Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
70 commits
Select commit Hold shift + click to select a range
4267891
[9.5](backport #7473) [Cloud Asset Inventory] Fix entity.attribute ma…
mergify[bot] Jul 27, 2026
935bf22
[9.5](backport #7277) [Asset Inventory][AWS] Update EC2, ELB and RDS …
mergify[bot] Aug 3, 2026
1fe1769
Bump cloudbeat version 9.5 to 9.5.1 (#7591)
elastic-vault-github-plugin-prod[bot] Aug 5, 2026
02412eb
chore(deps): bump github.com/aquasecurity/trivy to v0.71.1 (9.5) (#7695)
olegsu Aug 7, 2026
3316841
[9.5](backport #7424) fix(azure): drive Resource Graph pagination by …
mergify[bot] Aug 10, 2026
0234baf
chore(deps): update module oras.land/oras-go/v2 to v2.6.2 (9.5) (#7717)
elastic-renovate-prod[bot] Aug 10, 2026
c4234cc
chore(deps): update actions/checkout digest to 11d5960 (9.5) (#7749)
elastic-renovate-prod[bot] Aug 10, 2026
a77e540
chore(deps): update debian docker digest to 34cd9e9 (9.5) (#7750)
elastic-renovate-prod[bot] Aug 10, 2026
d814470
chore(deps): update github.com/bitnami/go-version digest to 2aa268a (…
elastic-renovate-prod[bot] Aug 10, 2026
ed49238
chore(deps): update github.com/dop251/goja digest to 493f220 (9.5) (#…
elastic-renovate-prod[bot] Aug 10, 2026
3b60b7f
chore(deps): update github.com/google/pprof digest to ef3492d (9.5) (…
elastic-renovate-prod[bot] Aug 10, 2026
1edd12d
chore(deps): update github.com/power-devops/perfstat digest to 884566…
elastic-renovate-prod[bot] Aug 10, 2026
0bf155c
chore(deps): update github.com/ianlancetaylor/demangle digest to 83e5…
elastic-renovate-prod[bot] Aug 10, 2026
9b77152
chore(deps): update python:3.14-slim docker digest to a7fb1e6 (9.5) (…
elastic-renovate-prod[bot] Aug 10, 2026
41ffed4
chore(deps): update github.com/lufia/plan9stats digest to 341c2f0 (9.…
elastic-renovate-prod[bot] Aug 10, 2026
e2c8fd9
chore(deps): update containerd (9.5) (#7763)
elastic-renovate-prod[bot] Aug 10, 2026
7bbced6
chore(deps): update golang docker digest to 2005724 (9.5) (#7759)
elastic-renovate-prod[bot] Aug 10, 2026
71b8b1c
chore(deps): update k8s.io/kube-openapi digest to d427ff9 (9.5) (#7760)
elastic-renovate-prod[bot] Aug 10, 2026
1533e10
chore(deps): update module github.com/ebitengine/purego to v0.10.2 (9…
elastic-renovate-prod[bot] Aug 10, 2026
af10bad
chore(deps): update module github.com/go-git/go-billy/v5 to v5.9.1 (9…
elastic-renovate-prod[bot] Aug 10, 2026
0bc977c
chore(deps): update module github.com/go-git/go-git/v5 to v5.19.2 (9.…
elastic-renovate-prod[bot] Aug 10, 2026
f6fb221
chore(deps): update module github.com/googleapis/enterprise-certifica…
elastic-renovate-prod[bot] Aug 10, 2026
763126c
chore(deps): update module github.com/go-asn1-ber/asn1-ber to v1.5.8 …
elastic-renovate-prod[bot] Aug 10, 2026
3b7425d
chore(deps): update kubernetes packages to v0.36.3 (9.5) (#7765)
elastic-renovate-prod[bot] Aug 10, 2026
8c95b3a
chore(deps): update module github.com/bitfield/gotestdox to v0.2.3 (9…
elastic-renovate-prod[bot] Aug 10, 2026
c4cdeb5
chore(deps): update module github.com/cloudflare/circl to v1.6.5 (9.5…
elastic-renovate-prod[bot] Aug 10, 2026
6e23d23
chore(deps): update module github.com/klauspost/compress to v1.19.2 (…
elastic-renovate-prod[bot] Aug 10, 2026
62c16b6
chore(deps): update module github.com/mattn/go-isatty to v0.0.24 (9.5…
elastic-renovate-prod[bot] Aug 10, 2026
11c782e
chore(deps): update module github.com/knadh/koanf/providers/confmap t…
elastic-renovate-prod[bot] Aug 10, 2026
f6fab5a
chore(deps): update module github.com/oklog/ulid/v2 to v2.1.2 (9.5) (…
elastic-renovate-prod[bot] Aug 10, 2026
788ff6d
chore(deps): update module github.com/mattn/go-shellwords to v1.0.14 …
elastic-renovate-prod[bot] Aug 10, 2026
036736e
chore(deps): update module github.com/shirou/gopsutil/v4 to v4.26.7 (…
elastic-renovate-prod[bot] Aug 10, 2026
5dce821
chore(deps): update module github.com/santhosh-tekuri/jsonschema/v6 t…
elastic-renovate-prod[bot] Aug 10, 2026
0d2dc71
chore(deps): update module github.com/pierrec/lz4/v4 to v4.1.28 (9.5)…
elastic-renovate-prod[bot] Aug 10, 2026
63b7d68
chore(deps): update module github.com/mattn/go-runewidth to v0.0.27 (…
elastic-renovate-prod[bot] Aug 11, 2026
c1f36e7
chore(deps): update module github.com/std-uritemplate/std-uritemplate…
elastic-renovate-prod[bot] Aug 11, 2026
d13710b
chore(deps): update module github.com/ulikunitz/xz to v0.5.16 (9.5) (…
elastic-renovate-prod[bot] Aug 11, 2026
02a2d1a
fix(deps): update module github.com/aws/smithy-go to v1.27.7 (9.5) (#…
elastic-renovate-prod[bot] Aug 11, 2026
1d5cf13
chore(deps): update module go.yaml.in/yaml/v3 to v3.0.5 (9.5) (#7790)
elastic-renovate-prod[bot] Aug 11, 2026
ec75ba2
chore(deps): update module helm.sh/helm/v4 to v4.2.3 (9.5) (#7791)
elastic-renovate-prod[bot] Aug 11, 2026
8585c4f
fix(deps): update module github.com/google/go-containerregistry to v0…
elastic-renovate-prod[bot] Aug 11, 2026
a94eaf6
chore(deps): update module k8s.io/kubectl to v0.36.3 (9.5) (#7792)
elastic-renovate-prod[bot] Aug 11, 2026
6b6b7de
chore(deps): update module github.com/knadh/koanf/v2 to v2.3.6 (9.5) …
elastic-renovate-prod[bot] Aug 11, 2026
beff323
fix(deps): update module github.com/go-logr/logr to v1.4.4 (9.5) (#7795)
elastic-renovate-prod[bot] Aug 11, 2026
cb56104
chore(deps): update golang.org/x (9.5) (#7799)
elastic-renovate-prod[bot] Aug 11, 2026
aecb371
chore(deps): update module github.com/azuread/microsoft-authenticatio…
elastic-renovate-prod[bot] Aug 11, 2026
bc712eb
chore(deps): update module github.com/coreos/go-oidc/v3 to v3.20.0 (9…
elastic-renovate-prod[bot] Aug 11, 2026
7f07de6
chore(deps): update module github.com/cheggaaa/pb/v3 to v3.2.0 (9.5) …
elastic-renovate-prod[bot] Aug 11, 2026
b8eb7df
chore(deps): update module github.com/googlecloudplatform/opentelemet…
elastic-renovate-prod[bot] Aug 11, 2026
d2495b2
chore(deps): update module github.com/gofrs/uuid/v5 to v5.5.1 (9.5) (…
elastic-renovate-prod[bot] Aug 11, 2026
42af012
chore(deps): update module github.com/letsencrypt/boulder to v0.20260…
elastic-renovate-prod[bot] Aug 11, 2026
2d20716
chore(deps): update module github.com/googlecloudplatform/opentelemet…
elastic-renovate-prod[bot] Aug 11, 2026
731f10e
chore(deps): update module github.com/lestrrat-go/jwx/v3 to v3.2.0 (9…
elastic-renovate-prod[bot] Aug 11, 2026
4108266
chore(deps): update module github.com/magiconair/properties to v1.18.…
elastic-renovate-prod[bot] Aug 11, 2026
1e6367c
chore(deps): update module github.com/redis/go-redis/v9 to v9.22.0 (9…
elastic-renovate-prod[bot] Aug 11, 2026
bf8ce56
chore(deps): update module modernc.org/memory to v1.12.0 (9.5) (#7820)
elastic-renovate-prod[bot] Aug 11, 2026
e002fc2
chore(deps): update module github.com/nikolalohinski/gonja/v2 to v2.9…
elastic-renovate-prod[bot] Aug 11, 2026
b199df2
chore(deps): update module modernc.org/libc to v1.75.3 (9.5) (#7819)
elastic-renovate-prod[bot] Aug 11, 2026
277032a
chore(deps): update golang docker digest to 7caba52 (9.5) (#7822)
elastic-renovate-prod[bot] Aug 11, 2026
1e99f64
chore(deps): update module github.com/go-ldap/ldap/v3 to v3.4.14 (9.5…
elastic-renovate-prod[bot] Aug 11, 2026
0926995
chore(deps): update docker (9.5) (#7797)
elastic-renovate-prod[bot] Aug 11, 2026
100c41f
chore(deps): update module github.com/gocsaf/csaf/v3 to v3.6.0 (9.5) …
elastic-renovate-prod[bot] Aug 11, 2026
90e1b26
chore(deps): update module github.com/prometheus/client_golang to v1.…
elastic-renovate-prod[bot] Aug 11, 2026
4182658
chore(deps): update module github.com/googlecloudplatform/opentelemet…
elastic-renovate-prod[bot] Aug 11, 2026
37f9f10
chore(deps): update module golang.org/x/mod to v0.39.0 (9.5) (#7823)
elastic-renovate-prod[bot] Aug 11, 2026
9f5ac65
chore(deps): update module github.com/prometheus/common to v0.70.1 (9…
elastic-renovate-prod[bot] Aug 11, 2026
3731369
fix(deps): update aws-sdk (9.5) (#7824)
elastic-renovate-prod[bot] Aug 11, 2026
b46aad0
fix(deps): update azure-sdk (9.5) (#7825)
elastic-renovate-prod[bot] Aug 11, 2026
ac77474
fix(deps): update module github.com/microsoftgraph/msgraph-sdk-go to …
elastic-renovate-prod[bot] Aug 11, 2026
c7c4cdb
ci: pin security-policies poetry env to python3.11
olegsu Aug 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/actions/hermit/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,10 @@ runs:
- if: ${{ inputs.init-tools == 'true' }}
name: Install security-policies poetry dependencies
shell: bash
run: cd ./security-policies && poetry install --no-root
run: |
cd ./security-policies
poetry env use python3.11
poetry install --no-root
- if: ${{ inputs.init-tools == 'true' }}
name: Install pre-commit repos
shell: bash
Expand Down
2 changes: 1 addition & 1 deletion .github/actions/kibana-ftr/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ runs:
echo "KIBANA_DIR=kibana" >> "${GITHUB_OUTPUT}"

- name: Checkout Kibana Repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
repository: elastic/kibana
ref: ${{ inputs.kibana_ref }}
Expand Down
2 changes: 1 addition & 1 deletion deploy/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM debian@sha256:35b8ff74ead4880f22090b617372daff0ccae742eb5674455d542bef71ef1999
FROM debian@sha256:34cd9e9fd437c0a095ec39cb2e73422c9f30821b0d0848ed74fd0d43bae4d958
RUN set -x && \
apt-get update && \
apt-get install -y --no-install-recommends \
Expand Down
2 changes: 1 addition & 1 deletion deploy/Dockerfile.debug
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM golang@sha256:efaccb5b497e90df3ebe5216cc25cd9f98e73874e2d638b56e38d4a3f098c41c
FROM golang@sha256:7caba5286b4c3613a337b709c573047d8ae62ee76106647313b61e72b99f20af
RUN go install github.com/go-delve/delve/cmd/dlv@latest
RUN set -x && \
apt-get update && \
Expand Down
274 changes: 137 additions & 137 deletions go.mod

Large diffs are not rendered by default.

573 changes: 288 additions & 285 deletions go.sum

Large diffs are not rendered by default.

26 changes: 13 additions & 13 deletions internal/inventory/asset.go
Original file line number Diff line number Diff line change
Expand Up @@ -182,11 +182,11 @@ type URL struct {

// Entity contains the identifiers of the asset
type Entity struct {
Id string `json:"id"`
Name string `json:"name"`
Source *string `json:"source"`
Raw *any `json:"raw"`
Attributes map[string]any `json:"attributes,omitempty"`
Id string `json:"id"`
Name string `json:"name"`
Source *string `json:"source"`
Raw *any `json:"raw"`
Details map[string]any `json:"Details,omitempty"`
AssetClassification

// non exported fields
Expand Down Expand Up @@ -451,28 +451,28 @@ func WithContainer(container Container) AssetEnricher {
}
}

// WithEntityAttributes sets non-ECS resource-specific attributes on the entity.
// WithEntityDetails sets non-ECS resource-specific attributes on the entity (entity.Details).
// Keys should use UpperCamelCase per the non-ECS field naming convention.
// A nil or empty map is a no-op.
func WithEntityAttributes(attrs map[string]any) AssetEnricher {
func WithEntityDetails(details map[string]any) AssetEnricher {
return func(a *AssetEvent) {
if len(attrs) == 0 {
if len(details) == 0 {
return
}
a.Entity.Attributes = attrs
a.Entity.Details = details
}
}

// WithCreatedAt sets the resource creation timestamp in entity.attributes["CreatedAt"].
// WithCreatedAt sets the resource creation timestamp in entity.Details["CreatedAt"].
// A nil time is a no-op.
func WithCreatedAt(t *time.Time) AssetEnricher {
return func(a *AssetEvent) {
if t == nil {
return
}
if a.Entity.Attributes == nil {
a.Entity.Attributes = make(map[string]any)
if a.Entity.Details == nil {
a.Entity.Details = make(map[string]any)
}
a.Entity.Attributes["CreatedAt"] = t
a.Entity.Details["CreatedAt"] = t
}
}
31 changes: 17 additions & 14 deletions internal/inventory/awsfetcher/fetcher_ec2_instance.go
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ func (e *ec2InstanceFetcher) Fetch(ctx context.Context, assetChannel chan<- inve
IP: buildIPs(i.PublicIpAddress, i.PrivateIpAddress),
MacAddress: i.GetResourceMacAddresses(),
}),
inventory.WithEntityAttributes(e.buildAttributes(i, tags, roleArnCache)),
inventory.WithEntityDetails(e.buildDetails(i, tags, roleArnCache)),
inventory.WithCreatedAt(i.LaunchTime),
iamFetcher,
)
Expand Down Expand Up @@ -177,43 +177,46 @@ func profileNameFromArn(arn string) string {
return arn[idx+len(marker):]
}

// buildAttributes collects non-ECS, resource-specific EC2 fields into entity.attributes,
// buildDetails collects non-ECS, resource-specific EC2 fields into entity.Details,
// using UpperCamelCase keys. Empty values are omitted so events stay clean and struct
// comparison in tests is stable.
func (e *ec2InstanceFetcher) buildAttributes(i *ec2.Ec2Instance, tags map[string]string, roleArnCache map[string]string) map[string]any {
attrs := map[string]any{}
func (e *ec2InstanceFetcher) buildDetails(i *ec2.Ec2Instance, tags map[string]string, roleArnCache map[string]string) map[string]any {
details := map[string]any{}
if v := pointers.Deref(i.ImageId); v != "" {
attrs["ImageId"] = v
details["ImageId"] = v
}
if v := string(i.Platform); v != "" {
attrs["Platform"] = v
details["Platform"] = v
}
if v := pointers.Deref(i.VpcId); v != "" {
attrs["VpcId"] = v
details["VpcId"] = v
}
if v := pointers.Deref(i.SubnetId); v != "" {
attrs["SubnetId"] = v
details["SubnetId"] = v
}
if i.State != nil {
if v := string(i.State.Name); v != "" {
attrs["State"] = v
details["State"] = v
}
}
if i.IamInstanceProfile != nil {
if profileArn := pointers.Deref(i.IamInstanceProfile.Arn); profileArn != "" {
attrs["InstanceProfileArn"] = profileArn
details["InstanceProfileArn"] = profileArn
if roleArn, ok := roleArnCache[profileArn]; ok && roleArn != "" {
attrs["RoleArn"] = roleArn
details["RoleArn"] = roleArn
}
}
}
if v := awslib.LookupTag(tags, "owner"); v != "" {
attrs["Owner"] = v
details["Owner"] = v
}
if v := awslib.LookupTag(tags, "costcenter", "cost-center", "cost_center"); v != "" {
attrs["CostCenter"] = v
details["CostCenter"] = v
}
return attrs
if v := awslib.LookupTag(tags, "role"); v != "" {
details["Role"] = v
}
return details
}

// buildIPs collects non-empty IP address strings into a slice, returning nil when none exist.
Expand Down
11 changes: 7 additions & 4 deletions internal/inventory/awsfetcher/fetcher_ec2_instance_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@ func makeTestInstance(launchTime *time.Time) *ec2beat.Ec2Instance {
{Key: pointers.Ref("key"), Value: pointers.Ref("value")},
{Key: pointers.Ref("Owner"), Value: pointers.Ref("team-infra")},
{Key: pointers.Ref("CostCenter"), Value: pointers.Ref("cc-1234")},
{Key: pointers.Ref("Role"), Value: pointers.Ref("sre")},
},
InstanceId: pointers.Ref("234567890"),
Architecture: ec2types.ArchitectureValuesX8664,
Expand Down Expand Up @@ -104,7 +105,7 @@ func TestEC2InstanceFetcher_Fetch(t *testing.T) {
"private-dns",
inventory.WithRelatedAssetIds([]string{"234567890"}),
inventory.WithRawAsset(instance1),
inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234"}),
inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234", "Role": "sre"}),
inventory.WithCloud(inventory.Cloud{
Provider: inventory.AwsCloudProvider,
Region: "us-east",
Expand All @@ -124,7 +125,7 @@ func TestEC2InstanceFetcher_Fetch(t *testing.T) {
IP: []string{"public-ip-addr", "private-ip-addre"},
MacAddress: []string{"mac1", "mac2"},
}),
inventory.WithEntityAttributes(map[string]any{
inventory.WithEntityDetails(map[string]any{
"ImageId": "image-id",
"Platform": "linux",
"VpcId": "vpc-id",
Expand All @@ -134,6 +135,7 @@ func TestEC2InstanceFetcher_Fetch(t *testing.T) {
"RoleArn": testRoleArn,
"Owner": "team-infra",
"CostCenter": "cc-1234",
"Role": "sre",
}),
inventory.WithCreatedAt(&launchTime),
inventory.WithUser(inventory.User{
Expand Down Expand Up @@ -193,7 +195,7 @@ func TestEC2InstanceFetcher_Fetch_ResolverError(t *testing.T) {
"private-dns",
inventory.WithRelatedAssetIds([]string{"234567890"}),
inventory.WithRawAsset(instance),
inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234"}),
inventory.WithLabels(map[string]string{"Name": "test-server", "key": "value", "Owner": "team-infra", "CostCenter": "cc-1234", "Role": "sre"}),
inventory.WithCloud(inventory.Cloud{
Provider: inventory.AwsCloudProvider,
Region: "us-east",
Expand All @@ -213,7 +215,7 @@ func TestEC2InstanceFetcher_Fetch_ResolverError(t *testing.T) {
IP: []string{"public-ip-addr", "private-ip-addre"},
MacAddress: []string{"mac1", "mac2"},
}),
inventory.WithEntityAttributes(map[string]any{
inventory.WithEntityDetails(map[string]any{
"ImageId": "image-id",
"Platform": "linux",
"VpcId": "vpc-id",
Expand All @@ -223,6 +225,7 @@ func TestEC2InstanceFetcher_Fetch_ResolverError(t *testing.T) {
// RoleArn is absent because the resolver failed.
"Owner": "team-infra",
"CostCenter": "cc-1234",
"Role": "sre",
}),
inventory.WithCreatedAt(&launchTime),
// WithUser falls back to the profile ARN when role resolution fails.
Expand Down
22 changes: 11 additions & 11 deletions internal/inventory/awsfetcher/fetcher_eks.go
Original file line number Diff line number Diff line change
Expand Up @@ -78,37 +78,37 @@ func (f *eksFetcher) Fetch(ctx context.Context, assetChannel chan<- inventory.As
AccountName: f.accountName,
ServiceName: "AWS EKS",
}),
inventory.WithEntityAttributes(buildEKSAttributes(cluster)),
inventory.WithEntityDetails(buildEKSDetails(cluster)),
inventory.WithCreatedAt(cluster.CreatedAt),
)
}
}

// buildEKSAttributes maps a cluster's non-ECS fields into entity.attributes using
// buildEKSDetails maps a cluster's non-ECS fields into entity.Details using
// UpperCamelCase keys. The endpoint-access booleans are always included as they are
// meaningful even when false; other empty values are omitted.
func buildEKSAttributes(cluster eks.Cluster) map[string]any {
attrs := map[string]any{
func buildEKSDetails(cluster eks.Cluster) map[string]any {
details := map[string]any{
"EndpointPublicAccess": cluster.EndpointPublicAccess,
"EndpointPrivateAccess": cluster.EndpointPrivateAccess,
}
if cluster.Status != "" {
attrs["Status"] = cluster.Status
details["Status"] = cluster.Status
}
if cluster.Version != "" {
attrs["Version"] = cluster.Version
details["Version"] = cluster.Version
}
if cluster.Endpoint != "" {
attrs["Endpoint"] = cluster.Endpoint
details["Endpoint"] = cluster.Endpoint
}
if cluster.RoleArn != "" {
attrs["RoleArn"] = cluster.RoleArn
details["RoleArn"] = cluster.RoleArn
}
if cluster.PlatformVersion != "" {
attrs["PlatformVersion"] = cluster.PlatformVersion
details["PlatformVersion"] = cluster.PlatformVersion
}
if v := cluster.GetOwnerTag(); v != "" {
attrs["OwnerTag"] = v
details["OwnerTag"] = v
}
return attrs
return details
}
4 changes: 2 additions & 2 deletions internal/inventory/awsfetcher/fetcher_eks_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@ func TestEKSFetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS EKS",
}),
inventory.WithEntityAttributes(map[string]any{
inventory.WithEntityDetails(map[string]any{
"EndpointPublicAccess": true,
"EndpointPrivateAccess": false,
"Status": "ACTIVE",
Expand All @@ -91,7 +91,7 @@ func TestEKSFetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS EKS",
}),
inventory.WithEntityAttributes(map[string]any{
inventory.WithEntityDetails(map[string]any{
"EndpointPublicAccess": false,
"EndpointPrivateAccess": false,
}),
Expand Down
16 changes: 8 additions & 8 deletions internal/inventory/awsfetcher/fetcher_elb.go
Original file line number Diff line number Diff line change
Expand Up @@ -94,27 +94,27 @@ func (f *elbFetcher) fetch(ctx context.Context, resourceName string, function el
}

for _, item := range awsResources {
var attrs map[string]any
var details map[string]any
var createdAt *time.Time
if r, ok := item.(elbInventoryResource); ok {
attrs = map[string]any{
details = map[string]any{
"DNSName": r.GetDNSName(),
"PubliclyAccessible": r.IsPubliclyAccessible(),
}
if f.AccountId != "" {
attrs["AccountID"] = f.AccountId
details["AccountID"] = f.AccountId
}
if v := r.GetLoadBalancerType(); v != "" {
attrs["LoadBalancerType"] = v
details["LoadBalancerType"] = v
}
if v := r.GetState(); v != "" {
attrs["State"] = v
details["State"] = v
}
if v := r.GetIPAddresses(); len(v) > 0 {
attrs["IPAddresses"] = v
details["IPAddresses"] = v
}
if v := r.GetOwnerTag(); v != "" {
attrs["OwnerTag"] = v
details["OwnerTag"] = v
}
createdAt = r.GetCreatedAt()
}
Expand All @@ -131,7 +131,7 @@ func (f *elbFetcher) fetch(ctx context.Context, resourceName string, function el
AccountName: f.AccountName,
ServiceName: "AWS Networking",
}),
inventory.WithEntityAttributes(attrs),
inventory.WithEntityDetails(details),
inventory.WithCreatedAt(createdAt),
)
}
Expand Down
16 changes: 11 additions & 5 deletions internal/inventory/awsfetcher/fetcher_elb_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -37,8 +37,8 @@ import (
)

func TestELBv1Fetcher_Fetch(t *testing.T) {
asset := elb.ElasticLoadBalancerInfo{
LoadBalancer: types.LoadBalancerDescription{
asset := elb.NewElasticLoadBalancerInfo(
types.LoadBalancerDescription{
AvailabilityZones: []string{"us-east-1a"},
CanonicalHostedZoneName: pointers.Ref("HZ-NAME"),
CanonicalHostedZoneNameID: pointers.Ref("HZ-ID"),
Expand All @@ -64,7 +64,11 @@ func TestELBv1Fetcher_Fetch(t *testing.T) {
Subnets: []string{"subnet-123"},
VPCId: pointers.Ref("vpc-id"),
},
}
"", // awsAccount
"", // region
nil,
[]string{"203.0.113.1", "203.0.113.2"}, // DNS-resolved by the provider in real code
)
in := []awslib.AwsResource{asset}

expected := []inventory.AssetEvent{
Expand All @@ -79,11 +83,13 @@ func TestELBv1Fetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS Networking",
}),
inventory.WithEntityAttributes(map[string]any{
inventory.WithEntityDetails(map[string]any{
"DNSName": "internal-my-elb-v1.us-east-1.elb.amazonaws.com",
"PubliclyAccessible": false, // scheme is "internal"
"AccountID": "123",
"LoadBalancerType": "classic",
"State": "active",
"IPAddresses": []string{"203.0.113.1", "203.0.113.2"},
}),
inventory.WithCreatedAt(asset.GetCreatedAt()),
),
Expand Down Expand Up @@ -134,7 +140,7 @@ func TestELBv2Fetcher_Fetch(t *testing.T) {
AccountName: "alias",
ServiceName: "AWS Networking",
}),
inventory.WithEntityAttributes(map[string]any{
inventory.WithEntityDetails(map[string]any{
"DNSName": "internal-my-elb-v2.us-east-1.elb.amazonaws.com",
"PubliclyAccessible": false, // scheme is internal
"AccountID": "123",
Expand Down
Loading
Loading