Skip to content

About

Asynchronous infrastructure state auditor and drift detection engine for Linux, OpenWrt, Cloudflare, and GitHub ecosystems. Features FIDO2 hardware-backed secret decryption and automated YAML topology generation.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

8 Commits

Folders and files

Repository files navigation

Infrastructure Audit Engine

An asynchronous, cross-domain state auditor and configuration drift detector. This engine aggregates runtime metrics, hardware accelerator status, and network topologies across local compute nodes, OpenWrt edge routers, and external SaaS providers (Cloudflare, GitHub). State is compiled into a normalized YAML registry to detect unauthorized or accidental configuration drift.

Core Features

  • Asynchronous SSH Collection: Parallelized execution across local network nodes extracting system heuristics, ZRAM mappings, Docker configurations, and hardware accelerator states (GPU/TPU).
  • Native OpenWrt Integration: Direct uci configuration parsing for granular edge router tracking and drift detection across interfaces, firewall rules, and DHCP states.
  • Cloudflare & GitHub Telemetry: Pulls active tunnel metrics, DNS records, Access policies, Worker deployments, and GitHub Actions runner states.
  • Hardware-Backed Trust: Integrates with age and FIDO2 tokens to decrypt .env.age secrets into a volatile RAM disk (/dev/shm) at runtime, guaranteeing zero-footprint credentials.
  • Noise-Filtered Drift Detection: Compares active state against historical baselines while automatically filtering transient data (load average, memory fluctuations) to surface only actionable configuration changes.
  • Portable Binary: Wraps execution and dependencies into a standalone binary via PyInstaller and Make.

Prerequisites

  • Python 3.12+
  • make
  • age (for environment decryption)
  • FIDO2 Hardware Key (configured via chezmoi or local age-identity.txt)
  • Target nodes require SSH access (Ed25519 or RSA dropbear/OpenSSH keys)

Installation & Build

  1. Clone the repository:

    git clone [https://github.com/RPDevs-Builds/infra-audit-engine.git](https://github.com/RPDevs-Builds/infra-audit-engine.git)
    cd infra-audit-engine
  2. Initialize the environment and compile the binary:

    make build

    This command creates the virtual environment, installs requirements, and compiles the orchestrator binary into the dist/ directory, bundling necessary configuration paths.

Configuration

Secrets and target arrays are managed via an .env (or .env.age) file at the project root.

Interactive Enrollment: Use the built-in enrollment script to correctly map and format new infrastructure targets:

make enroll

Note: If utilizing FIDO2 encryption, ensure you encrypt the updated .env file to .env.age using your local encryption script before executing the binary.

Usage

Execute the compiled standalone binary directly:

make run

Alternatively: ./dist/orchestrator

Expected Output

  1. Hardware decryption sequence initiates (requires physical FIDO2 touch).
  2. Asynchronous connections map target topologies.
  3. System outputs WARNING lines detailing line-item configuration drift.
  4. Active state merges to docs/CURRENT_ENV.yml.
  5. Previous state archives to docs/history/.

Directory Structure

.
├── Makefile
├── requirements.txt
├── .env.age                 # Hardware-encrypted configuration (Not committed)
├── src/
│   ├── orchestrator.py      # Main execution and drift logic
│   ├── config.py            # Environment boundary and decryption handling
│   ├── registry.py          # YAML state management and normalization
│   ├── enroll.py            # Target array generator
│   ├── models/
│   │   └── infrastructure.py # Pydantic schemas (Linux, OpenWrt, etc.)
│   └── modules/
│       ├── ssh_audit.py     # Local infrastructure collection
│       ├── cloudflare_api.py # SaaS API logic
│       └── github_api.py    # SaaS API logic
└── docs/
    ├── CURRENT_ENV.yml      # Live infrastructure state
    └── history/             # Retained rolling state backups

About

Asynchronous infrastructure state auditor and drift detection engine for Linux, OpenWrt, Cloudflare, and GitHub ecosystems. Features FIDO2 hardware-backed secret decryption and automated YAML topology generation.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages