Skip to main content

Varroa

Varroa is a security related openstack service. It is named after the varroa mite which could be considered a vulnerability to bees. It has several functions:

  • Track IP ownership over time in openstack
  • Store and manage discovered security risks from openstack resources.

It's main/initial purpose is to ingest security scan data, link these IP addresses to openstack resources and provide the ability for the owners of those resources to see these security risks.

Client

To install the client: pip install varroaclient

Source: https://github.com/NeCTAR-RC/python-varroaclient

Concepts

IP Usage

Varroa will keep track of what openstack resource owned an IP address for what period. It does this by consuming port create/update/delete events from neutron.

Security Risk Type

A security risk type is an admin defined type of security risk. An example could be "Password SSH allowed"

A security risk type has a name and a description. The description should describe what the security risk is and ideally the steps taken to fix this risk.

Security Risk

A security risk is the linkage of a security risk type to an openstack resource. eg. Compute instance with id XYZ has a "Password SSH allowed" security risk.

Only the IP address of the affected resource needs to be entered when creating a new security risk. Varroa will then process this entry and attempt to link that IP address to an Openstack resource.

Security Risk workflow/states

When you create a new security risk it will have the initial state of NEW. Varroa will attempt to link all NEW security risks with an openstack resource. If varroa finds a matching resource then it will add these details to the security risk Once varroa has attempted to link the IP to a resource it will change the status of the security risk to PROCESSED. If project_id/resource_id is null and status = PROCESSED it means varroa couldn't find a matching resource.

Installation

You can install varroa using helm onto a k8s cluster see https://github.com/NeCTAR-RC/varroa-helm

Release files for varroa 0.11.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for varroa 0.11.1
File Size Uploaded
varroa-0.11.1.tar.gz 33.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for varroa 0.11.1
File Interpreter ABI Platform
varroa-0.11.1-py3-none-any.whl Python 3 none any Details

Total release size: 92.4 kB

Release files / varroa-0.11.1.tar.gz

Download URL varroa-0.11.1.tar.gz
Size 33.6 kB
Tags Source
SHA-256 checksum
How to use checksums
4f39a78f9bc8ae73d906dff280c3fba767cef9703a1e8e3d64bd8193e16d0238
BLAKE2b-256 checksum
How to use checksums
cf6283b95f33b21b22f4be0868ad4104a7135f0a0e74189c36f25bbd880d592b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.12.3

Release files / varroa-0.11.1-py3-none-any.whl

Download URL varroa-0.11.1-py3-none-any.whl
Size 58.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
341a7154b3004dc54c42c0d60e0355219e1294f1ee1936f6c78880affb4d0c55
BLAKE2b-256 checksum
How to use checksums
174e53a951830707d9691f30a7bb229bcebbae19827597c7fa2fa69fb5bd802f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.11.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page