Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
227 commits
Select commit Hold shift + click to select a range
2c856d7
Adds developer tooling
jvanderhoof Jun 27, 2018
dc11e72
Merge pull request #3 from conjurdemos/start-stop-cli
infamousjoeg Jun 27, 2018
f7bcf99
Initial work on IAM authenticator demo
jvanderhoof Jul 16, 2018
7499b43
Update the README
jvanderhoof Jul 16, 2018
2458349
Standardize the account name as `demo`
jvanderhoof Jul 18, 2018
729532d
Initial work to build an auto-failover cluster
jvanderhoof Aug 11, 2018
1e37055
WIP Add Mutual TLS example for Conjur CA signing
micahlee Aug 20, 2018
0ad2f53
Finish initial end to end demo
micahlee Aug 20, 2018
2409a4c
Update demo to use POST instead of PUT for CA requests
micahlee Aug 22, 2018
5ac7b92
Update server certificate request to get PEM format directly from API
micahlee Aug 22, 2018
cce527c
Update certificate request to use latest endpoint
micahlee Aug 22, 2018
ef8a39e
Clean up demo scripts and README for smoother flow
micahlee Aug 22, 2018
d94094c
Merge pull request #6 from conjurdemos/ca_mutual_tls
jvanderhoof Aug 23, 2018
0b6cd2a
Initial Readme
jvanderhoof Aug 29, 2018
3c2892f
Adds a script which brings up a simple Conjur Cluster
jvanderhoof Sep 12, 2018
2c15fe3
Merge pull request #8 from conjurdemos/cluster
jvanderhoof Sep 12, 2018
080670a
Fix docker-compose image target
sgnn7 Sep 12, 2018
7eb82fa
Merge pull request #9 from sgnn7/patch-1
jvanderhoof Sep 13, 2018
57e0f28
Update Conjur image path to full path
jvanderhoof Sep 13, 2018
ec126f9
Update mutual TLS demo to use latest released Conjur version
micahlee Sep 18, 2018
b6af957
Update README.md
jvanderhoof Sep 20, 2018
bf57b5c
Update README.md
jvanderhoof Sep 20, 2018
97321ad
Small cleanup
jvanderhoof Sep 20, 2018
1734bed
Overview of current PS cluster setup playbook
jvanderhoof Sep 26, 2018
a479ad0
tool to generate certificates
jvanderhoof Sep 26, 2018
694a403
Rework certificate generator to make it more flexible
jvanderhoof Sep 28, 2018
9d8ea43
Ignore the generated folders and files
jvanderhoof Sep 28, 2018
25abb05
Added Readme
jvanderhoof Sep 28, 2018
d458bec
Small clarifications
jvanderhoof Sep 28, 2018
d2f36bb
Merge pull request #10 from conjurdemos/custom-certs
jvanderhoof Sep 28, 2018
8bf0aa0
Update README.md
jvanderhoof Sep 28, 2018
98c824e
Added the ability to set additional altnames
jvanderhoof Sep 29, 2018
f4da600
Merge pull request #11 from conjurdemos/custom-certs
jvanderhoof Sep 29, 2018
3e25df9
Update README.md
jvanderhoof Sep 29, 2018
4d16c4a
Adds a more modular set of policy files
jvanderhoof Oct 5, 2018
aefbc0d
Adds ability to install branch packages
jvanderhoof Oct 17, 2018
8f4a8eb
Merge pull request #12 from conjurdemos/installer
jvanderhoof Oct 18, 2018
1ddc6e8
Add 3rd part cert and master key options
jvanderhoof Oct 18, 2018
049aab9
Resolved final set of bad stash pop collisions
jvanderhoof Oct 18, 2018
93c6834
Merge pull request #13 from conjurdemos/cert-and-encrypted-cluster
jvanderhoof Oct 18, 2018
70eda6d
Update README.md
jvanderhoof Oct 18, 2018
8cc4506
Update README.md
jvanderhoof Oct 18, 2018
07dc5be
Added Flags to specify the appliance version
jvanderhoof Oct 18, 2018
36ef6f7
Adds required policy groups
jvanderhoof Oct 18, 2018
66cf775
Update README.md
jvanderhoof Oct 23, 2018
70799da
Update README.md
jvanderhoof Oct 23, 2018
41ca67f
expose syslog port
jvanderhoof Nov 1, 2018
403b090
strange hack that seems to be needed for audit logs to appear...
jvanderhoof Nov 1, 2018
3e4b459
Updates to support auto-failover
jvanderhoof Oct 19, 2018
51af553
tweaks to add auto-failover
jvanderhoof Oct 24, 2018
50b36a6
automatically accept cert
jvanderhoof Oct 24, 2018
944b2bd
Tweaks to support querying a follower
jvanderhoof Oct 29, 2018
06793e8
Adds the ability to pass a Conjur version
jvanderhoof Oct 29, 2018
c557ee1
remove port from follower client appliance url
Oct 31, 2018
76245f6
wait to enroll the master until all the standbys are configured, use …
Nov 2, 2018
0335b0b
Removed extra key encryption step
jvanderhoof Nov 2, 2018
a47281c
Merge pull request #14 from conjurdemos/auto-failover
jvanderhoof Nov 2, 2018
93e40cf
Updates to support auto-failover
jvanderhoof Oct 19, 2018
7b4c376
Update cert generate to include a load balancer
jvanderhoof Nov 1, 2018
2745930
updated certs, including config for a load balancer
jvanderhoof Nov 1, 2018
d45c0da
start working on load balancer
jvanderhoof Nov 1, 2018
c21c18f
port fix & updates to haproxy config
jvanderhoof Nov 2, 2018
68d7234
temp work
jvanderhoof Nov 2, 2018
dc4ecf2
updates to add a load balancer
jvanderhoof Nov 6, 2018
39c2b5d
Merge pull request #15 from conjurdemos/load-balancer
jvanderhoof Nov 6, 2018
256cda6
Update README.md
jvanderhoof Nov 6, 2018
956f68e
Revert "Adds Load balancer in front of cluster"
jvanderhoof Nov 6, 2018
9ad6cf4
Merge pull request #16 from conjurdemos/revert-15-load-balancer
jvanderhoof Nov 6, 2018
3a9b0df
Add initial framework for LDAP demo modeled after the simple cluster
micahlee Nov 6, 2018
62141bd
Implement ldap sync with non-TLS connection
micahlee Nov 7, 2018
acee80f
Ignore DS_Store files
micahlee Nov 7, 2018
7853420
Switch ldap integration demo to use TLS
micahlee Nov 7, 2018
0e2e2a4
Merge pull request #18 from conjurdemos/ldap-integration-demo
jvanderhoof Nov 13, 2018
a8d115f
Added Vim swapfiles to gitignore
sgnn7 Nov 15, 2018
1085e92
Modifed the cert generator to be able to build large-length chains
sgnn7 Nov 15, 2018
848011f
Added ability to specify desired leaf nodes to generate_certificate
sgnn7 Nov 19, 2018
71b0867
Updated README for simple-certificate generator
sgnn7 Nov 19, 2018
2900728
Merge pull request #20 from conjurdemos/19-long-cert-chains
micahlee Nov 19, 2018
06a9876
Update LDAP demo to use secure LDAP authentication
micahlee Nov 15, 2018
9a56d79
Correct variable names to match latest LDAP updates
micahlee Nov 16, 2018
4b9b9dd
Made ldap-integration compose forward the LDAP ports to host
sgnn7 Nov 19, 2018
b6d116e
Added real certificates to LDAP integration demo
sgnn7 Nov 19, 2018
f7e3477
Use TLS for LDAP sync and authn
micahlee Nov 19, 2018
c177c4b
Merge pull request #21 from conjurdemos/secure-ldap-authentication
sgnn7 Nov 19, 2018
3dda128
Updated the ldap-integration appliance image to 5.0-stable
sgnn7 Nov 21, 2018
0388529
Updated ldap integration start script to work with newest Docker
sgnn7 Nov 21, 2018
da70b23
Merge pull request #26 from conjurdemos/update-ldap-integration-image
micahlee Nov 21, 2018
2900f34
Include LDAP Integration demo in root README
micahlee Nov 21, 2018
83abbe6
Merge pull request #27 from conjurdemos/25-update-readme
sgnn7 Nov 27, 2018
fca4665
Updated CLI container version
jvanderhoof Nov 15, 2018
98afb83
added an example of an ID with escapable characters
jvanderhoof Dec 12, 2018
0dea6f5
Added final steps to demo generic resource creation
jvanderhoof Jan 8, 2019
946fbd0
Tweaks to the ldap-integration demo to insure the admin user can log in
jvanderhoof Jan 10, 2019
432b66f
Cert generator now auto-detects custom domains and limits CN to 64 chars
sgnn7 Jan 30, 2019
616edb2
Merge pull request #29 from conjurdemos/add-ability-to-change-domain
sgnn7 Jan 31, 2019
fdd6a78
Add AWS Cluster demo
micahlee Jan 31, 2019
c4e74c9
Merge pull request #30 from conjurdemos/demo-aws-cluster
jvanderhoof Feb 1, 2019
1ff965f
Added a simple policy creation/setter/watcher for v5 appliance
sgnn7 Jan 28, 2019
8ea8be5
Merge pull request #28 from conjurdemos/simple-policy-fetch-and-set
sgnn7 Feb 5, 2019
ba5bfe2
Add demo and utility scripts for AWS
micahlee Feb 6, 2019
bdb4a44
Add output information for init_cluster in AWS demo
micahlee Feb 6, 2019
d085650
Correct formatting typo in AWS demo README
micahlee Feb 6, 2019
99be56f
Add followers to AWS Cluster demo
micahlee Mar 8, 2019
cbc3e47
Updated script to support custom config
jvanderhoof May 6, 2019
6e9dcb3
combined cluster examples
jvanderhoof May 10, 2019
406dc72
removed vagrant folder
jvanderhoof May 10, 2019
45b71e3
Ingore vagrant folder
jvanderhoof May 10, 2019
9de30b3
Update README.md
jvanderhoof May 10, 2019
3d56f9e
Updated demo list
jvanderhoof May 10, 2019
b3d9a49
Added a sample policy with duplicate web-services
jvanderhoof May 14, 2019
949397b
Added a sample policy for replicating a UI bug
jvanderhoof May 14, 2019
6262b5e
Update AWS cluster demo to support latest Terraform version
micahlee Jul 30, 2019
5eb25e4
Update demo scripts to accept EULA when configuring master nodes
micahlee Jul 30, 2019
90edbaf
Merge pull request #39 from conjurdemos/38-eula-acceptance
micahlee Jul 30, 2019
734c273
Handle the conjur-intro PS upgrade to 9.4.
nahumcohen Aug 26, 2019
62c1246
Add Apache 2.0 license to repo
Sep 13, 2019
dd19000
Adding gitleaks config file
Sep 13, 2019
c0cb878
Merge pull request #41 from conjurdemos/add-license
sgnn7 Sep 14, 2019
9f7db78
Minor fix to the client and client-follower
shaharglazner Oct 29, 2019
8237908
Fix typo in README
micahlee Nov 19, 2019
ddd58e8
Add option to use -t flag in cluster demo
Dec 11, 2019
faab6a6
Merge pull request #43 from conjurdemos/add-tag-option
sgnn7 Dec 11, 2019
7ae2efe
Update Copyright
JakeQuilty Jan 3, 2020
be95080
Merge pull request #44 from JakeQuilty/patch-1
JakeQuilty Jan 6, 2020
1741160
Revamped script location and updated and expanded docs
jvanderhoof Jan 9, 2020
afc2b36
reverted the entrypoint to the original one
shaharglazner Jan 21, 2020
738f0f1
revert unintended changes
shaharglazner Jan 21, 2020
8742506
Merge pull request #42 from conjurdemos/bugfix/clients-docker-compose
micahlee Jan 21, 2020
5c40b8d
adding Java SDK client example and scripts to run it on openshift
ofiraburstein Feb 17, 2020
b69e304
Update to allow custom seccomp for docker-compose (#47)
h-artzi Feb 19, 2020
595525a
Merge pull request #46 from conjurdemos/OCP_installer_and_java_test
oburstein-hub Feb 20, 2020
9da0d3d
Add bug and feature request issue templates
JakeQuilty Feb 25, 2020
579b94f
Change the password for this demo to use new complexity requirements
sgnn7 Feb 26, 2020
d758681
Merge pull request #49 from conjurdemos/fix-cluster-demo
sgnn7 Feb 26, 2020
09378d2
Merge pull request #48 from conjurdemos/add-issue-templates
JakeQuilty Feb 27, 2020
7b358ef
fixing bug causing postgres failure when running with different proje…
ofiraburstein Mar 4, 2020
aed5c96
Improved the readability of the Conjur OpenShift demo README file
rafis3 Mar 4, 2020
924ce9e
Merge pull request #51 from conjurdemos/OCP_installer_and_java_test
oburstein-hub Mar 4, 2020
f388f8d
Merge pull request #50 from conjurdemos/openshift-install-readme-fixes
sgnn7 Mar 4, 2020
e5af2db
adding interactive mode to scripts + turning java installer to single…
ofiraburstein Mar 5, 2020
4b43ae2
Merge pull request #52 from conjurdemos/OCP_installer_and_java_test
oburstein-hub Mar 5, 2020
d6577c7
Update admin account password
jvanderhoof Mar 5, 2020
10a0042
Resolves merge conflicts
jvanderhoof Mar 5, 2020
9a2143e
Adding Secret Retrieval for demo
ofiraburstein Mar 9, 2020
289805a
Merge pull request #53 from conjurdemos/OCP_installer_and_java_test
oburstein-hub Mar 9, 2020
022a542
Add bug and feature request issue templates
JakeQuilty Feb 25, 2020
e334707
Merge branch 'master' into add-issue-templates
JakeQuilty Mar 10, 2020
78b40d4
Merge pull request #54 from conjurdemos/add-issue-templates
JakeQuilty Mar 10, 2020
0979066
Add CONTRIBUTING and link to it from README
Mar 16, 2020
807c50b
Merge pull request #55 from conjurdemos/30-add-contributing
Mar 17, 2020
daf3680
Fix postgres container initialization (postgres>9.4).
Mar 25, 2020
b42fb1b
Remove sudo/root requirements to run the demo.
Mar 25, 2020
2d9f591
Merge pull request #56 from jcosteatcyberark/fix/mutual-tls-demo-post…
sgnn7 Mar 27, 2020
a137e9f
Merge pull request #57 from jcosteatcyberark/fix/mutual-tls-demo-remo…
sgnn7 Mar 27, 2020
4318322
Fix 'Can't load /root/.rnd into RNG' error.
Mar 27, 2020
e5216f0
Merge pull request #58 from JfcAtCyberArk/master
sgnn7 Mar 27, 2020
38e54f5
Update start script to include non-HTTPS health port and logs
jvanderhoof Apr 3, 2020
e0332e1
Enables two additional kernel related system commands
jvanderhoof Apr 9, 2020
fd0d780
Removed reference to Conjur
jvanderhoof Apr 9, 2020
5838bc8
update seccomp file to include required sys calls (#59)
h-artzi Apr 14, 2020
2d6eeaa
provide examples for setting database connection information
jvanderhoof Apr 15, 2020
8e8b4ea
Jmeter performance test (#60)
h-artzi May 15, 2020
5148fb0
Moved JMeter tests into tools folder and linked from project root
jvanderhoof May 15, 2020
8b54461
"Update issue template"
JakeQuilty Jun 15, 2020
29822cf
Merge pull request #65 from conjurdemos/update-bug-template-10
Jun 15, 2020
069eb70
Update Jave API Client to use Maven Central dependency
BradleyBoutcher Jun 23, 2020
a72bfac
Merge pull request #66 from conjurdemos/java-api-client-maven
sgnn7 Jun 24, 2020
bd7a1f1
Adds multi-configuration support (#68)
jvanderhoof Jul 17, 2020
7cd43de
Adds policy loading
jvanderhoof Aug 5, 2020
4c87042
Adds backup, restore & upgrade functionality
jvanderhoof Aug 5, 2020
0e7f3dc
adds a flag for fixing the 11.6.0 backup/restore upgrade path
jvanderhoof Aug 7, 2020
af2bf68
fix main.tf to work with latest TF
Aug 11, 2020
dbbf7d8
fix jq with latest TF
Aug 11, 2020
52e2775
remove aws vars from main.tf
Aug 13, 2020
4fca63a
upadte README to include AWS env vars section
Aug 13, 2020
b23272c
remove AWS env vars
Aug 13, 2020
2b09c0b
Merge pull request #70 from guygiat/terraform-fix
guygiat Aug 13, 2020
9bb208a
Proposed changes to CLI to support manual testing (#71)
jvanderhoof Sep 15, 2020
7c92004
Update restore to pull the latest backup
jvanderhoof Sep 15, 2020
13ae19c
update seccomp file location
h-artzi Sep 11, 2020
3457541
Merge pull request #72 from conjurdemos/seccomp-location-update
micahlee Sep 21, 2020
b4d3a77
Update docs to use bin/cli instead of cli
jvanderhoof Sep 21, 2020
7c19624
Merge pull request #74 from conjurdemos/cli-fix
Sep 21, 2020
8bf0678
Add `jq` to API client container image
micahlee Oct 7, 2020
94af950
Reference the master LB rather than the specific DAP node
micahlee Oct 7, 2020
123902b
Merge pull request #77 from conjurdemos/cleanups
sgnn7 Oct 7, 2020
1c28977
Fixing jq
andresguisado Oct 14, 2020
9cbde8e
Merge pull request #79 from conjurdemos/terraform-fix
guygiat Oct 14, 2020
db23bc1
Fix broken validating packages scripts
JakeQuilty Oct 8, 2020
92ea267
Merge pull request #78 from conjurdemos/fix-validating-packages-scripts
JakeQuilty Nov 17, 2020
3c0641a
Adds support for Seed Service and Role visibility (#81)
jvanderhoof Nov 30, 2020
2679d65
Update dap
doodlesbykumbi Dec 3, 2020
af92cad
Update README.md
doodlesbykumbi Dec 3, 2020
bd02747
Update ./tools/simple-policy-test-v5/README.md
doodlesbykumbi Dec 3, 2020
8fa4e20
Certificates are generated prior to import (#75)
jvanderhoof Dec 14, 2020
fe73771
Add upgrade test script
micahlee Nov 25, 2020
61a373a
Merge pull request #80 from conjurdemos/upgrade-test
micahlee Dec 15, 2020
ef9b09f
Adds End-to-End testing for a DAP release (#85)
jvanderhoof Dec 17, 2020
0bdcbe6
Remove old networks before creating DAP network
jvanderhoof Dec 17, 2020
1b24662
Merge pull request #83 from conjurdemos/doodlesbykumbi-patch-1
Jan 4, 2021
a4ecdbd
cleanup: Fix shellcheck reports
micahlee Feb 9, 2021
f1dafce
Add final newline to curl output
micahlee Feb 9, 2021
45a3d82
Allow health checks to work with older DAP versions
micahlee Feb 9, 2021
be8e952
Add certificate generator support for rotation
micahlee Feb 9, 2021
5b35012
Add dap intro option to rotate node certificates
micahlee Feb 9, 2021
6d215d7
Separate key and certificate generation
micahlee Feb 10, 2021
3e69401
Correct the CA chain certificate order
micahlee Feb 10, 2021
0341bad
Merge pull request #88 from conjurdemos/195-certificate-rotation-testbed
micahlee Feb 11, 2021
09a96be
Updated start script to not allocate tty
telday Feb 19, 2021
92c2195
Merge pull request #90 from telday/master
diverdane Feb 23, 2021
772dd7b
Add pre-generated DH params
garymoon Mar 25, 2021
2d3802a
Add a Jenkinsfile to enable upgrades
garymoon Mar 25, 2021
abc30c0
Merge pull request #91 from conjurdemos/add-dhparams
h-artzi Mar 25, 2021
5f239e9
Add a Jenkinsfile (#92)
garymoon Mar 31, 2021
19c1e9e
Update java-api-client dependencies and plugins to latest versions
andytinkham Jun 8, 2022
8509d80
Merge pull request #96 from conjurdemos/update-java-example-dependencies
andytinkham Jun 9, 2022
626086b
Podman updates
jvanderhoof Dec 27, 2021
83ef9c6
Merge pull request #95 from conjurdemos/podman-rhel-update
ajay-vel Jun 13, 2022
50ebced
Bump tzinfo from 1.2.8 to 2.0.5
dependabot[bot] Jul 22, 2022
133865b
Merge pull request #98 from conjurdemos/dependabot/bundler/tzinfo-2.0.5
andytinkham Jul 22, 2022
bb29179
Updated image registry name
andytinkham Jul 25, 2022
25101ec
Merge pull request #99 from conjurdemos/clean-registry-names
andytinkham Jul 26, 2022
f8b90ad
Fix upgrade test
micahlee Jun 24, 2022
1e65787
Merge pull request #100 from conjurdemos/fix-upgrade-test
micahlee Aug 11, 2022
7338675
Update upgrade test to allow for upgrade paths
micahlee Aug 19, 2022
8c61b5e
Merge pull request #101 from conjurdemos/upgrade-test-multiple-versions
micahlee Aug 19, 2022
654a9bd
Example of a synchronizer "audit" role
jvanderhoof Aug 22, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 42 additions & 0 deletions .github/ISSUE_TEMPLATE/bug.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
---
name: Bug
about: Create a bug report to help us improve
title: ''
labels: component/demos, kind/bug
assignees: ''

---

## Summary
A clear and concise description of what the bug is.

## Steps to Reproduce
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

## Expected Results
A clear and concise description of what you expected to happen.

## Actual Results (including error logs, if applicable)
A clear and concise description of what actually did happen.

## Reproducible
* [ ] Always
* [ ] Sometimes
* [ ] Non-Reproducible

## Version/Tag number
What version of the product are you running? Any version info that you can share is helpful.
For example, you might give the version from Docker logs, the Docker tag, a specific download URL,
the output of the `/info` route, etc.

## Environment setup
Can you describe the environment in which this product is running? Is it running on a VM / in a container / in a cloud?
Which cloud provider? Which container orchestrator (including version)?
The more info you can share about your runtime environment, the better we may be able to reproduce the issue.

## Additional Information
Add any other context about the problem here.
27 changes: 27 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
name: Feature request
about: Suggest an idea for this project
title: ''
labels: kind/enhancement, component/demos
assignees: ''

---

## Is your feature request related to a problem? Please describe.

A clear and concise description of what the problem is. Ex.`I would like to see [...] because [...]`.
Please include the intended use case and what the feature would improve on so that we can prioritize
the feature accordingly.

## Describe the solution you would like

A clear and concise description of what the desired end result(s) would be.

## Describe alternatives you have considered

A clear and concise description of any alternative solutions or features that may be related to this that
you have considered.

## Additional context

Add any other context information about the feature request here.
31 changes: 31 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
cli_cache/*
**/cli_cache/*
*.tar

tools/simple-certificates/certificates/*
.DS_Store

logs/*
**/logs/*

# Editor files
*.sw[po]
vm/.vagrant

# JMeter results
tools/performance-tests/jmeter/jmeter_reports/*
tools/performance-tests/jmeter/jmeter.log

**/backup/*

files/haproxy/master/haproxy.cfg

# Generated Certificates
**/certificates/ca-chain.pem
**/certificates/dap_follower/
**/certificates/dap_master/
**/certificates/intermediate_ca/
**/certificates/root_ca/

# Versions plugin backup file (use git history instead)
**/pom.xml.versionsBackup
222 changes: 222 additions & 0 deletions .gitleaks.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,222 @@
title = "Secretless Broker gitleaks config"

# This is the config file for gitleaks. You can configure gitleaks what to search for and what to whitelist.
# If GITLEAKS_CONFIG environment variable
# is set, gitleaks will load configurations from that path. If option --config-path is set, gitleaks will load
# configurations from that path. Gitleaks does not whitelist anything by default.
# - https://www.ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_04B-3_Meli_paper.pdf
# - https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json
[[rules]]
description = "AWS Client ID"
regex = '''(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}'''
tags = ["key", "AWS"]

[[rules]]
description = "AWS Secret Key"
regex = '''(?i)aws(.{0,20})?(?-i)['\"][0-9a-zA-Z\/+]{40}['\"]'''
tags = ["key", "AWS"]

[[rules]]
description = "AWS MWS key"
regex = '''amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}'''
tags = ["key", "AWS", "MWS"]

[[rules]]
description = "PKCS8"
regex = '''-----BEGIN PRIVATE KEY-----'''
tags = ["key", "PKCS8"]

[[rules]]
description = "RSA"
regex = '''-----BEGIN RSA PRIVATE KEY-----'''
tags = ["key", "RSA"]

[[rules]]
description = "SSH"
regex = '''-----BEGIN OPENSSH PRIVATE KEY-----'''
tags = ["key", "SSH"]

[[rules]]
description = "PGP"
regex = '''-----BEGIN PGP PRIVATE KEY BLOCK-----'''
tags = ["key", "PGP"]

[[rules]]
description = "Facebook Secret Key"
regex = '''(?i)(facebook|fb)(.{0,20})?(?-i)['\"][0-9a-f]{32}['\"]'''
tags = ["key", "Facebook"]

[[rules]]
description = "Facebook Client ID"
regex = '''(?i)(facebook|fb)(.{0,20})?['\"][0-9]{13,17}['\"]'''
tags = ["key", "Facebook"]

[[rules]]
description = "Facebook access token"
regex = '''EAACEdEose0cBA[0-9A-Za-z]+'''
tags = ["key", "Facebook"]

[[rules]]
description = "Twitter Secret Key"
regex = '''(?i)twitter(.{0,20})?['\"][0-9a-z]{35,44}['\"]'''
tags = ["key", "Twitter"]

[[rules]]
description = "Twitter Client ID"
regex = '''(?i)twitter(.{0,20})?['\"][0-9a-z]{18,25}['\"]'''
tags = ["client", "Twitter"]

[[rules]]
description = "Github"
regex = '''(?i)github(.{0,20})?(?-i)['\"][0-9a-zA-Z]{35,40}['\"]'''
tags = ["key", "Github"]

[[rules]]
description = "LinkedIn Client ID"
regex = '''(?i)linkedin(.{0,20})?(?-i)['\"][0-9a-z]{12}['\"]'''
tags = ["client", "Twitter"]

[[rules]]
description = "LinkedIn Secret Key"
regex = '''(?i)linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]'''
tags = ["secret", "Twitter"]

[[rules]]
description = "Slack"
regex = '''xox[baprs]-([0-9a-zA-Z]{10,48})?'''
tags = ["key", "Slack"]

[[rules]]
description = "EC"
regex = '''-----BEGIN EC PRIVATE KEY-----'''
tags = ["key", "EC"]

[[rules]]
description = "Generic API key"
regex = '''(?i)(api_key|apikey)(.{0,20})?['|"][0-9a-zA-Z]{32,45}['|"]'''
tags = ["key", "API", "generic"]

[[rules]]
description = "Generic Secret"
regex = '''(?i)secret(.{0,20})?['|"][0-9a-zA-Z]{32,45}['|"]'''
tags = ["key", "Secret", "generic"]

[[rules]]
description = "Google API key"
regex = '''AIza[0-9A-Za-z\\-_]{35}'''
tags = ["key", "Google"]

[[rules]]
description = "Google Cloud Platform API key"
regex = '''(?i)(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z\\-_]{35}]['\"]'''
tags = ["key", "Google", "GCP"]

[[rules]]
description = "Google OAuth"
regex = '''(?i)(google|gcp|auth)(.{0,20})?['"][0-9]+-[0-9a-z_]{32}\.apps\.googleusercontent\.com['"]'''
tags = ["key", "Google", "OAuth"]

[[rules]]
description = "Google OAuth access token"
regex = '''ya29\.[0-9A-Za-z\-_]+'''
tags = ["key", "Google", "OAuth"]

[[rules]]
description = "Heroku API key"
regex = '''(?i)heroku(.{0,20})?['"][0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}['"]'''
tags = ["key", "Heroku"]

[[rules]]
description = "MailChimp API key"
regex = '''(?i)(mailchimp|mc)(.{0,20})?['"][0-9a-f]{32}-us[0-9]{1,2}['"]'''
tags = ["key", "Mailchimp"]

[[rules]]
description = "Mailgun API key"
regex = '''(?i)(mailgun|mg)(.{0,20})?['"][0-9a-z]{32}['"]'''
tags = ["key", "Mailgun"]

[[rules]]
description = "Password in URL"
regex = '''[a-zA-Z]{3,10}:\/\/[^\/\s:@]{3,20}:[^\/\s:@]{3,20}@.{1,100}\/?.?'''
tags = ["key", "URL", "generic"]

[[rules]]
description = "PayPal Braintree access token"
regex = '''access_token\$production\$[0-9a-z]{16}\$[0-9a-f]{32}'''
tags = ["key", "Paypal"]

[[rules]]
description = "Picatic API key"
regex = '''sk_live_[0-9a-z]{32}'''
tags = ["key", "Picatic"]

[[rules]]
description = "Slack Webhook"
regex = '''https://hooks.slack.com/services/T[a-zA-Z0-9_]{8}/B[a-zA-Z0-9_]{8}/[a-zA-Z0-9_]{24}'''
tags = ["key", "slack"]

[[rules]]
description = "Stripe API key"
regex = '''(?i)stripe(.{0,20})?['\"][sk|rk]_live_[0-9a-zA-Z]{24}'''
tags = ["key", "Stripe"]

[[rules]]
description = "Square access token"
regex = '''sq0atp-[0-9A-Za-z\-_]{22}'''
tags = ["key", "square"]

[[rules]]
description = "Square OAuth secret"
regex = '''sq0csp-[0-9A-Za-z\\-_]{43}'''
tags = ["key", "square"]

[[rules]]
description = "Twilio API key"
regex = '''(?i)twilio(.{0,20})?['\"][0-9a-f]{32}['\"]'''
tags = ["key", "twilio"]

[whitelist]
files = [
".gitleaks.toml",
"demos/cluster/files/certs/*", # sample certs for demos
"demos/simple-cluster/files/certs/*", # sample certs for demos
"demos/aws-authentication/jason-conjur-test.pem", # sample cert for aws auth
"demos/ldap-integration/certs/*" # sample certs for ldap demo
]
regexes = [
]
commits = [
"406dc7268f9b014bb8bc8acc7854a18114ac5346", # old commit with vagrant priv key
"6e9dcb3698a8a339c7112cf395cf7c2389d4150d" # old commit with vagrant priv key
]

# Additional Examples

# [[rules]]
# description = "Generic Key"
# regex = '''(?i)key(.{0,6})?(:|=|=>|:=)'''
# entropies = [
# "4.1-4.3",
# "5.5-6.3",
# ]
# entropyROI = "line"
# filetypes = [".go", ".py", ".c"]
# tags = ["key"]
# severity = "8"
#
#
# [[rules]]
# description = "Generic Key"
# regex = '''(?i)key(.{0,6})?(:|=|=>|:=)'''
# entropies = ["4.1-4.3"]
# filetypes = [".gee"]
# entropyROI = "line"
# tags = ["key"]
# severity = "medium"

# [[rules]]
# description = "Any pem file"
# filetypes = [".key"]
# tags = ["pem"]
# severity = "high"
16 changes: 16 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Contributing

For general contribution and community guidelines, please see the [community repo](https://github.com/cyberark/community).

## Contributing Workflow

1. [Fork the project](https://help.github.com/en/github/getting-started-with-github/fork-a-repo)
2. [Clone your fork](https://help.github.com/en/github/creating-cloning-and-archiving-repositories/cloning-a-repository)
3. Make local changes to your fork by editing files
3. [Commit your changes](https://help.github.com/en/github/managing-files-in-a-repository/adding-a-file-to-a-repository-using-the-command-line)
4. [Push your local changes to the remote server](https://help.github.com/en/github/using-git/pushing-commits-to-a-remote-repository)
5. [Create new Pull Request](https://help.github.com/en/github/collaborating-with-issues-and-pull-requests/creating-a-pull-request-from-a-fork)

From here your pull request will be reviewed and once you've responded to all
feedback it will be merged into the project. Congratulations, you're a
contributor!
4 changes: 4 additions & 0 deletions Gemfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
source 'https://rubygems.org'

gem 'cucumber'
gem 'rspec-expectations'
Loading