Skip to content

Commit 82cf216

Browse files
feat(mongodbatlas): add MongoDB Atlas provider PoC (#8312)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
1 parent 7916425 commit 82cf216

104 files changed

Lines changed: 6291 additions & 6 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/labeler.yml‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,11 @@ provider/iac:
3737
- any-glob-to-any-file: "prowler/providers/iac/**"
3838
- any-glob-to-any-file: "tests/providers/iac/**"
3939

40+
provider/mongodbatlas:
41+
- changed-files:
42+
- any-glob-to-any-file: "prowler/providers/mongodbatlas/**"
43+
- any-glob-to-any-file: "tests/providers/mongodbatlas/**"
44+
4045
github_actions:
4146
- changed-files:
4247
- any-glob-to-any-file: ".github/workflows/*"
@@ -52,11 +57,13 @@ mutelist:
5257
- any-glob-to-any-file: "prowler/providers/azure/lib/mutelist/**"
5358
- any-glob-to-any-file: "prowler/providers/gcp/lib/mutelist/**"
5459
- any-glob-to-any-file: "prowler/providers/kubernetes/lib/mutelist/**"
60+
- any-glob-to-any-file: "prowler/providers/mongodbatlas/lib/mutelist/**"
5561
- any-glob-to-any-file: "tests/lib/mutelist/**"
5662
- any-glob-to-any-file: "tests/providers/aws/lib/mutelist/**"
5763
- any-glob-to-any-file: "tests/providers/azure/lib/mutelist/**"
5864
- any-glob-to-any-file: "tests/providers/gcp/lib/mutelist/**"
5965
- any-glob-to-any-file: "tests/providers/kubernetes/lib/mutelist/**"
66+
- any-glob-to-any-file: "tests/providers/mongodbatlas/lib/mutelist/**"
6067

6168
integration/s3:
6269
- changed-files:

‎.github/workflows/sdk-pull-request.yml‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -234,6 +234,21 @@ jobs:
234234
run: |
235235
poetry run pytest -n auto --cov=./prowler/providers/iac --cov-report=xml:iac_coverage.xml tests/providers/iac
236236
237+
# Test MongoDB Atlas
238+
- name: MongoDB Atlas - Check if any file has changed
239+
id: mongodb-atlas-changed-files
240+
uses: tj-actions/changed-files@ed68ef82c095e0d48ec87eccea555d944a631a4c # v46.0.5
241+
with:
242+
files: |
243+
./prowler/providers/mongodbatlas/**
244+
./tests/providers/mongodbatlas/**
245+
.poetry.lock
246+
247+
- name: MongoDB Atlas - Test
248+
if: steps.mongodb-atlas-changed-files.outputs.any_changed == 'true'
249+
run: |
250+
poetry run pytest -n auto --cov=./prowler/providers/mongodbatlas --cov-report=xml:mongodb_atlas_coverage.xml tests/providers/mongodbatlas
251+
237252
# Common Tests
238253
- name: Lib - Test
239254
if: steps.are-non-ignored-files-changed.outputs.any_changed == 'true'

‎docs/basic-usage/prowler-cli.md‎

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
## Running Prowler
22

3-
Running Prowler requires specifying the provider (e.g `aws`, `gcp`, `azure`, `m365`, `github` or `kubernetes`):
3+
Running Prowler requires specifying the provider (e.g `aws`, `gcp`, `azure`, `kubernetes`, `m365`, `github`, `iac` or `mongodbatlas`):
44

55
???+ note
66
If no provider is specified, AWS is used by default for backward compatibility with Prowler v2.
@@ -255,3 +255,28 @@ prowler iac --scan-path ./my-iac-directory --exclude-path ./my-iac-directory/tes
255255
- For more details on supported scanners, see the [Trivy documentation](https://trivy.dev/latest/docs/scanner/vulnerability/)
256256

257257
See more details about IaC scanning in the [IaC Tutorial](../tutorials/iac/getting-started-iac.md) section.
258+
259+
## MongoDB Atlas
260+
261+
Prowler allows you to scan your MongoDB Atlas cloud database deployments for security and compliance issues.
262+
263+
Authentication is done using MongoDB Atlas API key pairs:
264+
265+
```console
266+
# Using command-line arguments
267+
prowler mongodbatlas --atlas-public-key <public_key> --atlas-private-key <private_key>
268+
269+
# Using environment variables
270+
export ATLAS_PUBLIC_KEY=<public_key>
271+
export ATLAS_PRIVATE_KEY=<private_key>
272+
prowler mongodbatlas
273+
```
274+
275+
You can filter scans to specific organizations or projects:
276+
277+
```console
278+
# Scan specific project
279+
prowler mongodbatlas --atlas-project-id <project_id>
280+
```
281+
282+
See more details about MongoDB Atlas Authentication in [Requirements](../getting-started/requirements.md#mongodb-atlas)

‎docs/developer-guide/provider.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ A provider is any platform or service that offers resources, data, or functional
1010
- Software as a Service (SaaS) Platforms (like Microsoft 365)
1111
- Development Platforms (like GitHub)
1212
- Container Orchestration Platforms (like Kubernetes)
13+
- Database-as-a-Service Platforms (like MongoDB Atlas)
1314

1415
For providers supported by Prowler, refer to [Prowler Hub](https://hub.prowler.com/).
1516

@@ -63,6 +64,7 @@ Given the complexity and variability of providers, use existing provider impleme
6364
- [Kubernetes](https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/kubernetes/kubernetes_provider.py)
6465
- [Microsoft365](https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/microsoft365/microsoft365_provider.py)
6566
- [GitHub](https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/github/github_provider.py)
67+
- [MongoDB Atlas](https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/mongodbatlas/mongodbatlas_provider.py)
6668

6769
### Basic Provider Implementation: Pseudocode Example
6870

‎docs/index.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ The official supported providers right now are:
1313
| **M365** | Official | Stable | UI, API, CLI |
1414
| **Github** | Official | Stable | UI, API, CLI |
1515
| **IaC** | Official | Beta | CLI |
16+
| **MongoDB Atlas** | Official | Beta | CLI |
1617
| **NHN** | Unofficial | Beta | CLI |
1718

1819
Prowler supports **auditing, incident response, continuous monitoring, hardening, forensic readiness, and remediation**.
Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
# MongoDB Atlas Authentication
2+
3+
MongoDB Atlas provider uses [HTTP Digest Authentication with API key pairs consisting of a public key and private key](https://www.mongodb.com/docs/atlas/configure-api-access/#grant-programmatic-access-to-service).
4+
5+
## Authentication Methods
6+
7+
### Command-Line Arguments
8+
9+
```bash
10+
prowler mongodbatlas --atlas-public-key <public_key> --atlas-private-key <private_key>
11+
```
12+
13+
### Environment Variables
14+
15+
```bash
16+
export ATLAS_PUBLIC_KEY=<public_key>
17+
export ATLAS_PRIVATE_KEY=<private_key>
18+
prowler mongodbatlas
19+
```
20+
21+
## Creating API Keys
22+
23+
### Step-by-Step Guide
24+
25+
1. **Log into MongoDB Atlas**
26+
- Access the MongoDB Atlas console
27+
28+
2. **Navigate to Access Manager**
29+
- Go to the organization or project access management section
30+
31+
3. **Select API Keys Tab**
32+
- Click on the "API Keys" tab
33+
34+
4. **Create API Key**
35+
- Click "Create API Key"
36+
- Provide a description for the key
37+
38+
5. **Set Permissions**
39+
- Grant minimum required permissions
40+
41+
6. **Save Credentials**
42+
- Note the public key and private key
43+
- Store credentials securely
44+
45+
For more details about MongoDB Atlas, see the [MongoDB Atlas Tutorial](../tutorials/mongodbatlas/getting-started-mongodbatlas.md).
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
# Getting Started with MongoDB Atlas
2+
3+
MongoDB Atlas provider enables security assessments of MongoDB Atlas cloud database deployments.
4+
5+
## Features
6+
7+
- **Authentication**: Supports MongoDB Atlas API key authentication
8+
- **Services**: Projects and clusters services
9+
- **Checks**: Network access security and encryption at rest validation
10+
11+
## Creating API Keys
12+
13+
To create MongoDB Atlas API keys:
14+
15+
1. **Log into MongoDB Atlas**: Access the MongoDB Atlas console
16+
2. **Navigate to Access Manager**: Go to the organization access management section:
17+
18+
- Click on Access Manager and Organization Access:
19+
20+
![Organization Access](./img/organization-access.png)
21+
22+
- After that click on the Applications tab inside the Access Manager:
23+
24+
![Project Access](./img/access-manager.png)
25+
26+
3. **Select API Keys Tab**: Click on the "API Keys" tab that appears in the image above
27+
28+
4. **Create API Key**: Click "Create API Key" and provide a description
29+
30+
![Create API Key](./img/create-api-key.png)
31+
32+
5. **Set Permissions**: Project permissions are recommended for security, you can modify them after creating the key
33+
34+
![Set Permissions](./img/modify-permission.png)
35+
36+
6. **Save Credentials**: Note the public key and private key and store them securely
37+
38+
![Save Credentials](./img/copy-key.png)
39+
40+
7. **Add IP Access List**: Add the IP where you are running Prowler to the IP Access List of the API Key. If you want to skip this step and use your API key in all type of IP addresses you need to uncheck the `Require IP Access List for the Atlas Administration API` button on the [Organization Settings](#needed-permissions), but this is not recommended.
41+
42+
![Organization Settings](./img/add-ip.png)
43+
44+
## Basic Usage
45+
46+
### Scan All Projects and Clusters
47+
48+
After storing your API keys, you can run Prowler with the following command:
49+
50+
```bash
51+
prowler mongodbatlas --atlas-public-key <key> --atlas-private-key <secret>
52+
```
53+
54+
Also, you can set your API keys as environment variables:
55+
56+
```bash
57+
export ATLAS_PUBLIC_KEY=<key>
58+
export ATLAS_PRIVATE_KEY=<secret>
59+
```
60+
61+
And then just run Prowler with the following command:
62+
63+
```bash
64+
prowler mongodbatlas
65+
```
66+
67+
### Scanning a Specific Project
68+
69+
If you want to scan a specific project, you can use the following argument added to the command above:
70+
71+
```bash
72+
prowler mongodbatlas --atlas-project-id <project-id>
73+
```
74+
75+
### Needed Permissions
76+
77+
MongoDB Atlas API keys require appropriate permissions to perform security checks:
78+
79+
- **Organization Read Only**: Provides read-only access to everything in the organization, including all projects in the organization.
80+
- If you want to be able to [audit the Auditing configuration for the project](https://www.mongodb.com/docs/api/doc/atlas-admin-api-v2/group/endpoint-auditing), **Organization Owner** is needed.
81+
82+
Also, it's important to note that the IP where you are running Prowler must be added to the IP Access List of the MongoDB Atlas organization API key. If you want to skip this step and use your API key in all type of IP addresses you need to uncheck the `Require IP Access List for the Atlas Administration API` button on the Organization Settings, that setting is [enabled by default](https://www.mongodb.com/docs/atlas/configure-api-access/#optional--require-an-ip-access-list-for-the-atlas-administration-api).
83+
84+
???+ warning
85+
If you want the check `organizations_api_access_list_required` to pass you will need to enable the API access list for the organization, so to make sure that your API Key is working you need to add your IP to the IP Access List of the organization. If you are running the check from Prowler Cloud, you will need to add our IP to the IP Access List.
86+
87+
![Organization Settings](./img/ip-access-list.png)
94.7 KB
Loading
97.2 KB
Loading
97.1 KB
Loading

0 commit comments

Comments
 (0)