An asynchronous, cross-domain state auditor and configuration drift detector. This engine aggregates runtime metrics, hardware accelerator status, and network topologies across local compute nodes, OpenWrt edge routers, and external SaaS providers (Cloudflare, GitHub). State is compiled into a normalized YAML registry to detect unauthorized or accidental configuration drift.
- Asynchronous SSH Collection: Parallelized execution across local network nodes extracting system heuristics, ZRAM mappings, Docker configurations, and hardware accelerator states (GPU/TPU).
- Native OpenWrt Integration: Direct
uciconfiguration parsing for granular edge router tracking and drift detection across interfaces, firewall rules, and DHCP states. - Cloudflare & GitHub Telemetry: Pulls active tunnel metrics, DNS records, Access policies, Worker deployments, and GitHub Actions runner states.
- Hardware-Backed Trust: Integrates with
ageand FIDO2 tokens to decrypt.env.agesecrets into a volatile RAM disk (/dev/shm) at runtime, guaranteeing zero-footprint credentials. - Noise-Filtered Drift Detection: Compares active state against historical baselines while automatically filtering transient data (load average, memory fluctuations) to surface only actionable configuration changes.
- Portable Binary: Wraps execution and dependencies into a standalone binary via PyInstaller and Make.
- Python 3.12+
makeage(for environment decryption)- FIDO2 Hardware Key (configured via
chezmoior localage-identity.txt) - Target nodes require SSH access (Ed25519 or RSA dropbear/OpenSSH keys)
-
Clone the repository:
git clone [https://github.com/RPDevs-Builds/infra-audit-engine.git](https://github.com/RPDevs-Builds/infra-audit-engine.git) cd infra-audit-engine -
Initialize the environment and compile the binary:
make build
This command creates the virtual environment, installs requirements, and compiles the
orchestratorbinary into thedist/directory, bundling necessary configuration paths.
Secrets and target arrays are managed via an .env (or .env.age) file at the project root.
Interactive Enrollment: Use the built-in enrollment script to correctly map and format new infrastructure targets:
make enrollNote: If utilizing FIDO2 encryption, ensure you encrypt the updated .env file to .env.age using your local encryption script before executing the binary.
Execute the compiled standalone binary directly:
make runAlternatively: ./dist/orchestrator
- Hardware decryption sequence initiates (requires physical FIDO2 touch).
- Asynchronous connections map target topologies.
- System outputs
WARNINGlines detailing line-item configuration drift. - Active state merges to
docs/CURRENT_ENV.yml. - Previous state archives to
docs/history/.
.
├── Makefile
├── requirements.txt
├── .env.age # Hardware-encrypted configuration (Not committed)
├── src/
│ ├── orchestrator.py # Main execution and drift logic
│ ├── config.py # Environment boundary and decryption handling
│ ├── registry.py # YAML state management and normalization
│ ├── enroll.py # Target array generator
│ ├── models/
│ │ └── infrastructure.py # Pydantic schemas (Linux, OpenWrt, etc.)
│ └── modules/
│ ├── ssh_audit.py # Local infrastructure collection
│ ├── cloudflare_api.py # SaaS API logic
│ └── github_api.py # SaaS API logic
└── docs/
├── CURRENT_ENV.yml # Live infrastructure state
└── history/ # Retained rolling state backups