Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions administration/cloud_capture/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,16 +20,16 @@ To set it up for your organization, see [Getting started with Cloud Capture](/ad
Cloud Capture connects to your cloud accounts using permissions that you manage. You configure Cloud Capture by activating it for different services, and Cloud Capture uses the permissions to regularly reach into your estate and record snapshots, sending the data into your Kosli organization. Cloud Capture uses details about your infrastructure, such as the name of an ECS cluster, to build environments within Kosli.

<Frame>
<img src="/images/administration/cloud-capture-overview.png" alt="Diagram showing Cloud Capture, inside Kosli, sending queries to and receiving snapshots from three customer cloud accounts, then passing the data to the Kosli API and database" />
<img src="/images/administration/cloud-capture-overview.png" alt="Diagram showing Cloud Capture, inside Kosli, sending queries to and receiving snapshots from three tenant cloud accounts, then passing the data to the Kosli API and database" />
</Frame>

## Security

The security of your cloud infrastructure is the primary driver behind the internal architecture of
Cloud Capture. You grant a read-only IAM role in your account, protected by an external ID that acts
as a shared secret between Kosli and you. On Kosli's side, each Cloud Capture job runs under a role
scoped to your organization alone, so a worker running for another customer cannot reach your cloud
account. Cloud Capture holds no customer data; snapshots go straight to Kosli through the same ingest
scoped to your organization alone, so a worker running for another tenant cannot reach your cloud
account. Cloud Capture holds no tenant data; snapshots go straight to Kosli through the same ingest
path as your existing pipelines. See [Cloud Capture Security](/administration/cloud_capture/security)
for the isolation model and the full list of permissions.

Expand Down
2 changes: 1 addition & 1 deletion administration/cloud_capture/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -322,7 +322,7 @@ gcloud infra-manager deployments apply \
</Tab>
</Tabs>

## How Kosli isolates customers
## How Kosli isolates tenants

Cloud Capture runs as a shared, autoscaled service, but each job runs under a role that is scoped to
one customer:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The heading was renamed to "tenants" but the sentence it introduces still says "customer", so the section contradicts its own title on the first line. Six further occurrences remain further down this file (130, 131, 166, 226, 331, 336, 343) — see the top-level comment for the full list.

Suggested change
one customer:
one tenant:

Expand Down
1 change: 1 addition & 0 deletions terraform-reference/resources/action.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
title: "kosli_action resource"
description: "Manages a Kosli action. Actions define webhook notifications triggered by environment compliance events."
icon: "cube"
mode: "wide"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks unrelated to the customer→tenant rename described in the PR body, and action.mdx becomes the only one of the ten pages in terraform-reference/resources/ with a mode field — the other nine (control, custom_attestation_type, environment, flow, logical_environment, policy, policy_attachment, service_account, service_account_api_key) have none, so this page will render at a different width from its siblings.

If it was committed by accident, drop it. If wide mode is wanted for the Terraform reference, it should be applied to all ten in a separate PR.

---

Manages a Kosli action. Actions define webhook notifications triggered by environment compliance events.
Expand Down
Loading