OPEN SOURCE · APACHE 2.0

frontdoor: an open source scanner for federated trust

Cloud scanners check what is wrong inside an account. frontdoor checks the ways in: the OIDC, SAML and cross-account trusts that let a GitHub workflow, a CI pipeline, a SaaS vendor or another cloud get credentials in your account.

It answers one question. Who on the outside can get in, and how far do they get once they are in?

Install and run

bash
go install github.com/secorvia/frontdoor/cmd/frontdoor@latest
frontdoor scan

It uses the credentials you already have (~/.aws, gcloud auth application-default, az login). Every call is a read. There is no config file, no account and no signup. Homebrew, a signed install script and the minimum IAM policy are in the README on GitHub.

What a scan looks like

text
$ frontdoor scan

  ▐ WHO CAN GET IN

    ANY GitHub Actions tenant              →  role/ci-deploy     privileged
    github.com/acme/api @ refs/heads/main  →  role/deploy-prod

  ▐ HOW FAR THEY GET

    github.com/acme/api @ refs/heads/main
      → role/deploy-prod          sts:AssumeRoleWithWebIdentity
        → [gcp] data-pipeline@acme-prod   BigQuery datasets
      One repo compromise reaches BigQuery datasets.

  2 external identities can enter your clouds. 1 accepts ANY GitHub repository.
  One of them crosses AWS into GCP and reaches BigQuery datasets.
  3 findings: 2 critical, 1 high.

The last path above starts on GitHub, enters AWS, and ends in BigQuery. Neither cloud's own scanner sees it end to end. FD031 explains how the two halves are joined.

The 15 rules

Each rule has its own page: what it means, what an attacker does with it, how to fix it, and when it is a false positive.

frontdoor detection rules, grouped by the worst severity each can report
RuleWhat it catchesSeverity
Can be critical
FD001GitHub Actions OIDC: no subject condition on IAM roleNo condition on the subject claim, so any tenant of that issuer can assume the rolecritical, high with a narrowing condition
FD002AWS OIDC audience claim not restrictedNo condition on the audience claimcritical to medium
FD003Open OIDC trust on a role that can escalate to adminAn open door on a role that can escalate to account takeovercritical
FD030GCP service account impersonation chain to adminChain. A federated identity that reaches something privileged, or a data store, through one or more hopscritical or high
FD031Cross-cloud attack path: AWS role into GCPCross-cloud chain. The path leaves the cloud it started incritical or high
High
FD010Org-wide GitHub subject: repo:org/* trusts every repoOrg-wide subject (repo:acme/*), meaning any repository in the orghigh
FD011GitHub OIDC role assumable from any branch or tagRepository pinned but any branch or tag can assumehigh
FD012GitHub OIDC accepts the pull_request contextThe pull_request context is accepted (pull_request_target risk)high
FD013Cross-account IAM role with no ExternalIdCross-account trust with no sts:ExternalId, the confused deputyhigh, medium without Organizations access
FD014Cross-account trust to an unidentified AWS accountTrust to an account that is neither yours nor a vendor we can identifyhigh, medium without Organizations access
FD015GitHub OIDC trust based on repository_owner aloneTrust rests on repository_owner alone, which is a name, not a stable idhigh
Medium
FD005IAM condition key namespaced to the wrong issuerSubject condition namespaced to the wrong issuer, so AWS never evaluates itmedium
FD020Long-lived AWS access keys alongside OIDC federationLong-lived access keys still active on an account that uses federationmedium
FD021Unused AWS OIDC or SAML identity providerUnused identity provider, or an external trust never assumedmedium
FD022AWS OIDC provider thumbprint missing or staleOIDC thumbprint missing, or not matching the issuer's current cert (AWS only)medium or low

What it does not do

frontdoor is not a general CSPM. It does not look at bucket ACLs, security groups, encryption or compliance frameworks. If you already run Prowler or something like it, run this alongside. It asks a question those tools do not.

Source, issues and releases: github.com/secorvia/frontdoor.

frontdoor answers this once, when you run it; Secorvia checks it continuously across every account you connect, on a free tier that needs no card.