Skip to content

Centralize cloud and Kubernetes permission categorizations - #447

Merged
carlospolop merged 1 commit into
masterfrom
centralize-permission-categorizations
Oct 5, 2026
Merged

carlospolop merged 1 commit into
masterfrom
centralize-permission-categorizations

Conversation

@carlospolop

Copy link
Copy Markdown
Collaborator

CloudPEASS and Blue-CloudPEASS currently maintain separate permission data. Add one canonical YAML file for each of AWS, GCP, Azure, and Kubernetes so future severity edits can be made in HackTricks Cloud and synchronized by both consumers.

The cloud files preserve the existing catalogs, exact/regex rules, audited overrides, severity caps, excluded identifiers, and complete permission combinations. Kubernetes uses 68 ordered declarative rules covering API groups, subresources, verbs, and scope, including constrained impersonation. No executable expressions are stored in the files. Add an editing guide and a permission categorization page in each platform section, with the four severity levels explained in bullets.

The shared sync script validates all four inputs before writing, records SHA-256 hashes and source provenance, and generates compatibility lists for each consumer. Consumer workflows will synchronize weekly and on manual dispatch; unrelated book commits produce no update.

Validation: canonical schema validation and GitHub Actions lint pass; mdBook builds and the generated YAML files match their sources. The local build reports existing missing-tabs/search-size/footnote warnings. Consumer migration preserves ratings for more than 53,000 cloud permission identifiers and all 57,030 Kubernetes matrix cases, including Kubernetes descriptions. CloudPEASS full suite: 780 passed, 1 skipped; Blue-CloudPEASS full suite: 119 passed before the final sync fixture additions, with final tests rerun in the consumer PRs.

@carlospolop
carlospolop merged commit cfaea7f into master Oct 5, 2026
1 check passed
@carlospolop
carlospolop deleted the centralize-permission-categorizations branch October 5, 2026 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant