chore: edited config.yaml for universal use cases, +readme.md
This commit is contained in:
31
README.md
31
README.md
@@ -0,0 +1,31 @@
|
|||||||
|
# Hydrogen
|
||||||
|
**Lightweight, extensible server security auditing — from a single YAML file.**
|
||||||
|
|
||||||
|
Hydrogen runs your security checks concurrently, evaluates severity, and delivers reports wherever you need them — disk, webhook, or your own custom transport. Focused on extensibility, built for your server.
|
||||||
|
|
||||||
|
### Why Hydrogen?
|
||||||
|
- **Extensible by design** — modules, renderers, and transports are all plugins. Write a Python class, drop it in, it works.
|
||||||
|
- **Concurrent by default** — checks run in parallel with configurable concurrency.
|
||||||
|
- **Multiple outputs** — JSON to disk _and_ a webhook to your SIEM? One config line each.
|
||||||
|
- **CI-native** — `strict_mode` + severity thresholds produce a clean exit code for your pipeline.
|
||||||
|
|
||||||
|
### Quick start
|
||||||
|
```sh
|
||||||
|
git clone https://github.com/agonyecho/hydrogen && cd hydrogen
|
||||||
|
pip install -e . # Installs hydrogen as local package
|
||||||
|
hydrogen -c config.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
or
|
||||||
|
|
||||||
|
```sh
|
||||||
|
git clone https://github.com/agonyecho/hydrogen && cd hydrogen
|
||||||
|
python -m venv venv && source ./venv/bin/activate && pip install -r requirements.txt
|
||||||
|
python main.py -c config.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
### Docs
|
||||||
|
- [Configuration](HYDROGEN_CONFIGURATION.md) — every YAML knob explained
|
||||||
|
- [Writing modules](HYDROGEN_SECURITY_MODULES.md) — `MANIFEST`, `build_worker`, `CONFIG_MODEL`
|
||||||
|
- [Writing transports](HYDROGEN_TRANSPORTS.md) — deliver reports anywhere
|
||||||
|
- [Writing renderers](HYDROGEN_RENDERERS.md) — JSON, Markdown, or your own format
|
||||||
|
|||||||
26
config.yaml
26
config.yaml
@@ -1,4 +1,3 @@
|
|||||||
## Script Behavior
|
|
||||||
exclude_categories: []
|
exclude_categories: []
|
||||||
fail_fast: false
|
fail_fast: false
|
||||||
dry_run: false
|
dry_run: false
|
||||||
@@ -8,30 +7,19 @@ logging:
|
|||||||
level: INFO
|
level: INFO
|
||||||
output: stdout
|
output: stdout
|
||||||
|
|
||||||
plugin_packages:
|
strict_mode: false
|
||||||
renderers:
|
allow_failures_below: critical
|
||||||
- reporting.exporters
|
|
||||||
transports:
|
|
||||||
- reporting.transports
|
|
||||||
modules: []
|
|
||||||
|
|
||||||
## Compliance
|
|
||||||
strict_mode: true # True - exits with code 1, triggering the CI response, False - exits with code: 0.
|
|
||||||
allow_failures_below: medium
|
|
||||||
|
|
||||||
## Reports
|
|
||||||
reports:
|
reports:
|
||||||
outputs:
|
outputs:
|
||||||
- renderer:
|
- renderer:
|
||||||
type: json
|
type: json
|
||||||
transport:
|
transport:
|
||||||
type: webhook
|
type: file
|
||||||
url: http://localhost:5000/webhook
|
path: reports/latest
|
||||||
method: POST
|
append_extension: true
|
||||||
payload_mode: rendered
|
|
||||||
|
|
||||||
## Module Specific Configuration
|
modules:
|
||||||
modules:
|
|
||||||
ssh:
|
ssh:
|
||||||
enabled: true
|
enabled: true
|
||||||
test-failure: true
|
test-failure: false
|
||||||
|
|||||||
@@ -59,7 +59,7 @@ class BaseTransport(ABC):
|
|||||||
|
|
||||||
|
|
||||||
class TypedTransport(BaseTransport, Generic[TReportTransport], ABC):
|
class TypedTransport(BaseTransport, Generic[TReportTransport], ABC):
|
||||||
config_model: type[TReportTransport] # type: ignore
|
config_model: type[TReportTransport] # type: ignore
|
||||||
|
|
||||||
def publish(self, rendered_report: RenderedReport, transport: ResolvedPluginConfig) -> str:
|
def publish(self, rendered_report: RenderedReport, transport: ResolvedPluginConfig) -> str:
|
||||||
if not isinstance(transport.config, self.config_model):
|
if not isinstance(transport.config, self.config_model):
|
||||||
|
|||||||
@@ -142,9 +142,7 @@ class SystemdWorker(BaseWorker):
|
|||||||
|
|
||||||
return findings
|
return findings
|
||||||
|
|
||||||
def _check_unit_permissions(
|
def _check_unit_permissions(self, unit: Path, findings: list[AuditFindings]) -> None:
|
||||||
self, unit: Path, findings: list[AuditFindings]
|
|
||||||
) -> None:
|
|
||||||
stat = unit.stat()
|
stat = unit.stat()
|
||||||
if stat.st_uid != 0:
|
if stat.st_uid != 0:
|
||||||
findings.append(
|
findings.append(
|
||||||
|
|||||||
Reference in New Issue
Block a user