Skip to content

Commit

Permalink
One-OE config files for CIS Level 1 & 2
Browse files Browse the repository at this point in the history
  • Loading branch information
paalonso committed Oct 28, 2024
1 parent 367a6e5 commit 97a30a1
Show file tree
Hide file tree
Showing 11 changed files with 3,815 additions and 1,346 deletions.

Large diffs are not rendered by default.

1,163 changes: 535 additions & 628 deletions blueprints/one-oe/runtime/one-stack/oci_open_lz_one-oe_network.auto.tfvars.json

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,146 @@
{
"cloud_guard_configuration": {
"enable_cloud_guard": "true",
"tenancy_id": "TENANCY-ROOT",
"compartment_id": "TENANCY-ROOT",
"target_resource_id": "TENANCY-ROOT",
"name_prefix": null,
"self_manage_resources": "false",
"target_resource_name": null,
"target_resource_type": "COMPARTMENT",
"enable_cloned_recipes": "false",
"configuration_detector_recipe_name": null,
"activity_detector_recipe_name": null,
"threat_detector_recipe_name": null,
"responder_recipe_name": null,
"targets": {
"CG-TGT-ROOT-KEY": {
"name": "cg-tgt-root",
"compartment_id": "TENANCY-ROOT",
"target_resource_type": "COMPARTMENT",
"resource_id": "TENANCY-ROOT",
"use_cloned_recipes": "false"
}
}
},
"security_zones_configuration": {
"tenancy_ocid": "TENANCY-ROOT",
"recipes": {
"SZ-RCP-LZP-01-CIS-LVL-1-KEY": {
"name": "sz-rcp-lzp-01-CIS-Level-1",
"description": "Recipe 01 CIS Level 1",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "1"
},
"SZ-RCP-LZP-02-CIS-LVL-2-KEY": {
"name": "sz-rcp-lzp-02-CIS-Level-2",
"description": "Recipe 02 CIS Level 2",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2"
},
"SZ-RCP-LZP-03-SHARED-NETWORK-KEY": {
"name": "sz-rcp-lzp-03-shared-network",
"description": "Recipe 03 Shared Network",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2",
"security_policies_ocids": [
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaavolswrbfqy6qn2qe7zek2dumml6pbmyzv47q6jfwdatrywmqumba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaayxn5ccbavcx5w35uoozguju5zlovvtbnuvnrduxpdp3vsho33lba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaazlzn66zeazf5npw46qah3wlqpfrugv7w4tjbomit2msr43stidga",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaw6v2nz4unovq3joqk6pguxpaqriws2vzd7gvpldgai47tl72wseq"

]
},
"SZ-RCP-LZP-04-ENV-NETWORK-KEY": {
"name": "sz-rcp-lzp-04-environment-network",
"description": "Recipe 04 Environment Network",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2",
"security_policies_ocids": [
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaavolswrbfqy6qn2qe7zek2dumml6pbmyzv47q6jfwdatrywmqumba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaayxn5ccbavcx5w35uoozguju5zlovvtbnuvnrduxpdp3vsho33lba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaazlzn66zeazf5npw46qah3wlqpfrugv7w4tjbomit2msr43stidga",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaw6v2nz4unovq3joqk6pguxpaqriws2vzd7gvpldgai47tl72wseq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaak5wxfr2r6kxmtd6bq6hqhyywfkj6pcnl74g3iui6qnlq7rof4ezq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaabs6kboflsfan2lihfnodhbeb75r4nxiolhlobvj6vqclx6j5yyha",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa6j7b5bf3ytsno7a45r7xupqt2q342q2hlecnf7fgqpkq67stakda",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaamewv6k5a7cik6ds6m6bsijwkiixpfzgsqzvrjlns5pxg6lslrzgq"
]
},
"SZ-RCP-LZP-05-WORKLOADS-KEY": {
"name": "sz-rcp-lzp-05-workloads",
"description": "Recipe 05 Workloads",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2",
"security_policies_ocids": [
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaavolswrbfqy6qn2qe7zek2dumml6pbmyzv47q6jfwdatrywmqumba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaayxn5ccbavcx5w35uoozguju5zlovvtbnuvnrduxpdp3vsho33lba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaazlzn66zeazf5npw46qah3wlqpfrugv7w4tjbomit2msr43stidga",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaw6v2nz4unovq3joqk6pguxpaqriws2vzd7gvpldgai47tl72wseq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaak5wxfr2r6kxmtd6bq6hqhyywfkj6pcnl74g3iui6qnlq7rof4ezq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaabs6kboflsfan2lihfnodhbeb75r4nxiolhlobvj6vqclx6j5yyha",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa6j7b5bf3ytsno7a45r7xupqt2q342q2hlecnf7fgqpkq67stakda",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaamewv6k5a7cik6ds6m6bsijwkiixpfzgsqzvrjlns5pxg6lslrzgq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaf45c2imtiuyxbccuwrh3s7is5lokpx5ksr4heu46c6mz6k35dsqa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa5qtljtbaeacnhfhr7hfs5nd3jp6jin6grbdgf6izkf4ukxmatjpa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa6oycc62uuvpi6oddkzku6x2vzhraud7ynkbdeols5i4khwroklva",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaauvfkentmqda6mq7lxekkstjpe7kwgmrpkadzt7krhrt66tliourq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa544n6cyqrq6tato53ohh7vcz523af5dtuz6x54efhs6mb7bcw54a",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaay32fadjsdgsytdpyn4busugqftko2shttseljqbagapngiatxepa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaqlpaf5tc3xfqdzdw2rtx7hk4ifywzml3eh3upspeh4s6x4epaskq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaxou4266jlusvklor34czqvloa64k5dsok5cejug2bxi2jvqy32zq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaak2x2aomzhqoeg2bf4zgqyr3bg2ppsfhupn2xvu66zpuz7kbvae5a",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaauah5cz3vxzpdvw4uz32hcgcmhogvuhacgyc7z3al42tfjey46eea",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaawebiliesbgzdguac5m5u332oj66afaab6ruovydpsdoexloguweq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa2lfkaypfwyykhbz65zlgc4lvypl64axzhnsqmegllgiyxbweruya",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaah3k66efqfgo5ccjgvtkwbfpzj5yjajmw7vt5eub6ma4jp6su55zq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaajscm24dhll5wk65k6q4mmkopiykpqrumtururitjaxk3j4ibe3ua",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaol3pxbbikegih24c7l4um7wqeeun2dpkvgm3izz5syf755xfscgq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaawol5fz6qkrkxm5ui7n3car44e5wbs54thnku2hjxwaedi5ee6htq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaegi6cweu5jqwipqhj5quz4pebfd76djed4lfogslzuawqavkrsjq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaarkvvuzwtc6xwwr57zg6fymgkco3lbt35c7r4lnahw4ab5i3vkbrq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaauhuzsidaju3mwy3llsetvm3dlc6ftel65ielfu7h4hg6q2cfsrxa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaawec56szedvf6hogbbnu7cxywm4xkmta53wuo7lenceiqyr4bx5hq"
]
}
},
"security_zones": {
"SZ-TGT-LZP-CISL1-KEY": {
"name": "sz-tgt-lzp-cisl1",
"compartment_id": "CMP-LANDINGZONE-P-KEY",
"recipe_key": "SZ-RCP-LZP-01-CIS-LVL-1-KEY"
}
}
},
"scanning_configuration": {
"default_compartment_id": "CMP-LZP-SECURITY-KEY",
"host_recipes": {
"VSS-RECH-LZP-KEY": {
"name": "vss-rech-lzp",
"port_scan_level": "STANDARD",
"schedule_settings": {
"type": "WEEKLY",
"day_of_week": "SUNDAY"
},
"agent_settings": {
"scan_level": "STANDARD",
"vendor": "OCI",
"cis_benchmark_scan_level": "STRICT"
},
"file_scan_settings": {
"enable": true,
"scan_recurrence": "FREQ=WEEKLY;INTERVAL=2;WKST=SU",
"folders_to_scan": ["/"],
"operating_system": "LINUX"
}
}
},
"host_targets": {
"VSS-TGT-LZP-KEY": {
"name": "vss-tgt-lzp",
"target_compartment_id": "CMP-LANDINGZONE-P-KEY",
"host_recipe_id": "VSS-RECH-LZP-KEY"
}
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,181 @@
{
"cloud_guard_configuration": {
"enable_cloud_guard": "true",
"tenancy_id": "TENANCY-ROOT",
"reporting_region": "eu-frankfurt-1",
"compartment_id": "TENANCY-ROOT",
"target_resource_id": "TENANCY-ROOT",
"name_prefix": null,
"self_manage_resources": "false",
"target_resource_name": null,
"target_resource_type": "COMPARTMENT",
"enable_cloned_recipes": "false",
"configuration_detector_recipe_name": null,
"activity_detector_recipe_name": null,
"threat_detector_recipe_name": null,
"responder_recipe_name": null,
"targets": {
"CG-TGT-ROOT-KEY": {
"name": "cg-tgt-root",
"compartment_id": "TENANCY-ROOT",
"target_resource_type": "COMPARTMENT",
"resource_id": "TENANCY-ROOT",
"use_cloned_recipes": "false"
}
}
},
"security_zones_configuration": {
"reporting_region": "eu-frankfurt-1",
"tenancy_ocid": "TENANCY-ROOT",
"recipes": {
"SZ-RCP-LZP-01-CIS-LVL-1-KEY": {
"name": "sz-rcp-lzp-01-CIS-Level-1",
"description": "Recipe 01 CIS Level 1",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "1"
},
"SZ-RCP-LZP-02-CIS-LVL-2-KEY": {
"name": "sz-rcp-lzp-02-CIS-Level-2",
"description": "Recipe 02 CIS Level 2",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2"
},
"SZ-RCP-LZP-03-SHARED-NETWORK-KEY": {
"name": "sz-rcp-lzp-03-shared-network",
"description": "Recipe 03 Shared Network",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2",
"security_policies_ocids": [
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaavolswrbfqy6qn2qe7zek2dumml6pbmyzv47q6jfwdatrywmqumba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaayxn5ccbavcx5w35uoozguju5zlovvtbnuvnrduxpdp3vsho33lba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaazlzn66zeazf5npw46qah3wlqpfrugv7w4tjbomit2msr43stidga",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaw6v2nz4unovq3joqk6pguxpaqriws2vzd7gvpldgai47tl72wseq"

]
},
"SZ-RCP-LZP-04-ENV-NETWORK-KEY": {
"name": "sz-rcp-lzp-04-environment-network",
"description": "Recipe 04 Environment Network",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2",
"security_policies_ocids": [
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaavolswrbfqy6qn2qe7zek2dumml6pbmyzv47q6jfwdatrywmqumba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaayxn5ccbavcx5w35uoozguju5zlovvtbnuvnrduxpdp3vsho33lba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaazlzn66zeazf5npw46qah3wlqpfrugv7w4tjbomit2msr43stidga",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaw6v2nz4unovq3joqk6pguxpaqriws2vzd7gvpldgai47tl72wseq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaak5wxfr2r6kxmtd6bq6hqhyywfkj6pcnl74g3iui6qnlq7rof4ezq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaabs6kboflsfan2lihfnodhbeb75r4nxiolhlobvj6vqclx6j5yyha",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa6j7b5bf3ytsno7a45r7xupqt2q342q2hlecnf7fgqpkq67stakda",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaamewv6k5a7cik6ds6m6bsijwkiixpfzgsqzvrjlns5pxg6lslrzgq"
]
},
"SZ-RCP-LZP-05-WORKLOADS-KEY": {
"name": "sz-rcp-lzp-05-workloads",
"description": "Recipe 05 Workloads",
"compartment_id": "CMP-LZP-SECURITY-KEY",
"cis_level": "2",
"security_policies_ocids": [
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaavolswrbfqy6qn2qe7zek2dumml6pbmyzv47q6jfwdatrywmqumba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaayxn5ccbavcx5w35uoozguju5zlovvtbnuvnrduxpdp3vsho33lba",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaazlzn66zeazf5npw46qah3wlqpfrugv7w4tjbomit2msr43stidga",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaw6v2nz4unovq3joqk6pguxpaqriws2vzd7gvpldgai47tl72wseq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaak5wxfr2r6kxmtd6bq6hqhyywfkj6pcnl74g3iui6qnlq7rof4ezq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaabs6kboflsfan2lihfnodhbeb75r4nxiolhlobvj6vqclx6j5yyha",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa6j7b5bf3ytsno7a45r7xupqt2q342q2hlecnf7fgqpkq67stakda",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaamewv6k5a7cik6ds6m6bsijwkiixpfzgsqzvrjlns5pxg6lslrzgq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaf45c2imtiuyxbccuwrh3s7is5lokpx5ksr4heu46c6mz6k35dsqa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa5qtljtbaeacnhfhr7hfs5nd3jp6jin6grbdgf6izkf4ukxmatjpa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa6oycc62uuvpi6oddkzku6x2vzhraud7ynkbdeols5i4khwroklva",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaauvfkentmqda6mq7lxekkstjpe7kwgmrpkadzt7krhrt66tliourq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa544n6cyqrq6tato53ohh7vcz523af5dtuz6x54efhs6mb7bcw54a",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaay32fadjsdgsytdpyn4busugqftko2shttseljqbagapngiatxepa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaqlpaf5tc3xfqdzdw2rtx7hk4ifywzml3eh3upspeh4s6x4epaskq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaxou4266jlusvklor34czqvloa64k5dsok5cejug2bxi2jvqy32zq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaak2x2aomzhqoeg2bf4zgqyr3bg2ppsfhupn2xvu66zpuz7kbvae5a",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaauah5cz3vxzpdvw4uz32hcgcmhogvuhacgyc7z3al42tfjey46eea",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaawebiliesbgzdguac5m5u332oj66afaab6ruovydpsdoexloguweq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaa2lfkaypfwyykhbz65zlgc4lvypl64axzhnsqmegllgiyxbweruya",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaah3k66efqfgo5ccjgvtkwbfpzj5yjajmw7vt5eub6ma4jp6su55zq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaajscm24dhll5wk65k6q4mmkopiykpqrumtururitjaxk3j4ibe3ua",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaol3pxbbikegih24c7l4um7wqeeun2dpkvgm3izz5syf755xfscgq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaawol5fz6qkrkxm5ui7n3car44e5wbs54thnku2hjxwaedi5ee6htq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaaegi6cweu5jqwipqhj5quz4pebfd76djed4lfogslzuawqavkrsjq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaarkvvuzwtc6xwwr57zg6fymgkco3lbt35c7r4lnahw4ab5i3vkbrq",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaauhuzsidaju3mwy3llsetvm3dlc6ftel65ielfu7h4hg6q2cfsrxa",
"ocid1.securityzonessecuritypolicy.oc1..aaaaaaaawec56szedvf6hogbbnu7cxywm4xkmta53wuo7lenceiqyr4bx5hq"
]
}
},
"security_zones": {
"SZ-TGT-LZP-CISL2-KEY": {
"name": "sz-tgt-lzp-cisl2",
"compartment_id": "CMP-LANDINGZONE-P-KEY",
"recipe_key": "SZ-RCP-LZP-02-CIS-LVL-2-KEY"
},
"SZ-TGT-LZP-SHARED_NETWORK-KEY": {
"name": "sz-tgt-lzp-shared-network",
"compartment_id": "CMP-LZP-NETWORK-KEY",
"recipe_key": "SZ-RCP-LZP-03-SHARED-NETWORK-KEY"
},
"SZ-TGT-LZP-P-SHARED-NETWORK-KEY": {
"name": "sz-tgt-lzp-environment-network",
"compartment_id": "CMP-LZP-P-NETWORK-KEY",
"recipe_key": "SZ-RCP-LZP-04-ENV-NETWORK-KEY"
},
"SZ-TGT-LZP-P-PROJ1-KEY": {
"name": "sz-tgt-lzp-proj1",
"compartment_id": "CMP-LZP-P-PROJ1-KEY",
"recipe_key": "SZ-RCP-LZP-05-WORKLOADS-KEY"
}
}
},
"scanning_configuration": {
"default_compartment_id": "CMP-LZP-SECURITY-KEY",
"host_recipes": {
"VSS-RECH-LZP-KEY": {
"name": "vss-rech-lzp",
"port_scan_level": "STANDARD",
"schedule_settings": {
"type": "WEEKLY",
"day_of_week": "SUNDAY"
},
"agent_settings": {
"scan_level": "STANDARD",
"vendor": "OCI",
"cis_benchmark_scan_level": "STRICT"
},
"file_scan_settings": {
"enable": true,
"scan_recurrence": "FREQ=WEEKLY;INTERVAL=2;WKST=SU",
"folders_to_scan": ["/"],
"operating_system": "LINUX"
}
}
},
"host_targets": {
"VSS-TGT-LZP-KEY": {
"name": "vss-tgt-lzp",
"target_compartment_id": "CMP-LANDINGZONE-P-KEY",
"host_recipe_id": "VSS-RECH-LZP-KEY"
}
}
},
"vaults_configuration": {
"default_compartment_id": "CMP-LZP-SECURITY-KEY",
"vaults": {
"VLT-LZP-SHARED-SECURITY-KEY": {
"name": "vlt-lzp-shared-security"
}
},
"keys": {
"KEY-LZP-OSS-AUDIT-BKT-KEY": {
"name": "key-lzp-oss-audit-bkt",
"protection_mode": "SOFTWARE",
"vault_key": "VLT-LZP-SHARED-SECURITY-KEY",
"service_grantees": ["objectstorage-eu-frankfurt-1"],
"group_grantees": ["grp-security-admins"],
"versions": ["1","2"]
}
}
}
}
Loading

0 comments on commit 97a30a1

Please sign in to comment.