Skip to content

feat(scanner): propose enterprise Supply Chain security pack — Container Registry + Terraform state exposure #214

Description

@TFT444

Summary

Part of the A03 Software Supply Chain Failures gap tracked in #213. This is the piece that's ready to build now — no new credential/auth work required, only a new SDK dependency.

Adds a new Supply Chain rule category (AZ-SC-*) covering Azure Container Registry hardening and Terraform/IaC state exposure.

Rules

Container Registry (4 rules) — needs azure-mgmt-containerregistry (new dependency, not currently in requirements.txt). All four properties below are confirmed real and SDK-readable against Microsoft's own Registry/RegistryProperties model docs:

  1. Admin user enabled on ACR — admin_user_enabled true creates a shared, non-attributable credential outside RBAC.
  2. ACR allows public network access — public_network_access == "Enabled".
  3. ACR allows anonymous pull — anonymous_pull_enabled true lets any network client pull every image with no authentication; per PSRule's Azure.ACR.AnonymousAccess, repository-scoped tokens can't limit this once it's on.
  4. ACR has no image retention/quarantine policy — no automated cleanup of untrusted or stale images.

Terraform/IaC state exposure (2 rules) — reuses azure-mgmt-storage, already a dependency, at the per-container level instead of the per-account level checked today:

  1. Public Terraform state container — a blob container matching a tfstate/terraform name pattern has public_access != "None".
  2. State container has no versioning/soft-delete — a corrupted or overwritten state file can't be recovered.

Notes / caveats to design around

  • PSRule's anonymous-pull rule documents a known false-positive case: registries intentionally used for public OCI distribution. The rule should allow this to be an explicit, documented exception rather than a hard fail.
  • Follows the existing scanner/rules/_enterprise_resilience_common.py shared-evaluator pattern established in the PR feat(scanner): add Azure enterprise resilience security packs #198 enterprise resilience rule packs.

Out of scope (tracked separately)

Azure DevOps pipeline/service-connection exposure — see the linked follow-up issues, since that requires a new credential type against dev.azure.com rather than Azure Resource Manager.

Acceptance criteria

  • azure-mgmt-containerregistry added to requirements.txt
  • 6 new rule files under scanner/rules/az_sc_*.py following the standard rule template
  • New Supply Chain category added to cis_azure_benchmark.json, nist_csf.json, iso27001.json, soc2.json
  • Matching playbooks under playbooks/cli/
  • Unit tests covering compliant/non-compliant/indeterminate (API failure) paths for each rule
  • docs/rules-reference.md and docs/adding-a-rule.md updated

Parent issue: #213

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

coreCore team ownership not for studentsenhancementNew feature or requestnew-ruleAdding a new misconfiguration scan rule

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions