feat(honeytoken): plugin kind + DB models + store (epic #256 Task 1) - #265
Open
LiorFink00 wants to merge 1 commit into
Open
LiorFink00 wants to merge 1 commit into
LiorFink00 wants to merge 1 commit into
Conversation
Foundation for the third-party SaaS honeytoken feature (epic #256): fake credentials created inside Datadog/Salesforce/AWS whose use is detected by polling each platform's audit log. - base.py: HoneytokenPlugin ABC (connect/create_token/revoke_token/poll_usage) + TokenUsageEvent dataclass. - loader.py: "honeytoken" added to _KINDS (discovery/loading is kind-agnostic). - db.py: honeytoken_connections, honeytokens, honeytoken_usage_logs, with a (honeytoken_id, event_id) uniqueness key for poll dedup. - migration honeytoken_tables_v1 (off endpoint_ephemeral_v1). - store: connection + token CRUD, state transitions, and usage recording (deduped by the platform's event id) + listing. Migration note: this and the vault stack both fork the DAG at endpoint_ephemeral_v1; whichever merges second re-points its down_revision (or a merge migration is added). Single head on this branch (test_migrations passes). Ported from the enterprise implementation; no enterprise-only subsystems brought over. API routes (#256 Task 2), usage poller (Task 3), and the provider plugins follow in later PRs. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018DARDAxeg4NM8FKoyGMQZy
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Foundation for the third-party SaaS honeytoken feature (epic #256) — fake credentials created inside Datadog / Salesforce / AWS, whose use is detected by polling each platform's audit log and alerted through thumper's existing pipeline. This is Task 1 of 8; it lands the plumbing only (no user-facing capability yet).
base.py—HoneytokenPluginABC (connect/create_token/revoke_token/poll_usage) +TokenUsageEventdataclass.loader.py—"honeytoken"added to_KINDS; discovery/loading is kind-agnostic (verified by the loader test).db.py—honeytoken_connections,honeytokens,honeytoken_usage_logs, with a(honeytoken_id, event_id)uniqueness key for poll dedup.honeytoken_tables_v1(offendpoint_ephemeral_v1).pending → active → triggered), and usage recording deduped by the platform's event id.Independent of the vault stack
This branches off⚠️ Migration DAG note: both fork at
main, not the vault PRs — the two features are separate epics (#255 vault, #256 honeytoken).endpoint_ephemeral_v1, so whichever merges second must re-point itsdown_revision(or add a merge migration). Single head on this branch —test_migrationspasses.Testing
test_honeytoken_plugin_loader.py(4): kind is known, manifest discovered, internal fields stripped, plugin instantiates.test_honeytoken_store.py(12): connection CRUD, cascade delete, token CRUD, active filter, mark-used, usage-log dedup by event id, newest-first.Ported from the enterprise implementation (no enterprise-only subsystems). API routes (Task 2), usage poller (Task 3), and provider plugins follow.
🤖 Generated with Claude Code