cloud-custodian / cloud-custodian/community
Vulnerable App Before, Secure Env After with c7n
- Dominant language
- Shell
- Stars
- 10
- Forks
- 5
- PR merge metrics
- No merged PRs in 30d
Description
Hello @castrojo, during @LiamRandall's Governance-as-Code day talk this afternoon, I suggested an interesting community project would be Liam's vulnerable app and cloud deployment, the PeopleFacts app, or similar projects like [flaws.cloud](https://flaws.cloud), [flaws2.cloud](https://flaws2.cloud), or [cloudgoat](https://github.com/RhinoSecurityLabs/cloudgoat) with a focus on detection and protection with c7n tooling. We can take one of these sample environments with a before and after theme, and the after theme being an assessment with recommended c7n rules to prevent breach.
I am willing to commit some time to this project starting in November and the months following. Let me know how I would need to formulate a plan for review by c7n core devs and/or community members that are here, get buy-in and support for such a plan. If there is limited interest, I can work on it as a separate personal project and update on status here.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.