence, or post-deployment control-plane activity.
- Unsupported resource skipped: `aws_cloudwatch_log_group.processor`

Limits

Unsupported or intentionally scoped areas

  • AWS support is intentionally limited to a curated v1 resource set rather than the full Terraform AWS provider.
  • Subnet public/private classification prefers explicit route table associations and NAT or internet routes when present, but it does not model main-route-table inheritance or every routing edge case.
  • IAM analysis resolves inline role policies, customer-managed role-policy attachments, and EC2 instance profiles present in the plan, but it does not expand AWS-managed policy documents that are not materialized in Terraform state.
  • Resource-policy analysis focuses on explicit policy documents and Lambda permission resources present in the plan; it does not model every service-specific condition key or every downstream runtime authorization path.
  • The engine reasons over Terraform planned values only and does not validate runtime drift, runtime audit evidence, or post-deployment control-plane activity.
  • Unsupported resource skipped: aws_cloudwatch_log_group.processor