Secure Exoscale with cnspec
Scan Exoscale organizations against security and compliance best practices with cnspec.
Scan your Exoscale organization to find security risks before they become incidents. cnspec evaluates compute instances, security groups, SKS Kubernetes clusters, network load balancers, block storage, managed databases (DBaaS), KMS keys, IAM, and DNS across every zone, all without installing agents on your infrastructure.
New to cnspec? Read the Quickstart to install cnspec and run your first scan. To scan other platforms, see the cloud scanning overview.
Prerequisites
To scan Exoscale with cnspec, you must have:
- cnspec installed on your workstation
- An Exoscale organization
- An Exoscale API key and secret
Authenticate
cnspec authenticates with an Exoscale API key and its secret. cnspec only makes read calls, so a key bound to a role with read access to the services you want to assess is enough.
- Log in to the Exoscale Portal.
- In the left navigation, choose IAM > API Keys.
- Create a new key and bind it to a role with read access to the services you want to scan.
- Copy the key (it starts with
EXO) and the secret. The portal shows the secret only once.
If you use the Exoscale CLI, you can create the key with exo iam api-key create <name> <role> instead.
You can pass the credentials on the command line with --api-key and --api-secret, or export them once and reuse them across commands:
export EXOSCALE_API_KEY=EXOxxxxxxxxxxxxxxxxxxxxxxxx
export EXOSCALE_API_SECRET=your_secret_hereThese are the same variable names the Exoscale CLI and Terraform provider use. cnspec also reads the legacy EXOSCALE_KEY and EXOSCALE_SECRET variables.
Verify with a quick Exoscale check
Confirm that cnspec can reach your Exoscale organization:
cnspec run exoscale -c 'exoscale.organization { name id }'If cnspec connects, it prints your organization's name and ID. If the key and secret don't match, Exoscale rejects the request and cnspec reports invalid Exoscale API credentials.
Scan Exoscale
Scan your Exoscale organization:
cnspec scan exoscaleOr pass the credentials explicitly:
cnspec scan exoscale --api-key EXO_API_KEY --api-secret EXO_API_SECRETWhen the scan completes, cnspec prints each check with a pass or fail result and an overall risk score from 0 (no risk) to 100 (highest risk). To learn how to read a report in depth, see Understand Scan Results.
Limit the zones to scan
By default, cnspec queries every Exoscale zone in parallel. To limit the scan to specific zones, use the --zones flag with a comma-separated list, or set the EXOSCALE_ZONES environment variable:
cnspec scan exoscale --zones ch-gva-2,de-fra-1If a value doesn't match a zone name, cnspec reports unknown Exoscale zone and lists the available zones.
Discover resources during a scan
cnspec connects to your Exoscale organization as a single asset and, by default, also discovers its instances, security groups, SKS clusters, network load balancers, and DBaaS services as their own assets. Use the --discover flag to choose which resource types become their own assets:
| Value | Discovers |
|---|---|
auto | Every supported resource type |
all | Every supported resource type |
instances | Compute instances |
security-groups | Security groups |
sks-clusters | SKS Kubernetes clusters |
nlbs | Network load balancers |
dbaas-services | Managed database (DBaaS) services |
cnspec scan exoscale --discover instances,sks-clustersFilter resources by label
Use the --filters flag to narrow scans to resources with specific labels. labels keeps resources that carry any of the listed labels, either as key=value or as a bare key to match any value. exclude:labels drops resources that carry any of the listed labels:
cnspec scan exoscale --filters labels=env=prod,team --filters exclude:labels=tier=devThe filters apply to queries as well as to discovery. Security groups and DBaaS services don't carry labels, so an include filter leaves them out of the scan.
Write your own policies
Mondoo doesn't yet ship an out-of-the-box Exoscale policy, so use the checks below as a starting point and create your own policies to meet your specific requirements.
Asset model
The organization is the root asset and reports the exoscale-organization platform. Discovered assets report exoscale-compute-instance, exoscale-security-group, exoscale-sks-cluster, exoscale-nlb, and exoscale-dbaas-service. Every Exoscale platform belongs to the exoscale family.
Organization-wide resources, such as security groups, anti-affinity groups, SSH keys, IAM, and DNS, are read once. Zonal resources, such as instances, instance pools, templates, snapshots, private networks, elastic IPs, network load balancers, SKS clusters, block storage, DBaaS services, and KMS keys, are collected from every zone and each one carries its zone. If a zone refuses a call because the API key's role doesn't allow it or the service isn't enabled for your organization, cnspec skips that zone and still collects from the others.
Explore and test checks interactively
Open a cnspec shell to discover resources and try out checks:
cnspec shell exoscaleList the zones cnspec queries
cnspec> exoscale.zones { name apiEndpoint }Find security group rules open to the internet
cnspec> exoscale.securityGroups { name rules.where(direction == "ingress" && network == "0.0.0.0/0") { protocol startPort endPort } }Find instances with secure boot disabled or an unencrypted disk
cnspec> exoscale.instances.where(securebootEnabled != true || diskEncrypted != true) { name zone securebootEnabled diskEncrypted }Find SKS clusters whose API server is reachable from anywhere
cnspec> exoscale.sksClusters.where(allowedNetworks.contains("0.0.0.0/0")) { name zone version allowedNetworks }Find SKS clusters without audit logging
cnspec> exoscale.sksClusters.where(auditEnabled != true) { name zone version }Find DBaaS services that accept connections from any address
cnspec> exoscale.dbaasServices.where(ipFilter.contains("0.0.0.0/0")) { name type zone }Find unencrypted block storage volumes
cnspec> exoscale.blockStorageVolumes.where(encrypted != true) { name zone size }Check KMS key rotation
cnspec> exoscale.kmsKeys { name originZone multiZone rotationEnabled rotationPeriod }List API keys and the role each is bound to
cnspec> exoscale.iamApiKeys { name key role { name } }Find users without two-factor authentication
cnspec> exoscale.iamUsers.where(twoFactorAuthentication != true) { email role { name } }Review roles and their policies
cnspec> exoscale.iamRoles { name editable policy { defaultServiceStrategy services { name type } } }Learn more
- Exoscale Resource Pack Reference: every Exoscale resource and field cnspec can query
- Write Effective MQL: a guide to authoring checks and queries