DevSecOps icon indicating copy to clipboard operation
DevSecOps copied to clipboard

Base infrastructure for future DevSecOps environment in AWS

GSA DevSecOps

GSA DevSecOps Information

This repo contains information related to DevSecOps at GSA. The code that has been previously located in this project has been split out into different locations. This repo will now only contain documentation and links to relevant DevSecOps information.

The plaform is called the GSA Readily Available Computing Environment (GRACE). Named in honor of Rear Admiral Grace Hopper.

GRACE implements 1 AWS subaccount per VPC, per environment, per app:

1-1-1-1: 1 AWS account == 1 Environment == 1 VPC == 1 application

You may wish to consult the following example repos for ideas or templates to implement GRACE.

Public

Repository Build Status
GSA/ansible-activclient CircleCI
GSA/ansible-bigfix CircleCI
GSA/ansible-bit9 CircleCI
GSA/ansible-cloudwatch CircleCI
GSA/ansible-cylance CircleCI
GSA/ansible-fireeye CircleCI
GSA/ansible-firstboot CircleCI
GSA/ansible-forescout CircleCI
GSA/ansible-nessus CircleCI
GSA/ansible-snare CircleCI
GSA/ansible-solarwinds CircleCI
GSA/ansible-vrealize_orchestrator CircleCI
GSA/cloudwatch-ansible-callback-plugin No Builds
GSA/github-copy No Builds
GSA/grace-alerting CircleCI
GSA/grace-ansible-batch CircleCI
GSA/grace-ansible-lambda CircleCI
GSA/grace-ansible-template CircleCI
GSA/grace-app No Builds
GSA/grace-circleci-builder CircleCI
GSA/grace-citest CircleCI
GSA/grace-cloudcustodian CircleCI
GSA/grace-config CircleCI
GSA/grace-config-differ CircleCI
GSA/grace-decider CircleCI
GSA/grace-ecr CircleCI
GSA/grace-fcs-network CircleCI
GSA/grace-iam CircleCI
GSA/grace-inventory CircleCI
GSA/grace-log-parser CircleCI
GSA/grace-logging CircleCI
GSA/grace-paas-backup No Builds
GSA/grace-paas-elb No Builds
GSA/grace-paas-network CircleCI
GSA/grace-paas-rds CircleCI
GSA/grace-rotate-accesskeys CircleCI
GSA/grace-secrets-sync-lambda CircleCI
GSA/grace-securityhub CircleCI
GSA/grace-style-guide No Builds
GSA/grace-template No Builds
GSA/grace-tftest CircleCI

Private

Repository Build Status
GSA/cabgsa CircleCI
GSA/idto-sandbox CircleCI
GSA/g-grace CircleCI
GSA/grace-actions CircleCI
GSA/grace-build CircleCI
GSA/grace-core CircleCI
GSA/grace-customer CircleCI
GSA/grace-guardrails No Builds
GSA/grace-inventory-tests CircleCI
GSA/grace-paas-baseline CircleCI
GSA/grace-paas-iam CircleCI
GSA/grace-repos CircleCI
GSA/grace-ssp No Builds
GSA/IDT-BigFix CircleCI
GSA/idt-hybrid-ansible No Builds
GSA/idt-hybrid-vra No Builds
GSA/idt-hybrid-vro No Builds
GSA/tgw-core No Builds

Deprecated

Repository Build Status
GSA/ansible-role-fireeyehx No Builds
GSA/aws-account-broker CircleCI
GSA/ansible-fluentd CircleCI
GSA/devsecops-cloud-custodian-rules No Builds
GSA/devsecops-ebs-backup CircleCI
GSA/devsecops-ekk-stack CircleCI
GSA/devsecops-example CircleCI
GSA/devsecops-iam-roles No Builds
GSA/devsecops-log-forwarding CircleCI
GSA/devsecops-subaccount-admin No Builds
GSA/grace-account-lockout No Builds
GSA/grace-example CircleCI
GSA/grace-rhel-ami CircleCI
GSA/grace-sqs-poc No Builds
GSA/grace-tenant-cleanup No Builds
GSA/grace-tf-module-budget CircleCI
GSA/grace-tf-module-member-account CircleCI
GSA/grace-ubuntu-ami CircleCI
GSA/security-benchmarks CircleCI