Centralize cloud and Kubernetes permission categorizations - #447
Merged
Merged
Conversation
This was referenced Oct 5, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CloudPEASS and Blue-CloudPEASS currently maintain separate permission data. Add one canonical YAML file for each of AWS, GCP, Azure, and Kubernetes so future severity edits can be made in HackTricks Cloud and synchronized by both consumers.
The cloud files preserve the existing catalogs, exact/regex rules, audited overrides, severity caps, excluded identifiers, and complete permission combinations. Kubernetes uses 68 ordered declarative rules covering API groups, subresources, verbs, and scope, including constrained impersonation. No executable expressions are stored in the files. Add an editing guide and a permission categorization page in each platform section, with the four severity levels explained in bullets.
The shared sync script validates all four inputs before writing, records SHA-256 hashes and source provenance, and generates compatibility lists for each consumer. Consumer workflows will synchronize weekly and on manual dispatch; unrelated book commits produce no update.
Validation: canonical schema validation and GitHub Actions lint pass; mdBook builds and the generated YAML files match their sources. The local build reports existing missing-tabs/search-size/footnote warnings. Consumer migration preserves ratings for more than 53,000 cloud permission identifiers and all 57,030 Kubernetes matrix cases, including Kubernetes descriptions. CloudPEASS full suite: 780 passed, 1 skipped; Blue-CloudPEASS full suite: 119 passed before the final sync fixture additions, with final tests rerun in the consumer PRs.