Skip to content

Releases: prabhakaran-jm/zero-trust-explainer

v1.0.0 - Initial Release

Choose a tag to compare

@prabhakaran-jm prabhakaran-jm released this 02 Nov 15:09

Release v1.0.0 - Initial Release 🚀

Zero-Trust Explainer - AI-Powered Security Analysis for Google Cloud Run

Built for Google Cloud Run Hackathon 2025 🎉

🎯 Overview

Zero-Trust Explainer (ZTE) transforms raw security findings into actionable intelligence using Google AI Studio and Gemini Pro. It helps security teams identify IAM misconfigurations, understand blast radius, prioritize risks, and generate production-ready remediation code.

✨ Key Features

🤖 AI-Powered Security Analysis

  • AI-Powered Explanations: Transform technical findings into business language with blast radius analysis
  • Smart Risk Prioritization: AI-driven priority scoring and remediation urgency assessment
  • Automated Fixes: Generate production-ready Terraform code with step-by-step implementation guides
  • Executive Summaries: High-level reporting with compliance impact for stakeholders

🔍 Security Scanning

  • Real-Time Scanning: Scan Cloud Run services for IAM misconfigurations
  • Comprehensive Detection: Identifies unauthenticated access, over-permissive roles, exposed secrets, and more
  • Findings Management: Query findings from BigQuery with filtering by severity and job ID

📁 Reporting & Integration

  • Signed Reports: Generate and download comprehensive security reports via signed Cloud Storage URLs
  • Modern UI: React/Vite frontend with AI indicators, job cards, and interactive dashboards
  • RESTful API: Complete REST API for integration with existing security tools

🏗️ Architecture

  • Frontend: React/Vite application deployed on Cloud Run
  • Backend API: FastAPI application with AI Studio integration
  • Scan Processor: Cloud Run Job for asynchronous security scanning
  • Propose Job: Cloud Run Job for AI-powered report generation
  • Data Layer: Pub/Sub, BigQuery, Cloud Storage, Secret Manager
  • Infrastructure: Fully managed with Terraform (Infrastructure as Code)

🛠️ Technology Stack

  • Frontend: React 18, Vite, Modern CSS
  • Backend: FastAPI, Python 3.11+
  • AI: Google AI Studio, Gemini Pro (gemini-2.0-flash)
  • Cloud: Google Cloud Run, Pub/Sub, BigQuery, Cloud Storage
  • Infrastructure: Terraform
  • Container: Docker

📦 What's Included

  • Complete source code for frontend and backend
  • Terraform infrastructure definitions
  • Comprehensive documentation
  • API documentation
  • Architecture diagrams
  • AI Studio prompt documentation
  • Deployment guides

🔗 Quick Links

🐛 Recent Fixes

Bug Fixes

  • Fixed remediation roadmap formatting for phase keys (phase1, phase2, etc.)
  • Fixed recommendations.map TypeError by normalizing recommendations to always be an array
  • Updated architecture diagram reference
  • Improved error handling in AI response parsing

Improvements

  • Enhanced UI with proper card formatting for remediation roadmap
  • Added priority badges with color coding
  • Improved data normalization for AI summary responses
  • Enhanced error handling and fallback mechanisms

📝 Recent Commits

  • 7e8dea8 - Fix recommendations.map TypeError: normalize recommendations to always be array
  • 7912655 - Fix remediation roadmap formatting: handle phase keys and update architecture diagram reference
  • 2be8617 - Added updated architecture diagram
  • 575dbe0 - Update documentation: Add AI Summary feature to architecture diagrams
  • 50ae58b - Code quality: Remove debug logging and improve CORS security

🚀 Getting Started

See the README.md for complete setup instructions. Quick start:

  1. Configure Google AI Studio API key
  2. Set up GCP project and enable required APIs
  3. Deploy infrastructure with Terraform
  4. Build and deploy frontend and backend
  5. Start scanning Cloud Run services!

📄 License

Apache 2.0

🙏 Acknowledgments

Built for the Google Cloud Run Hackathon 2025.

Special thanks to:

  • Google AI Studio for Gemini Pro integration
  • The Cloud Run team for an amazing serverless platform
  • The open-source community for inspiration

Full Changelog: See commits for detailed changes.