Skip to content

[WIP] feat(crypto): conforma integration - #2725

Draft
gildub wants to merge 1 commit into
guacsec:mainfrom
gildub:TC-conforma-integration
Draft

gildub wants to merge 1 commit into
guacsec:mainfrom
gildub:TC-conforma-integration

Conversation

@gildub

@gildub gildub commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary by Sourcery

Integrate Conforma as the external policy engine for cryptographic algorithm and PQC readiness evaluation.

New Features:

  • Add Conforma-backed cryptographic algorithm policy evaluation with PQC readiness rules.
  • Expose optional Conforma policy configuration through server startup settings and provide a sample policy configuration.

Bug Fixes:

  • Require Conforma configuration for crypto policy evaluation instead of silently using an embedded policy.

Enhancements:

  • Map Conforma violations and warnings back to individual cryptographic assets and policy verdicts.

Tests:

  • Update crypto policy evaluation coverage to verify failure when Conforma is not configured.
@sourcery-ai

sourcery-ai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Reviewer's Guide

Introduces CBOM crypto-algorithm APIs with local verdict reporting and optional on-demand Conforma policy evaluation. The implementation queries persisted crypto assets, classifies algorithms using duplicated Rust/Rego rules, invokes a temporary Podman Conforma server when configured, exposes the results through authenticated HTTP endpoints and OpenAPI, and wires policy configuration through the server CLI/environment.

Sequence diagram for crypto policy evaluation

sequenceDiagram
    participant Client
    participant API as evaluate_policy
    participant Service as CryptoService
    participant DB as ReadOnlyDatabase
    participant Podman
    participant Conforma

    Client->>API: POST /v3/crypto/policy/evaluate
    API->>DB: begin()
    API->>Service: evaluate_policy(sbom_id, connection)
    Service->>DB: Query crypto algorithms and nodes
    Service->>Podman: start_server()
    Podman-->>Service: container_id
    Service->>Podman: get_port(container_id)
    Podman-->>Service: port
    Service->>Conforma: GET /ready
    Conforma-->>Service: ready
    Service->>Conforma: POST /v1/validate/input
    Conforma-->>Service: violations and warnings
    Service->>Podman: stop_server(container_id)
    Service-->>API: PolicyEvaluationResponse
    API-->>Client: 200 policy results and summary
Loading

Flow diagram for crypto algorithm verdict classification

flowchart TD
    A[Crypto algorithm] --> B{PQC-safe name?}
    B -->|yes| C[Compliant]
    B -->|no| D{Weak algorithm or small RSA/DSA key?}
    D -->|yes| E[NonCompliant]
    D -->|no| F[Warning]
    C --> G[CryptoAlgorithmSummary or AlgorithmPolicyResult]
    E --> G
    F --> G
Loading

File-Level Changes

Change Details Files
Adds crypto algorithm discovery and policy-evaluation APIs backed by SBOM crypto entities.
  • Registers authenticated, paginated algorithm listing and policy evaluation routes.
  • Queries algorithm assets and associated nodes, returning policy verdicts and evaluation summaries.
  • Adds OpenAPI schemas and endpoint documentation.
modules/fundamental/src/crypto/endpoints/mod.rs
modules/fundamental/src/crypto/endpoints/test.rs
modules/fundamental/src/crypto/model.rs
modules/fundamental/src/crypto/service/mod.rs
modules/fundamental/src/endpoints.rs
modules/fundamental/src/lib.rs
entity/src/sbom_crypto.rs
openapi.yaml
Implements local crypto-policy classification and a Conforma-backed evaluation path.
  • Classifies PQC-safe, weak, classical, and unknown algorithms into compliant, non-compliant, and warning verdicts.
  • Adds equivalent Rego policy rules for Conforma, including SHA-1, weak cipher, DES, and small-key RSA/DSA checks.
  • Starts a temporary Podman-hosted Conforma server, waits for readiness, submits algorithm JSON, maps violations and warnings by node ID, and cleans up the container.
modules/fundamental/src/crypto/service/policy.rs
modules/fundamental/src/crypto/policy.rego
modules/fundamental/src/crypto/service/conforma.rs
Adds configurable Conforma policy wiring and default policy configuration.
  • Introduces an optional CONFORMA_POLICY CLI/environment setting and passes it into the fundamental module.
  • Adds an EnterpriseContractPolicy configuration pointing to the repository Rego policy.
  • Adds the JSON-enabled HTTP client dependency required for Conforma communication.
server/src/profile/api.rs
modules/fundamental/src/endpoints.rs
etc/conforma/policy.yaml
modules/fundamental/Cargo.toml
Cargo.lock
Adds coverage for policy classification and API integration behavior.
  • Tests algorithm verdicts across PQC, weak, classical, unknown, key-size, and malformed-property cases.
  • Tests CBOM ingestion followed by algorithm listing and verifies that evaluation fails when Conforma is not configured.
modules/fundamental/src/crypto/service/policy.rs
modules/fundamental/src/crypto/endpoints/test.rs

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@gildub
gildub force-pushed the TC-conforma-integration branch from 62fda65 to b41d652 Compare September 30, 2026 13:30
@gildub
gildub force-pushed the TC-conforma-integration branch from b41d652 to af4820f Compare October 1, 2026 09:10

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant