GitHub

Zero Trust Access Drift

The Zero Trust Access fuzzer compares live Cloudflare Access state (apps, policies, groups, service tokens) with what infrahive declares. It catches drift terraform plan cannot see: dashboard-made policies on managed apps, precedence squatting, orphan apps, declared hosts with no Access app, and expiring service tokens. CFO runs it once per scheduled run against plan.

Running

The fuzzer, exactly as CFO runs it (reads the token from Secret Manager, impersonates hb-infra-dev-sa for GCP reads):

./zig/zig build fuzz -- zero_trust_drift

Through CFO, without the infra_drift plans. Results are merged locally and not uploaded; add --upload only if you mean to update devhive:

./zig/zig build scripts -- cfo --fuzzer zero_trust_drift

The audit itself, for local debugging (this is the command devhive shows; add --pending-ref origin/<branch> to preview a PR):

./zig/zig build scripts -- zero_trust_drift

How It Works

src/fuzz_tests/zero_trust_drift.py fetches cloudflare-access-audit-read-token from prj-c-secrets-a7cc as the ambient gcloud identity (cfo-runner in CircleCI), then runs src/scripts/zero_trust_drift/main.py --gcp gcloud --fail-on error with the token and CLOUDSDK_AUTH_IMPERSONATE_SERVICE_ACCOUNT=hb-infra-dev-sa@prj-b-seed-c80c.iam.gserviceaccount.com set for the audit only. It prints the audit’s summary.md into the task output.

The run fails when the audit reports an error finding, when the audit crashes, or when any GCP lookup in resolved/gcp_lookups.json is unresolved (so broken impersonation cannot pass silently). warn findings never fail it.

Results

  • is_critical: a failure makes CFO exit 1, so the CFO-scheduled CircleCI check on that plan commit goes red.
  • Merge strategy LATEST: devhive keeps only the newest run per branch, so the row clears on the next clean run.
  • The Command column shows ./zig/zig build scripts -- zero_trust_drift.

Source

  • src/fuzz_tests/zero_trust_drift.py (CFO wrapper)
  • src/scripts/zero_trust_drift/ (the audit)
Edit this page