Skip to content

A chalice API gateway wrapper around aws_ir. **Highly experimental**

License

Notifications You must be signed in to change notification settings

ThreatResponse/aws_ir-api

Repository files navigation

aws_ir-api

A chalice API gateway wrapper around aws_ir.
Highly experimental

Preparation

  1. Create a role to associate with the privileges in this api ( incident-pony-role.json Coming soon. )
  2. Deploy that role. Allow lambda.amazonaws.com to assumerole.
  3. Update aws_ir-api/.chalice/config.json with the new role ARN. If this deployment is for Ephemeral Systems Incident-Pony do nothing.
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "lambda.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

Getting Started with aws_ir-api

  1. Checkout aws_ir git submodule git submodule update
  2. Install the requirements for the chalice project pip install -r aws_ir-api/requirements.txt
  3. Install aws_ir requirements `pip install -r aws_ir-api/aws_ir/requirements.txt
  4. Run from within aws_ir-api chalice deploy

Testing the AWS_IR-api

  1. This is equipped with a variety of py.tests. You can run them by running py.test tests/ or live reload run using nose bin/nosetests --with-watch

Note: Some of these tests require explicit creation of "dummy users" in a testing account. See the section on CFN templates.

Setting up CloudFormation and boto3

In order to use the cloudformation stack templates in CFN folder you will need to set up two boto3 profiles. The default should be your ThreatResponse account credential for incident pony access and the second should be your "test" account mocking a user or consumer of the IR tool suite. The tests assume that this boto profile is a "named" profile for proper test coverage. The name should be "incident-account" do this by editing ~/.aws/credentials.

[default]
aws_access_key_id = AKIA***************
aws_secret_access_key = 19*******************************

[incident-account]
aws_access_key_id = AK*************************
aws_secret_access_key = Uzkb**************************

Testing instance provisioning

CloudFormation assumes that you're testing in us-west-2. You'll need an ssh keypair called incident-pony-response setup in the incident-accout. I store the private part of my keypair in Credstash.

About

A chalice API gateway wrapper around aws_ir. **Highly experimental**

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published