docs(security): add Telegram egress inventory [skip ci]
This commit is contained in:
@@ -48,6 +48,8 @@
|
||||
|
||||
2026-06-16 再新增 `docs/security/CD-RUNNER-SECRET-INJECTION-POST-INCIDENT-READBACK-PLAN.md` 與 `docs/security/cd-runner-secret-injection-post-incident-readback-plan.snapshot.json`,將同一批 CD pipeline、Code Review、Deploy alerts、Runner attestation 與 Secret parity / injection owner 轉成事故後回讀計畫。固定 `readback_candidate_count=5`、`c0_readback_candidate_count=4`、`c1_readback_candidate_count=1`、`write_capable_readback_candidate_count=5`、`required_readback_field_count=33`、`reviewer_check_count=30`、`outcome_lane_count=11`、`blocked_action_count=52`,讓 `secret_metadata` 從 `68%` 推進到 `70%`,讓 `gitea_workflow_runner_source_control` 從 `72%` 推進到 `74%`,高價值配置平均維持 `71%`,需 live evidence 類別仍為 `9`。此更新只補上 actor、時間窗、workflow diff state、runner executor / host、workspace cleanup、permission scope、secret name parity、secret injection route、step-env secret guard、log redaction、deploy marker / Gitea run、webhook / notification receipt、before / after deploy state、跨專案同步、rollback、post-check、防再發與 no-false-green 的脫敏回讀欄位;post-incident readback received / accepted、workflow 修改、dispatch、runner 變更、repo secret 變更、secret value collection、secret injection change、webhook / deploy key / branch protection / CODEOWNERS 變更、Gitea action dispatch、K8s secret injection、ArgoCD sync、production deploy、runtime gate 與 action button 仍全部為 `0 / false`。
|
||||
|
||||
2026-06-18 再新增 `docs/security/TELEGRAM-NOTIFICATION-EGRESS-INVENTORY.md` 與 `docs/security/telegram-notification-egress-inventory.snapshot.json`,把 repo 內 direct Telegram Bot API `sendMessage` 旁路固定成 notification egress 清冊。固定 `direct_bot_api_call_count=18`、`direct_bot_api_file_count=11`、workflow `13`、ops script `4`、API direct `1`、`gateway_normalized_callsite_count=56`、`gateway_final_exit_formatter_present_count=1`、`required_owner_field_count=18`、`reviewer_check_count=14`、`outcome_lane_count=9`、`blocked_action_count=22`。此更新只表示旁路已可重跑盤點;owner response、formatter convergence accepted、delivery receipt accepted、workflow / script modification、Telegram send、Bot API call、secret collection、production write、runtime gate 與 action button 仍全部為 `0 / false`。
|
||||
|
||||
## 1.2c 2026-06-18 Backup / Restore / Escrow 事故後回讀計畫
|
||||
|
||||
已新增 `docs/security/BACKUP-RESTORE-POST-INCIDENT-READBACK-PLAN.md` 與 `docs/security/backup-restore-post-incident-readback-plan.snapshot.json`,將 38 個 backup / restore / escrow / retention surface 轉成事故後回讀計畫。固定 `readback_candidate_count=38`、`write_capable_readback_candidate_count=27`、`live_evidence_required_readback_candidate_count=38`、`restore_drill_readback_required_candidate_count=38`、`offsite_or_escrow_readback_required_candidate_count=20`、`retention_or_remote_delete_readback_required_candidate_count=17`、`required_readback_field_count=34`、`reviewer_check_count=32`、`outcome_lane_count=11`、`blocked_action_count=51`,讓 `backup_restore_credential` 從 `64%` 推進到 `66%`,高價值配置平均維持 `71%`,需 live evidence 類別仍為 `9`。
|
||||
|
||||
@@ -83,6 +83,12 @@
|
||||
|
||||
此更新讓 `secret_metadata` 類別成熟度從 `68%` 推進到 `70%`,讓 `gitea_workflow_runner_source_control` 類別成熟度從 `72%` 推進到 `74%`。它只表示 workflow diff state、runner attestation、executor / host、workspace cleanup、permission scope、secret name parity、secret injection route、step-env secret guard、log redaction、deploy marker / Gitea run、webhook / notification receipt、before / after deploy state、cross-project sync、rollback、post-check、post-change monitoring、recurrence guard 與 no-false-green 已有事故後脫敏回讀欄位;post-incident readback received / accepted、workflow 修改、workflow dispatch、runner 變更、GitHub hosted runner、repo secret 變更、secret value collection、secret injection change、webhook / deploy key / branch protection / CODEOWNERS 變更、Gitea action dispatch、K8s secret injection、ArgoCD sync、production deploy、runtime gate 仍全部為 `0 / false`。
|
||||
|
||||
### 0.3c-2 2026-06-18 Telegram notification egress 旁路清冊
|
||||
|
||||
`telegram_notification_egress_inventory_v1` 已把 repo 內 direct Telegram Bot API `sendMessage` 旁路納入只讀清冊。固定 `direct_bot_api_file_count=11`、`direct_bot_api_call_count=18`、`workflow_direct_bot_api_call_count=13`、`ops_script_direct_bot_api_call_count=4`、`api_direct_bot_api_call_count=1`、`gateway_normalized_callsite_count=56`、`gateway_final_exit_formatter_present_count=1`。
|
||||
|
||||
此更新只表示 `.gitea/workflows`、`scripts/ops` 與 `apps/api/src/services/channel_hub.py` 的 direct egress 已可重跑盤點,不代表已遷移。owner response received / accepted、formatter convergence accepted、redaction contract accepted、delivery receipt accepted、direct Bot API migration authorized、Telegram send、Bot API call、workflow / script modification、secret collection、raw payload storage、production write、runtime gate 仍全部為 `0 / false`。
|
||||
|
||||
### 0.3d 2026-06-15 Public / Admin / API runtime config 變更證據驗收
|
||||
|
||||
`public_runtime_config_change_evidence_acceptance_v1` 已把公開產品頁、AwoooP 後台、API / CORS、frontend env、Sentry tunnel、webhook / callback 與跨產品 runtime route 轉成 metadata-only 變更證據驗收只讀帳本。固定 `candidates=6`、`c0=5`、`c1=1`、`write_capable=6`、`source_refs=20`、`required_evidence_fields=21`、`reviewer_checks=21`、`outcome_lanes=8`、`blocked_actions=32`。
|
||||
|
||||
@@ -88,6 +88,12 @@
|
||||
|
||||
同步邊界:IwoooS headline 維持 `64%`,active runtime gate 維持 `0`;post-incident readback received / accepted、workflow diff state accepted、runner attestation accepted、secret name parity accepted、secret injection route accepted、deploy marker readback accepted、Gitea run readback accepted、log redaction readback accepted、workflow modification、workflow dispatch、runner change、repo secret change、secret injection change、webhook / deploy key / branch protection / CODEOWNERS change、K8s secret injection、ArgoCD sync、production deploy、runtime gate 與 action buttons 全部仍為 `0 / false`。本段只更新文件、snapshot、guard、覆蓋矩陣、投影契約與前端 marker,不呼叫 Gitea / GitHub API、不讀 secret store、不讀 secret value、不修改 workflow、不啟用 runner、不 rotate secret、不 dispatch workflow、不觸發部署。
|
||||
|
||||
## 0.00aaaa1 2026-06-18 Telegram 通知出口旁路清冊
|
||||
|
||||
本輪把 repo 內 direct Telegram Bot API `sendMessage` 旁路納入 notification egress 只讀清冊:`telegram_notification_egress_inventory_v1` 固定 `direct_bot_api_file_count=11`、`direct_bot_api_call_count=18`、`workflow_direct_bot_api_call_count=13`、`ops_script_direct_bot_api_call_count=4`、`api_direct_bot_api_call_count=1`、`gateway_normalized_callsite_count=56`、`gateway_final_exit_formatter_present_count=1`、`required_owner_field_count=18`、`reviewer_check_count=14`、`outcome_lane_count=9`、`blocked_action_count=22`。這是 metadata-only 清冊,不是 owner response received / accepted、formatter convergence accepted、delivery receipt accepted、workflow / script modification、Telegram send、Bot API call、secret collection、production write 或 runtime gate。
|
||||
|
||||
同步邊界:IwoooS headline 維持 `64%`,active runtime gate 維持 `0`;direct Bot API migration authorized、Telegram send authorized、Bot API call authorized、workflow modification authorized、script modification authorized、secret value collection、raw payload storage、production write、runtime gate 與 action buttons 全部仍為 `0 / false`。本段只更新文件、snapshot、guard 與通知模型,不改 workflow、不重構 API、不呼叫 Telegram、不讀 Bot token、不 dispatch workflow、不觸發部署。
|
||||
|
||||
## 0.00aaa 2026-06-15 K8s / ArgoCD GitOps 變更證據驗收
|
||||
|
||||
本輪把 K8s / ArgoCD 從 owner response acceptance 推進到 GitOps 變更證據驗收只讀帳本:`k8s_argocd_change_evidence_acceptance_v1` 固定 `candidates=4`、`c0=3`、`write_capable=4`、`required_evidence_fields=18`、`reviewer_checks=18`、`outcome_lanes=8`、`blocked_actions=28`,並讓 `k8s_production_gitops` 只讀治理成熟度 `62% -> 64%`,高價值配置平均只讀成熟度仍維持 `68%`。這是 metadata-only 收件驗收,不是 change evidence received / accepted、runtime approval package、ArgoCD API read、ArgoCD sync、kubectl action、Helm upgrade、NetworkPolicy apply、NodePort change、RBAC change、live cluster read、production write 或 runtime gate。
|
||||
|
||||
110
docs/security/TELEGRAM-NOTIFICATION-EGRESS-INVENTORY.md
Normal file
110
docs/security/TELEGRAM-NOTIFICATION-EGRESS-INVENTORY.md
Normal file
@@ -0,0 +1,110 @@
|
||||
# Telegram 通知出口治理清冊
|
||||
|
||||
| 項目 | 內容 |
|
||||
|------|------|
|
||||
| 日期 | 2026-06-18 |
|
||||
| 狀態 | `inventory_ready_no_runtime_action` |
|
||||
| 工具 | `scripts/security/telegram-notification-egress-inventory.py` |
|
||||
| Snapshot | `docs/security/telegram-notification-egress-inventory.snapshot.json` |
|
||||
| 模式 | repo-only scan;不讀 secret、不送 Telegram、不改 workflow / script |
|
||||
| runtime gate | `0` |
|
||||
|
||||
## 1. 目的
|
||||
|
||||
TelegramGateway 已經把 `send_alert_notification()`、`send_text()` 與 `_send_request("sendMessage", ...)` 收斂到最後出口 formatter,能把主機資源壓力、Wazuh、Kali、Nginx drift、Backup / Restore / Escrow、Provider freshness 與 supply-chain drift 轉成 `ai_automation_alert_card_v1`。
|
||||
|
||||
但 repo 內仍有 workflow、ops script 與一條 API path 直接呼叫 Telegram Bot API。這些路徑可能繞過 TelegramGateway 的 formatter、dedup、outbound mirror、KM / PlayBook / Verifier 沉澱與 no-false-green gate,因此必須先建清冊,再分批收斂。
|
||||
|
||||
此清冊只建立 metadata-only evidence,不代表允許 live Telegram send、workflow 修改、script 修改、secret 讀取或 production write。
|
||||
|
||||
## 2. 固定數字
|
||||
|
||||
| 指標 | 數值 | 解讀 |
|
||||
|------|------|------|
|
||||
| `scanned_file_count` | `554` | 掃描 `.gitea/workflows`、`scripts/ops`、`scripts/ci`、`apps/api/src` |
|
||||
| `direct_bot_api_file_count` | `11` | 仍有 11 個檔案直接呼叫 Bot API |
|
||||
| `direct_bot_api_call_count` | `18` | 直接 `sendMessage` call site 總數 |
|
||||
| `workflow_direct_bot_api_call_count` | `13` | Gitea workflow 直送 Telegram |
|
||||
| `ops_script_direct_bot_api_call_count` | `4` | ops script 直送 Telegram fallback |
|
||||
| `api_direct_bot_api_call_count` | `1` | API `channel_hub.py` interim path 直送 Telegram |
|
||||
| `gateway_normalized_callsite_count` | `56` | 已進入 TelegramGateway / final-exit formatter 的 call site |
|
||||
| `gateway_final_exit_formatter_present_count` | `1` | `normalize_telegram_send_message_payload()` 已存在 |
|
||||
| `required_owner_field_count` | `18` | 收斂前需要 owner 補齊的欄位 |
|
||||
| `reviewer_check_count` | `14` | reviewer 必檢規則 |
|
||||
| `outcome_lane_count` | `9` | 收件結果分流 |
|
||||
| `blocked_action_count` | `22` | 清冊階段明確禁止動作 |
|
||||
|
||||
所有 `owner_response_received / accepted`、formatter convergence accepted、delivery receipt accepted、Telegram send、Bot API call、workflow modification、script modification、secret collection、raw payload storage、production write、runtime gate 與 action button 都維持 `0 / false`。
|
||||
|
||||
## 3. 目前 direct Bot API surface
|
||||
|
||||
| 類別 | Call count | 代表路徑 |
|
||||
|------|------------|----------|
|
||||
| Gitea workflow | `13` | `.gitea/workflows/cd.yaml`、`.gitea/workflows/cd-dev.yaml`、`.gitea/workflows/code-review.yaml`、`.gitea/workflows/deploy-alerts.yaml`、`.gitea/workflows/e2e-health.yaml`、`.gitea/workflows/run-migration.yml` |
|
||||
| Ops script | `4` | `scripts/ops/docker-health-monitor.sh`、`scripts/ops/pg-backup.sh`、`scripts/ops/dr-drill.sh`、`scripts/ops/backup-from-110.sh` |
|
||||
| API direct path | `1` | `apps/api/src/services/channel_hub.py` |
|
||||
|
||||
上述路徑不一定全部錯誤;例如 ops script 可能是 API 離線 fallback。但只要它直接呼叫 Bot API `sendMessage`,就必須被視為通知出口治理 surface:需有 owner、訊息形狀、redaction、formatter convergence、delivery receipt 與 no-false-green 驗收。
|
||||
|
||||
## 4. Owner 必填欄位
|
||||
|
||||
每個 direct Bot API surface 收斂前至少需要:
|
||||
|
||||
1. `egress_surface_id`
|
||||
2. `owner_role_or_team`
|
||||
3. `routing_purpose`
|
||||
4. `current_sender`
|
||||
5. `target_chat_route`
|
||||
6. `message_shape_contract`
|
||||
7. `redaction_contract`
|
||||
8. `formatter_convergence_plan`
|
||||
9. `delivery_receipt_ref`
|
||||
10. `dedup_or_fingerprint_plan`
|
||||
11. `fallback_or_degraded_mode`
|
||||
12. `migration_or_exception_reason`
|
||||
13. `maintenance_window`
|
||||
14. `rollback_owner`
|
||||
15. `postcheck_evidence_ref`
|
||||
16. `no_secret_value_attestation`
|
||||
17. `no_raw_payload_attestation`
|
||||
18. `no_false_green_attestation`
|
||||
|
||||
所有 evidence 只能是脫敏 ref、commit、run id、job id、artifact pointer 或收件編號;不得貼 Bot token、chat secret、secret hash、partial token、原始訊息 payload、未脫敏 workflow log 或工作視窗內容。
|
||||
|
||||
## 5. Reviewer checks
|
||||
|
||||
Reviewer 必須確認:
|
||||
|
||||
- direct Bot API surface 已列入 snapshot,不能只靠 `rg` 手工看過。
|
||||
- owner role / target route / routing purpose 明確。
|
||||
- 訊息形狀要收斂成 `ai_automation_alert_card_v1` 或有明確例外理由。
|
||||
- redaction contract、formatter convergence path 與 delivery receipt metadata 存在。
|
||||
- fallback mode 不會把 raw payload、完整路徑、內網 IP、secret、工作視窗內容或個人 namespace 送出去。
|
||||
- workflow / script / API 修改需另走 owner approval 與維護窗口。
|
||||
- 清冊本身沒有送 Telegram、沒有 dispatch workflow、沒有讀 secret。
|
||||
- 不把 route `200`、CD success、UI 可見或 Telegram 送達當成 AI 自動化閉環完成。
|
||||
|
||||
## 6. Outcome lanes
|
||||
|
||||
| Lane | 說明 |
|
||||
|------|------|
|
||||
| `waiting_owner_response` | 尚未收到 owner 回覆;所有 accepted / runtime count 維持 0 |
|
||||
| `request_owner_route_supplement` | 缺 owner、target route 或 routing purpose |
|
||||
| `request_formatter_convergence_plan` | 缺 formatter convergence 或例外理由 |
|
||||
| `request_redaction_contract` | 缺 redaction / no-raw-payload attestation |
|
||||
| `request_delivery_receipt_metadata` | 缺 delivery receipt metadata 或 dedup / fingerprint plan |
|
||||
| `quarantine_secret_or_raw_payload` | 收到 secret value、raw payload、raw log 或未脫敏截圖時隔離 |
|
||||
| `reject_false_green_claim` | 把 route 200、CD success、UI 可見或 Telegram 送達當驗收時拒收 |
|
||||
| `ready_for_notification_egress_review` | metadata 合格後進 reviewer review |
|
||||
| `waiting_runtime_gate` | 即使 reviewer accepted,runtime send / workflow modification 仍需獨立批准 |
|
||||
|
||||
## 7. 禁止動作
|
||||
|
||||
此清冊階段明確禁止 Telegram 實發、Bot API call、workflow 修改、未批准 script 修改、secret value / hash / partial token / chat id 收集、保存 raw message payload、保存未脫敏 workflow log、改 chat route、改 Bot token、rotate secret、workflow dispatch、production deploy、把 route 200 / CD success / UI 可見當通知驗收、跳過 formatter convergence、跳過 redaction review、開 runtime gate 或新增 action button。
|
||||
|
||||
## 8. 下一步
|
||||
|
||||
1. 先把 Gitea workflow 13 個 direct send 分成 CD / code-review / migration / health 類,決定哪些改走 AWOOI Alertmanager / TelegramGateway,哪些保留為 break-glass fallback。
|
||||
2. `scripts/ops/docker-health-monitor.sh`、`pg-backup.sh`、`dr-drill.sh`、`backup-from-110.sh` 需要 owner 確認 API 離線 fallback 的訊息形狀與 redaction contract。
|
||||
3. `apps/api/src/services/channel_hub.py` 的 interim Telegram path 需要評估是否改走 TelegramGateway 或至少套同一個 normalization / mirror / receipt 契約。
|
||||
4. 每個遷移都必須單獨做 owner approval、maintenance window、rollback owner、no-secret-value evidence 與 post-check;不得用本清冊直接改 workflow 或送 Telegram。
|
||||
2059
docs/security/telegram-notification-egress-inventory.snapshot.json
Normal file
2059
docs/security/telegram-notification-egress-inventory.snapshot.json
Normal file
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user