Repository navigation
Add Azure Network Layer assurance and routing checks - #252
Merged
Vishnu2707 merged 7 commits intoAug 13, 2026
Merged
Conversation
Signed-off-by: ritiksah141 <ritiksah141@gmail.com>
Signed-off-by: ritiksah141 <ritiksah141@gmail.com>
Signed-off-by: ritiksah141 <ritiksah141@gmail.com>
Signed-off-by: ritiksah141 <ritiksah141@gmail.com>
Signed-off-by: ritiksah141 <ritiksah141@gmail.com>
ritiksah141
marked this pull request as ready for review
August 12, 2026 22:37
ritiksah141
requested review from
SHAURYAKSHARMA24,
Vishnu2707 and
parthrohit22
as code owners
August 12, 2026 22:37
Signed-off-by: ritiksah141 <ritiksah141@gmail.com>
Collaborator
|
@ritiksah141 - One thing, can you confirm nothing downstream pattern matches on the old TBD- prefix specifically, since this rename touches almost every rule's mapping and that logic isn't shown in the diff. If get_compliance_score() just checks key existence we're fine, but worth a quick check before i go ahead and merge it. |
Signed-off-by: ritiksah141 <ritiksah141@gmail.com>
Collaborator
Author
|
@Vishnu2707, I verified that: |
Vishnu2707
approved these changes
Aug 13, 2026
Vishnu2707
left a comment
Collaborator
There was a problem hiding this comment.
Good, thanks for confirming that. No other changes from my side, this looks good to merge.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds Azure public-cloud Network Layer assurance with complete addressing, routing, transit, protection, and observability coverage plus customer-actionable Layer 3 routing checks.
What changed
GET /api/assurance/network-layerreporting with separate catalog coverage and evidence freshness.AZ-NET-*scanner rule by its actual OSI behavior.AZ-NET-016for network interfaces with IP forwarding enabled.AZ-NET-017for explicit IPv4 or IPv6 default user-defined routes using the direct Internet next hop.CIS mapping decisions
All CIS mappings were audited against CIS Microsoft Azure Foundations Benchmark 2.0.0.
AZ-KV-006now maps to the genuine RBAC recommendation 8.6, whileAZ-KV-004maps to recoverability recommendation 8.5. Rules without a direct benchmark recommendation use rule-specificN/A-*identifiers instead of unresolvedTBD-*placeholders.N/Ais an explicit reviewed decision: it prevents OpenShield from claiming that a rule implements an unrelated CIS recommendation and preserves the repository invariant that each numbered CIS control maps to one OpenShield rule. This includes the Layer 3 routing checks, Layer 2 MACsec checks, application identity checks, supply-chain checks, the overlapping Key Vault soft-delete prerequisite, and the proactive 30-day certificate-renewal check.Verification
Type of change
Testing
Checklist
Signed-off-bytrailerAZ-NET-*rule is classifiedRelated issues
Files to review
The main implementation can be reviewed in this order:
compliance/assurance/network_layer.json— complete Layer 3 catalog, controls, evidence, automation decisions, and OSI classifications.api/services/network_layer_assurance.py— closed validation and report generation.scanner/rules/az_net_016.pyandscanner/rules/az_net_017.py— new actionable Layer 3 checks.scanner/azure_client.py— authoritative NIC and route-table inventory accessors.tests/test_network_layer_assurance.pyandtests/test_rules_network.py— catalog, endpoint, rule, empty-inventory, and failure-path coverage.playbooks/cli/fix_az_net_016.shandplaybooks/cli/fix_az_net_017.sh— confirmation-based remediation.compliance/frameworks/*.json— CIS, NIST, ISO 27001, and SOC 2 mappings.scanner/engine.py,.github/workflows/ci.yml, andtests/test_engine_integration.py— bug: scanner engine loads rule modules that CI validation and doc counts never see #244 rule-discovery fix and regression guard.docs/network-layer-assurance.mdandCHANGELOG.md— responsibility boundary, limitations, and release entry.