Skip to content

feat(honeytoken): plugin kind + DB models + store (epic #256 Task 1) - #265

Open
LiorFink00 wants to merge 1 commit into
mainfrom
feat/honeytoken-foundation
Open

LiorFink00 wants to merge 1 commit into
mainfrom
feat/honeytoken-foundation

Conversation

@LiorFink00

Copy link
Copy Markdown
Collaborator

What

Foundation for the third-party SaaS honeytoken feature (epic #256) — fake credentials created inside Datadog / Salesforce / AWS, whose use is detected by polling each platform's audit log and alerted through thumper's existing pipeline. This is Task 1 of 8; it lands the plumbing only (no user-facing capability yet).

  • base.py — HoneytokenPlugin ABC (connect / create_token / revoke_token / poll_usage) + TokenUsageEvent dataclass.
  • loader.py — "honeytoken" added to _KINDS; discovery/loading is kind-agnostic (verified by the loader test).
  • db.py — honeytoken_connections, honeytokens, honeytoken_usage_logs, with a (honeytoken_id, event_id) uniqueness key for poll dedup.
  • migration honeytoken_tables_v1 (off endpoint_ephemeral_v1).
  • store — connection + token CRUD, state transitions (pending → active → triggered), and usage recording deduped by the platform's event id.

Independent of the vault stack

This branches off main, not the vault PRs — the two features are separate epics (#255 vault, #256 honeytoken). ⚠️ Migration DAG note: both fork at endpoint_ephemeral_v1, so whichever merges second must re-point its down_revision (or add a merge migration). Single head on this branch — test_migrations passes.

Testing

  • test_honeytoken_plugin_loader.py (4): kind is known, manifest discovered, internal fields stripped, plugin instantiates.
  • test_honeytoken_store.py (12): connection CRUD, cascade delete, token CRUD, active filter, mark-used, usage-log dedup by event id, newest-first.
  • Full suite: 385 passed, 1 skipped, ruff clean.

Ported from the enterprise implementation (no enterprise-only subsystems). API routes (Task 2), usage poller (Task 3), and provider plugins follow.

🤖 Generated with Claude Code

Foundation for the third-party SaaS honeytoken feature (epic #256): fake
credentials created inside Datadog/Salesforce/AWS whose use is detected by
polling each platform's audit log.

- base.py: HoneytokenPlugin ABC (connect/create_token/revoke_token/poll_usage)
  + TokenUsageEvent dataclass.
- loader.py: "honeytoken" added to _KINDS (discovery/loading is kind-agnostic).
- db.py: honeytoken_connections, honeytokens, honeytoken_usage_logs, with a
  (honeytoken_id, event_id) uniqueness key for poll dedup.
- migration honeytoken_tables_v1 (off endpoint_ephemeral_v1).
- store: connection + token CRUD, state transitions, and usage recording
  (deduped by the platform's event id) + listing.

Migration note: this and the vault stack both fork the DAG at
endpoint_ephemeral_v1; whichever merges second re-points its down_revision (or a
merge migration is added). Single head on this branch (test_migrations passes).

Ported from the enterprise implementation; no enterprise-only subsystems brought
over. API routes (#256 Task 2), usage poller (Task 3), and the provider plugins
follow in later PRs.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DARDAxeg4NM8FKoyGMQZy
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant