5 ms·
Show HN: Fix – An open source cloud asset inventory for cloud security engineers
Hi, we’re Lukas, Lars and Matthias, and we're building “Fix” (https://fix.security https://fix.security). Fix is an open source cloud asset inventory for developers to track their infrastructure’s security posture aka “cloud security posture management” (CSPM).
How Fix works:
Fix takes a snapshot of your inventory on an hourly basis by calling the cloud APIs, runs policy and compliance checks such as the CIS benchmark against that inventory, and provides the findings in a dashboard, via .csv export or API so that developers can use the raw data and build workflows. We’re also working on data sync to S3 and RDBMS like Postgres, MySQL and Snowflake.
One of Fix’s unique feature is our graph-based inventory, highlighting the connections between resources. Unlike traditional cloud security tools that just list assets, Fix also displays their interconnections. We maintain a large graph, where nodes are indexed JSON documents representing your cloud resources, and different edges signify various dependencies. This allows flexible searches and policy creation using our search syntax.
For example:
Find large EC2 instances:
search is(aws_ec2_instance) and instance_cores > 8
Find unused EBS volumes with last reading IOPS more than 30d ago:
search is(aws_ec2_volume) and volume_status = available and last_access > 30d
Find IAM policies that are attached to users instead of groups or roles:
search is(aws_iam_user) {attached_policy: --> is(aws_iam_policy)} user_policies!=[] or attached_policy!=null
Find SNS topics that are not encrypted at rest using KMS CMKs:
search is(aws_sns_topic) with(empty, --> is(aws_kms_key))
We also have a CLI tool (https://github.com/someengineering/fixctl https://github.com/someengineering/fixctl) where you can use the raw json or yaml formatted results from the searches as an input into your pipelines. We also support full text search. For example, some developers like to tag their resources with their name:
search “lukas”
will produce a list of all resources that contain the string “lukas”.
Full text search comes in handy when you want find a particular string (e.g. an IP address) across all your cloud accounts to figure out which account and region a resource is located in.
There are existing security tools that use a graph, e.g. Wiz or Cisco with Lightspin (now Panoptica). Those enterprise tools have a few characteristics that we think make them less attractive for developers:
- They require talking to a sales rep
- They run you through a procurement process
- They try to lock you into their platform
Fix on the other hand is:
- self-service sign-up with a free tier
- available through the AWS Marketplace (coming soon)
- open source
We price Fix based on # of cloud accounts you collect data from, with a fair-usage limit of 200,000 (two hundred thousand) resources per account. Our lowest paid tier starts at $90 / month with three cloud accounts included.
Fix Security is built with our open source project “Fix Inventory”:
https://github.com/someengineering/fixinventory https://github.com/someengineering/fixinventory
The open source has richer functionality than our SaaS app. It's multi-cloud and supports AWS, GCP, Azure, DigitalOcean, VMWare and Kubernetes. Over time, our plan is to support all these platforms in our SaaS app as well.
Fix Inventory can update resources, including tags, and clean resources up based on age, usage, or policy non-compliance. Currently, this "mutating" function is not in the SaaS version. Fix Inventory is read-write, Fix Security is read-only.
Fix Inventory was born in D2iQ (now Nutanix). It was Lukas' solution to managing and securing a growing cloud infrastructure.
I would love your feedback on our solution. We’re here to help write your first queries. Just ping us on Discord (https://discord.gg/fixsecurity https://discord.gg/fixsecurity) and let us know you’re coming from HN. Also, I would love to hear what security tooling you use today and what you like / dislike about it.
Cheers
- scapecast 3y agowell my formatting sure as heck doesn't look great....
- jc_811 3y agoAny comparison to the other CSPM vendors out there? (Eg Wiz, Orca, etc)
- mdaniel 3y ago> We price Fix ;-) but, in seriousness > Currently, Fix Inventory can collect AWS, Google Cloud, DigitalOcean, VMWare Vsphere, OneLogin, and Slack resources That's kind of a weird mix of control planes, and it seems that Azure is actually present, just just not listed in the readme: https://github.com/someengineering/fixinventory/tree/4.0.1/plugins/azure#fix-plugin-azure https://github.com/someengineering/fixinventory/tree/4.0.1/p... (AGPLv3 for those interested in such things)
- lloesche 3y agoWe're currently working on Azure, but it's not stable enough to be listed here. > > AWS, Google Cloud, DigitalOcean, VMWare Vsphere, OneLogin, and Slack > kind of a weird mix of control planes :D agreed. Two of these things are not like the others. There are also Github, Posthog and Scarf plugins. To explain, Fix Inventory doesn't care about Cloud resources per se. It can create an inventory of whatever kind of resources. fixcore maintains a large graph of resources and makes them searchable. fixworker runs collector plugins and ships their results to the core. In theory you could build a plugin that monitors the sensors of your farm's greenhouses and run automations and reporting on them. Slack for instance is there because when you want to notify a user on Slack it makes it convenient to lookup their internal Slack ID based on e.g. their Email address. So you might do lookups like: AWS resource tag -> OneLogin User -> Email -> Slack UID.
- mdaniel 3y agoI dunno if this interests you, but you actually have influence over the formatting of https://github.com/someengineering/fix-cf/blob/main/fix-role-lambda.cf.template https://github.com/someengineering/fix-cf/blob/main/fix-role... via .gitattributes communicating to GH that it's actually yaml: https://github.com/github-linguist/linguist/blob/master/docs/overrides.md#using-gitattributes https://github.com/github-linguist/linguist/blob/master/docs...