Zero Trust Access Drift
The Zero Trust Access fuzzer compares live Cloudflare Access state
(apps, policies, groups, service tokens) with what infrahive declares.
It catches drift terraform plan cannot see: dashboard-made
policies on managed apps, precedence squatting, orphan apps, declared
hosts with no Access app, and expiring service tokens. CFO runs it once
per scheduled run against plan.
Running
The fuzzer, exactly as CFO runs it (reads the token from Secret
Manager, impersonates hb-infra-dev-sa for GCP reads):
./zig/zig build fuzz -- zero_trust_driftThrough CFO, without the infra_drift plans. Results are merged
locally and not uploaded; add --upload only if you mean to
update devhive:
./zig/zig build scripts -- cfo --fuzzer zero_trust_driftThe audit itself, for local debugging (this is the command devhive
shows; add --pending-ref origin/<branch> to preview a
PR):
./zig/zig build scripts -- zero_trust_driftHow It Works
src/fuzz_tests/zero_trust_drift.py fetches
cloudflare-access-audit-read-token from
prj-c-secrets-a7cc as the ambient gcloud identity
(cfo-runner in CircleCI), then runs
src/scripts/zero_trust_drift/main.py --gcp gcloud --fail-on error
with the token and
CLOUDSDK_AUTH_IMPERSONATE_SERVICE_ACCOUNT=hb-infra-dev-sa@prj-b-seed-c80c.iam.gserviceaccount.com
set for the audit only. It prints the audit’s summary.md
into the task output.
The run fails when the audit reports an error finding,
when the audit crashes, or when any GCP lookup in
resolved/gcp_lookups.json is unresolved (so broken
impersonation cannot pass silently). warn findings never
fail it.
Results
is_critical: a failure makes CFO exit 1, so theCFO-scheduledCircleCI check on thatplancommit goes red.- Merge strategy
LATEST: devhive keeps only the newest run per branch, so the row clears on the next clean run. - The Command column shows
./zig/zig build scripts -- zero_trust_drift.
Source
src/fuzz_tests/zero_trust_drift.py(CFO wrapper)src/scripts/zero_trust_drift/(the audit)