chore: edited config.yaml for universal use cases, +readme.md
This commit is contained in:
31
README.md
31
README.md
@@ -0,0 +1,31 @@
|
||||
# Hydrogen
|
||||
**Lightweight, extensible server security auditing — from a single YAML file.**
|
||||
|
||||
Hydrogen runs your security checks concurrently, evaluates severity, and delivers reports wherever you need them — disk, webhook, or your own custom transport. Focused on extensibility, built for your server.
|
||||
|
||||
### Why Hydrogen?
|
||||
- **Extensible by design** — modules, renderers, and transports are all plugins. Write a Python class, drop it in, it works.
|
||||
- **Concurrent by default** — checks run in parallel with configurable concurrency.
|
||||
- **Multiple outputs** — JSON to disk _and_ a webhook to your SIEM? One config line each.
|
||||
- **CI-native** — `strict_mode` + severity thresholds produce a clean exit code for your pipeline.
|
||||
|
||||
### Quick start
|
||||
```sh
|
||||
git clone https://github.com/agonyecho/hydrogen && cd hydrogen
|
||||
pip install -e . # Installs hydrogen as local package
|
||||
hydrogen -c config.yaml
|
||||
```
|
||||
|
||||
or
|
||||
|
||||
```sh
|
||||
git clone https://github.com/agonyecho/hydrogen && cd hydrogen
|
||||
python -m venv venv && source ./venv/bin/activate && pip install -r requirements.txt
|
||||
python main.py -c config.yaml
|
||||
```
|
||||
|
||||
### Docs
|
||||
- [Configuration](HYDROGEN_CONFIGURATION.md) — every YAML knob explained
|
||||
- [Writing modules](HYDROGEN_SECURITY_MODULES.md) — `MANIFEST`, `build_worker`, `CONFIG_MODEL`
|
||||
- [Writing transports](HYDROGEN_TRANSPORTS.md) — deliver reports anywhere
|
||||
- [Writing renderers](HYDROGEN_RENDERERS.md) — JSON, Markdown, or your own format
|
||||
|
||||
24
config.yaml
24
config.yaml
@@ -1,4 +1,3 @@
|
||||
## Script Behavior
|
||||
exclude_categories: []
|
||||
fail_fast: false
|
||||
dry_run: false
|
||||
@@ -8,30 +7,19 @@ logging:
|
||||
level: INFO
|
||||
output: stdout
|
||||
|
||||
plugin_packages:
|
||||
renderers:
|
||||
- reporting.exporters
|
||||
transports:
|
||||
- reporting.transports
|
||||
modules: []
|
||||
strict_mode: false
|
||||
allow_failures_below: critical
|
||||
|
||||
## Compliance
|
||||
strict_mode: true # True - exits with code 1, triggering the CI response, False - exits with code: 0.
|
||||
allow_failures_below: medium
|
||||
|
||||
## Reports
|
||||
reports:
|
||||
outputs:
|
||||
- renderer:
|
||||
type: json
|
||||
transport:
|
||||
type: webhook
|
||||
url: http://localhost:5000/webhook
|
||||
method: POST
|
||||
payload_mode: rendered
|
||||
type: file
|
||||
path: reports/latest
|
||||
append_extension: true
|
||||
|
||||
## Module Specific Configuration
|
||||
modules:
|
||||
ssh:
|
||||
enabled: true
|
||||
test-failure: true
|
||||
test-failure: false
|
||||
|
||||
@@ -142,9 +142,7 @@ class SystemdWorker(BaseWorker):
|
||||
|
||||
return findings
|
||||
|
||||
def _check_unit_permissions(
|
||||
self, unit: Path, findings: list[AuditFindings]
|
||||
) -> None:
|
||||
def _check_unit_permissions(self, unit: Path, findings: list[AuditFindings]) -> None:
|
||||
stat = unit.stat()
|
||||
if stat.st_uid != 0:
|
||||
findings.append(
|
||||
|
||||
Reference in New Issue
Block a user