Active findings
0Built-in scenario
aws/sample_aws_safe_plan.jsonSafe Plan Demo
Analyzed sample_aws_safe_plan.json with 28 normalized resources and 6 trust boundaries.
Analysis gaps
0Trust boundaries
6Resources
28Observations
2Analysis coverage
Audit trail for this run
Sensitive resource labels are assumptions based on resource class. tfSTRIDE does not assess stored data contents from the plan.
Resource coverage
- Provider resources considered
- 28
- Normalized resources
- 28
No unsupported AWS resource types were encountered.
Rule coverage
- Registered rules
- 104
- Disabled rules
- 0
No enabled rules produced findings.
Analysis gaps
Unassessed operation paths
No operation gaps were reported by the 5 analysis families that ran. This does not establish complete authorization coverage.
Findings
Severity bands
High
0No high findings.
Medium
0No medium findings.
Low
0No low findings.
Observations
Controls and mitigating signals
RDS instance is private and storage encrypted
aws_db_instance.app is kept off direct internet paths and has storage encryption enabled, which reduces straightforward data exposure risk.
S3 public access is reduced by a public access block
aws_s3_bucket.artifacts includes public-looking ACL or policy signals, but an attached public access block materially reduces that exposure.
Trust boundaries
Crossings that drive the model
- Source
aws_iam_role.workload - Relationship
- admin-to-workload-plane
- Destination
aws_lambda_function.processor
Rationale: The workload inherits permissions from the attached identity. This attachment does not establish authority to modify or operate the workload.
- Source
aws_subnet.public_edge - Relationship
- public-subnet-to-private-subnet
- Destination
aws_subnet.private_app
Rationale: VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation.
- Source
aws_subnet.public_edge - Relationship
- public-subnet-to-private-subnet
- Destination
aws_subnet.private_data
Rationale: VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation.
- Source
aws_instance.app - Relationship
- workload-to-data-store
- Destination
aws_db_instance.app
Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.
- Source
aws_lambda_function.processor - Relationship
- workload-to-data-store
- Destination
aws_db_instance.app
Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.
- Source
aws_lambda_function.processor - Relationship
- workload-to-data-store
- Destination
aws_s3_bucket.artifacts
Rationale: Application or function workloads cross into a higher-sensitivity data plane when their attached role allows S3 actions such as s3:GetObject.
Raw outputs
Stable contract and markdown
JSON report
{
"kind": "tfstride-report",
"version": "1.3",
"tool": {
"name": "tfstride",
"version": "0.5.0"
},
"title": "Safe Plan Demo",
"analyzed_file": "sample_aws_safe_plan.json",
"analyzed_path": "sample_aws_safe_plan.json",
"summary": {
"normalized_resources": 28,
"unsupported_resources": 0,
"trust_boundaries": 6,
"active_findings": 0,
"total_findings": 0,
"suppressed_findings": 0,
"baselined_findings": 0,
"severity_counts": {
"high": 0,
"medium": 0,
"low": 0
}
},
"filtering": {
"total_findings": 0,
"active_findings": 0,
"suppressed_findings": 0,
"baselined_findings": 0,
"suppressions_path": null,
"baseline_path": null
},
"analysis_coverage": {
"resources": {
"total_resources": 28,
"provider_resources": 28,
"normalized_resources": 28,
"unsupported_resources": 0,
"plan_time_unknown_resources": 0,
"unsupported_resource_types": {}
},
"rules": {
"registered_rule_count": 104,
"enabled_rules": [
"aws-public-compute-broad-ingress",
"aws-lambda-public-invocation",
"aws-load-balancer-http-public-listener",
"aws-load-balancer-listener-tls-certificate-missing",
"aws-load-balancer-listener-ssl-policy-weak-or-unknown",
"aws-public-alb-waf-missing",
"aws-cloudfront-viewer-http-allowed",
"aws-cloudfront-viewer-tls-policy-weak-or-unknown",
"aws-cloudfront-access-logging-not-configured",
"aws-public-cloudfront-waf-missing",
"aws-api-gateway-cors-permissive",
"aws-public-api-gateway-waf-missing",
"aws-api-gateway-public-route-authorization-none",
"aws-api-gateway-stage-access-logs-missing",
"aws-cloudtrail-multi-region-disabled",
"aws-cloudtrail-log-file-validation-disabled",
"aws-cloudtrail-management-events-disabled",
"aws-cloudtrail-data-events-not-modeled",
"aws-cloudtrail-insight-selectors-missing",
"aws-guardduty-detector-disabled-or-missing",
"aws-securityhub-account-missing",
"aws-config-recorder-disabled-or-missing",
"aws-config-delivery-channel-missing",
"aws-access-analyzer-not-configured",
"aws-macie-not-enabled-for-sensitive-storage",
"aws-rds-storage-encryption-disabled",
"aws-rds-public-endpoint-enabled",
"aws-rds-backup-retention-insufficient",
"aws-rds-deletion-protection-disabled",
"aws-rds-customer-managed-kms-key-missing",
"aws-rds-multi-az-disabled",
"aws-rds-performance-insights-disabled",
"aws-rds-cloudwatch-log-exports-missing",
"aws-rds-iam-auth-disabled",
"aws-dynamodb-customer-managed-kms-key-missing",
"aws-dynamodb-point-in-time-recovery-disabled-or-unknown",
"aws-dynamodb-deletion-protection-disabled-or-unknown",
"aws-s3-public-access",
"aws-s3-customer-managed-encryption-missing",
"aws-s3-versioning-disabled",
"aws-s3-object-lock-retention-missing",
"aws-s3-lifecycle-noncurrent-retention-insufficient",
"aws-ecr-image-tag-mutability-enabled",
"aws-ecr-customer-managed-encryption-missing",
"aws-ecr-repository-scanning-disabled",
"aws-workload-image-not-digest-pinned",
"aws-workload-ecr-mutable-tag",
"aws-workload-can-modify-image-repository",
"aws-ecs-sensitive-environment-value-inline",
"aws-ecs-secret-access-blast-radius",
"aws-public-ecs-secret-access",
"aws-public-ecs-secret-tampering",
"aws-public-ecs-secret-disruption",
"aws-public-ecs-cloudtrail-disruption",
"aws-public-ecs-s3-mutation-access",
"aws-public-ecs-s3-object-disruption",
"aws-public-ecs-s3-bucket-topology-disruption",
"aws-public-ecs-dynamodb-mutation-access",
"aws-public-ecs-dynamodb-item-disruption",
"aws-public-ecs-dynamodb-table-topology-disruption",
"aws-public-ecs-dynamodb-read-access",
"aws-public-ecs-kms-decrypt-access",
"aws-public-ecs-kms-signing-access",
"aws-public-ecs-kms-key-disruption",
"aws-public-ecs-kms-authorization-delegation",
"aws-public-ecs-messaging-mutation-access",
"aws-public-ecs-sqs-message-disruption",
"aws-public-ecs-messaging-topology-disruption",
"aws-public-ecs-sqs-receive-access",
"aws-sns-customer-managed-encryption-missing",
"aws-sqs-customer-managed-encryption-missing",
"aws-sqs-message-retention-insufficient",
"aws-sqs-dead-letter-queue-not-configured",
"aws-secretsmanager-customer-managed-kms-key-missing",
"aws-secretsmanager-recovery-window-too-short",
"aws-secretsmanager-rotation-not-configured-or-too-long",
"aws-kms-key-rotation-disabled-or-unknown",
"aws-kms-key-deletion-window-too-short",
"aws-kms-key-policy-lockout-safety-check-bypassed",
"aws-kms-grant-broad-authorization",
"aws-workload-secretsmanager-vpc-endpoint-missing",
"aws-workload-kms-vpc-endpoint-missing",
"aws-workload-s3-vpc-endpoint-missing",
"aws-vpc-endpoint-policy-broad-access",
"aws-vpc-flow-logs-not-configured",
"aws-vpc-flow-log-traffic-type-incomplete",
"aws-vpc-flow-log-destination-missing",
"aws-eks-api-endpoint-public-unrestricted",
"aws-eks-private-endpoint-not-enabled",
"aws-eks-secrets-encryption-not-configured",
"aws-eks-control-plane-logging-incomplete",
"aws-eks-authentication-mode-weak-or-unknown",
"aws-eks-vpc-cni-network-policy-not-enabled",
"aws-database-permissive-ingress",
"aws-missing-tier-segmentation",
"aws-sensitive-resource-policy-external-access",
"aws-service-resource-policy-external-access",
"aws-iam-wildcard-permissions",
"aws-iam-privileged-role-assignment",
"aws-workload-role-sensitive-permissions",
"aws-private-data-transitive-exposure",
"aws-control-plane-sensitive-workload-chain",
"aws-role-trust-expansion",
"aws-role-trust-missing-narrowing"
],
"disabled_rules": [],
"severity_overrides": {},
"finding_counts_by_rule": {
"aws-public-compute-broad-ingress": 0,
"aws-lambda-public-invocation": 0,
"aws-load-balancer-http-public-listener": 0,
"aws-load-balancer-listener-tls-certificate-missing": 0,
"aws-load-balancer-listener-ssl-policy-weak-or-unknown": 0,
"aws-public-alb-waf-missing": 0,
"aws-cloudfront-viewer-http-allowed": 0,
"aws-cloudfront-viewer-tls-policy-weak-or-unknown": 0,
"aws-cloudfront-access-logging-not-configured": 0,
"aws-public-cloudfront-waf-missing": 0,
"aws-api-gateway-cors-permissive": 0,
"aws-public-api-gateway-waf-missing": 0,
"aws-api-gateway-public-route-authorization-none": 0,
"aws-api-gateway-stage-access-logs-missing": 0,
"aws-cloudtrail-multi-region-disabled": 0,
"aws-cloudtrail-log-file-validation-disabled": 0,
"aws-cloudtrail-management-events-disabled": 0,
"aws-cloudtrail-data-events-not-modeled": 0,
"aws-cloudtrail-insight-selectors-missing": 0,
"aws-guardduty-detector-disabled-or-missing": 0,
"aws-securityhub-account-missing": 0,
"aws-config-recorder-disabled-or-missing": 0,
"aws-config-delivery-channel-missing": 0,
"aws-access-analyzer-not-configured": 0,
"aws-macie-not-enabled-for-sensitive-storage": 0,
"aws-rds-storage-encryption-disabled": 0,
"aws-rds-public-endpoint-enabled": 0,
"aws-rds-backup-retention-insufficient": 0,
"aws-rds-deletion-protection-disabled": 0,
"aws-rds-customer-managed-kms-key-missing": 0,
"aws-rds-multi-az-disabled": 0,
"aws-rds-performance-insights-disabled": 0,
"aws-rds-cloudwatch-log-exports-missing": 0,
"aws-rds-iam-auth-disabled": 0,
"aws-dynamodb-customer-managed-kms-key-missing": 0,
"aws-dynamodb-point-in-time-recovery-disabled-or-unknown": 0,
"aws-dynamodb-deletion-protection-disabled-or-unknown": 0,
"aws-s3-public-access": 0,
"aws-s3-customer-managed-encryption-missing": 0,
"aws-s3-versioning-disabled": 0,
"aws-s3-object-lock-retention-missing": 0,
"aws-s3-lifecycle-noncurrent-retention-insufficient": 0,
"aws-ecr-image-tag-mutability-enabled": 0,
"aws-ecr-customer-managed-encryption-missing": 0,
"aws-ecr-repository-scanning-disabled": 0,
"aws-workload-image-not-digest-pinned": 0,
"aws-workload-ecr-mutable-tag": 0,
"aws-workload-can-modify-image-repository": 0,
"aws-ecs-sensitive-environment-value-inline": 0,
"aws-ecs-secret-access-blast-radius": 0,
"aws-public-ecs-secret-access": 0,
"aws-public-ecs-secret-tampering": 0,
"aws-public-ecs-secret-disruption": 0,
"aws-public-ecs-cloudtrail-disruption": 0,
"aws-public-ecs-s3-mutation-access": 0,
"aws-public-ecs-s3-object-disruption": 0,
"aws-public-ecs-s3-bucket-topology-disruption": 0,
"aws-public-ecs-dynamodb-mutation-access": 0,
"aws-public-ecs-dynamodb-item-disruption": 0,
"aws-public-ecs-dynamodb-table-topology-disruption": 0,
"aws-public-ecs-dynamodb-read-access": 0,
"aws-public-ecs-kms-decrypt-access": 0,
"aws-public-ecs-kms-signing-access": 0,
"aws-public-ecs-kms-key-disruption": 0,
"aws-public-ecs-kms-authorization-delegation": 0,
"aws-public-ecs-messaging-mutation-access": 0,
"aws-public-ecs-sqs-message-disruption": 0,
"aws-public-ecs-messaging-topology-disruption": 0,
"aws-public-ecs-sqs-receive-access": 0,
"aws-sns-customer-managed-encryption-missing": 0,
"aws-sqs-customer-managed-encryption-missing": 0,
"aws-sqs-message-retention-insufficient": 0,
"aws-sqs-dead-letter-queue-not-configured": 0,
"aws-secretsmanager-customer-managed-kms-key-missing": 0,
"aws-secretsmanager-recovery-window-too-short": 0,
"aws-secretsmanager-rotation-not-configured-or-too-long": 0,
"aws-kms-key-rotation-disabled-or-unknown": 0,
"aws-kms-key-deletion-window-too-short": 0,
"aws-kms-key-policy-lockout-safety-check-bypassed": 0,
"aws-kms-grant-broad-authorization": 0,
"aws-workload-secretsmanager-vpc-endpoint-missing": 0,
"aws-workload-kms-vpc-endpoint-missing": 0,
"aws-workload-s3-vpc-endpoint-missing": 0,
"aws-vpc-endpoint-policy-broad-access": 0,
"aws-vpc-flow-logs-not-configured": 0,
"aws-vpc-flow-log-traffic-type-incomplete": 0,
"aws-vpc-flow-log-destination-missing": 0,
"aws-eks-api-endpoint-public-unrestricted": 0,
"aws-eks-private-endpoint-not-enabled": 0,
"aws-eks-secrets-encryption-not-configured": 0,
"aws-eks-control-plane-logging-incomplete": 0,
"aws-eks-authentication-mode-weak-or-unknown": 0,
"aws-eks-vpc-cni-network-policy-not-enabled": 0,
"aws-database-permissive-ingress": 0,
"aws-missing-tier-segmentation": 0,
"aws-sensitive-resource-policy-external-access": 0,
"aws-service-resource-policy-external-access": 0,
"aws-iam-wildcard-permissions": 0,
"aws-iam-privileged-role-assignment": 0,
"aws-workload-role-sensitive-permissions": 0,
"aws-private-data-transitive-exposure": 0,
"aws-control-plane-sensitive-workload-chain": 0,
"aws-role-trust-expansion": 0,
"aws-role-trust-missing-narrowing": 0
}
},
"references": {
"unresolved_reference_count": 0,
"symbolically_resolved_relationships": 0,
"ambiguous_symbolic_relationships": 0,
"unresolved_symbolic_relationships": 0,
"unsupported_symbolic_relationships": 0,
"unresolved_references": []
}
},
"operation_gaps": {
"reporting_families": [
{
"provider": "aws",
"name": "ecs_s3_access"
},
{
"provider": "aws",
"name": "ecs_s3_bucket_topology"
},
{
"provider": "aws",
"name": "ecs_s3_mutation"
},
{
"provider": "aws",
"name": "ecs_s3_object_deletion"
},
{
"provider": "aws",
"name": "ecs_s3_protected_data"
}
],
"records": []
},
"resource_sensitivity": {
"basis": "resource_class_assumption",
"data_contents_state": "not_assessed",
"explanation": "Sensitive resource labels are assumptions based on resource class. tfSTRIDE does not assess stored data contents from the plan."
},
"inventory": {
"provider": "aws",
"unsupported_resources": [],
"metadata": {
"primary_account_id": "222233334444",
"supported_resource_types": [
"aws_accessanalyzer_analyzer",
"aws_api_gateway_authorizer",
"aws_api_gateway_method",
"aws_api_gateway_rest_api",
"aws_api_gateway_stage",
"aws_apigatewayv2_api",
"aws_apigatewayv2_route",
"aws_apigatewayv2_stage",
"aws_caller_identity",
"aws_cloudfront_distribution",
"aws_cloudtrail",
"aws_config_configuration_recorder",
"aws_config_configuration_recorder_status",
"aws_config_delivery_channel",
"aws_db_instance",
"aws_dynamodb_resource_policy",
"aws_dynamodb_table",
"aws_ecr_registry_scanning_configuration",
"aws_ecr_repository",
"aws_ecs_cluster",
"aws_ecs_service",
"aws_ecs_task_definition",
"aws_eks_addon",
"aws_eks_cluster",
"aws_flow_log",
"aws_guardduty_detector",
"aws_iam_instance_profile",
"aws_iam_openid_connect_provider",
"aws_iam_policy",
"aws_iam_role",
"aws_iam_role_policy",
"aws_iam_role_policy_attachment",
"aws_instance",
"aws_internet_gateway",
"aws_kms_alias",
"aws_kms_grant",
"aws_kms_key",
"aws_kms_key_policy",
"aws_lambda_function",
"aws_lambda_function_url",
"aws_lambda_permission",
"aws_lb",
"aws_lb_listener",
"aws_lb_listener_rule",
"aws_lb_target_group",
"aws_macie2_account",
"aws_nat_gateway",
"aws_route_table",
"aws_route_table_association",
"aws_s3_bucket",
"aws_s3_bucket_lifecycle_configuration",
"aws_s3_bucket_object_lock_configuration",
"aws_s3_bucket_policy",
"aws_s3_bucket_public_access_block",
"aws_s3_bucket_server_side_encryption_configuration",
"aws_s3_bucket_versioning",
"aws_secretsmanager_secret",
"aws_secretsmanager_secret_policy",
"aws_secretsmanager_secret_rotation",
"aws_security_group",
"aws_security_group_rule",
"aws_securityhub_account",
"aws_sns_topic",
"aws_sqs_queue",
"aws_sqs_queue_redrive_policy",
"aws_subnet",
"aws_vpc",
"aws_vpc_endpoint",
"aws_wafv2_web_acl",
"aws_wafv2_web_acl_association"
],
"total_input_resources": 28,
"provider_resource_count": 28,
"normalized_resource_count": 28,
"unsupported_resource_types": {}
},
"resources": [
{
"address": "aws_db_instance.app",
"provider": "aws",
"resource_type": "aws_db_instance",
"name": "app",
"category": "data",
"identifier": "db-safe-001",
"arn": "arn:aws:rds:us-east-1:222233334444:db:safe-customer-db",
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [
"sg-safe-db-001"
],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "sensitive",
"metadata": {
"engine": "postgres",
"rds_publicly_accessible_state": "disabled",
"rds_backup_retention_period": 14,
"rds_deletion_protection_state": "enabled",
"rds_multi_az_state": "unknown",
"rds_kms_key_id": "arn:aws:kms:us-east-1:222233334444:key/rds",
"rds_performance_insights_enabled_state": "unknown",
"rds_enabled_cloudwatch_logs_exports": [
"postgresql"
],
"rds_iam_database_authentication_enabled_state": "unknown",
"rds_posture_uncertainties": [],
"db_subnet_group_name": "safe-private-data",
"publicly_accessible": false,
"public_access_reasons": [],
"public_exposure_reasons": [],
"storage_encrypted": true,
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:rds:us-east-1:222233334444:db:safe-customer-db",
"state": "known"
}
],
"kms_encryption_dependencies": [
{
"dependent_address": "aws_db_instance.app",
"dependent_resource_type": "aws_db_instance",
"dependency_source_address": "aws_db_instance.app",
"dependency_source_type": "aws_db_instance",
"configuration_path": [
"kms_key_id"
],
"configured_key_reference": "arn:aws:kms:us-east-1:222233334444:key/rds",
"reference_provenance": "planned_value",
"reference_kind": "key_arn",
"resolution_state": "unresolved",
"encryption_ownership_state": "customer_managed",
"candidate_targets": [],
"key_address": null,
"key_arn": null,
"key_id": null,
"alias_address": null,
"alias_name": null,
"alias_arn": null,
"key_origin": null,
"multi_region_state": null,
"posture_uncertainties": [
"KMS reference arn:aws:kms:us-east-1:222233334444:key/rds does not resolve to a modeled key or alias"
]
}
],
"kms_encryption_dependency_uncertainties": [
"aws_db_instance.app: KMS reference arn:aws:kms:us-east-1:222233334444:key/rds does not resolve to a modeled key or alias"
],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_flow_log.vpc",
"provider": "aws",
"resource_type": "aws_flow_log",
"name": "vpc",
"category": "network",
"identifier": "fl-safe-vpc",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"name": "vpc",
"flow_log_id": "fl-safe-vpc",
"flow_log_target_type": "vpc",
"flow_log_target_id": "vpc-00000002",
"flow_log_traffic_type": "ALL",
"flow_log_destination_type": "cloud-watch-logs",
"flow_log_log_group_name": "/aws/vpc-flow-logs/safe-main",
"flow_log_iam_role_arn": "arn:aws:iam::111122223333:role/vpc-flow-logs",
"flow_log_max_aggregation_interval": 60,
"flow_log_destination_options": {},
"flow_log_posture_uncertainties": [],
"tags": {},
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_iam_policy.artifact_read",
"provider": "aws",
"resource_type": "aws_iam_policy",
"name": "artifact_read",
"category": "iam",
"identifier": "safe-artifact-read",
"arn": "arn:aws:iam::222233334444:policy/safe-artifact-read",
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [
{
"effect": "Allow",
"actions": [
"s3:GetObject"
],
"resources": [
"arn:aws:s3:::safe-artifacts/*"
],
"principals": [],
"principal_entries": [],
"conditions": []
}
],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"policy_document": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject"
],
"Resource": [
"arn:aws:s3:::safe-artifacts/*"
]
}
]
},
"iam_policy_completeness_state": "complete",
"iam_policy_posture_uncertainties": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:iam::222233334444:policy/safe-artifact-read",
"state": "known"
}
],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_iam_policy.observability",
"provider": "aws",
"resource_type": "aws_iam_policy",
"name": "observability",
"category": "iam",
"identifier": "safe-observability",
"arn": "arn:aws:iam::222233334444:policy/safe-observability",
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [
{
"effect": "Allow",
"actions": [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"resources": [
"arn:aws:logs:us-east-1:222233334444:log-group:/aws/lambda/safe-processor:*",
"arn:aws:logs:us-east-1:222233334444:log-group:/aws/ec2/safe-app:*"
],
"principals": [],
"principal_entries": [],
"conditions": []
}
],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"policy_document": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": [
"arn:aws:logs:us-east-1:222233334444:log-group:/aws/lambda/safe-processor:*",
"arn:aws:logs:us-east-1:222233334444:log-group:/aws/ec2/safe-app:*"
]
}
]
},
"iam_policy_completeness_state": "complete",
"iam_policy_posture_uncertainties": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:iam::222233334444:policy/safe-observability",
"state": "known"
}
],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_iam_role.workload",
"provider": "aws",
"resource_type": "aws_iam_role",
"name": "workload",
"category": "iam",
"identifier": "safe-workload-role",
"arn": "arn:aws:iam::222233334444:role/safe-workload-role",
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [
{
"effect": "Allow",
"actions": [
"s3:GetObject"
],
"resources": [
"arn:aws:s3:::safe-artifacts/*"
],
"principals": [],
"principal_entries": [],
"conditions": []
}
],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"assume_role_policy": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "sts:AssumeRole",
"Principal": {
"Service": "lambda.amazonaws.com"
}
}
]
},
"trust_principals": [
"lambda.amazonaws.com"
],
"trust_statements": [
{
"principals": [
"lambda.amazonaws.com"
],
"principal_entries": [
{
"kind": "Service",
"value": "lambda.amazonaws.com"
}
],
"narrowing_condition_keys": [],
"narrowing_conditions": [],
"has_narrowing_conditions": false
}
],
"inline_policy_names": [],
"iam_policy_completeness_state": "complete",
"iam_policy_posture_uncertainties": [],
"iam_permissions_boundary_state": "not_configured",
"iam_permissions_boundary_uncertainties": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:iam::222233334444:role/safe-workload-role",
"state": "known"
}
],
"iam_role_policy_inputs": {
"inline_statement_count": 0,
"completeness_state": "complete",
"posture_uncertainties": [],
"inline_policy_names": [],
"merged_statements": [
{
"effect": "Allow",
"actions": [
"s3:GetObject"
],
"resources": [
"arn:aws:s3:::safe-artifacts/*"
],
"principals": [],
"principal_entries": [],
"conditions": []
}
]
},
"attached_policy_arns": [
"arn:aws:iam::222233334444:policy/safe-artifact-read"
],
"attached_policy_addresses": [
"aws_iam_policy.artifact_read"
],
"privileged_access_grants": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_iam_role_policy_attachment.workload_artifact_read",
"provider": "aws",
"resource_type": "aws_iam_role_policy_attachment",
"name": "workload_artifact_read",
"category": "iam",
"identifier": "safe-workload-artifact-read",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"role": "safe-workload-role",
"policy_arn": "arn:aws:iam::222233334444:policy/safe-artifact-read",
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_instance.app",
"provider": "aws",
"resource_type": "aws_instance",
"name": "app",
"category": "compute",
"identifier": "i-safe-001",
"arn": "arn:aws:ec2:us-east-1:222233334444:instance/i-safe-001",
"vpc_id": "vpc-00000002",
"subnet_ids": [
"subnet-safe-private-app-001"
],
"security_group_ids": [
"sg-safe-app-001"
],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"ami": "ami-safe-123456",
"instance_type": "t3.small",
"associate_public_ip_address": false,
"iam_instance_profile": null,
"tags": {
"Tier": "app"
},
"public_access_reasons": [],
"public_exposure_reasons": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:ec2:us-east-1:222233334444:instance/i-safe-001",
"state": "known"
}
],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": true,
"direct_internet_reachable": false
}
},
{
"address": "aws_internet_gateway.main",
"provider": "aws",
"resource_type": "aws_internet_gateway",
"name": "main",
"category": "network",
"identifier": "igw-safe-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_lambda_function.processor",
"provider": "aws",
"resource_type": "aws_lambda_function",
"name": "processor",
"category": "compute",
"identifier": "safe-processor",
"arn": "arn:aws:lambda:us-east-1:222233334444:function:safe-processor",
"vpc_id": "vpc-00000002",
"subnet_ids": [
"subnet-safe-private-app-001"
],
"security_group_ids": [
"sg-safe-app-001"
],
"attached_role_arns": [
"arn:aws:iam::222233334444:role/safe-workload-role"
],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"runtime": "python3.12",
"handler": "handler.main",
"vpc_enabled": true,
"container_image_references": [],
"container_image_posture_uncertainties": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:lambda:us-east-1:222233334444:function:safe-processor",
"state": "known"
}
],
"ecr_write_paths": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": true,
"direct_internet_reachable": false
}
},
{
"address": "aws_lb.web",
"provider": "aws",
"resource_type": "aws_lb",
"name": "web",
"category": "edge",
"identifier": "alb-safe-001",
"arn": "arn:aws:elasticloadbalancing:us-east-1:222233334444:loadbalancer/app/safe-web/123456",
"vpc_id": "vpc-00000002",
"subnet_ids": [
"subnet-safe-private-app-001"
],
"security_group_ids": [
"sg-safe-lb-001"
],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"internal": true,
"load_balancer_type": "application",
"load_balancer_ip_address_type": "ipv4",
"network_attachments": {
"security_groups": [
"sg-safe-lb-001"
],
"security_groups_complete": true,
"security_group_path": [
"security_groups"
],
"subnets": [
"subnet-safe-private-app-001"
],
"subnets_complete": true,
"subnet_path": [
"subnets"
]
},
"public_access_reasons": [],
"public_exposure_reasons": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:elasticloadbalancing:us-east-1:222233334444:loadbalancer/app/safe-web/123456",
"state": "known"
}
],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": true,
"direct_internet_reachable": false
}
},
{
"address": "aws_nat_gateway.main",
"provider": "aws",
"resource_type": "aws_nat_gateway",
"name": "main",
"category": "network",
"identifier": "nat-safe-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [
"subnet-safe-public-001"
],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"allocation_id": "eipalloc-safe-001",
"connectivity_type": "public",
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": true,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_route_table.private",
"provider": "aws",
"resource_type": "aws_route_table",
"name": "private",
"category": "network",
"identifier": "rtb-safe-private-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"routes": [
{
"cidr_block": "0.0.0.0/0",
"nat_gateway_id": "nat-safe-001"
}
],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_route_table.public",
"provider": "aws",
"resource_type": "aws_route_table",
"name": "public",
"category": "network",
"identifier": "rtb-safe-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"routes": [
{
"cidr_block": "0.0.0.0/0",
"gateway_id": "igw-safe-001"
}
],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_route_table_association.private_app",
"provider": "aws",
"resource_type": "aws_route_table_association",
"name": "private_app",
"category": "network",
"identifier": "rtassoc-safe-private-app-001",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"route_table_id": "rtb-safe-private-001",
"subnet_id": "subnet-safe-private-app-001",
"gateway_id": null,
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_route_table_association.private_data",
"provider": "aws",
"resource_type": "aws_route_table_association",
"name": "private_data",
"category": "network",
"identifier": "rtassoc-safe-private-data-001",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"route_table_id": "rtb-safe-private-001",
"subnet_id": "subnet-safe-private-data-001",
"gateway_id": null,
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_route_table_association.public_edge",
"provider": "aws",
"resource_type": "aws_route_table_association",
"name": "public_edge",
"category": "network",
"identifier": "rtassoc-safe-public-001",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"route_table_id": "rtb-safe-001",
"subnet_id": "subnet-safe-public-001",
"gateway_id": null,
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_s3_bucket.artifacts",
"provider": "aws",
"resource_type": "aws_s3_bucket",
"name": "artifacts",
"category": "data",
"identifier": "safe-artifacts",
"arn": "arn:aws:s3:::safe-artifacts",
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [
{
"effect": "Allow",
"actions": [
"s3:GetObject"
],
"resources": [
"arn:aws:s3:::safe-artifacts/*"
],
"principals": [
"*"
],
"principal_entries": [
{
"kind": "unknown",
"value": "*"
}
],
"conditions": []
}
],
"public_access_configured": true,
"public_exposure": false,
"data_sensitivity": "sensitive",
"metadata": {
"bucket": "safe-artifacts",
"acl": "public-read",
"policy_document": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": [
"s3:GetObject"
],
"Resource": "arn:aws:s3:::safe-artifacts/*"
}
]
},
"s3_bucket_policy_state": "configured",
"s3_bucket_policy_completeness_state": "complete",
"s3_bucket_policy_uncertainties": [],
"public_access_reasons": [
"bucket ACL `public-read` grants public access",
"bucket policy allows anonymous access"
],
"public_exposure_reasons": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [
{
"field": "arn",
"value": "arn:aws:s3:::safe-artifacts",
"state": "known"
}
],
"public_access_block": {
"block_public_acls": true,
"block_public_policy": true,
"ignore_public_acls": true,
"restrict_public_buckets": true
},
"kms_encryption_dependencies": [],
"kms_encryption_dependency_uncertainties": [],
"public_access_configured": true,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_s3_bucket_public_access_block.artifacts",
"provider": "aws",
"resource_type": "aws_s3_bucket_public_access_block",
"name": "artifacts",
"category": "data",
"identifier": "safe-artifacts-public-block",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"bucket": "safe-artifacts",
"block_public_acls": true,
"block_public_policy": true,
"ignore_public_acls": true,
"restrict_public_buckets": true,
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_security_group.app",
"provider": "aws",
"resource_type": "aws_security_group",
"name": "app",
"category": "network",
"identifier": "sg-safe-app-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [
{
"direction": "egress",
"protocol": "-1",
"from_port": 0,
"to_port": 0,
"cidr_blocks": [
"0.0.0.0/0"
],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [],
"description": null
},
{
"direction": "ingress",
"protocol": "tcp",
"from_port": 8080,
"to_port": 8080,
"cidr_blocks": [],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [
"sg-safe-lb-001"
],
"description": "App traffic from ALB"
}
],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"security_group_traffic_rules": [
{
"path": [
"egress",
0
],
"rule_direction": "egress",
"protocol": "all",
"from_port": 0,
"to_port": 0,
"cidr_blocks": [
"0.0.0.0/0"
],
"ipv6_cidr_blocks": [],
"security_groups": [],
"security_group_path": [
"egress",
0,
"security_groups"
],
"self": null,
"selectors_complete": true
}
],
"security_group_traffic_rules_known": true,
"description": "Application tier only reachable from the load balancer",
"group_name": "safe-app-sg",
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"standalone_rule_addresses": [
"aws_security_group_rule.app_from_lb"
],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_security_group.db",
"provider": "aws",
"resource_type": "aws_security_group",
"name": "db",
"category": "network",
"identifier": "sg-safe-db-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [
{
"direction": "egress",
"protocol": "-1",
"from_port": 0,
"to_port": 0,
"cidr_blocks": [
"0.0.0.0/0"
],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [],
"description": null
},
{
"direction": "ingress",
"protocol": "tcp",
"from_port": 5432,
"to_port": 5432,
"cidr_blocks": [],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [
"sg-safe-app-001"
],
"description": "Postgres from app tier"
}
],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"security_group_traffic_rules": [
{
"path": [
"egress",
0
],
"rule_direction": "egress",
"protocol": "all",
"from_port": 0,
"to_port": 0,
"cidr_blocks": [
"0.0.0.0/0"
],
"ipv6_cidr_blocks": [],
"security_groups": [],
"security_group_path": [
"egress",
0,
"security_groups"
],
"self": null,
"selectors_complete": true
}
],
"security_group_traffic_rules_known": true,
"description": "Database ingress only from the app tier",
"group_name": "safe-db-sg",
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"standalone_rule_addresses": [
"aws_security_group_rule.db_from_app"
],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_security_group.lb",
"provider": "aws",
"resource_type": "aws_security_group",
"name": "lb",
"category": "network",
"identifier": "sg-safe-lb-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [
{
"direction": "ingress",
"protocol": "tcp",
"from_port": 443,
"to_port": 443,
"cidr_blocks": [
"10.10.0.0/16"
],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [],
"description": "HTTPS from internal clients"
},
{
"direction": "egress",
"protocol": "-1",
"from_port": 0,
"to_port": 0,
"cidr_blocks": [
"0.0.0.0/0"
],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [],
"description": null
}
],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"security_group_traffic_rules": [
{
"path": [
"ingress",
0
],
"rule_direction": "ingress",
"protocol": "tcp",
"from_port": 443,
"to_port": 443,
"cidr_blocks": [
"10.10.0.0/16"
],
"ipv6_cidr_blocks": [],
"security_groups": [],
"security_group_path": [
"ingress",
0,
"security_groups"
],
"self": null,
"selectors_complete": true
},
{
"path": [
"egress",
0
],
"rule_direction": "egress",
"protocol": "all",
"from_port": 0,
"to_port": 0,
"cidr_blocks": [
"0.0.0.0/0"
],
"ipv6_cidr_blocks": [],
"security_groups": [],
"security_group_path": [
"egress",
0,
"security_groups"
],
"self": null,
"selectors_complete": true
}
],
"security_group_traffic_rules_known": true,
"description": "Internal load balancer ingress only",
"group_name": "safe-lb-sg",
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_security_group_rule.app_from_lb",
"provider": "aws",
"resource_type": "aws_security_group_rule",
"name": "app_from_lb",
"category": "network",
"identifier": "sgrule-safe-app-001",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [
{
"direction": "ingress",
"protocol": "tcp",
"from_port": 8080,
"to_port": 8080,
"cidr_blocks": [],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [
"sg-safe-lb-001"
],
"description": "App traffic from ALB"
}
],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"security_group_id": "sg-safe-app-001",
"security_group_traffic_rules": [
{
"path": [],
"rule_direction": "ingress",
"protocol": "tcp",
"from_port": 8080,
"to_port": 8080,
"cidr_blocks": [],
"ipv6_cidr_blocks": [],
"security_groups": [
"sg-safe-lb-001"
],
"security_group_path": [
"source_security_group_id"
],
"self": null,
"selectors_complete": true
}
],
"security_group_traffic_rules_known": true,
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_security_group_rule.db_from_app",
"provider": "aws",
"resource_type": "aws_security_group_rule",
"name": "db_from_app",
"category": "network",
"identifier": "sgrule-safe-db-001",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [
{
"direction": "ingress",
"protocol": "tcp",
"from_port": 5432,
"to_port": 5432,
"cidr_blocks": [],
"ipv6_cidr_blocks": [],
"referenced_security_group_ids": [
"sg-safe-app-001"
],
"description": "Postgres from app tier"
}
],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"security_group_id": "sg-safe-db-001",
"security_group_traffic_rules": [
{
"path": [],
"rule_direction": "ingress",
"protocol": "tcp",
"from_port": 5432,
"to_port": 5432,
"cidr_blocks": [],
"ipv6_cidr_blocks": [],
"security_groups": [
"sg-safe-app-001"
],
"security_group_path": [
"source_security_group_id"
],
"self": null,
"selectors_complete": true
}
],
"security_group_traffic_rules_known": true,
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_subnet.private_app",
"provider": "aws",
"resource_type": "aws_subnet",
"name": "private_app",
"category": "network",
"identifier": "subnet-safe-private-app-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"cidr_block": "10.10.2.0/24",
"availability_zone": "us-east-1a",
"map_public_ip_on_launch": false,
"tags": {
"Tier": "app"
},
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"is_public_subnet": false,
"route_table_ids": [
"rtb-safe-private-001"
],
"has_public_route": false,
"has_nat_gateway_egress": true,
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"direct_internet_reachable": false
}
},
{
"address": "aws_subnet.private_data",
"provider": "aws",
"resource_type": "aws_subnet",
"name": "private_data",
"category": "network",
"identifier": "subnet-safe-private-data-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"cidr_block": "10.10.3.0/24",
"availability_zone": "us-east-1a",
"map_public_ip_on_launch": false,
"tags": {
"Tier": "data"
},
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"is_public_subnet": false,
"route_table_ids": [
"rtb-safe-private-001"
],
"has_public_route": false,
"has_nat_gateway_egress": true,
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"direct_internet_reachable": false
}
},
{
"address": "aws_subnet.public_edge",
"provider": "aws",
"resource_type": "aws_subnet",
"name": "public_edge",
"category": "network",
"identifier": "subnet-safe-public-001",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"cidr_block": "10.10.1.0/24",
"availability_zone": "us-east-1a",
"map_public_ip_on_launch": true,
"tags": {
"Tier": "edge"
},
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"is_public_subnet": true,
"route_table_ids": [
"rtb-safe-001"
],
"has_public_route": true,
"has_nat_gateway_egress": false,
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"direct_internet_reachable": false
}
},
{
"address": "aws_vpc.main",
"provider": "aws",
"resource_type": "aws_vpc",
"name": "main",
"category": "network",
"identifier": "vpc-00000002",
"arn": null,
"vpc_id": null,
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"cidr_block": "10.10.0.0/16",
"tags": {
"Name": "safe-main"
},
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
},
{
"address": "aws_vpc_endpoint.s3",
"provider": "aws",
"resource_type": "aws_vpc_endpoint",
"name": "s3",
"category": "network",
"identifier": "vpce-safe-s3",
"arn": null,
"vpc_id": "vpc-00000002",
"subnet_ids": [],
"security_group_ids": [],
"attached_role_arns": [],
"network_rules": [],
"policy_statements": [],
"public_access_configured": false,
"public_exposure": false,
"data_sensitivity": "standard",
"metadata": {
"vpc_endpoint_id": "vpce-safe-s3",
"vpc_endpoint_service_name": "com.amazonaws.us-east-1.s3",
"vpc_endpoint_service_family": "s3",
"vpc_endpoint_type": "Gateway",
"vpc_endpoint_vpc_id": "vpc-00000002",
"vpc_endpoint_route_table_ids": [
"rtb-safe-private-001"
],
"vpc_endpoint_subnet_ids": [],
"vpc_endpoint_security_group_ids": [],
"vpc_endpoint_private_dns_enabled_state": "unknown",
"vpc_endpoint_policy_document": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject"
],
"Resource": [
"arn:aws:s3:::safe-artifacts/*"
]
}
]
},
"vpc_endpoint_dns_entries": [],
"vpc_endpoint_dns_names": [],
"vpc_endpoint_posture_uncertainties": [],
"account_identity_source_mode": "managed",
"account_identity_arn_inputs": [],
"public_access_reasons": [],
"public_exposure_reasons": [],
"public_access_configured": false,
"internet_ingress": false,
"internet_ingress_capable": false,
"internet_ingress_reasons": [],
"in_public_subnet": false,
"has_nat_gateway_egress": false,
"direct_internet_reachable": false
}
}
]
},
"trust_boundaries": [
{
"identifier": "admin-to-workload-plane:aws_iam_role.workload->aws_lambda_function.processor",
"boundary_type": "admin-to-workload-plane",
"source": "aws_iam_role.workload",
"target": "aws_lambda_function.processor",
"description": "aws_lambda_function.processor uses aws_iam_role.workload as its runtime identity.",
"rationale": "The workload inherits permissions from the attached identity. This attachment does not establish authority to modify or operate the workload."
},
{
"identifier": "public-subnet-to-private-subnet:aws_subnet.public_edge->aws_subnet.private_app",
"boundary_type": "public-subnet-to-private-subnet",
"source": "aws_subnet.public_edge",
"target": "aws_subnet.private_app",
"description": "aws_subnet.public_edge and aws_subnet.private_app occupy separate trust zones in the same network.",
"rationale": "VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation."
},
{
"identifier": "public-subnet-to-private-subnet:aws_subnet.public_edge->aws_subnet.private_data",
"boundary_type": "public-subnet-to-private-subnet",
"source": "aws_subnet.public_edge",
"target": "aws_subnet.private_data",
"description": "aws_subnet.public_edge and aws_subnet.private_data occupy separate trust zones in the same network.",
"rationale": "VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation."
},
{
"identifier": "workload-to-data-store:aws_instance.app->aws_db_instance.app",
"boundary_type": "workload-to-data-store",
"source": "aws_instance.app",
"target": "aws_db_instance.app",
"description": "aws_instance.app can interact with aws_db_instance.app.",
"rationale": "Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group."
},
{
"identifier": "workload-to-data-store:aws_lambda_function.processor->aws_db_instance.app",
"boundary_type": "workload-to-data-store",
"source": "aws_lambda_function.processor",
"target": "aws_db_instance.app",
"description": "aws_lambda_function.processor can interact with aws_db_instance.app.",
"rationale": "Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group."
},
{
"identifier": "workload-to-data-store:aws_lambda_function.processor->aws_s3_bucket.artifacts",
"boundary_type": "workload-to-data-store",
"source": "aws_lambda_function.processor",
"target": "aws_s3_bucket.artifacts",
"description": "aws_lambda_function.processor can interact with aws_s3_bucket.artifacts.",
"rationale": "Application or function workloads cross into a higher-sensitivity data plane when their attached role allows S3 actions such as s3:GetObject."
}
],
"findings": [],
"suppressed_findings": [],
"baselined_findings": [],
"observations": [
{
"title": "RDS instance is private and storage encrypted",
"observation_id": "aws-rds-private-encrypted",
"affected_resources": [
"aws_db_instance.app"
],
"rationale": "aws_db_instance.app is kept off direct internet paths and has storage encryption enabled, which reduces straightforward data exposure risk.",
"category": "data-protection",
"evidence": [
{
"key": "database_posture",
"values": [
"publicly_accessible is false",
"storage_encrypted is true",
"no attached security group allows internet ingress",
"engine is postgres"
]
}
]
},
{
"title": "S3 public access is reduced by a public access block",
"observation_id": "aws-s3-public-access-block-observed",
"affected_resources": [
"aws_s3_bucket.artifacts",
"aws_s3_bucket_public_access_block.artifacts"
],
"rationale": "aws_s3_bucket.artifacts includes public-looking ACL or policy signals, but an attached public access block materially reduces that exposure.",
"category": "data-protection",
"evidence": [
{
"key": "mitigated_public_access",
"values": [
"bucket ACL `public-read` would otherwise grant public access",
"bucket policy would otherwise allow anonymous access"
]
},
{
"key": "control_posture",
"values": [
"block_public_acls is true",
"block_public_policy is true",
"ignore_public_acls is true",
"restrict_public_buckets is true"
]
}
]
}
],
"limitations": [
"AWS support is intentionally limited to a curated v1 resource set rather than the full Terraform AWS provider.",
"Subnet public/private classification prefers explicit route table associations and NAT or internet routes when present, but it does not model main-route-table inheritance or every routing edge case.",
"IAM analysis resolves inline role policies, customer-managed role-policy attachments, and EC2 instance profiles present in the plan, but it does not expand AWS-managed policy documents that are not materialized in Terraform state.",
"Resource-policy analysis focuses on explicit policy documents and Lambda permission resources present in the plan; it does not model every service-specific condition key or every downstream runtime authorization path.",
"The engine reasons over Terraform planned values only and does not validate runtime drift, runtime audit evidence, or post-deployment control-plane activity."
]
}
Markdown report
# Safe Plan Demo
- Analyzed file: `sample_aws_safe_plan.json`
- Provider: `aws`
- Normalized resources: `28`
- Unsupported resources: `0`
## Summary
This run identified **6 trust boundaries** and **0 findings** across **28 normalized resources**.
- High severity findings: `0`
- Medium severity findings: `0`
- Low severity findings: `0`
## Analysis Coverage
- Terraform resources seen: `28`
- Provider resources considered: `28`
- Normalized resources: `28`
- Unsupported resources: `0`
- Resources with plan-time unknown values: `0`
- Registered provider rules (AWS): `104`
- Enabled provider rules (AWS): `104`
- Disabled rules: `0`
- Severity overrides: `0`
- Configuration-reference resolution: `0 symbolic`, `0 ambiguous`, `0 unresolved`, `0 unsupported`
- Recorded unresolved modeled references: `0`
Sensitive resource labels are assumptions based on resource class. tfSTRIDE does not assess stored data contents from the plan.
## Discovered Trust Boundaries
### `public-subnet-to-private-subnet`
- Source: `aws_subnet.public_edge`
- Target: `aws_subnet.private_app`
- Description: aws_subnet.public_edge and aws_subnet.private_app occupy separate trust zones in the same network.
- Rationale: VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation.
### `public-subnet-to-private-subnet`
- Source: `aws_subnet.public_edge`
- Target: `aws_subnet.private_data`
- Description: aws_subnet.public_edge and aws_subnet.private_data occupy separate trust zones in the same network.
- Rationale: VPC membership resolves to `aws_vpc.main`. The network contains a publicly routable segment and a private trust zone. Common network membership does not establish packet reachability; routes and traffic controls require separate evaluation.
### `workload-to-data-store`
- Source: `aws_instance.app`
- Target: `aws_db_instance.app`
- Description: aws_instance.app can interact with aws_db_instance.app.
- Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.
### `workload-to-data-store`
- Source: `aws_lambda_function.processor`
- Target: `aws_db_instance.app`
- Description: aws_lambda_function.processor can interact with aws_db_instance.app.
- Rationale: Application or function workloads cross into a higher-sensitivity data plane when database ingress security groups explicitly trust the workload security group.
### `workload-to-data-store`
- Source: `aws_lambda_function.processor`
- Target: `aws_s3_bucket.artifacts`
- Description: aws_lambda_function.processor can interact with aws_s3_bucket.artifacts.
- Rationale: Application or function workloads cross into a higher-sensitivity data plane when their attached role allows S3 actions such as s3:GetObject.
### `admin-to-workload-plane`
- Source: `aws_iam_role.workload`
- Target: `aws_lambda_function.processor`
- Description: aws_lambda_function.processor uses aws_iam_role.workload as its runtime identity.
- Rationale: The workload inherits permissions from the attached identity. This attachment does not establish authority to modify or operate the workload.
## Findings
### High
No findings in this severity band.
### Medium
No findings in this severity band.
### Low
No findings in this severity band.
## Controls Observed
### RDS instance is private and storage encrypted
- Category: `data-protection`
- Affected resources: `aws_db_instance.app`
- Rationale: aws_db_instance.app is kept off direct internet paths and has storage encryption enabled, which reduces straightforward data exposure risk.
- Evidence:
- database posture: publicly_accessible is false; storage_encrypted is true; no attached security group allows internet ingress; engine is postgres
### S3 public access is reduced by a public access block
- Category: `data-protection`
- Affected resources: `aws_s3_bucket.artifacts`, `aws_s3_bucket_public_access_block.artifacts`
- Rationale: aws_s3_bucket.artifacts includes public-looking ACL or policy signals, but an attached public access block materially reduces that exposure.
- Evidence:
- mitigated public access: bucket ACL `public-read` would otherwise grant public access; bucket policy would otherwise allow anonymous access
- control posture: block_public_acls is true; block_public_policy is true; ignore_public_acls is true; restrict_public_buckets is true
## Limitations / Unsupported Resources
- AWS support is intentionally limited to a curated v1 resource set rather than the full Terraform AWS provider.
- Subnet public/private classification prefers explicit route table associations and NAT or internet routes when present, but it does not model main-route-table inheritance or every routing edge case.
- IAM analysis resolves inline role policies, customer-managed role-policy attachments, and EC2 instance profiles present in the plan, but it does not expand AWS-managed policy documents that are not materialized in Terraform state.
- Resource-policy analysis focuses on explicit policy documents and Lambda permission resources present in the plan; it does not model every service-specific condition key or every downstream runtime authorization path.
- The engine reasons over Terraform planned values only and does not validate runtime drift, runtime audit evidence, or post-deployment control-plane activity.
Limits
Unsupported or intentionally scoped areas
- AWS support is intentionally limited to a curated v1 resource set rather than the full Terraform AWS provider.
- Subnet public/private classification prefers explicit route table associations and NAT or internet routes when present, but it does not model main-route-table inheritance or every routing edge case.
- IAM analysis resolves inline role policies, customer-managed role-policy attachments, and EC2 instance profiles present in the plan, but it does not expand AWS-managed policy documents that are not materialized in Terraform state.
- Resource-policy analysis focuses on explicit policy documents and Lambda permission resources present in the plan; it does not model every service-specific condition key or every downstream runtime authorization path.
- The engine reasons over Terraform planned values only and does not validate runtime drift, runtime audit evidence, or post-deployment control-plane activity.