OPEN SOURCE · APACHE 2.0
frontdoor: an open source scanner for federated trust
Cloud scanners check what is wrong inside an account. frontdoor checks the ways in: the OIDC, SAML and cross-account trusts that let a GitHub workflow, a CI pipeline, a SaaS vendor or another cloud get credentials in your account.
It answers one question. Who on the outside can get in, and how far do they get once they are in?
Install and run
go install github.com/secorvia/frontdoor/cmd/frontdoor@latest
frontdoor scanIt uses the credentials you already have (~/.aws, gcloud auth application-default, az login). Every call is a read. There is no config file, no account and no signup. Homebrew, a signed install script and the minimum IAM policy are in the README on GitHub.
What a scan looks like
$ frontdoor scan
▐ WHO CAN GET IN
ANY GitHub Actions tenant → role/ci-deploy privileged
github.com/acme/api @ refs/heads/main → role/deploy-prod
▐ HOW FAR THEY GET
github.com/acme/api @ refs/heads/main
→ role/deploy-prod sts:AssumeRoleWithWebIdentity
→ [gcp] data-pipeline@acme-prod BigQuery datasets
One repo compromise reaches BigQuery datasets.
2 external identities can enter your clouds. 1 accepts ANY GitHub repository.
One of them crosses AWS into GCP and reaches BigQuery datasets.
3 findings: 2 critical, 1 high.The last path above starts on GitHub, enters AWS, and ends in BigQuery. Neither cloud's own scanner sees it end to end. FD031 explains how the two halves are joined.
The 15 rules
Each rule has its own page: what it means, what an attacker does with it, how to fix it, and when it is a false positive.
| Rule | What it catches | Severity |
|---|---|---|
| Can be critical | ||
FD001GitHub Actions OIDC: no subject condition on IAM role | No condition on the subject claim, so any tenant of that issuer can assume the role | critical, high with a narrowing condition |
FD002AWS OIDC audience claim not restricted | No condition on the audience claim | critical to medium |
FD003Open OIDC trust on a role that can escalate to admin | An open door on a role that can escalate to account takeover | critical |
FD030GCP service account impersonation chain to admin | Chain. A federated identity that reaches something privileged, or a data store, through one or more hops | critical or high |
FD031Cross-cloud attack path: AWS role into GCP | Cross-cloud chain. The path leaves the cloud it started in | critical or high |
| High | ||
FD010Org-wide GitHub subject: repo:org/* trusts every repo | Org-wide subject (repo:acme/*), meaning any repository in the org | high |
FD011GitHub OIDC role assumable from any branch or tag | Repository pinned but any branch or tag can assume | high |
FD012GitHub OIDC accepts the pull_request context | The pull_request context is accepted (pull_request_target risk) | high |
FD013Cross-account IAM role with no ExternalId | Cross-account trust with no sts:ExternalId, the confused deputy | high, medium without Organizations access |
FD014Cross-account trust to an unidentified AWS account | Trust to an account that is neither yours nor a vendor we can identify | high, medium without Organizations access |
FD015GitHub OIDC trust based on repository_owner alone | Trust rests on repository_owner alone, which is a name, not a stable id | high |
| Medium | ||
FD005IAM condition key namespaced to the wrong issuer | Subject condition namespaced to the wrong issuer, so AWS never evaluates it | medium |
FD020Long-lived AWS access keys alongside OIDC federation | Long-lived access keys still active on an account that uses federation | medium |
FD021Unused AWS OIDC or SAML identity provider | Unused identity provider, or an external trust never assumed | medium |
FD022AWS OIDC provider thumbprint missing or stale | OIDC thumbprint missing, or not matching the issuer's current cert (AWS only) | medium or low |
What it does not do
frontdoor is not a general CSPM. It does not look at bucket ACLs, security groups, encryption or compliance frameworks. If you already run Prowler or something like it, run this alongside. It asks a question those tools do not.
Source, issues and releases: github.com/secorvia/frontdoor.
frontdoor answers this once, when you run it; Secorvia checks it continuously across every account you connect, on a free tier that needs no card.