Skip to content

[Cloud Asset Inventory] Fix entity.attribute mapping bug by renaming it to entity.Details - #7473

Merged
kubasobon merged 2 commits into
elastic:mainfrom
kubasobon:asset-inventory/fix-entity-attributes
Jul 23, 2026
Merged

kubasobon merged 2 commits into
elastic:mainfrom
kubasobon:asset-inventory/fix-entity-attributes

Conversation

@kubasobon

@kubasobon kubasobon commented Jul 23, 2026 •

Copy link
Copy Markdown
Member

Summary of your changes

For: #incident-3395-failing-quality-gate-for-entity-store-synthetics
Incident Slack: https://elastic.slack.com/archives/C0BJQCSBT47

Publishing asset details as entity.attributes breaks Entity Store extraction. This, along with related integrations PR, fixes the issue by using entity.Details instead. Integrations PR contains an ingest pipeline that ensures even old Cloudbeat versions that publish entity.attributes get remapped to Details. This allows extraction to work as intended.

Related Issues

Towards https://github.com/elastic/security-team/issues/18408

Re-align the Entity struct fields; renaming Attributes (10 chars) to
Details (7 chars) shortened the longest field name, so gofmt/gci flagged
the stale column padding in internal/inventory/asset.go.
@mergify

mergify Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@kubasobon
kubasobon added this pull request to the merge queue Jul 23, 2026
Merged via the queue into elastic:main with commit 815379b Jul 23, 2026
12 checks passed
@kubasobon
kubasobon deleted the asset-inventory/fix-entity-attributes branch July 23, 2026 18:07
kubasobon added a commit that referenced this pull request Jul 27, 2026
…pping bug by renaming it to entity.Details (#7474)

### Summary of your changes

For: #incident-3395-failing-quality-gate-for-entity-store-synthetics
Incident Slack: https://elastic.slack.com/archives/C0BJQCSBT47

Publishing asset details as `entity.attributes` breaks Entity Store
extraction. This, along with related integrations PR, fixes the issue by
using `entity.Details` instead. Integrations PR contains an ingest
pipeline that ensures even old Cloudbeat versions that publish
`entity.attributes` get remapped to `Details`. This allows extraction to
work as intended.

### Related Issues

Towards https://github.com/elastic/security-team/issues/18408
<hr>This is an automatic backport of pull request #7473 done by
[Mergify](https://mergify.com).

Co-authored-by: Kuba Soboń <wtty.fool@gmail.com>
kubasobon added a commit that referenced this pull request Jul 30, 2026
…7277)

### Summary of your changes

> [!NOTE]
> **Stacked on #7473.** This PR is based on
`asset-inventory/fix-entity-attributes`, which renames the
`entity.attributes` (flattened) bag to `entity.Details` to fix the
Entity Store generic-extraction bug. All new fields below are therefore
emitted under **`entity.Details.*`** (not `entity.attributes.*`). Please
review/merge #7473 first; this PR's diff shows only the InfoSec fetcher
changes on top of it.

| Resource | Field | Change |
| -------------------- | --------------------------------- |
------------------------------------------------------------------------------------------------------------------------
|
| **EC2** | `entity.Details.Role` | Added `LookupTag(tags, "role")` in
`buildDetails` |
| **RDS** | `entity.Details.DBInstanceStatus` | Added `Status` field to
wrapper struct; mapped from `DBInstanceStatus` in provider; emitted in
fetcher |
| **ELB v2** (ALB/NLB) | `entity.Details.IPAddresses` |
`GetIPAddresses()` now also collects `PrivateIPv4Address` and
`IPv6Address` per AZ address (previously only `IpAddress`) |
| **ELB v1** (Classic) | `entity.Details.State` | `GetState()` returns
`"active"` (hardcoded as classic API exposes no state field) |
| **ELB v1** (Classic) | `entity.Details.IPAddresses` | DNS-resolves the
ELB `DNSName` at fetch time via injectable `hostResolver`; soft-fails to
empty on error |

### Related Issues

Closes elastic/security-team#18294

### Checklist
- [x] I have added tests that prove my fix is effective or that my
feature works
kubasobon added a commit that referenced this pull request Aug 3, 2026
…fetchers for InfoSec (#7482)

### Summary of your changes

> [!NOTE]
> **Stacked on #7473.** This PR is based on
`asset-inventory/fix-entity-attributes`, which renames the
`entity.attributes` (flattened) bag to `entity.Details` to fix the
Entity Store generic-extraction bug. All new fields below are therefore
emitted under **`entity.Details.*`** (not `entity.attributes.*`). Please
review/merge #7473 first; this PR's diff shows only the InfoSec fetcher
changes on top of it.

| Resource | Field | Change |
| -------------------- | --------------------------------- |
------------------------------------------------------------------------------------------------------------------------
|
| **EC2** | `entity.Details.Role` | Added `LookupTag(tags, "role")` in
`buildDetails` |
| **RDS** | `entity.Details.DBInstanceStatus` | Added `Status` field to
wrapper struct; mapped from `DBInstanceStatus` in provider; emitted in
fetcher |
| **ELB v2** (ALB/NLB) | `entity.Details.IPAddresses` |
`GetIPAddresses()` now also collects `PrivateIPv4Address` and
`IPv6Address` per AZ address (previously only `IpAddress`) |
| **ELB v1** (Classic) | `entity.Details.State` | `GetState()` returns
`"active"` (hardcoded as classic API exposes no state field) |
| **ELB v1** (Classic) | `entity.Details.IPAddresses` | DNS-resolves the
ELB `DNSName` at fetch time via injectable `hostResolver`; soft-fails to
empty on error |

### Related Issues

Closes https://github.com/elastic/security-team/issues/18294

### Checklist
- [x] I have added tests that prove my fix is effective or that my
feature works
<hr>This is an automatic backport of pull request #7277 done by
[Mergify](https://mergify.com).

Co-authored-by: Kuba Soboń <wtty.fool@gmail.com>
kubasobon added a commit that referenced this pull request Sep 8, 2026
…7277)

### Summary of your changes

> [!NOTE]
> **Stacked on #7473.** This PR is based on
`asset-inventory/fix-entity-attributes`, which renames the
`entity.attributes` (flattened) bag to `entity.Details` to fix the
Entity Store generic-extraction bug. All new fields below are therefore
emitted under **`entity.Details.*`** (not `entity.attributes.*`). Please
review/merge #7473 first; this PR's diff shows only the InfoSec fetcher
changes on top of it.

| Resource | Field | Change |
| -------------------- | --------------------------------- |
------------------------------------------------------------------------------------------------------------------------
|
| **EC2** | `entity.Details.Role` | Added `LookupTag(tags, "role")` in
`buildDetails` |
| **RDS** | `entity.Details.DBInstanceStatus` | Added `Status` field to
wrapper struct; mapped from `DBInstanceStatus` in provider; emitted in
fetcher |
| **ELB v2** (ALB/NLB) | `entity.Details.IPAddresses` |
`GetIPAddresses()` now also collects `PrivateIPv4Address` and
`IPv6Address` per AZ address (previously only `IpAddress`) |
| **ELB v1** (Classic) | `entity.Details.State` | `GetState()` returns
`"active"` (hardcoded as classic API exposes no state field) |
| **ELB v1** (Classic) | `entity.Details.IPAddresses` | DNS-resolves the
ELB `DNSName` at fetch time via injectable `hostResolver`; soft-fails to
empty on error |

### Related Issues

Closes elastic/security-team#18294

### Checklist
- [x] I have added tests that prove my fix is effective or that my
feature works
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants