Company
Date Published
Author
Toni de la Fuente
Word count
815
Language
English
Hacker News points
None

Summary

In a proof-of-concept initiative, Toni de la Fuente explores the integration of "breadcrumbs" in cloud security, focusing on Prowler's capability to trace original Infrastructure-as-Code (IaC) from deployed cloud objects by leveraging tags and metadata left by cloud deployments. By updating EC2 instances in an AWS environment and utilizing tools like Yor.io for auto-tagging Terraform resources, the approach aims to enhance transparency and ease for users by connecting deployed objects back to their codebase. The proof-of-concept introduces a new output format in Prowler, allowing users to access findings through a simple code path, and highlights the potential for further development using AI, such as OpenAI's model for suggesting code fixes. The project invites feedback and aims to transition from a proof-of-concept to a feature in Prowler's future versions, while also encouraging users to explore the various traces different cloud deployments leave, from Helm Charts in Kubernetes to CloudFormation in AWS.