Devnullit

joined 1 month ago
[–] [email protected] 1 points 18 hours ago* (last edited 16 hours ago)

Yea it's a good complement to those tools too, but for plain compliance mods, use flowpipe. Steampipe is more of a realtime view of resources, where wiz and orca are more scanners with state. You can kind of mimik it with steampipe but it's a lot of extra work. Credentials handling is entirely dependent on the plugin being used. So use a wrapper to pull whatever info from your secrets store (vault, sops, etc) and inject it in your local env/configs

[–] [email protected] 1 points 1 day ago* (last edited 1 day ago) (2 children)

Sorry, I don't. I learned by using. It's like any other tool, play with it, and look at the code and docs. What's your use case? From the sound of it, it's more a config managment issue than steampipe issue. I can try and help. Also they are active on slack and respond to bugs pretty quick in my experience.

[–] [email protected] 3 points 1 day ago* (last edited 1 day ago) (4 children)

Depends on the plugin used, but you can tool it up to use env variables or whatever the plugin supports, you can also change perms locally or host it in service mode with no direct access other than a postgres connection, it's postgres under the hood so you can add roles etc if you want. I use a wrapper to generate configs/envs on startup pulling from ssm parameters or secrets on Aws

[–] [email protected] 3 points 2 weeks ago (1 children)

https://scedc.caltech.edu/recent/ another source for the next one, since boost for reddit is dead I'm not really checking reddit anymore so here's hoping for more activity on lemmy