Skip to content

Commit

Permalink
Misc spellcheck + client release updates
Browse files Browse the repository at this point in the history
Signed-off-by: Tim Smith <[email protected]>
  • Loading branch information
tas50 committed Mar 23, 2024
1 parent 5885b59 commit 7a001b4
Show file tree
Hide file tree
Showing 11 changed files with 144 additions and 114 deletions.
3 changes: 3 additions & 0 deletions .github/actions/spelling/line_forbidden.patterns
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,9 @@
# s.b. email
\be-mail\b

# s.b. APIs
\bapis\b

#
# Product Names
#
Expand Down
96 changes: 62 additions & 34 deletions docs/cnspec/cnspec-adv-install/registration-keys.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,58 +33,86 @@ The `cnspec status` command validates cnspec registration and ensures that commu

```bash title="Unregistered cnspec"
cnspec status
→ Time: 2023-01-13T16:12:44-08:00
→ Version: 7.12.1 (API Version: 7)
→ API ConnectionConfig: https://us.api.mondoo.com
→ API Status: SERVING
→ API Time: 2023-01-14T00:12:45Z
→ API Version: 7
→ Space:
→ loaded configuration from /Users/stella/.config/mondoo/mondoo.yml using source default
→ Platform: macos
→ Version: 13.4.1
→ Hostname: stella.home
→ IP: 192.168.254.21
→ Time: 2024-02-27T12:07:41-08:00
→ Version: 10.8.4 (API Version: 10)
→ Latest Version: 10.8.4
→ Installed Providers: core | mock | os
→ API ConnectionConfig: https://api.edge.mondoo.com
→ API Status: SERVING
→ API Time: 2024-02-27T20:07:42Z
→ API Version: 10
x client is not registered
x could not connect to mondoo platform
```

```bash title="Correctly registered client"
cnspec status
→ Time: 2023-01-13T16:12:44-08:00
→ Version: 7.12.1 (API Version: 7)
→ API ConnectionConfig: https://us.api.mondoo.com
→ API Status: SERVING
→ API Time: 2023-01-14T00:11:18Z
→ API Version: 7
→ Space: //captain.api.mondoo.app/spaces/lunalectric-prod-eks
→ Client: //agents.api.mondoo.app/spaces/lunalectric-prod-eks/agents/1N9EGTzvlizF1n7vPtz21y7XFA3
→ Service Account: //agents.api.mondoo.app/spaces/lunalectric-prod-eks/serviceaccounts/1N9EGTzvlizF1n7vPtz21y7XFA3
→ loaded configuration from /Users/mwezi/.config/mondoo/mondoo.yml using source default
→ Platform: macos
→ Version: 13.4.1
→ Hostname: mwezi.home
→ IP: 192.168.254.21
→ Time: 2024-02-27T12:07:41-08:00
→ Version: 10.8.4 (API Version: 10)
→ Latest Version: 10.8.4
→ Installed Providers: arista | aws | azure | core | mock | os
→ API ConnectionConfig: https://api.edge.mondoo.com
→ API Status: SERVING
→ API Time: 2024-02-27T20:07:42Z
→ API Version: 10
→ Owner: //captain.api.mondoo.app/spaces/lunalectric-team-workstations
→ Client: //agents.api.mondoo.app/spaces/lunalectric-team-workstations/agents/2SARlZgQnFLAzj7jfiS1Fx2HBz8
→ Service Account: //agents.api.mondoo.app/spaces/lunalectric-team-workstations/serviceaccounts/2bMtksUk9EjrI5MC3tTf6UmhNC2
→ client is registered
→ client authenticated successfully
```

```bash title="Invalid cnspec registration"
cnspec status
→ Time: 2023-01-13T16:17:50-08:00
→ Version: 7.12.1 (API Version: 7)
→ API ConnectionConfig: https://us.api.mondoo.com
→ API Status: SERVING
→ API Time: 2023-01-14T00:17:50Z
→ API Version: 7
→ Space: //captain.api.mondoo.app/spaces/lunalectric-prod-eks
→ Client: //agents.api.mondoo.app/spaces/lunalectric-prod-eks/agents/1N9EGTzvlizF1n7vPtz21y7XFA3
→ Service Account: //agents.api.mondoo.app/spaces/lunalectric-prod-eks/serviceaccounts/1N9EGTzvlizF1n7vPtz21y7XFA3
→ loaded configuration from /Users/cosmo/.config/mondoo/mondoo.yml using source default
→ Platform: macos
→ Version: 13.4.1
→ Hostname: cosmo.home
→ IP: 192.168.254.21
→ Time: 2024-02-27T12:07:41-08:00
→ Version: 10.8.4 (API Version: 10)
→ Latest Version: 10.8.4
→ Installed Providers: arista | aws | azure | core | mock | os
→ API ConnectionConfig: https://api.edge.mondoo.com
→ API Status: SERVING
→ API Time: 2024-02-27T20:07:42Z
→ API Version: 10
→ Owner: //captain.api.mondoo.app/spaces/lunalectric-team-workstations
→ Client: //agents.api.mondoo.app/spaces/lunalectric-team-workstations/agents/2SARlZgQnFLAzj7jfiS1Fx2HBz8
→ Service Account: //agents.api.mondoo.app/spaces/lunalectric-team-workstations/serviceaccounts/2bMtksUk9EjrI5MC3tTf6UmhNC2
→ client is registered
x could not connect to mondoo platform error="rpc error: code = Unauthenticated desc = request permission unauthenticated"permission unauthenticated"
```
```bash title="No current system time (clock skew detected)"
cnspec status
→ Time: 2023-01-10T16:19:39-08:00
→ Version: 7.12.1 (API Version: 7)
→ API ConnectionConfig: https://us.api.mondoo.com
→ API Status: SERVING
→ API Time: 2023-01-14T00:19:46Z
→ API Version: 7
→ Space: //captain.api.mondoo.app/spaces/lunalectric-prod-eks
→ Client: //agents.api.mondoo.app/spaces/lunalectric-prod-eks/agents/1N9EGTzvlizF1n7vPtz21y7XFA3
→ Service Account: //agents.api.mondoo.app/spaces/lunalectric-prod-eks/serviceaccounts/1N9EGTzvlizF1n7vPtz21y7XFA3
cnspec status
→ loaded configuration from /Users/cosmo/.config/mondoo/mondoo.yml using source default
→ Platform: macos
→ Version: 13.4.1
→ Hostname: tsuki.home
→ IP: 192.168.254.21
→ Time: 2024-02-27T12:07:41-08:00
→ Version: 10.8.4 (API Version: 10)
→ Latest Version: 10.8.4
→ Installed Providers: aws | azure | core | mock | os
→ API ConnectionConfig: https://api.edge.mondoo.com
→ API Status: SERVING
→ API Time: 2024-02-27T20:07:42Z
→ API Version: 10
→ Owner: //captain.api.mondoo.app/spaces/lunalectric-team-workstations
→ Client: //agents.api.mondoo.app/spaces/lunalectric-team-workstations/agents/2SARlZgQnFLAzj7jfiS1Fx2HBz8
→ Service Account: //agents.api.mondoo.app/spaces/lunalectric-team-workstations/serviceaccounts/2bMtksUk9EjrI5MC3tTf6UmhNC2
→ client is registered
→ client authenticated successfully
! possible clock skew detected: 72h0m6.277868s
Expand Down
23 changes: 11 additions & 12 deletions docs/cnspec/cnspec-adv-install/registration.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,21 +54,20 @@ The `cnspec status` command validates cnspec registration and ensures that commu

```bash title="Unregistered cnspec"
cnspec status
→ loaded configuration from /Users/stella/.config/mondoo/mondoo.yml using source default
→ Platform: macos
→ Version: 13.4.1
→ Hostname: stella.home
→ IP: 192.168.254.21
→ Time: 2024-02-27T12:07:41-08:00
→ Version: 10.5.0 (API Version: 10)
→ Latest Version: 10.5.0
→ Installed Providers: core | mock | os
→ API ConnectionConfig: https://api.edge.mondoo.com
→ Platform: ubuntu
→ Version: 24.04
→ Hostname: luna-server-1
→ IP: 172.17.0.2
→ Time: 2024-03-23T17:39:10Z
→ Version: 10.8.4 (API Version: 10)
→ Latest Version: 10.8.4
→ Installed Providers: core | os | mock
→ API ConnectionConfig: https://us.api.mondoo.com
→ API Status: SERVING
→ API Time: 2024-02-27T20:07:42Z
→ API Time: 2024-03-23T17:39:10Z
→ API Version: 10
x client is not registered
x could not connect to mondoo platform
x The Mondoo Platform credentials provided at /root/.config/mondoo/mondoo.yml didn't successfully authenticate with Mondoo Platform. Please re-authenticate with Mondoo Platform. To learn how, read https://mondoo.com/docs/cnspec/cnspec-adv-install/registration/.
```
```bash title="Correctly registered client"
Expand Down
2 changes: 1 addition & 1 deletion docs/cnspec/cnspec-adv-install/update.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ To learn about cnspec provider versioning, read [Manage cnspec Providers](/cnspe

## How cnspec versioning works

Mondoo's versioning policy is _based on_ the semantic versioning standard. For example, in version 6.3.2, 6 is the major version, 3 is the minor version, and 2 is the patch. When we release a new version, we increment one of these three version components depending on the type of changes we introduce.
Mondoo's versioning policy is _based on_ the semantic versioning standard. For example, in version 10.8.4, 10 is the major version, 8 is the minor version, and 4 is the patch. When we release a new version, we increment one of these three version components depending on the type of changes we introduce.

### Breaking changes policy

Expand Down
10 changes: 5 additions & 5 deletions docs/platform/infra/cloud/aws/aws-integration-faq.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ When the CloudFormation stack is deleted, the lambda function receives a notific

## How much will operating the Mondoo AWS Integration cost?

Most of the costs associated with the Mondoo AWS Integration fall into the free tier category. Over the course of a month, an example AWS Integration incurred this resource usage:
Most of the costs associated with the Mondoo AWS Integration fall into the AWS Free Tier category. Over the course of a month, an example AWS integration incurred this resource usage:

- CloudWatch PutLogs: 1GB (First 5GB per month of log data ingested is free)
- CloudWatch TimedStorage: 0.16GB (First 5GB-mo per month of logs storage is free)
Expand All @@ -123,12 +123,12 @@ Most of the costs associated with the Mondoo AWS Integration fall into the free
- SNS HTTP: 2,000 notifications (First 100,000 Amazon SNS HTTP/HTTPS Notifications per month are free)
- SNS requests: 3,000 requests (First 1,000,000 Amazon SNS API Requests per month are free)
- SQS requests: 626,000 requests (First 1,000,000 Amazon SQS Requests per month are free)
- Simple Storage Service--Tier1: 257 requests ($0.00 per request - PUT, COPY, POST, or LIST requests under the monthly global free tier)
- Simple Storage Service--Tier2: 41 requests ($0.00 per request - GET and all other requests under the monthly global free tier)
- Simple Storage Service--Tier1: 257 requests ($0.00 per request - PUT, COPY, POST, or LIST requests under the monthly global Free Tier)
- Simple Storage Service--Tier2: 41 requests ($0.00 per request - GET and all other requests under the monthly global Free Tier)

## What do you about rate limiting?
## What do you about rate-limiting?

We spread out scan jobs to prevent too many calls to the EC2 and SSM apis. If the Lambda function encounters a rate limiting error, it automatically pauses all scan jobs for 15 minutes.
We spread out scan jobs to prevent too many calls to the EC2 and SSM APIs. If the Lambda function encounters a rate-limiting error, it automatically pauses all scan jobs for 15 minutes.

## Can I see what runs?

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ A common misconfiguration seen in AWS Organizations that interferes with success

To ensure your Organizations are configured as needed, go to the [AWS Organizations console](https://console.aws.amazon.com/organizations/v2) and check your structure:

- The top level entity of the Organization is 'root', assigned an ID that uses this format: `r-ab12`
- The top-level entity of the Organization is 'root', assigned an ID that uses this format: `r-ab12`

- The 'root' spans a tree of one or more OUs with IDs that use this format: `ou-ab12-1234abcd`

Expand Down Expand Up @@ -135,7 +135,7 @@ The [AWSLambdaVPCAccessExecutionRole](https://docs.aws.amazon.com/lambda/latest/

Should your Lambda function require VPC access to be able to scan instances, please refer to AWS documentation on [Configuring a Lambda function to access resources in a VPC](https://docs.aws.amazon.com/lambda/latest/dg/configuration-vpc.html#vpc-configuring) to grant the Lambda function access to the appropriate VPC.

Security groups for all AWS SSM managed instances must include an egress rule to allow outbound traffic on port 443 (HTTPS) to [Mondoo Platform](https://console.mondoo.com) at IP address `34.98.71.94` to send results back to your account.
Security groups for all AWS SSM-managed instances must include an egress rule to allow outbound traffic on port 443 (HTTPS) to [Mondoo Platform](https://console.mondoo.com) at IP address `34.98.71.94` to send results back to your account.

## Logging and metrics

Expand Down
2 changes: 1 addition & 1 deletion docs/platform/infra/opsys/automation/ansible.md
Original file line number Diff line number Diff line change
Expand Up @@ -381,7 +381,7 @@ Overall CVSS score: 0.0
Scanned 1 assets
Ubuntu 18.04.6 LTS
Ubuntu 22.04 LTS
C mysystem.internal.dmz
For detailed output, run this scan with "-o full".
Expand Down
Loading

0 comments on commit 7a001b4

Please sign in to comment.