Skip to main content

Bona

PyPI version License: MIT

Infrastructure asset graph — the Joern for cloud.

Discovers, maps, and graphs CSP resources via AWS Config. Produces nodes + edges that feed into Neptune for compliance analysis, impact assessment, and risk scoring.

Standalone package. No dependency on graphrag-toolkit.

Installation

pip install bona

Dependencies

Bona has minimal dependencies:

  • boto3>=1.35.0 — AWS SDK for resource discovery
  • pydantic>=2.0 — Data validation and schema models

Bona is a standalone package. It does not depend on graphrag-document-graph, graphrag-codeproperty-graph, or graphrag-toolkit-lexical-graph.

Quick Start

# Discover all resources in an account
bona discover --account 123456789012 --region us-east-1

# Enumerate AWS services (for recipe generation)
bona services

# Check compliance state
bona compliance --account 123456789012

Python API

from bona import AWSProvider, DiscoveryPipeline

provider = AWSProvider(account_id="123456789012", region="us-east-1")
result = provider.discover()

print(result.summary())
# → Discovered 142 resources, 287 relationships, 3 findings in 4521ms

for resource in result.resources:
    print(f"{resource.resource_type}: {resource.name}")

for edge in result.relationships:
    print(f"{edge.source_id} --{edge.edge_type}--> {edge.target_id}")

Architecture

AWS Config (already running) → Bona reads → normalizes → outputs graph schema
                                                              ↓
                                                    Neptune (via AI-LENS)

Bona is thin. AWS Config does the heavy lifting. Bona just transforms the output into a graph schema compatible with the GraphRAG Toolkit ecosystem.

Package Structure

bona/
  ├── providers/        AWS, Azure, GCP, Application adapters
  │   └── aws/          AWS Config + Resource Explorer + Inspector
  ├── pipeline/         discover → transform → load → enrich
  ├── schema/           AssetNode, AssetEdge, DiscoveryResult
  ├── query/            graph traversal, compliance, impact analysis
  └── cli.py            standalone CLI tool

Dependency Chain

bona (standalone)
├── boto3>=1.35.0
└── pydantic>=2.0

Bona is independent. It produces graph-compatible output but does not import or require any graphrag packages.

Contributing

See CONTRIBUTING.md for development setup, testing, and PR guidelines.

License

MIT — see LICENSE for details.

Metadata

Release files for bona 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bona 0.2.0
File Size Uploaded
bona-0.2.0.tar.gz 14.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bona 0.2.0
File Interpreter ABI Platform
bona-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 33.7 kB

Release files / bona-0.2.0.tar.gz

Download URL bona-0.2.0.tar.gz
Size 14.9 kB
Tags Source
SHA-256 checksum
How to use checksums
1c1bb75250c9c5900fdef33685214f78e8a5428f472d7cd39a002e57b5c0c25d
BLAKE2b-256 checksum
How to use checksums
502a0d120786723a340349189fefb0c6b5e67480e34a365f204cd8e4cb76614d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / bona-0.2.0-py3-none-any.whl

Download URL bona-0.2.0-py3-none-any.whl
Size 18.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6c0ebda65aaf287ddae0acec934d55d292eb59b2f9ccea2269bea9b1277a4d33
BLAKE2b-256 checksum
How to use checksums
d4e0e9e9930435c496cfce5185c78096408d23f7339e81554bbf111a9e8aa5bc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

0.7.0

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

This release

0.2.0 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page