{"resources":{"alicloud":{"id":"alicloud","name":"alicloud","fields":{"accountId":{"name":"accountId","type":"\u0007","title":"Account (UID) that the active credential belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"acr":{"name":"acr","type":"\u001balicloud.acr","title":"Alibaba Cloud Container Registry","desc":"Container Registry (ACR) instances in the account and what is published through them: the namespaces that group repositories, the repositories themselves and whether each is readable without credentials, the replication rules that copy images to other regions or accounts, and the scan rules that decide whether an image is examined before it runs. The images an ACK cluster pulls come from here, so this is where a container supply chain begins.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"actiontrail":{"name":"actiontrail","type":"\u001balicloud.actiontrail","title":"Alibaba Cloud ActionTrail","desc":"Audit trail configuration for an Alibaba Cloud account. Exposes the trails that record management and data-plane API events, including where each trail delivers events (an OSS bucket or a Log Service project), whether it spans the resource directory, and its live logging and delivery health. Use it to audit whether API activity is being recorded and successfully delivered.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"alb":{"name":"alb","type":"\u001balicloud.alb","title":"Alibaba Cloud Application Load Balancer","desc":"ALB (Layer-7) load balancers across an Alibaba Cloud account. Exposes the application load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether HTTPS listeners use a strong TLS policy, and whether access logging is enabled.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"antiddos":{"name":"antiddos","type":"\u001balicloud.antiddos","title":"Alibaba Cloud Anti-DDoS","desc":"Anti-DDoS Pro and Premium instances and the assets they protect for an Alibaba Cloud account. Anti-DDoS is a center service. Exposes the scrubbing instances, their subscription health, and the web domains and forwarding ports under protection. Use it to audit which assets are protected and whether an instance's protection has lapsed (expired, disabled, or in debt).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cen":{"name":"cen","type":"\u001balicloud.cen","title":"Cloud Enterprise Network","desc":"Transit networking for the account. Exposes the CEN instances, each of which joins the networks attached to it into one routing domain, so a workload in one attached VPC can reach a workload in another regardless of region.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cloudFirewall":{"name":"cloudFirewall","type":"\u001balicloud.cloudFirewall","title":"Alibaba Cloud Cloud Firewall","desc":"Cloud Firewall access-control state for an Alibaba Cloud account. Cloud Firewall is a center service. Exposes whether the firewall service is active, its edition, and the internet-boundary control policies (the allow and deny rules). Use it to audit whether the firewall is enabled and whether any rule broadly permits inbound traffic.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cloudsso":{"name":"cloudsso","type":"\u001balicloud.cloudsso","title":"CloudSSO","desc":"Workforce identity and account access for an Alibaba Cloud resource directory. Exposes the CloudSSO directories in the account, and through them the workforce users and groups, the access configurations that define what a session may do, and the assignments that grant those configurations on individual member accounts.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"config":{"name":"config","type":"\u001balicloud.config","title":"Alibaba Cloud Cloud Config","desc":"Configuration-compliance state for an Alibaba Cloud account. Exposes the Config rules that continuously evaluate resource configuration, the account-wide compliance summary, and whether the configuration recorder and its delivery channels are active. Use it to audit whether configuration recording is enabled and how many resources are non-compliant.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cs":{"name":"cs","type":"\u001balicloud.cs","title":"Alibaba Cloud Container Service for Kubernetes","desc":"ACK clusters across an Alibaba Cloud account. Exposes the Kubernetes clusters in every enabled region, including their type and version, network layout, API server exposure, control-plane audit logging, workload-identity (RRSA) settings, node pools, and installed addons. Use it to audit whether a cluster's API server is reachable from the internet and whether audit logging is enabled.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ecs":{"name":"ecs","type":"\u001balicloud.ecs","title":"Elastic Compute Service (ECS)","desc":"Compute resources in a region, including virtual machine instances, their attached block-storage disks, machine images, SSH key pairs, and the security groups that filter instance traffic. Fans out over every region enabled on the account.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"es":{"name":"es","type":"\u001balicloud.es","title":"Alibaba Cloud Elasticsearch","desc":"Elasticsearch clusters in the account. A cluster holds indexed copies of whatever was shipped into it, which is often log and application data, and it can be published on a public endpoint of its own alongside a Kibana console. Reports what each cluster accepts connections on and which addresses are allowed to reach it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ess":{"name":"ess","type":"\u001balicloud.ess","title":"Auto Scaling","desc":"Scaling groups and the scaling configurations they launch instances from, across every enabled region on the account. Instances created by a scaling group are transient, so the scaling configuration is the durable record of how they are built: the user data written into them, the RAM role and security groups they receive, the image they boot, and the metadata service hardening they inherit.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"fc":{"name":"fc","type":"\u001balicloud.fc","title":"Alibaba Cloud Function Compute","desc":"Function Compute (FC 3.0) functions across an Alibaba Cloud account. Exposes the serverless functions in every enabled region, along with their triggers. Use it to audit function execution roles, network placement, public egress and invocation, and whether environment variables might carry secrets.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"kms":{"name":"kms","type":"\u001balicloud.kms","title":"Alibaba Cloud Key Management Service","desc":"Encryption keys and secrets managed for an Alibaba Cloud account. Exposes the customer master keys across all enabled regions, including their lifecycle state, cryptographic spec, rotation configuration, and protection level, and the secrets held in Secrets Manager along with the master key that protects each one. Use it to audit key rotation, deletion protection, and whether keys are backed by a hardware security module.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"log":{"name":"log","type":"\u001balicloud.log","title":"Alibaba Cloud Log Service","desc":"Log Service (SLS) projects and their logstores across an Alibaba Cloud account. Exposes the projects in every enabled region and, within each, the logstores that ingest and store logs, including their retention period and server-side encryption configuration. Log Service is the delivery target for ActionTrail trails and VPC flow logs, so these resources anchor the account's logging posture.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"mongodb":{"name":"mongodb","type":"\u001balicloud.mongodb","title":"ApsaraDB for MongoDB","desc":"Managed MongoDB service in an Alibaba Cloud account. Exposes the MongoDB instances across every enabled region through instances, spanning replica set, sharded cluster, and serverless deployments together with their security posture.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"nas":{"name":"nas","type":"\u001balicloud.nas","title":"Alibaba Cloud NAS file storage","desc":"Apsara File Storage NAS file systems and access controls across an Alibaba Cloud account. Exposes the file systems in every enabled region, their mount targets, and the access groups and rules that govern which clients may mount them. Use it to audit whether file systems are encrypted and whether their exports are open to overly broad client ranges.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"nlb":{"name":"nlb","type":"\u001balicloud.nlb","title":"Alibaba Cloud Network Load Balancer","desc":"NLB (Layer-4) load balancers across an Alibaba Cloud account. Exposes the network load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether security groups are applied, and whether TCPSSL listeners use a strong TLS policy.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"oss":{"name":"oss","type":"\u001balicloud.oss","title":"Object Storage Service","desc":"Entry point for the Object Storage Service (OSS) in an Alibaba Cloud account. Exposes every bucket the credential can list across all regions through buckets, from which per-bucket access control, encryption, versioning, logging, tagging, and public-access posture are reachable.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"polardb":{"name":"polardb","type":"\u001balicloud.polardb","title":"PolarDB","desc":"Entry point for querying ApsaraDB for PolarDB, the cloud-native relational database service. Exposes the PolarDB clusters provisioned across every enabled region through clusters.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ram":{"name":"ram","type":"\u001balicloud.ram","title":"Alibaba Cloud Resource Access Management","desc":"Identity and access configuration for an Alibaba Cloud account. Exposes the RAM users, user groups, roles, and permission policies defined in the account, along with the account-wide password policy and the console and credential security preferences.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"rds":{"name":"rds","type":"\u001balicloud.rds","title":"ApsaraDB RDS","desc":"ApsaraDB relational database instances in an Alibaba Cloud account. Exposes the RDS instances discovered across every enabled region through instances, from which the database engine and version, the network placement, and the security posture (SSL/TLS, TDE encryption, public accessibility, and IP address whitelist) can be audited.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"redis":{"name":"redis","type":"\u001balicloud.redis","title":"ApsaraDB for Redis","desc":"Entry point for the ApsaraDB for Redis (Tair) instances in an Alibaba Cloud account. Enumerates every Redis and Tair instance across the enabled regions through instances, each of which exposes its configuration and security posture.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"regions":{"name":"regions","type":"\u0019\u0007","title":"Region IDs enabled on the account, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceManager":{"name":"resourceManager","type":"\u001balicloud.resourceManager","title":"Alibaba Cloud Resource Directory","desc":"Multi-account governance structure for an Alibaba Cloud account. Exposes the resource directory (the organization), the management and member accounts it contains, the folder hierarchy that groups them, and the control policies available to restrict member-account permissions. Use it to audit organization membership and whether control policies are enabled.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"sas":{"name":"sas","type":"\u001balicloud.sas","title":"Security Center","desc":"Threat detection and posture management for the account. Exposes the subscription edition and quota, the protected machines and whether their agents are reporting, the vulnerabilities and baseline check failures found across them, and the alerts raised by threat detection.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"slb":{"name":"slb","type":"\u001balicloud.slb","title":"Server Load Balancer","desc":"Classic Load Balancer (CLB) resources in an Alibaba Cloud account. Exposes the CLB instances discovered across every enabled region through loadBalancers, from which listeners, backend servers, addressing, and protection settings can be audited.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpc":{"name":"vpc","type":"\u001balicloud.vpc","title":"Virtual Private Cloud (VPC)","desc":"Entry point for the Alibaba Cloud VPC networking service. Exposes the VPCs, vSwitches, route tables, NAT gateways, elastic IP addresses, and network ACLs defined across every enabled region on the account.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"waf":{"name":"waf","type":"\u001balicloud.waf","title":"Alibaba Cloud Web Application Firewall","desc":"WAF 3.0 instances and the resources they protect for an Alibaba Cloud account. WAF is a center service with one instance per account in each of the China and international centers. Exposes the instance edition and subscription state, the protected objects (domains and cloud-native resources), and the CNAME domains with their TLS configuration. Use it to audit which web assets are behind WAF and whether their listeners terminate TLS.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud","desc":"Entry point for querying an Alibaba Cloud account. Exposes the account identity and the region IDs enabled on the account, and is the root from which the RAM, ECS, Auto Scaling, VPC, OSS, SLB, ALB, NLB, and managed-database resources are reached, along with the Container Service for Kubernetes, Function Compute, NAS file storage, Web Application Firewall, Cloud Firewall, Anti-DDoS, Security Center, Key Management Service, ActionTrail, Log Service, Cloud Config, CloudSSO, Cloud Enterprise Network, and Resource Directory resources.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr":{"id":"alicloud.acr","name":"alicloud.acr","fields":{"instance":{"name":"instance","type":"\u001balicloud.acr.instance","title":"Container Registry instance","desc":"A single Enterprise Edition registry, keyed by instanceId. Reports the edition and state of the instance, whether its internet endpoint is switched on and which addresses that endpoint accepts, and the namespaces, repositories, replication rules and scan rules it holds.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.acr.instance","title":"Container Registry Enterprise Edition instances in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"namespace":{"name":"namespace","type":"\u001balicloud.acr.namespace","title":"Container Registry namespace","desc":"A namespace groups repositories inside one registry and sets the defaults new repositories inherit. Selected by namespaceName within an instance. The defaults matter on their own: a namespace that creates repositories on push and hands them public visibility turns a mistyped image name into a world-readable repository.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"repository":{"name":"repository","type":"\u001balicloud.acr.repository","title":"Container Registry repository","desc":"One image repository, keyed by repoId. Reports whether the repository is readable without credentials, whether its tags can be overwritten after they have been deployed, and which namespace holds it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"scanRule":{"name":"scanRule","type":"\u001balicloud.acr.scanRule","title":"Container Registry scan rule","desc":"A rule that decides which images are examined and when, keyed by scanRuleId. A registry with no scan rule only examines an image when someone asks it to, so an image can be pulled and run without ever having been looked at.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"syncRule":{"name":"syncRule","type":"\u001balicloud.acr.syncRule","title":"Container Registry replication rule","desc":"A rule that copies images between registries, keyed by syncRuleId. Reports what the rule matches and where the copies land, so a rule that moves images into another account or region is visible as one.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Container Registry","desc":"Container Registry (ACR) instances in the account and what is published through them: the namespaces that group repositories, the repositories themselves and whether each is readable without credentials, the replication rules that copy images to other regions or accounts, and the scan rules that decide whether an image is examined before it runs. The images an ACK cluster pulls come from here, so this is where a container supply chain begins.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.instance":{"id":"alicloud.acr.instance","name":"alicloud.acr.instance","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceSpecification":{"name":"instanceSpecification","type":"\u0007","is_mandatory":true,"title":"Enterprise Edition specification","desc":"The purchased edition, such as Enterprise_Basic, Enterprise_Standard, or Enterprise_Advanced. Vulnerability scanning and some replication features are only available above the basic edition.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceStatus":{"name":"instanceStatus","type":"\u0007","is_mandatory":true,"title":"Instance status","desc":"RUNNING for an instance serving traffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointAclEnabled":{"name":"internetEndpointAclEnabled","type":"\u0004","title":"Whether an address list gates the internet endpoint","desc":"False on an enabled internet endpoint means every source address may reach the registry, leaving repository visibility as the only control.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointAclEntries":{"name":"internetEndpointAclEntries","type":"\u0019\u0007","title":"Addresses allowed to reach the internet endpoint","desc":"The CIDR entries of the endpoint's address list. Empty when no list is configured, which is not a restriction: an enabled endpoint with no entries and no list enforcement accepts every source.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointDomains":{"name":"internetEndpointDomains","type":"\u0019\u0007","title":"Public domains the instance answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointEnabled":{"name":"internetEndpointEnabled","type":"\u0004","title":"Whether the instance is reachable over the internet","desc":"False means images can only be pulled from inside a linked VPC. True means the registry answers on a public domain, and internetEndpointAclEnabled decides whether anything narrows who may reach it.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","is_mandatory":true,"title":"Time the instance was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaces":{"name":"namespaces","type":"\u0019\u001balicloud.acr.namespace","title":"Namespaces defined in the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the instance lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"repositories":{"name":"repositories","type":"\u0019\u001balicloud.acr.repository","title":"Repositories held in the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scanRules":{"name":"scanRules","type":"\u0019\u001balicloud.acr.scanRule","title":"Rules that decide which images are scanned and when","desc":"Empty when no scan rule is configured, in which case images are only examined if someone starts a scan by hand.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRules":{"name":"syncRules","type":"\u0019\u001balicloud.acr.syncRule","title":"Replication rules that copy images in or out of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the instance","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry instance","desc":"A single Enterprise Edition registry, keyed by instanceId. Reports the edition and state of the instance, whether its internet endpoint is switched on and which addresses that endpoint accepts, and the namespaces, repositories, replication rules and scan rules it holds.","min_provider_version":"13.4.1","defaults":"instanceName instanceSpecification instanceStatus regionId","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.namespace":{"id":"alicloud.acr.namespace","name":"alicloud.acr.namespace","fields":{"autoCreateRepo":{"name":"autoCreateRepo","type":"\u0004","is_mandatory":true,"title":"Whether pushing an unknown repository name creates it","desc":"True means a push to a name that does not exist yet creates the repository with the namespace defaults rather than failing, so a typo or an unreviewed push lands a new repository.","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultRepoType":{"name":"defaultRepoType","type":"\u0007","is_mandatory":true,"title":"Visibility given to a repository created in this namespace","desc":"Either PUBLIC or PRIVATE. PUBLIC together with autoCreateRepo means an automatically created repository is readable without credentials.","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultTagImmutability":{"name":"defaultTagImmutability","type":"\u0004","is_mandatory":true,"title":"Tag immutability given to a repository created in this namespace","desc":"False means new repositories allow an existing tag to be repointed at different content.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance holding the namespace","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceId":{"name":"namespaceId","type":"\u0007","is_mandatory":true,"title":"Namespace ID","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceName":{"name":"namespaceName","type":"\u0007","is_mandatory":true,"title":"Namespace name, used as the selection key within an instance","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceStatus":{"name":"namespaceStatus","type":"\u0007","is_mandatory":true,"title":"Namespace status","desc":"Either NORMAL or DELETING.","provider":"go.mondoo.com/mql/providers/alicloud"},"repositories":{"name":"repositories","type":"\u0019\u001balicloud.acr.repository","title":"Repositories in the namespace","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the namespace belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the namespace belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry namespace","desc":"A namespace groups repositories inside one registry and sets the defaults new repositories inherit. Selected by namespaceName within an instance. The defaults matter on their own: a namespace that creates repositories on push and hands them public visibility turns a mistyped image name into a world-readable repository.","min_provider_version":"13.4.1","defaults":"namespaceName defaultRepoType autoCreateRepo","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.repository":{"id":"alicloud.acr.repository","name":"alicloud.acr.repository","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the repository was created","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance holding the repository","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","title":"Whether the repository can be pulled from the internet without credentials","desc":"True only when the repository is PUBLIC and its instance answers on the internet: a public repository inside an instance with no internet endpoint is still reachable only from a linked VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","is_mandatory":true,"title":"Time the repository was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"namespace":{"name":"namespace","type":"\u001balicloud.acr.namespace","title":"Namespace holding the repository","provider":"go.mondoo.com/mql/providers/alicloud"},"repoBuildType":{"name":"repoBuildType","type":"\u0007","is_mandatory":true,"title":"How images reach the repository","desc":"MANUAL for images pushed by a client, AUTO for images produced by a build rule in the registry.","provider":"go.mondoo.com/mql/providers/alicloud"},"repoId":{"name":"repoId","type":"\u0007","is_mandatory":true,"title":"Repository ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"repoName":{"name":"repoName","type":"\u0007","is_mandatory":true,"title":"Repository name","provider":"go.mondoo.com/mql/providers/alicloud"},"repoNamespaceName":{"name":"repoNamespaceName","type":"\u0007","is_mandatory":true,"title":"Name of the namespace holding the repository","provider":"go.mondoo.com/mql/providers/alicloud"},"repoStatus":{"name":"repoStatus","type":"\u0007","is_mandatory":true,"title":"Repository status","provider":"go.mondoo.com/mql/providers/alicloud"},"repoType":{"name":"repoType","type":"\u0007","is_mandatory":true,"title":"Repository visibility","desc":"Either PUBLIC, which needs no credentials to pull, or PRIVATE.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the repository belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the repository belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"summary":{"name":"summary","type":"\u0007","is_mandatory":true,"title":"Repository summary","provider":"go.mondoo.com/mql/providers/alicloud"},"tagImmutability":{"name":"tagImmutability","type":"\u0004","is_mandatory":true,"title":"Whether an existing tag can be overwritten","desc":"False means a tag can be repointed at different content after it has been deployed, so the image reviewed at build time is not necessarily the one that runs.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry repository","desc":"One image repository, keyed by repoId. Reports whether the repository is readable without credentials, whether its tags can be overwritten after they have been deployed, and which namespace holds it.","min_provider_version":"13.4.1","defaults":"repoNamespaceName repoName repoType tagImmutability","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.scanRule":{"id":"alicloud.acr.scanRule","name":"alicloud.acr.scanRule","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance the rule applies to","provider":"go.mondoo.com/mql/providers/alicloud"},"repoTagFilterPattern":{"name":"repoTagFilterPattern","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which tags are scanned","desc":"Empty when the rule covers every tag in scope.","provider":"go.mondoo.com/mql/providers/alicloud"},"ruleName":{"name":"ruleName","type":"\u0007","is_mandatory":true,"title":"Scan rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"scanRuleId":{"name":"scanRuleId","type":"\u0007","is_mandatory":true,"title":"Scan rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"scanScope":{"name":"scanScope","type":"\u0007","is_mandatory":true,"title":"What the rule covers","desc":"REPO for a single repository, or the wider scope the rule was created with.","provider":"go.mondoo.com/mql/providers/alicloud"},"scanType":{"name":"scanType","type":"\u0007","is_mandatory":true,"title":"What the scan looks for","desc":"VUL runs the cloud security scanner for vulnerabilities, SBOM runs content analysis to inventory what an image contains.","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerType":{"name":"triggerType","type":"\u0007","is_mandatory":true,"title":"How the scan fires","desc":"AUTO for a scan triggered by a push, so an image is examined as it arrives rather than on request.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the rule was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry scan rule","desc":"A rule that decides which images are examined and when, keyed by scanRuleId. A registry with no scan rule only examines an image when someone asks it to, so an image can be pulled and run without ever having been looked at.","min_provider_version":"13.4.1","defaults":"ruleName scanType scanScope triggerType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.syncRule":{"id":"alicloud.acr.syncRule","name":"alicloud.acr.syncRule","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossUser":{"name":"crossUser","type":"\u0004","is_mandatory":true,"title":"Whether the rule crosses an account boundary","desc":"True means the other end of the rule belongs to a different Alibaba Cloud account, so images leave this account entirely.","provider":"go.mondoo.com/mql/providers/alicloud"},"localInstanceId":{"name":"localInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance the rule was defined on","provider":"go.mondoo.com/mql/providers/alicloud"},"localNamespaceName":{"name":"localNamespaceName","type":"\u0007","is_mandatory":true,"title":"Namespace the rule reads from","provider":"go.mondoo.com/mql/providers/alicloud"},"localRegionId":{"name":"localRegionId","type":"\u0007","is_mandatory":true,"title":"Region of the instance the rule was defined on","provider":"go.mondoo.com/mql/providers/alicloud"},"localRepoName":{"name":"localRepoName","type":"\u0007","is_mandatory":true,"title":"Repository the rule reads from","desc":"Empty for a rule scoped to a whole namespace.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","is_mandatory":true,"title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceNameFilter":{"name":"namespaceNameFilter","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which namespaces the rule covers","provider":"go.mondoo.com/mql/providers/alicloud"},"repoNameFilter":{"name":"repoNameFilter","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which repositories the rule covers","provider":"go.mondoo.com/mql/providers/alicloud"},"syncDirection":{"name":"syncDirection","type":"\u0007","is_mandatory":true,"title":"Direction images move","desc":"FROM copies from the source instance to the target instance, TO copies from the target instance back to the source.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRuleId":{"name":"syncRuleId","type":"\u0007","is_mandatory":true,"title":"Replication rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRuleName":{"name":"syncRuleName","type":"\u0007","is_mandatory":true,"title":"Replication rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"syncScope":{"name":"syncScope","type":"\u0007","is_mandatory":true,"title":"What the rule matches","desc":"NAMESPACE replicates a whole namespace, REPO replicates a single repository. A NAMESPACE rule keeps applying to repositories created after the rule was written.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncTrigger":{"name":"syncTrigger","type":"\u0007","is_mandatory":true,"title":"How the rule fires","desc":"INITIATIVE for a replication started on purpose, PASSIVE for one triggered by a push.","provider":"go.mondoo.com/mql/providers/alicloud"},"tagFilter":{"name":"tagFilter","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which tags the rule copies","provider":"go.mondoo.com/mql/providers/alicloud"},"targetInstanceId":{"name":"targetInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance images are copied to","desc":"The target can belong to another account, which has no resource here, so this is the only view of it.","provider":"go.mondoo.com/mql/providers/alicloud"},"targetNamespaceName":{"name":"targetNamespaceName","type":"\u0007","is_mandatory":true,"title":"Namespace images are copied into","provider":"go.mondoo.com/mql/providers/alicloud"},"targetRegionId":{"name":"targetRegionId","type":"\u0007","is_mandatory":true,"title":"Region images are copied to","provider":"go.mondoo.com/mql/providers/alicloud"},"targetRepoName":{"name":"targetRepoName","type":"\u0007","is_mandatory":true,"title":"Repository images are copied into","desc":"Empty for a rule scoped to a whole namespace.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry replication rule","desc":"A rule that copies images between registries, keyed by syncRuleId. Reports what the rule matches and where the copies land, so a rule that moves images into another account or region is visible as one.","min_provider_version":"13.4.1","defaults":"syncRuleName syncDirection targetRegionId crossUser","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.actiontrail":{"id":"alicloud.actiontrail","name":"alicloud.actiontrail","fields":{"trail":{"name":"trail","type":"\u001balicloud.actiontrail.trail","title":"ActionTrail trail","desc":"A single audit trail, keyed by name. Exposes the event categories it captures (read, write, or all), the OSS bucket and Log Service project it delivers to, the delivery roles, whether it is an organization trail, and its live logging and delivery status. Use it to confirm a trail is actively logging and delivering events without errors.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"trails":{"name":"trails","type":"\u0019\u001balicloud.actiontrail.trail","title":"Trails configured in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud ActionTrail","desc":"Audit trail configuration for an Alibaba Cloud account. Exposes the trails that record management and data-plane API events, including where each trail delivers events (an OSS bucket or a Log Service project), whether it spans the resource directory, and its live logging and delivery health. Use it to audit whether API activity is being recorded and successfully delivered.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.actiontrail.trail":{"id":"alicloud.actiontrail.trail","name":"alicloud.actiontrail.trail","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the trail was created","provider":"go.mondoo.com/mql/providers/alicloud"},"eventRW":{"name":"eventRW","type":"\u0007","is_mandatory":true,"title":"Event categories the trail records","desc":"One of Write, Read, or All.","provider":"go.mondoo.com/mql/providers/alicloud"},"homeRegion":{"name":"homeRegion","type":"\u0007","is_mandatory":true,"title":"Region the trail was created in","provider":"go.mondoo.com/mql/providers/alicloud"},"isLogging":{"name":"isLogging","type":"\u0004","title":"Whether the trail is actively logging events","desc":"The live logging state reported by ActionTrail, which can differ from the configured status.","provider":"go.mondoo.com/mql/providers/alicloud"},"isOrganizationTrail":{"name":"isOrganizationTrail","type":"\u0004","is_mandatory":true,"title":"Whether the trail records events across all accounts in the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryError":{"name":"latestDeliveryError","type":"\u0007","title":"Most recent event-delivery error, empty when the last delivery succeeded","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryLogServiceError":{"name":"latestDeliveryLogServiceError","type":"\u0007","title":"Most recent Log Service delivery error, empty when the last delivery succeeded","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryLogServiceTime":{"name":"latestDeliveryLogServiceTime","type":"\t","title":"Time of the most recent successful delivery to Log Service, null when none","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryTime":{"name":"latestDeliveryTime","type":"\t","title":"Time of the most recent successful event delivery, null when none","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Trail name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"organizationId":{"name":"organizationId","type":"\u0007","is_mandatory":true,"title":"Resource directory (organization) ID for an organization trail, empty otherwise","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucket":{"name":"ossBucket","type":"\u001balicloud.oss.bucket","title":"OSS bucket that receives delivered events","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucketLocation":{"name":"ossBucketLocation","type":"\u0007","is_mandatory":true,"title":"Region of the OSS bucket, for example oss-cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucketName":{"name":"ossBucketName","type":"\u0007","is_mandatory":true,"title":"Name of the OSS bucket that receives delivered events, empty when not delivering to OSS","provider":"go.mondoo.com/mql/providers/alicloud"},"ossKeyPrefix":{"name":"ossKeyPrefix","type":"\u0007","is_mandatory":true,"title":"Object-name prefix applied to delivered event files","provider":"go.mondoo.com/mql/providers/alicloud"},"ossWriteRoleArn":{"name":"ossWriteRoleArn","type":"\u0007","is_mandatory":true,"title":"RAM role ARN ActionTrail assumes to write to the OSS bucket","provider":"go.mondoo.com/mql/providers/alicloud"},"slsProject":{"name":"slsProject","type":"\u001balicloud.log.project","title":"Log Service project that receives delivered events","provider":"go.mondoo.com/mql/providers/alicloud"},"slsProjectArn":{"name":"slsProjectArn","type":"\u0007","is_mandatory":true,"title":"ARN of the Log Service project that receives delivered events, empty when not delivering to SLS","provider":"go.mondoo.com/mql/providers/alicloud"},"slsWriteRoleArn":{"name":"slsWriteRoleArn","type":"\u0007","is_mandatory":true,"title":"RAM role ARN ActionTrail assumes to write to the Log Service project","provider":"go.mondoo.com/mql/providers/alicloud"},"startLoggingTime":{"name":"startLoggingTime","type":"\t","is_mandatory":true,"title":"Time the trail most recently started logging","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Configuration state of the trail","desc":"One of Enable, Disable, or Fresh. Fresh means the trail was created but has never started logging.","provider":"go.mondoo.com/mql/providers/alicloud"},"stopLoggingTime":{"name":"stopLoggingTime","type":"\t","is_mandatory":true,"title":"Time the trail most recently stopped logging, empty while logging","provider":"go.mondoo.com/mql/providers/alicloud"},"trailArn":{"name":"trailArn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the trail","provider":"go.mondoo.com/mql/providers/alicloud"},"trailRegion":{"name":"trailRegion","type":"\u0007","is_mandatory":true,"title":"Region whose events the trail records, or All for a multi-region trail","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the trail was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ActionTrail trail","desc":"A single audit trail, keyed by name. Exposes the event categories it captures (read, write, or all), the OSS bucket and Log Service project it delivers to, the delivery roles, whether it is an organization trail, and its live logging and delivery status. Use it to confirm a trail is actively logging and delivering events without errors.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb":{"id":"alicloud.alb","name":"alicloud.alb","fields":{"listener":{"name":"listener","type":"\u001balicloud.alb.listener","title":"Application Load Balancer listener","desc":"A single listener on an ALB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy for HTTPS/QUIC listeners, and the server groups it forwards to. Use it to audit whether an HTTPS listener enforces a strong TLS policy and presents certificates.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.alb.loadBalancer","title":"Application Load Balancer instance","desc":"A single ALB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC and security groups it runs in, its access-logging configuration, and its listeners. Use it to audit public exposure and access logging. For example alicloud.alb.loadBalancer(loadBalancerId: \"alb-xxx\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001balicloud.alb.loadBalancer","title":"Application load balancers across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroup":{"name":"serverGroup","type":"\u001balicloud.alb.serverGroup","title":"Application Load Balancer server group","desc":"A single ALB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward requests to. Exposes the backend protocol, scheduling algorithm, health-check configuration, and the VPC the group belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverGroups":{"name":"serverGroups","type":"\u0019\u001balicloud.alb.serverGroup","title":"ALB server groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Application Load Balancer","desc":"ALB (Layer-7) load balancers across an Alibaba Cloud account. Exposes the application load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether HTTPS listeners use a strong TLS policy, and whether access logging is enabled.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.listener":{"id":"alicloud.alb.listener","name":"alicloud.alb.listener","fields":{"certificateIds":{"name":"certificateIds","type":"\u0019\u0007","title":"Server certificate IDs presented by the listener","desc":"Empty for non-TLS listeners. A populated list confirms the HTTPS/QUIC listener presents a server certificate.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"gzipEnabled":{"name":"gzipEnabled","type":"\u0004","is_mandatory":true,"title":"Whether response gzip compression is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"http2Enabled":{"name":"http2Enabled","type":"\u0004","is_mandatory":true,"title":"Whether HTTP/2 is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"idleTimeout":{"name":"idleTimeout","type":"\u0005","is_mandatory":true,"title":"Idle connection timeout in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"listenerId":{"name":"listenerId","type":"\u0007","is_mandatory":true,"title":"Listener ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.alb.loadBalancer","title":"Load balancer the listener belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the load balancer the listener belongs to","desc":"Deprecated in favor of loadBalancer.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"mutualTlsEnabled":{"name":"mutualTlsEnabled","type":"\u0004","title":"Whether mutual TLS (client certificate authentication) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the listener serves on","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Listener protocol, one of HTTP, HTTPS, or QUIC","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the listener resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"requestTimeout":{"name":"requestTimeout","type":"\u0005","is_mandatory":true,"title":"Request timeout in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyId":{"name":"securityPolicyId","type":"\u0007","is_mandatory":true,"title":"TLS security policy applied to the listener, empty for non-TLS listeners","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroups":{"name":"serverGroups","type":"\u0019\u001balicloud.alb.serverGroup","title":"Server groups the listener forwards requests to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Listener status, for example Running, Configuring, or Stopped","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the listener","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Application Load Balancer listener","desc":"A single listener on an ALB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy for HTTPS/QUIC listeners, and the server groups it forwards to. Use it to audit whether an HTTPS listener enforces a strong TLS policy and presents certificates.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.loadBalancer":{"id":"alicloud.alb.loadBalancer","name":"alicloud.alb.loadBalancer","fields":{"accessLogProject":{"name":"accessLogProject","type":"\u001balicloud.log.project","title":"Log Service project that receives access logs, null when access logging is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"accessLogStore":{"name":"accessLogStore","type":"\u001balicloud.log.logstore","title":"Log Service logstore that receives access logs, null when access logging is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"accessLoggingEnabled":{"name":"accessLoggingEnabled","type":"\u0004","is_mandatory":true,"title":"Whether access logging to Log Service is enabled","desc":"True when the load balancer delivers access logs to a Log Service project and logstore. When false, request-level access logs are not retained.","provider":"go.mondoo.com/mql/providers/alicloud"},"addressAllocatedMode":{"name":"addressAllocatedMode","type":"\u0007","is_mandatory":true,"title":"Address allocation mode, either Fixed or Dynamic","provider":"go.mondoo.com/mql/providers/alicloud"},"addressIpVersion":{"name":"addressIpVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the address, either IPv4 or DualStack","provider":"go.mondoo.com/mql/providers/alicloud"},"addressType":{"name":"addressType","type":"\u0007","is_mandatory":true,"title":"Address type","desc":"Either Internet (internet-facing) or Intranet (internal only).","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageId":{"name":"bandwidthPackageId","type":"\u0007","is_mandatory":true,"title":"ID of the bandwidth package bound to the load balancer, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (billing) status of the load balancer, for example Normal","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the load balancer was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtectionEnabled":{"name":"deletionProtectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"dnsName":{"name":"dnsName","type":"\u0007","is_mandatory":true,"title":"DNS name assigned to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"edition":{"name":"edition","type":"\u0007","is_mandatory":true,"title":"Load balancer edition, one of Basic, Standard, or StandardWithWaf","provider":"go.mondoo.com/mql/providers/alicloud"},"internetFacing":{"name":"internetFacing","type":"\u0004","title":"Whether the load balancer serves traffic from the public internet","desc":"True when the address type is Internet. An internet-facing load balancer is reachable from outside the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6AddressType":{"name":"ipv6AddressType","type":"\u0007","is_mandatory":true,"title":"IPv6 address type, either Internet or Intranet","provider":"go.mondoo.com/mql/providers/alicloud"},"listeners":{"name":"listeners","type":"\u0019\u001balicloud.alb.listener","title":"Listeners configured on the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"Load balancer ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionStatus":{"name":"modificationProtectionStatus","type":"\u0007","is_mandatory":true,"title":"Modification-protection status, either NonProtection or ConsoleProtection","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Load balancer name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the load balancer resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the load balancer","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the load balancer belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Load balancer status","desc":"For example Active, Inactive, Provisioning, or Configuring.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the load balancer runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the load balancer attaches to across its zones","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Application Load Balancer instance","desc":"A single ALB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC and security groups it runs in, its access-logging configuration, and its listeners. Use it to audit public exposure and access logging. For example alicloud.alb.loadBalancer(loadBalancerId: \"alb-xxx\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.serverGroup":{"id":"alicloud.alb.serverGroup","name":"alicloud.alb.serverGroup","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the server group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossZoneEnabled":{"name":"crossZoneEnabled","type":"\u0004","is_mandatory":true,"title":"Whether cross-zone load balancing is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckEnabled":{"name":"healthCheckEnabled","type":"\u0004","is_mandatory":true,"title":"Whether health checks are enabled for the group","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckPath":{"name":"healthCheckPath","type":"\u0007","is_mandatory":true,"title":"Health-check request path, for HTTP health checks","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckProtocol":{"name":"healthCheckProtocol","type":"\u0007","is_mandatory":true,"title":"Health-check protocol, one of HTTP, TCP, or gRPC","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Server group name","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Backend protocol, one of HTTP, HTTPS, or gRPC","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the server group resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the server group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduler":{"name":"scheduler","type":"\u0007","is_mandatory":true,"title":"Scheduling algorithm, one of Wrr, Wlc, or Sch","provider":"go.mondoo.com/mql/providers/alicloud"},"server":{"name":"server","type":"\u001balicloud.alb.serverGroup.server","title":"ALB backend server","desc":"One server an ALB server group forwards requests to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverCount":{"name":"serverCount","type":"\u0005","is_mandatory":true,"title":"Number of backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroupId":{"name":"serverGroupId","type":"\u0007","is_mandatory":true,"title":"Server group ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"servers":{"name":"servers","type":"\u0019\u001balicloud.alb.serverGroup.server","title":"Servers in the group","desc":"What the load balancer forwards to. An internet-facing ALB makes every one of these reachable from the public internet on the listener's port.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Server group status","provider":"go.mondoo.com/mql/providers/alicloud"},"stickySessionEnabled":{"name":"stickySessionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether session stickiness is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"stickySessionType":{"name":"stickySessionType","type":"\u0007","is_mandatory":true,"title":"Session stickiness type, either Insert or Server","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the server group","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Server group type, one of Instance, Ip, or Fc","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Application Load Balancer server group","desc":"A single ALB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward requests to. Exposes the backend protocol, scheduling algorithm, health-check configuration, and the VPC the group belongs to.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.serverGroup.server":{"id":"alicloud.alb.serverGroup.server","name":"alicloud.alb.serverGroup.server","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Backend server description","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the backend","desc":"Null unless serverType is Ecs, or when the instance can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"remoteIpEnabled":{"name":"remoteIpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the client IP is preserved to the backend","desc":"False means the backend sees the load balancer's address instead of the caller's, which affects any allowlist or log the backend keeps.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"ID of the backend server","desc":"An ECS instance ID, an elastic network interface ID, an IP address, or a Function Compute function, depending on serverType.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverIp":{"name":"serverIp","type":"\u0007","is_mandatory":true,"title":"IP address the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverType":{"name":"serverType","type":"\u0007","is_mandatory":true,"title":"Kind of backend","desc":"One of Ecs, Eni, Ip, or Fc.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Backend server status","provider":"go.mondoo.com/mql/providers/alicloud"},"weight":{"name":"weight","type":"\u0005","is_mandatory":true,"title":"Share of traffic the server receives","desc":"A weight of 0 takes the server out of rotation without detaching it.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ALB backend server","desc":"One server an ALB server group forwards requests to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","min_provider_version":"13.4.1","defaults":"serverType serverId serverIp port weight","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos":{"id":"alicloud.antiddos","name":"alicloud.antiddos","fields":{"instance":{"name":"instance","type":"\u001balicloud.antiddos.instance","title":"Anti-DDoS instance","desc":"A single Anti-DDoS Pro or Premium instance, keyed by instanceId. Exposes the mitigation edition, forwarding state, and subscription window, and is the parent of the protected web domains and forwarding ports. Use it to confirm an instance is enabled and not expired. Protection is effectively off when the instance is expired or not forwarding traffic.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.antiddos.instance","title":"Anti-DDoS Pro and Premium instances across the China and international centers","provider":"go.mondoo.com/mql/providers/alicloud"},"networkRule":{"name":"networkRule","type":"\u001balicloud.antiddos.networkRule","title":"Anti-DDoS protected forwarding port","desc":"A single non-web (Layer-4) forwarding rule on an Anti-DDoS instance, keyed by the instanceId, protocol, and frontend port. Exposes the frontend and backend ports and the origin servers. Use it to enumerate the TCP and UDP ports under Anti-DDoS protection.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"webRule":{"name":"webRule","type":"\u001balicloud.antiddos.webRule","title":"Anti-DDoS protected web domain","desc":"A single web domain protected by an Anti-DDoS instance, keyed by the owning instanceId and domain. Exposes the scrubbing CNAME, the HTTP flood (CC) protection state, the certificate, and the origin servers. Use it to audit whether a protected domain has CC protection and a non-expired certificate.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Anti-DDoS","desc":"Anti-DDoS Pro and Premium instances and the assets they protect for an Alibaba Cloud account. Anti-DDoS is a center service. Exposes the scrubbing instances, their subscription health, and the web domains and forwarding ports under protection. Use it to audit which assets are protected and whether an instance's protection has lapsed (expired, disabled, or in debt).","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos.instance":{"id":"alicloud.antiddos.instance","name":"alicloud.antiddos.instance","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"debtStatus":{"name":"debtStatus","type":"\u0005","is_mandatory":true,"title":"Overdue-payment status, 0 when there is no overdue payment","provider":"go.mondoo.com/mql/providers/alicloud"},"edition":{"name":"edition","type":"\u0005","is_mandatory":true,"title":"Mitigation edition","desc":"0 (Premium Insurance), 1 (Premium Unlimited), 2 (Premium mainland acceleration), or 9 (Pro Profession).","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the instance is forwarding (protecting) traffic","desc":"False when the instance is not forwarding service traffic, which means its protection is effectively off.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Time the instance subscription expires","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Anti-DDoS instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"Anti-DDoS instance IP that scrubbed traffic is delivered from","provider":"go.mondoo.com/mql/providers/alicloud"},"ipMode":{"name":"ipMode","type":"\u0007","is_mandatory":true,"title":"Forwarding mode of the instance IP, for example fnat","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the instance, either Ipv4 or Ipv6","provider":"go.mondoo.com/mql/providers/alicloud"},"networkRules":{"name":"networkRules","type":"\u0019\u001balicloud.antiddos.networkRule","title":"Non-web (TCP/UDP) forwarding ports protected by the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the instance belongs to, either cn-hangzhou or ap-southeast-1","provider":"go.mondoo.com/mql/providers/alicloud"},"remark":{"name":"remark","type":"\u0007","is_mandatory":true,"title":"Instance remark","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Instance status","desc":"1 (Normal) or 2 (Expired). An expired instance no longer scrubs traffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"webRules":{"name":"webRules","type":"\u0019\u001balicloud.antiddos.webRule","title":"Web (HTTP/HTTPS) domains protected by the instance","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Anti-DDoS instance","desc":"A single Anti-DDoS Pro or Premium instance, keyed by instanceId. Exposes the mitigation edition, forwarding state, and subscription window, and is the parent of the protected web domains and forwarding ports. Use it to confirm an instance is enabled and not expired. Protection is effectively off when the instance is expired or not forwarding traffic.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos.networkRule":{"id":"alicloud.antiddos.networkRule","name":"alicloud.antiddos.networkRule","fields":{"backendPort":{"name":"backendPort","type":"\u0005","is_mandatory":true,"title":"Backend (origin) port traffic is forwarded to","provider":"go.mondoo.com/mql/providers/alicloud"},"frontendPort":{"name":"frontendPort","type":"\u0005","is_mandatory":true,"title":"Frontend (listener) port scrubbed traffic arrives on","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the Anti-DDoS instance the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Forwarding protocol, either tcp or udp","provider":"go.mondoo.com/mql/providers/alicloud"},"realServers":{"name":"realServers","type":"\u0019\u0007","is_mandatory":true,"title":"Origin servers traffic is forwarded to after scrubbing","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Anti-DDoS protected forwarding port","desc":"A single non-web (Layer-4) forwarding rule on an Anti-DDoS instance, keyed by the instanceId, protocol, and frontend port. Exposes the frontend and backend ports and the origin servers. Use it to enumerate the TCP and UDP ports under Anti-DDoS protection.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos.webRule":{"id":"alicloud.antiddos.webRule","name":"alicloud.antiddos.webRule","fields":{"ccEnabled":{"name":"ccEnabled","type":"\u0004","is_mandatory":true,"title":"Whether HTTP flood (CC) protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"ccRuleEnabled":{"name":"ccRuleEnabled","type":"\u0004","is_mandatory":true,"title":"Whether a CC protection rule is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"certExpireTime":{"name":"certExpireTime","type":"\t","is_mandatory":true,"title":"Expiry time of the bound certificate, null when no certificate is configured","provider":"go.mondoo.com/mql/providers/alicloud"},"certName":{"name":"certName","type":"\u0007","is_mandatory":true,"title":"Name of the certificate bound to the domain, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"cname":{"name":"cname","type":"\u0007","is_mandatory":true,"title":"Anti-DDoS scrubbing CNAME that traffic must resolve to","provider":"go.mondoo.com/mql/providers/alicloud"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Protected hostname, used with the instance ID as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the Anti-DDoS instance protecting the domain","provider":"go.mondoo.com/mql/providers/alicloud"},"penalized":{"name":"penalized","type":"\u0004","is_mandatory":true,"title":"Whether the domain is currently penalized (blocked) for abnormal traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyTypes":{"name":"proxyTypes","type":"\u0019\n","is_mandatory":true,"title":"Protocols and listener ports the domain serves","desc":"Each entry lists the proxyType (http, https, websocket, or websockets) and the proxyPorts it listens on.","provider":"go.mondoo.com/mql/providers/alicloud"},"realServers":{"name":"realServers","type":"\u0019\n","is_mandatory":true,"title":"Origin servers traffic is forwarded to after scrubbing","desc":"Each entry lists the realServer (an IP or hostname) and its rsType (0 for an IP, 1 for a domain).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the domain belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Anti-DDoS protected web domain","desc":"A single web domain protected by an Anti-DDoS instance, keyed by the owning instanceId and domain. Exposes the scrubbing CNAME, the HTTP flood (CC) protection state, the certificate, and the origin servers. Use it to audit whether a protected domain has CC protection and a non-expired certificate.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cen":{"id":"alicloud.cen","name":"alicloud.cen","fields":{"attachment":{"name":"attachment","type":"\u001balicloud.cen.attachment","title":"Network attached to a Cloud Enterprise Network","desc":"A single network joined to a CEN, keyed by the cenId and the attached network's ID. The childInstanceType names what kind of network it is, and childInstanceOwnerId reveals attachments owned by another account, which extend reachability outside the account boundary.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instance":{"name":"instance","type":"\u001balicloud.cen.instance","title":"Cloud Enterprise Network instance","desc":"A single CEN, keyed by cenId. Every network attached to it can route to every other attached network, so the attachments list is the reachability boundary: a VPC attached here is reachable from every other attached VPC, across regions and across accounts, before security-group and ACL rules are considered.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.cen.instance","title":"Cloud Enterprise Network instances in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Enterprise Network","desc":"Transit networking for the account. Exposes the CEN instances, each of which joins the networks attached to it into one routing domain, so a workload in one attached VPC can reach a workload in another regardless of region.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cen.attachment":{"id":"alicloud.cen.attachment","name":"alicloud.cen.attachment","fields":{"attachTime":{"name":"attachTime","type":"\t","is_mandatory":true,"title":"Time the network was attached","provider":"go.mondoo.com/mql/providers/alicloud"},"cenId":{"name":"cenId","type":"\u0007","is_mandatory":true,"title":"ID of the CEN the network is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceId":{"name":"childInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the attached network","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceOwnerId":{"name":"childInstanceOwnerId","type":"\u0005","is_mandatory":true,"title":"Account (UID) that owns the attached network","desc":"A value other than the scanned account means the CEN reaches into another account, extending the routing domain past the account boundary.","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceRegionId":{"name":"childInstanceRegionId","type":"\u0007","is_mandatory":true,"title":"Region the attached network lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceType":{"name":"childInstanceType","type":"\u0007","is_mandatory":true,"title":"Kind of attached network","desc":"One of VPC, VBR for a virtual border router carrying an Express Connect circuit, or CCN for a Cloud Connect Network.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Attachment status, for example Attached or Attaching","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC behind a VPC attachment","desc":"Null for a VBR or CCN attachment, and for a VPC owned by another account, which the scanned credential cannot read.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network attached to a Cloud Enterprise Network","desc":"A single network joined to a CEN, keyed by the cenId and the attached network's ID. The childInstanceType names what kind of network it is, and childInstanceOwnerId reveals attachments owned by another account, which extend reachability outside the account boundary.","min_provider_version":"13.2.5","defaults":"childInstanceId childInstanceType childInstanceRegionId status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cen.instance":{"id":"alicloud.cen.instance","name":"alicloud.cen.instance","fields":{"attachments":{"name":"attachments","type":"\u0019\u001balicloud.cen.attachment","title":"Networks attached to the CEN","provider":"go.mondoo.com/mql/providers/alicloud"},"cenId":{"name":"cenId","type":"\u0007","is_mandatory":true,"title":"CEN instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the CEN was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the CEN instance","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6Level":{"name":"ipv6Level","type":"\u0007","is_mandatory":true,"title":"Whether the CEN carries IPv6 traffic","desc":"ENABLE when IPv6 routing is on, DISABLE when the CEN carries IPv4 only.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the CEN instance","provider":"go.mondoo.com/mql/providers/alicloud"},"protectionLevel":{"name":"protectionLevel","type":"\u0007","is_mandatory":true,"title":"Level of DDoS protection applied to the CEN","desc":"FULL when protection covers every attached network, or REDUCE for the basic level.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the CEN instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the CEN belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Instance status, for example Creating or Active","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the CEN, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Enterprise Network instance","desc":"A single CEN, keyed by cenId. Every network attached to it can route to every other attached network, so the attachments list is the reachability boundary: a VPC attached here is reachable from every other attached VPC, across regions and across accounts, before security-group and ACL rules are considered.","min_provider_version":"13.2.5","defaults":"cenId name status protectionLevel","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall":{"id":"alicloud.cloudFirewall","name":"alicloud.cloudFirewall","fields":{"controlPolicies":{"name":"controlPolicies","type":"\u0019\u001balicloud.cloudFirewall.controlPolicy","title":"Internet-boundary control policies in both the inbound and outbound directions","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPolicy":{"name":"controlPolicy","type":"\u001balicloud.cloudFirewall.controlPolicy","title":"Cloud Firewall control policy","desc":"A single internet-boundary access-control rule, keyed by aclUuid. A rule permits or denies traffic between a source and destination on given ports and protocols. Exposes the action, source, destination, and whether it is enabled. Use it to find enabled rules that broadly accept inbound traffic (for example an accept rule with source 0.0.0.0/0).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"edition":{"name":"edition","type":"\u0005","title":"Cloud Firewall edition","desc":"2 (Premium), 3 (Enterprise), 4 (Ultimate), or 10 (pay-as-you-go). 0 when the service is not provisioned.","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","title":"Whether the Cloud Firewall service is active for the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Cloud Firewall","desc":"Cloud Firewall access-control state for an Alibaba Cloud account. Cloud Firewall is a center service. Exposes whether the firewall service is active, its edition, and the internet-boundary control policies (the allow and deny rules). Use it to audit whether the firewall is enabled and whether any rule broadly permits inbound traffic.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall.controlPolicy":{"id":"alicloud.cloudFirewall.controlPolicy","name":"alicloud.cloudFirewall.controlPolicy","fields":{"aclUuid":{"name":"aclUuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action taken on matching traffic","desc":"One of accept (allow), drop (deny), or log (monitor only).","provider":"go.mondoo.com/mql/providers/alicloud"},"applicationName":{"name":"applicationName","type":"\u0007","is_mandatory":true,"title":"Application-layer protocol the rule matches, for example HTTP or ANY","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"destPort":{"name":"destPort","type":"\u0007","is_mandatory":true,"title":"Destination port or port range","provider":"go.mondoo.com/mql/providers/alicloud"},"destination":{"name":"destination","type":"\u0007","is_mandatory":true,"title":"Destination address, CIDR, domain, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationType":{"name":"destinationType","type":"\u0007","is_mandatory":true,"title":"Destination type, for example net, group, domain, or location","provider":"go.mondoo.com/mql/providers/alicloud"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Traffic direction the rule applies to, either in (inbound) or out (outbound)","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is enabled","desc":"A disabled rule is configured but not enforced.","provider":"go.mondoo.com/mql/providers/alicloud"},"hitTimes":{"name":"hitTimes","type":"\u0005","is_mandatory":true,"title":"Cumulative number of times the rule has matched traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"order":{"name":"order","type":"\u0005","is_mandatory":true,"title":"Rule priority order","provider":"go.mondoo.com/mql/providers/alicloud"},"proto":{"name":"proto","type":"\u0007","is_mandatory":true,"title":"Protocol, one of ANY, TCP, UDP, or ICMP","provider":"go.mondoo.com/mql/providers/alicloud"},"source":{"name":"source","type":"\u0007","is_mandatory":true,"title":"Source address, CIDR, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceType":{"name":"sourceType","type":"\u0007","is_mandatory":true,"title":"Source type, for example net (CIDR), group (address book), or location","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Firewall control policy","desc":"A single internet-boundary access-control rule, keyed by aclUuid. A rule permits or denies traffic between a source and destination on given ports and protocols. Exposes the action, source, destination, and whether it is enabled. Use it to find enabled rules that broadly accept inbound traffic (for example an accept rule with source 0.0.0.0/0).","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso":{"id":"alicloud.cloudsso","name":"alicloud.cloudsso","fields":{"accessAssignment":{"name":"accessAssignment","type":"\u001balicloud.cloudsso.accessAssignment","title":"CloudSSO access assignment","desc":"A grant binding a CloudSSO user or group to an access configuration on one member account. This is the edge that turns a permission set into effective access: it names who (principal), what (access configuration), and where (target account).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"accessConfiguration":{"name":"accessConfiguration","type":"\u001balicloud.cloudsso.accessConfiguration","title":"CloudSSO access configuration","desc":"A named set of permissions that a CloudSSO user assumes on a member account, keyed by the directoryId and accessConfigurationId. The permission policies determine what a session created from this configuration may do, and the session duration determines how long it lasts. An access configuration grants nothing until an assignment binds it to a principal and an account.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"directories":{"name":"directories","type":"\u0019\u001balicloud.cloudsso.directory","title":"CloudSSO directories in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"directory":{"name":"directory","type":"\u001balicloud.cloudsso.directory","title":"CloudSSO directory","desc":"A CloudSSO directory, the container for a workforce identity population and the access it holds on the resource directory. The directoryId selects the directory, for example `alicloud.cloudsso.directory(directoryId: \"d-00example\")`. Exposes the users and groups in the directory, the access configurations and their assignments, the password policy, and the multi-factor and credential-retrieval settings that govern how members sign in.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"enabled":{"name":"enabled","type":"\u0004","title":"Whether CloudSSO is enabled for the account","desc":"False when the service has never been enabled, in which case the account manages access through RAM users and roles alone.","provider":"go.mondoo.com/mql/providers/alicloud"},"group":{"name":"group","type":"\u001balicloud.cloudsso.group","title":"CloudSSO group","desc":"A group of workforce users in a CloudSSO directory, keyed by the directoryId and groupId. Access assignments made to a group apply to every member, so the members list is what turns a group-level grant into the set of people who actually hold it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"mfaDevice":{"name":"mfaDevice","type":"\u001balicloud.cloudsso.mfaDevice","title":"CloudSSO multi-factor authentication device","desc":"A second-factor device bound to a CloudSSO user, keyed by deviceId. Exposes the device type and when it became effective.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"passwordPolicy":{"name":"passwordPolicy","type":"\u001balicloud.cloudsso.passwordPolicy","title":"CloudSSO password policy","desc":"Password requirements applied to users in a CloudSSO directory. Exposes the length, character-class, reuse, and expiration rules, along with the failed-sign-in lockout threshold.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"permissionPolicy":{"name":"permissionPolicy","type":"\u001balicloud.cloudsso.permissionPolicy","title":"CloudSSO permission policy","desc":"A permission policy attached to a CloudSSO access configuration. A System policy is one of the Alibaba Cloud managed policies, reachable through ramPolicy; an Inline policy carries its statements in policyDocument on this resource. Between them they define everything a session created from the access configuration is allowed to do.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"user":{"name":"user","type":"\u001balicloud.cloudsso.user","title":"CloudSSO user","desc":"A workforce user in a CloudSSO directory, keyed by the directoryId and userId. Exposes the user profile, whether the account was created directly or synchronized from an external identity provider, the multi-factor devices bound to it, and the groups it belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"CloudSSO","desc":"Workforce identity and account access for an Alibaba Cloud resource directory. Exposes the CloudSSO directories in the account, and through them the workforce users and groups, the access configurations that define what a session may do, and the assignments that grant those configurations on individual member accounts.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.accessAssignment":{"id":"alicloud.cloudsso.accessAssignment","name":"alicloud.cloudsso.accessAssignment","fields":{"accessConfiguration":{"name":"accessConfiguration","type":"\u001balicloud.cloudsso.accessConfiguration","title":"Access configuration the assignment grants","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationId":{"name":"accessConfigurationId","type":"\u0007","is_mandatory":true,"title":"ID of the access configuration the assignment grants","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationName":{"name":"accessConfigurationName","type":"\u0007","is_mandatory":true,"title":"Name of the access configuration the assignment grants","provider":"go.mondoo.com/mql/providers/alicloud"},"account":{"name":"account","type":"\u001balicloud.resourceManager.account","title":"Member account the assignment grants access on","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the assignment was created","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the assignment belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"group":{"name":"group","type":"\u001balicloud.cloudsso.group","title":"Group the assignment was made to","desc":"Null when the assignment was made to a single user.","provider":"go.mondoo.com/mql/providers/alicloud"},"principalId":{"name":"principalId","type":"\u0007","is_mandatory":true,"title":"ID of the principal the assignment grants access to","provider":"go.mondoo.com/mql/providers/alicloud"},"principalName":{"name":"principalName","type":"\u0007","is_mandatory":true,"title":"Name of the principal","provider":"go.mondoo.com/mql/providers/alicloud"},"principalType":{"name":"principalType","type":"\u0007","is_mandatory":true,"title":"Principal type","desc":"Either User for an assignment made to a single user, or Group for one made to a group, in which case every member of the group holds the access.","provider":"go.mondoo.com/mql/providers/alicloud"},"targetId":{"name":"targetId","type":"\u0007","is_mandatory":true,"title":"ID of the account the assignment grants access on","provider":"go.mondoo.com/mql/providers/alicloud"},"targetName":{"name":"targetName","type":"\u0007","is_mandatory":true,"title":"Name of the account the assignment grants access on","provider":"go.mondoo.com/mql/providers/alicloud"},"targetPath":{"name":"targetPath","type":"\u0007","is_mandatory":true,"title":"Path of the target account in the resource directory hierarchy","provider":"go.mondoo.com/mql/providers/alicloud"},"targetType":{"name":"targetType","type":"\u0007","is_mandatory":true,"title":"Target type, for example RD-Account for a resource directory member account","provider":"go.mondoo.com/mql/providers/alicloud"},"user":{"name":"user","type":"\u001balicloud.cloudsso.user","title":"User the assignment was made to","desc":"Null when the assignment was made to a group.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO access assignment","desc":"A grant binding a CloudSSO user or group to an access configuration on one member account. This is the edge that turns a permission set into effective access: it names who (principal), what (access configuration), and where (target account).","min_provider_version":"13.2.5","defaults":"principalName accessConfigurationName targetName","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.accessConfiguration":{"id":"alicloud.cloudsso.accessConfiguration","name":"alicloud.cloudsso.accessConfiguration","fields":{"accessConfigurationId":{"name":"accessConfigurationId","type":"\u0007","is_mandatory":true,"title":"Access configuration ID, used with directoryId as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationName":{"name":"accessConfigurationName","type":"\u0007","is_mandatory":true,"title":"Name of the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the access configuration was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the access configuration belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"permissionPolicies":{"name":"permissionPolicies","type":"\u0019\u001balicloud.cloudsso.permissionPolicy","title":"Permission policies attached to the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"relayState":{"name":"relayState","type":"\u0007","is_mandatory":true,"title":"Initial console page a session lands on","provider":"go.mondoo.com/mql/providers/alicloud"},"sessionDuration":{"name":"sessionDuration","type":"\u0005","is_mandatory":true,"title":"Maximum length of a session created from this configuration, in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the access configuration was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO access configuration","desc":"A named set of permissions that a CloudSSO user assumes on a member account, keyed by the directoryId and accessConfigurationId. The permission policies determine what a session created from this configuration may do, and the session duration determines how long it lasts. An access configuration grants nothing until an assignment binds it to a principal and an account.","min_provider_version":"13.2.5","defaults":"accessConfigurationName sessionDuration","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.directory":{"id":"alicloud.cloudsso.directory","name":"alicloud.cloudsso.directory","fields":{"accessAssignments":{"name":"accessAssignments","type":"\u0019\u001balicloud.cloudsso.accessAssignment","title":"Assignments granting access configurations on member accounts","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurations":{"name":"accessConfigurations","type":"\u0019\u001balicloud.cloudsso.accessConfiguration","title":"Access configurations defined in the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"allowUserToGetCredentials":{"name":"allowUserToGetCredentials","type":"\u0004","title":"Whether users may retrieve long-lived access credentials for themselves","desc":"True lets a signed-in user mint credentials that outlive the sign-in session, widening the window in which a compromised session is useful.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the directory was created","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"Directory ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryName":{"name":"directoryName","type":"\u0007","is_mandatory":true,"title":"Name of the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"groups":{"name":"groups","type":"\u0019\u001balicloud.cloudsso.group","title":"Groups in the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"loginNetworkMasks":{"name":"loginNetworkMasks","type":"\u0007","title":"Network ranges users may sign in from","desc":"Semicolon-separated CIDR blocks restricting where sign-ins are accepted. Empty when sign-in is accepted from anywhere.","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaAuthenticationStatus":{"name":"mfaAuthenticationStatus","type":"\u0007","title":"When multi-factor authentication is demanded of users signing in","desc":"One of Enabled, where every sign-in requires a second factor, Byp, where it is required only for sign-ins the service judges risky, or Disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordPolicy":{"name":"passwordPolicy","type":"\u001balicloud.cloudsso.passwordPolicy","title":"Password requirements for users in the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the directory is hosted in","provider":"go.mondoo.com/mql/providers/alicloud"},"scimSynchronizationEnabled":{"name":"scimSynchronizationEnabled","type":"\u0004","title":"Whether SCIM synchronization from an external identity provider is enabled","desc":"When enabled, the user and group population is managed by the external provider, so accounts deactivated there stop being usable here.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the directory was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"users":{"name":"users","type":"\u0019\u001balicloud.cloudsso.user","title":"Users in the directory","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO directory","desc":"A CloudSSO directory, the container for a workforce identity population and the access it holds on the resource directory. The directoryId selects the directory, for example `alicloud.cloudsso.directory(directoryId: \"d-00example\")`. Exposes the users and groups in the directory, the access configurations and their assignments, the password policy, and the multi-factor and credential-retrieval settings that govern how members sign in.","min_provider_version":"13.2.5","defaults":"directoryId directoryName region","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.group":{"id":"alicloud.cloudsso.group","name":"alicloud.cloudsso.group","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the group","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"groupId":{"name":"groupId","type":"\u0007","is_mandatory":true,"title":"Group ID, used with directoryId as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"groupName":{"name":"groupName","type":"\u0007","is_mandatory":true,"title":"Name of the group","provider":"go.mondoo.com/mql/providers/alicloud"},"members":{"name":"members","type":"\u0019\u001balicloud.cloudsso.user","title":"Users that belong to the group","provider":"go.mondoo.com/mql/providers/alicloud"},"provisionType":{"name":"provisionType","type":"\u0007","is_mandatory":true,"title":"How the group came to exist","desc":"Either Manual for a group created directly in the directory, or Synchronized for one provisioned from an external identity provider.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the group was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO group","desc":"A group of workforce users in a CloudSSO directory, keyed by the directoryId and groupId. Access assignments made to a group apply to every member, so the members list is what turns a group-level grant into the set of people who actually hold it.","min_provider_version":"13.2.5","defaults":"groupName provisionType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.mfaDevice":{"id":"alicloud.cloudsso.mfaDevice","name":"alicloud.cloudsso.mfaDevice","fields":{"deviceId":{"name":"deviceId","type":"\u0007","is_mandatory":true,"title":"Device ID","provider":"go.mondoo.com/mql/providers/alicloud"},"deviceName":{"name":"deviceName","type":"\u0007","is_mandatory":true,"title":"Name of the device","provider":"go.mondoo.com/mql/providers/alicloud"},"deviceType":{"name":"deviceType","type":"\u0007","is_mandatory":true,"title":"Device type, for example TOTP for an authenticator application","provider":"go.mondoo.com/mql/providers/alicloud"},"effectiveTime":{"name":"effectiveTime","type":"\t","is_mandatory":true,"title":"Time the device became effective","provider":"go.mondoo.com/mql/providers/alicloud"},"userId":{"name":"userId","type":"\u0007","is_mandatory":true,"title":"ID of the user the device is bound to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO multi-factor authentication device","desc":"A second-factor device bound to a CloudSSO user, keyed by deviceId. Exposes the device type and when it became effective.","min_provider_version":"13.2.5","defaults":"deviceName deviceType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.passwordPolicy":{"id":"alicloud.cloudsso.passwordPolicy","name":"alicloud.cloudsso.passwordPolicy","fields":{"hardExpire":{"name":"hardExpire","type":"\u0004","is_mandatory":true,"title":"Whether an expired password blocks sign-in outright","desc":"True locks the user out until an administrator resets the password, rather than prompting for a change at the next sign-in.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxLoginAttempts":{"name":"maxLoginAttempts","type":"\u0005","is_mandatory":true,"title":"Number of consecutive failed sign-ins before the account is locked","provider":"go.mondoo.com/mql/providers/alicloud"},"maxPasswordAge":{"name":"maxPasswordAge","type":"\u0005","is_mandatory":true,"title":"Number of days a password remains valid","provider":"go.mondoo.com/mql/providers/alicloud"},"maxPasswordLength":{"name":"maxPasswordLength","type":"\u0005","is_mandatory":true,"title":"Maximum number of characters a password may contain","provider":"go.mondoo.com/mql/providers/alicloud"},"minPasswordDifferentChars":{"name":"minPasswordDifferentChars","type":"\u0005","is_mandatory":true,"title":"Minimum number of characters that must differ from the previous password","provider":"go.mondoo.com/mql/providers/alicloud"},"minPasswordLength":{"name":"minPasswordLength","type":"\u0005","is_mandatory":true,"title":"Minimum number of characters a password must contain","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordNotContainUsername":{"name":"passwordNotContainUsername","type":"\u0004","is_mandatory":true,"title":"Whether the password is barred from containing the user name","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordReusePrevention":{"name":"passwordReusePrevention","type":"\u0005","is_mandatory":true,"title":"Number of previous passwords that may not be reused","provider":"go.mondoo.com/mql/providers/alicloud"},"requireLowerCaseChars":{"name":"requireLowerCaseChars","type":"\u0004","is_mandatory":true,"title":"Whether a lowercase letter is required","provider":"go.mondoo.com/mql/providers/alicloud"},"requireNumbers":{"name":"requireNumbers","type":"\u0004","is_mandatory":true,"title":"Whether a digit is required","provider":"go.mondoo.com/mql/providers/alicloud"},"requireSymbols":{"name":"requireSymbols","type":"\u0004","is_mandatory":true,"title":"Whether a symbol is required","provider":"go.mondoo.com/mql/providers/alicloud"},"requireUpperCaseChars":{"name":"requireUpperCaseChars","type":"\u0004","is_mandatory":true,"title":"Whether an uppercase letter is required","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO password policy","desc":"Password requirements applied to users in a CloudSSO directory. Exposes the length, character-class, reuse, and expiration rules, along with the failed-sign-in lockout threshold.","min_provider_version":"13.2.5","defaults":"minPasswordLength maxLoginAttempts","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.permissionPolicy":{"id":"alicloud.cloudsso.permissionPolicy","name":"alicloud.cloudsso.permissionPolicy","fields":{"accessConfigurationId":{"name":"accessConfigurationId","type":"\u0007","is_mandatory":true,"title":"ID of the access configuration the policy is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"addTime":{"name":"addTime","type":"\t","is_mandatory":true,"title":"Time the policy was attached to the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the access configuration belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"policyDocument":{"name":"policyDocument","type":"\u0007","is_mandatory":true,"title":"Permission statements of an inline policy, as a JSON string","desc":"Empty for a System policy, whose statements are exposed through ramPolicy instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"policyName":{"name":"policyName","type":"\u0007","is_mandatory":true,"title":"Name of the permission policy","provider":"go.mondoo.com/mql/providers/alicloud"},"policyType":{"name":"policyType","type":"\u0007","is_mandatory":true,"title":"Policy type","desc":"Either System for an Alibaba Cloud managed policy or Inline for a policy defined on the access configuration itself.","provider":"go.mondoo.com/mql/providers/alicloud"},"ramPolicy":{"name":"ramPolicy","type":"\u001balicloud.ram.policy","title":"Managed policy behind a System permission policy","desc":"The Alibaba Cloud managed policy of the same name, so its statements can be read the same way as for a RAM identity. Null for an Inline policy.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO permission policy","desc":"A permission policy attached to a CloudSSO access configuration. A System policy is one of the Alibaba Cloud managed policies, reachable through ramPolicy; an Inline policy carries its statements in policyDocument on this resource. Between them they define everything a session created from the access configuration is allowed to do.","min_provider_version":"13.2.5","defaults":"policyName policyType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.user":{"id":"alicloud.cloudsso.user","name":"alicloud.cloudsso.user","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the user was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the user belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email address of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"firstName":{"name":"firstName","type":"\u0007","is_mandatory":true,"title":"First name of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"groups":{"name":"groups","type":"\u0019\u001balicloud.cloudsso.group","title":"Groups the user belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"lastName":{"name":"lastName","type":"\u0007","is_mandatory":true,"title":"Last name of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaDevices":{"name":"mfaDevices","type":"\u0019\u001balicloud.cloudsso.mfaDevice","title":"Multi-factor authentication devices bound to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"provisionType":{"name":"provisionType","type":"\u0007","is_mandatory":true,"title":"How the user account came to exist","desc":"Either Manual for a user created directly in the directory, or Synchronized for one provisioned from an external identity provider. A manual user survives deprovisioning at the identity provider.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"User status","desc":"Either Enabled or Disabled. A disabled user cannot sign in but keeps its group memberships and assignments.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the user was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"userId":{"name":"userId","type":"\u0007","is_mandatory":true,"title":"User ID, used with directoryId as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"Sign-in name of the user","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO user","desc":"A workforce user in a CloudSSO directory, keyed by the directoryId and userId. Exposes the user profile, whether the account was created directly or synchronized from an external identity provider, the multi-factor devices bound to it, and the groups it belongs to.","min_provider_version":"13.2.5","defaults":"userName displayName status provisionType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config":{"id":"alicloud.config","name":"alicloud.config","fields":{"aggregator":{"name":"aggregator","type":"\u001balicloud.config.aggregator","title":"Cloud Config aggregator","desc":"An account group that collects configuration and compliance data from other accounts into this one, keyed by aggregatorId. An RD aggregator covers a folder of the resource directory and grows as accounts join it, while a CUSTOM aggregator covers a fixed list of accounts and silently omits any account added afterwards.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"aggregators":{"name":"aggregators","type":"\u0019\u001balicloud.config.aggregator","title":"Account groups that aggregate configuration data from member accounts","desc":"An aggregator collects configuration and compliance data from other accounts into this one, either from the whole resource directory or from a hand-picked set of accounts.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePack":{"name":"compliancePack","type":"\u001balicloud.config.compliancePack","title":"Cloud Config compliance pack","desc":"A named bundle of Config rules evaluated together, keyed by compliancePackId. Reports the pack definition, the template it was built from, the risk level assigned to it, and the rules it carries, so a pack that is present but not yet evaluating is distinguishable from one that is active.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"compliancePacks":{"name":"compliancePacks","type":"\u0019\u001balicloud.config.compliancePack","title":"Compliance packs applied in the account","desc":"A compliance pack bundles Config rules into a single evaluated set. Reports the pack inventory, the risk level assigned to each, and the rules a pack carries.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceSummary":{"name":"complianceSummary","type":"\n","title":"Account-wide compliance summary","desc":"Counts of compliant and non-compliant rules and resources. Keys include compliantRuleCount, nonCompliantRuleCount, totalRuleCount, compliantResourceCount, nonCompliantResourceCount, totalResourceCount, and the highRisk, mediumRisk, and lowRisk non-compliant resource counts.","provider":"go.mondoo.com/mql/providers/alicloud"},"deliveryChannel":{"name":"deliveryChannel","type":"\u001balicloud.config.deliveryChannel","title":"Cloud Config delivery channel","desc":"A destination Cloud Config writes configuration snapshots, configuration change notifications, and compliance results to, keyed by channelId. The destination is an OSS bucket, a Log Service logstore, or a Message Service topic, reached through ossBucket and logstore where the destination has a resource of its own. The enabled flag reports whether delivery is running, and the four notification toggles report which payload kinds are sent, so a channel that exists but delivers nothing an audit pipeline reads is distinguishable from one that is working.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"deliveryChannels":{"name":"deliveryChannels","type":"\u0019\u001balicloud.config.deliveryChannel","title":"Delivery channels that export configuration data and compliance results","desc":"A recording account that has no enabled delivery channel keeps its configuration history only inside the Cloud Config console, so nothing reaches the OSS bucket, logstore, or message topic an audit pipeline reads. Empty when no delivery channel is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"evaluationResult":{"name":"evaluationResult","type":"\u001balicloud.config.evaluationResult","title":"Cloud Config rule evaluation result","desc":"The outcome of one Config rule examining one resource. Reports the compliance verdict, the annotation naming what failed, the rule and compliance pack that produced it, and when the resource last failed and was last brought back into compliance. Where rules describes the checks that exist, this describes what they actually found.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"nonCompliantResults":{"name":"nonCompliantResults","type":"\u0019\u001balicloud.config.evaluationResult","title":"Non-compliant evaluation results across every rule in the account","desc":"The resources that currently fail a Config rule, each carrying the rule that flagged it, the annotation explaining why, and the risk level. This is the evaluated outcome, whereas rules reports only which rules exist.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"recordedResourceTypes":{"name":"recordedResourceTypes","type":"\u0019\u0007","title":"Resource types the configuration recorder captures","provider":"go.mondoo.com/mql/providers/alicloud"},"recorderEnabled":{"name":"recorderEnabled","type":"\u0004","title":"Whether the configuration recorder is registered and actively recording","desc":"True when the recorder status is REGISTERED. When false, resource configuration changes are not being captured.","provider":"go.mondoo.com/mql/providers/alicloud"},"recorderStatus":{"name":"recorderStatus","type":"\u0007","title":"Configuration-recorder status","desc":"One of REGISTRABLE, BUILDING, REGISTERED, or REBUILDING. REGISTERED means recording is active.","provider":"go.mondoo.com/mql/providers/alicloud"},"rule":{"name":"rule","type":"\u001balicloud.config.rule","title":"Cloud Config rule","desc":"A single Config rule, keyed by configRuleId. A rule continuously evaluates whether resources of a given type meet a configuration requirement and reports each resource as compliant or non-compliant. Exposes the rule definition, risk level, evaluation source, and current compliance result.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"rules":{"name":"rules","type":"\u0019\u001balicloud.config.rule","title":"Config rules defined in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Cloud Config","desc":"Configuration-compliance state for an Alibaba Cloud account. Exposes the Config rules that continuously evaluate resource configuration, the account-wide compliance summary, and whether the configuration recorder and its delivery channels are active. Use it to audit whether configuration recording is enabled and how many resources are non-compliant.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.aggregator":{"id":"alicloud.config.aggregator","name":"alicloud.config.aggregator","fields":{"accountCount":{"name":"accountCount","type":"\u0005","is_mandatory":true,"title":"Number of member accounts the aggregator collects from","provider":"go.mondoo.com/mql/providers/alicloud"},"aggregatorId":{"name":"aggregatorId","type":"\u0007","is_mandatory":true,"title":"Aggregator ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"aggregatorName":{"name":"aggregatorName","type":"\u0007","is_mandatory":true,"title":"Aggregator name","provider":"go.mondoo.com/mql/providers/alicloud"},"aggregatorType":{"name":"aggregatorType","type":"\u0007","is_mandatory":true,"title":"Aggregator type","desc":"Either RD, covering a resource directory folder, or CUSTOM, covering a fixed set of accounts.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the aggregator was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Aggregator description","provider":"go.mondoo.com/mql/providers/alicloud"},"folder":{"name":"folder","type":"\u001balicloud.resourceManager.folder","title":"Resource directory folder the aggregator covers","desc":"Null for a CUSTOM aggregator, which names accounts rather than a folder.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Aggregator status","desc":"0 while the account group is being created, and 1 once it is created.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the aggregator","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config aggregator","desc":"An account group that collects configuration and compliance data from other accounts into this one, keyed by aggregatorId. An RD aggregator covers a folder of the resource directory and grows as accounts join it, while a CUSTOM aggregator covers a fixed list of accounts and silently omits any account added afterwards.","min_provider_version":"13.4.1","defaults":"aggregatorName aggregatorType accountCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.compliancePack":{"id":"alicloud.config.compliancePack","name":"alicloud.config.compliancePack","fields":{"compliancePackId":{"name":"compliancePackId","type":"\u0007","is_mandatory":true,"title":"Compliance pack ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePackName":{"name":"compliancePackName","type":"\u0007","is_mandatory":true,"title":"Compliance pack name","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePackTemplateId":{"name":"compliancePackTemplateId","type":"\u0007","is_mandatory":true,"title":"ID of the template the pack was built from","desc":"Empty for a pack assembled from individual rules rather than a template.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the pack was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Compliance pack description","provider":"go.mondoo.com/mql/providers/alicloud"},"riskLevel":{"name":"riskLevel","type":"\u0005","is_mandatory":true,"title":"Risk level assigned to the pack","desc":"One of 1 (high), 2 (medium), or 3 (low).","provider":"go.mondoo.com/mql/providers/alicloud"},"rules":{"name":"rules","type":"\u0019\u001balicloud.config.rule","title":"Config rules the pack evaluates","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Compliance pack status","desc":"Either ACTIVE, meaning the pack is evaluating, or CREATING.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the pack","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config compliance pack","desc":"A named bundle of Config rules evaluated together, keyed by compliancePackId. Reports the pack definition, the template it was built from, the risk level assigned to it, and the rules it carries, so a pack that is present but not yet evaluating is distinguishable from one that is active.","min_provider_version":"13.4.1","defaults":"compliancePackName status riskLevel","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.deliveryChannel":{"id":"alicloud.config.deliveryChannel","name":"alicloud.config.deliveryChannel","fields":{"assumeRole":{"name":"assumeRole","type":"\u001balicloud.ram.role","title":"RAM role Cloud Config assumes to write to the destination","desc":"Null when the channel is configured without an assume-role ARN.","provider":"go.mondoo.com/mql/providers/alicloud"},"channelId":{"name":"channelId","type":"\u0007","is_mandatory":true,"title":"Delivery channel ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"compliantSnapshot":{"name":"compliantSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether compliant evaluation results are delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"condition":{"name":"condition","type":"\u0007","is_mandatory":true,"title":"Filter that limits which resources the channel delivers","desc":"A JSON expression evaluated against each configuration item. Empty when the channel delivers every item.","provider":"go.mondoo.com/mql/providers/alicloud"},"configurationItemChangeNotification":{"name":"configurationItemChangeNotification","type":"\u0004","is_mandatory":true,"title":"Whether configuration change notifications are delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"configurationSnapshot":{"name":"configurationSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether the scheduled resource snapshot is delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Delivery channel description","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the channel is delivering","desc":"False when the channel exists but is disabled, in which case nothing reaches the destination.","provider":"go.mondoo.com/mql/providers/alicloud"},"logstore":{"name":"logstore","type":"\u001balicloud.log.logstore","title":"Log Service logstore the channel delivers to","desc":"Null when the channel targets an OSS bucket or a Message Service topic.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Delivery channel name","provider":"go.mondoo.com/mql/providers/alicloud"},"nonCompliantNotification":{"name":"nonCompliantNotification","type":"\u0004","is_mandatory":true,"title":"Whether non-compliant evaluation results are delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucket":{"name":"ossBucket","type":"\u001balicloud.oss.bucket","title":"OSS bucket the channel delivers to","desc":"Null when the channel targets a Log Service logstore or a Message Service topic.","provider":"go.mondoo.com/mql/providers/alicloud"},"oversizedDataOssTargetArn":{"name":"oversizedDataOssTargetArn","type":"\u0007","is_mandatory":true,"title":"ARN of the OSS bucket that receives payloads too large for the channel","desc":"Empty when no oversized-data bucket is configured, in which case an oversized payload is dropped rather than delivered elsewhere.","provider":"go.mondoo.com/mql/providers/alicloud"},"snapshotTime":{"name":"snapshotTime","type":"\u0007","is_mandatory":true,"title":"Delivery time of the scheduled resource snapshot","desc":"An ISO 8601 timestamp whose hour selects the daily delivery time, for example 2021-09-15T16:00:00Z. Empty when snapshot delivery is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"targetArn":{"name":"targetArn","type":"\u0007","is_mandatory":true,"title":"ARN of the destination the channel writes to","desc":"An OSS bucket, a Message Service topic, or a Log Service logstore. Message Service topics have no resource of their own, so this is the only complete view of the destination.","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Destination service","desc":"One of OSS, MNS, or SLS.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config delivery channel","desc":"A destination Cloud Config writes configuration snapshots, configuration change notifications, and compliance results to, keyed by channelId. The destination is an OSS bucket, a Log Service logstore, or a Message Service topic, reached through ossBucket and logstore where the destination has a resource of its own. The enabled flag reports whether delivery is running, and the four notification toggles report which payload kinds are sent, so a channel that exists but delivers nothing an audit pipeline reads is distinguishable from one that is working.","min_provider_version":"13.4.1","defaults":"name type enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.evaluationResult":{"id":"alicloud.config.evaluationResult","name":"alicloud.config.evaluationResult","fields":{"annotation":{"name":"annotation","type":"\u0007","is_mandatory":true,"title":"Explanation of the verdict","desc":"Names the setting that failed, such as the ports a security group leaves open. Empty for a compliant resource.","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePack":{"name":"compliancePack","type":"\u001balicloud.config.compliancePack","title":"Compliance pack the rule was evaluated under","desc":"Null when the rule does not belong to a pack.","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceType":{"name":"complianceType","type":"\u0007","is_mandatory":true,"title":"Compliance verdict","desc":"One of COMPLIANT, NON_COMPLIANT, NOT_APPLICABLE, INSUFFICIENT_DATA, or IGNORED.","provider":"go.mondoo.com/mql/providers/alicloud"},"configRule":{"name":"configRule","type":"\u001balicloud.config.rule","title":"Config rule that produced the result","provider":"go.mondoo.com/mql/providers/alicloud"},"ignoreDate":{"name":"ignoreDate","type":"\u0007","is_mandatory":true,"title":"Date the result was set to be ignored","desc":"Formatted as yyyy-MM-dd. Empty unless the result has been ignored, which suppresses it from the compliance summary without fixing the resource.","provider":"go.mondoo.com/mql/providers/alicloud"},"invokedTime":{"name":"invokedTime","type":"\t","is_mandatory":true,"title":"Time the rule last evaluated the resource","provider":"go.mondoo.com/mql/providers/alicloud"},"lastCompliantFixedTime":{"name":"lastCompliantFixedTime","type":"\t","is_mandatory":true,"title":"Time the resource was last brought back into compliance","provider":"go.mondoo.com/mql/providers/alicloud"},"lastNonCompliantTime":{"name":"lastNonCompliantTime","type":"\t","is_mandatory":true,"title":"Time the resource was last recorded as non-compliant","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the evaluated resource lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"remediationEnabled":{"name":"remediationEnabled","type":"\u0004","is_mandatory":true,"title":"Whether a remediation is configured for the rule","desc":"False means a failing resource stays failing until someone acts on it.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the evaluated resource belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceId":{"name":"resourceId","type":"\u0007","is_mandatory":true,"title":"ID of the evaluated resource","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceName":{"name":"resourceName","type":"\u0007","is_mandatory":true,"title":"Name of the evaluated resource","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceType":{"name":"resourceType","type":"\u0007","is_mandatory":true,"title":"Type of the evaluated resource","desc":"An Alibaba Cloud resource type such as ACS::ECS::Instance.","provider":"go.mondoo.com/mql/providers/alicloud"},"resultRecordedTime":{"name":"resultRecordedTime","type":"\t","is_mandatory":true,"title":"Time the result was recorded","provider":"go.mondoo.com/mql/providers/alicloud"},"riskLevel":{"name":"riskLevel","type":"\u0005","is_mandatory":true,"title":"Risk level of the rule that produced the result","desc":"One of 1 (high), 2 (medium), or 3 (low).","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config rule evaluation result","desc":"The outcome of one Config rule examining one resource. Reports the compliance verdict, the annotation naming what failed, the rule and compliance pack that produced it, and when the resource last failed and was last brought back into compliance. Where rules describes the checks that exist, this describes what they actually found.","min_provider_version":"13.4.1","defaults":"resourceName resourceType complianceType riskLevel","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.rule":{"id":"alicloud.config.rule","name":"alicloud.config.rule","fields":{"automationType":{"name":"automationType","type":"\u0007","is_mandatory":true,"title":"Automation type applied to non-compliant resources, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceCount":{"name":"complianceCount","type":"\u0005","is_mandatory":true,"title":"Number of resources in the current compliance result","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePackId":{"name":"compliancePackId","type":"\u0007","is_mandatory":true,"title":"ID of the compliance pack the rule belongs to, empty when the rule is standalone","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceType":{"name":"complianceType","type":"\u0007","is_mandatory":true,"title":"Compliance result type","desc":"One of COMPLIANT, NON_COMPLIANT, NOT_APPLICABLE, or INSUFFICIENT_DATA.","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleArn":{"name":"configRuleArn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleId":{"name":"configRuleId","type":"\u0007","is_mandatory":true,"title":"Config rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleName":{"name":"configRuleName","type":"\u0007","is_mandatory":true,"title":"Config rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleState":{"name":"configRuleState","type":"\u0007","is_mandatory":true,"title":"Rule state","desc":"One of ACTIVE, INACTIVE, EVALUATING, or DELETING.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"evaluationResults":{"name":"evaluationResults","type":"\u0019\u001balicloud.config.evaluationResult","title":"Resources the rule has evaluated and the verdict for each","desc":"The evaluated outcome of the rule, one entry per resource it examined, carrying the compliance verdict and the annotation explaining it.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"maximumExecutionFrequency":{"name":"maximumExecutionFrequency","type":"\u0007","title":"Maximum interval at which a periodic rule re-evaluates","desc":"One of One_Hour, Three_Hours, Six_Hours, Twelve_Hours, or TwentyFour_Hours. Empty for change-triggered rules.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceTypesScope":{"name":"resourceTypesScope","type":"\u0019\u0007","is_mandatory":true,"title":"Resource types the rule evaluates","provider":"go.mondoo.com/mql/providers/alicloud"},"riskLevel":{"name":"riskLevel","type":"\u0005","is_mandatory":true,"title":"Risk level of a non-compliant result","desc":"1 for high, 2 for medium, 3 for low.","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceIdentifier":{"name":"sourceIdentifier","type":"\u0007","is_mandatory":true,"title":"Identifier of the managed rule or custom evaluation function","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceOwner":{"name":"sourceOwner","type":"\u0007","is_mandatory":true,"title":"Owner of the rule's evaluation logic","desc":"ALIYUN for a managed rule, or a custom source such as CUSTOM_FC for a Function Compute-backed rule.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the rule","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config rule","desc":"A single Config rule, keyed by configRuleId. A rule continuously evaluates whether resources of a given type meet a configuration requirement and reports each resource as compliant or non-compliant. Exposes the rule definition, risk level, evaluation source, and current compliance result.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs":{"id":"alicloud.cs","name":"alicloud.cs","fields":{"cluster":{"name":"cluster","type":"\u001balicloud.cs.cluster","title":"Container Service for Kubernetes cluster","desc":"A single ACK cluster, keyed by clusterId within its region. Exposes the cluster type and Kubernetes version, the VPC, vSwitches, and security group it runs in, the pod and service CIDRs, the public and intranet API server endpoints, and the derived internet-exposure of the API server. Node pools, installed addons, control-plane audit logging, and workload-identity (RRSA) settings are reached from here. For example alicloud.cs.cluster(clusterId: \"c1a2b3\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"clusters":{"name":"clusters","type":"\u0019\u001balicloud.cs.cluster","title":"Kubernetes clusters across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePool":{"name":"nodePool","type":"\u001balicloud.cs.nodePool","title":"Container Service for Kubernetes node pool","desc":"A single node pool within an ACK cluster, keyed by nodePoolId. Exposes the node instance configuration, scaling and management policy, OS hardening flags, disk encryption, and the typed references to the security groups, vSwitches, RAM role, and KMS key the nodes use. Use it to audit node disk encryption, OS hardening, and automatic CVE patching.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Container Service for Kubernetes","desc":"ACK clusters across an Alibaba Cloud account. Exposes the Kubernetes clusters in every enabled region, including their type and version, network layout, API server exposure, control-plane audit logging, workload-identity (RRSA) settings, node pools, and installed addons. Use it to audit whether a cluster's API server is reachable from the internet and whether audit logging is enabled.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs.cluster":{"id":"alicloud.cs.cluster","name":"alicloud.cs.cluster","fields":{"addons":{"name":"addons","type":"\u0019\n","title":"Addons installed in the cluster","desc":"Each entry lists the name, version, and state of an installed addon, for example security-inspector, logtail-ds, terway-eniip, or csi-plugin. Use it to audit which security and observability addons are present.","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerInternetExposed":{"name":"apiServerInternetExposed","type":"\u0004","is_mandatory":true,"title":"Whether the Kubernetes API server is reachable from the internet","desc":"True when the cluster exposes a public API server endpoint. A publicly reachable API server broadens the attack surface of the control plane.","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerIntranetEndpoint":{"name":"apiServerIntranetEndpoint","type":"\u0007","is_mandatory":true,"title":"Intranet (private) API server endpoint","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerPublicEndpoint":{"name":"apiServerPublicEndpoint","type":"\u0007","is_mandatory":true,"title":"Public (internet) API server endpoint","desc":"The internet-facing Kubernetes API server URL. Empty when the API server has no public endpoint.","provider":"go.mondoo.com/mql/providers/alicloud"},"auditLogEnabled":{"name":"auditLogEnabled","type":"\u0004","title":"Whether Kubernetes API server audit logging is enabled","desc":"True when the control-plane audit component ships logs to Log Service. When false, API server activity is not being recorded.","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterDomain":{"name":"clusterDomain","type":"\u0007","is_mandatory":true,"title":"Cluster local DNS domain, for example cluster.local","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterId":{"name":"clusterId","type":"\u0007","is_mandatory":true,"title":"Cluster ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterSpec":{"name":"clusterSpec","type":"\u0007","is_mandatory":true,"title":"Managed-tier specification","desc":"For example ack.pro.small or ack.standard. Empty for dedicated Kubernetes clusters.","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterType":{"name":"clusterType","type":"\u0007","is_mandatory":true,"title":"Cluster type","desc":"One of Kubernetes (dedicated), ManagedKubernetes, Ask (serverless), or ExternalKubernetes.","provider":"go.mondoo.com/mql/providers/alicloud"},"containerCidr":{"name":"containerCidr","type":"\u0007","is_mandatory":true,"title":"Pod CIDR block","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPlaneLogComponents":{"name":"controlPlaneLogComponents","type":"\u0019\u0007","title":"Control-plane components shipping logs to Log Service","desc":"For example apiserver, audit, kcm (kube-controller-manager), scheduler, or ccm (cloud-controller-manager). Empty when control-plane logging is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPlaneLogProject":{"name":"controlPlaneLogProject","type":"\u001balicloud.log.project","title":"Log Service project that receives the control-plane logs","desc":"Null when control-plane logging is not configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPlaneLogTtl":{"name":"controlPlaneLogTtl","type":"\u0005","title":"Retention in days of the control-plane logs, 0 when logging is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Time the cluster was created","provider":"go.mondoo.com/mql/providers/alicloud"},"currentVersion":{"name":"currentVersion","type":"\u0007","is_mandatory":true,"title":"Running Kubernetes version","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled for the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"initVersion":{"name":"initVersion","type":"\u0007","is_mandatory":true,"title":"Kubernetes version the cluster was created with","provider":"go.mondoo.com/mql/providers/alicloud"},"ipStack":{"name":"ipStack","type":"\u0007","is_mandatory":true,"title":"IP stack of the cluster","desc":"One of ipv4, ipv6, or dual.","provider":"go.mondoo.com/mql/providers/alicloud"},"maintenanceWindow":{"name":"maintenanceWindow","type":"\n","is_mandatory":true,"title":"Maintenance window configuration","desc":"The scheduled maintenance window, with enable, duration, maintenanceTime, recurrence, and weeklyPeriod. Null when no window is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Cluster name","provider":"go.mondoo.com/mql/providers/alicloud"},"networkMode":{"name":"networkMode","type":"\u0007","is_mandatory":true,"title":"Cluster network mode, for example vpc or overlay","provider":"go.mondoo.com/mql/providers/alicloud"},"nextVersion":{"name":"nextVersion","type":"\u0007","is_mandatory":true,"title":"Next Kubernetes version available for upgrade, empty when up to date","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePools":{"name":"nodePools","type":"\u0019\u001balicloud.cs.nodePool","title":"Node pools in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"oidcIssuerUrl":{"name":"oidcIssuerUrl","type":"\u0007","title":"OIDC issuer URL for workload identity, empty when RRSA is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"privateZone":{"name":"privateZone","type":"\u0004","is_mandatory":true,"title":"Whether PrivateZone (private DNS) is enabled for the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"profile":{"name":"profile","type":"\u0007","is_mandatory":true,"title":"Cluster profile, for example Default, Serverless, or Edge","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyMode":{"name":"proxyMode","type":"\u0007","is_mandatory":true,"title":"kube-proxy mode, either iptables or ipvs","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the cluster resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the cluster","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"rrsaEnabled":{"name":"rrsaEnabled","type":"\u0004","title":"Whether RAM Roles for Service Accounts (RRSA) workload identity is enabled","desc":"True when the cluster issues OIDC tokens for pod-level RAM authorization instead of relying on the shared worker node role.","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroup":{"name":"securityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Security group applied to the cluster nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"serviceCidr":{"name":"serviceCidr","type":"\u0007","is_mandatory":true,"title":"Service CIDR block","provider":"go.mondoo.com/mql/providers/alicloud"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Total number of nodes in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Cluster lifecycle state","desc":"For example running, initial, failed, or deleting.","provider":"go.mondoo.com/mql/providers/alicloud"},"subnetCidr":{"name":"subnetCidr","type":"\u0007","is_mandatory":true,"title":"Node subnet CIDR block","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"timezone":{"name":"timezone","type":"\u0007","is_mandatory":true,"title":"Time zone configured for the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"updated":{"name":"updated","type":"\t","is_mandatory":true,"title":"Time the cluster was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the cluster runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the cluster's control plane and nodes attach to","provider":"go.mondoo.com/mql/providers/alicloud"},"workerRamRole":{"name":"workerRamRole","type":"\u001balicloud.ram.role","title":"Worker node RAM role, null when the cluster has no worker RAM role","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the cluster's managed resources reside in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Service for Kubernetes cluster","desc":"A single ACK cluster, keyed by clusterId within its region. Exposes the cluster type and Kubernetes version, the VPC, vSwitches, and security group it runs in, the pod and service CIDRs, the public and intranet API server endpoints, and the derived internet-exposure of the API server. Node pools, installed addons, control-plane audit logging, and workload-identity (RRSA) settings are reached from here. For example alicloud.cs.cluster(clusterId: \"c1a2b3\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs.nodePool":{"id":"alicloud.cs.nodePool","name":"alicloud.cs.nodePool","fields":{"autoRepair":{"name":"autoRepair","type":"\u0004","is_mandatory":true,"title":"Whether managed nodes are automatically repaired","provider":"go.mondoo.com/mql/providers/alicloud"},"autoScalingEnabled":{"name":"autoScalingEnabled","type":"\u0004","is_mandatory":true,"title":"Whether autoscaling is enabled for the node pool","provider":"go.mondoo.com/mql/providers/alicloud"},"autoScalingType":{"name":"autoScalingType","type":"\u0007","is_mandatory":true,"title":"Autoscaling type, for example cpu, gpu, or spot","provider":"go.mondoo.com/mql/providers/alicloud"},"autoUpgrade":{"name":"autoUpgrade","type":"\u0004","is_mandatory":true,"title":"Whether managed nodes are automatically upgraded","provider":"go.mondoo.com/mql/providers/alicloud"},"autoVulFix":{"name":"autoVulFix","type":"\u0004","is_mandatory":true,"title":"Whether managed nodes automatically receive CVE fixes","provider":"go.mondoo.com/mql/providers/alicloud"},"cisEnabled":{"name":"cisEnabled","type":"\u0004","is_mandatory":true,"title":"Whether CIS benchmark hardening is enabled for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"cluster":{"name":"cluster","type":"\u001balicloud.cs.cluster","title":"Cluster the node pool belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterId":{"name":"clusterId","type":"\u0007","is_mandatory":true,"title":"ID of the cluster the node pool belongs to","desc":"A node pool ID is unique only within its cluster, so both are needed to identify a node pool.","provider":"go.mondoo.com/mql/providers/alicloud"},"cmsEnabled":{"name":"cmsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the CloudMonitor agent is installed on nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"cpuPolicy":{"name":"cpuPolicy","type":"\u0007","is_mandatory":true,"title":"CPU management policy, either none or static","provider":"go.mondoo.com/mql/providers/alicloud"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Time the node pool was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dataDisks":{"name":"dataDisks","type":"\u0019\n","is_mandatory":true,"title":"Data disks attached to nodes","desc":"Each entry lists the category, size, encrypted, kmsKeyId, performanceLevel, and autoSnapshotPolicyId of a data disk.","provider":"go.mondoo.com/mql/providers/alicloud"},"desiredSize":{"name":"desiredSize","type":"\u0005","is_mandatory":true,"title":"Desired number of nodes in the pool","provider":"go.mondoo.com/mql/providers/alicloud"},"failedNodes":{"name":"failedNodes","type":"\u0005","is_mandatory":true,"title":"Number of failed nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"healthyNodes":{"name":"healthyNodes","type":"\u0005","is_mandatory":true,"title":"Number of healthy nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Image the node pool launches nodes from","desc":"Null on a node pool that names no image, and on one whose image is not visible to the account, for example a public image that has been retired.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"ID of the image used for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"imageType":{"name":"imageType","type":"\u0007","is_mandatory":true,"title":"Image type used for nodes, for example AliyunLinux or ContainerOS","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Node billing method","desc":"Either PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceTypes":{"name":"instanceTypes","type":"\u0019\u0007","is_mandatory":true,"title":"ECS instance types used for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthOut":{"name":"internetMaxBandwidthOut","type":"\u0005","is_mandatory":true,"title":"Maximum outbound internet bandwidth in Mbps assigned to nodes, 0 when nodes have no public bandwidth","provider":"go.mondoo.com/mql/providers/alicloud"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether this is the cluster's default node pool","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPair":{"name":"keyPair","type":"\u0007","is_mandatory":true,"title":"Key pair name used for node SSH access, empty when password or managed login is used","provider":"go.mondoo.com/mql/providers/alicloud"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Kubernetes labels applied to nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"managed":{"name":"managed","type":"\u0004","is_mandatory":true,"title":"Whether the node pool is managed (control-plane operated)","provider":"go.mondoo.com/mql/providers/alicloud"},"maxInstances":{"name":"maxInstances","type":"\u0005","is_mandatory":true,"title":"Maximum number of nodes when autoscaling is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"minInstances":{"name":"minInstances","type":"\u0005","is_mandatory":true,"title":"Minimum number of nodes when autoscaling is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"multiAzPolicy":{"name":"multiAzPolicy","type":"\u0007","is_mandatory":true,"title":"Multi-zone scaling policy, for example PRIORITY, COST_OPTIMIZED, or BALANCE","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Node pool name","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePoolId":{"name":"nodePoolId","type":"\u0007","is_mandatory":true,"title":"Node pool ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePoolState":{"name":"nodePoolState","type":"\u0007","is_mandatory":true,"title":"Node pool state, for example active or scaling","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u001balicloud.ram.role","title":"RAM role assigned to the nodes, null when the node pool has no RAM role","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the node pool resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the node pool","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the node pool belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"runtime":{"name":"runtime","type":"\u0007","is_mandatory":true,"title":"Container runtime, for example containerd or docker","provider":"go.mondoo.com/mql/providers/alicloud"},"runtimeVersion":{"name":"runtimeVersion","type":"\u0007","is_mandatory":true,"title":"Container runtime version","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to the nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"securityHardeningOs":{"name":"securityHardeningOs","type":"\u0004","is_mandatory":true,"title":"Whether OS security hardening is applied to nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"servingNodes":{"name":"servingNodes","type":"\u0005","is_mandatory":true,"title":"Number of nodes serving workloads","provider":"go.mondoo.com/mql/providers/alicloud"},"socEnabled":{"name":"socEnabled","type":"\u0004","is_mandatory":true,"title":"Whether MLPS (Multi-Level Protection Scheme) compliance hardening is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"spotStrategy":{"name":"spotStrategy","type":"\u0007","is_mandatory":true,"title":"Spot instance strategy","desc":"One of NoSpot, SpotWithPriceLimit, or SpotAsPriceGo.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskCategory":{"name":"systemDiskCategory","type":"\u0007","is_mandatory":true,"title":"System disk category, for example cloud_essd","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskEncryptAlgorithm":{"name":"systemDiskEncryptAlgorithm","type":"\u0007","is_mandatory":true,"title":"System disk encryption algorithm, for example aes-256 or sm4","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskEncrypted":{"name":"systemDiskEncrypted","type":"\u0004","is_mandatory":true,"title":"Whether the system disk is encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskKmsKey":{"name":"systemDiskKmsKey","type":"\u001balicloud.kms.key","title":"KMS key used to encrypt the system disk, null when the system disk is not encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskSize":{"name":"systemDiskSize","type":"\u0005","is_mandatory":true,"title":"System disk size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"taints":{"name":"taints","type":"\u0019\n","is_mandatory":true,"title":"Kubernetes taints applied to nodes","desc":"Each entry lists the key, value, and effect (NoSchedule, PreferNoSchedule, or NoExecute) of a node taint.","provider":"go.mondoo.com/mql/providers/alicloud"},"teeEnabled":{"name":"teeEnabled","type":"\u0004","is_mandatory":true,"title":"Whether trusted (confidential) computing is enabled for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"totalNodes":{"name":"totalNodes","type":"\u0005","is_mandatory":true,"title":"Total number of nodes in the pool","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Node pool type, for example ess or edge","provider":"go.mondoo.com/mql/providers/alicloud"},"unschedulable":{"name":"unschedulable","type":"\u0004","is_mandatory":true,"title":"Whether nodes are marked unschedulable","provider":"go.mondoo.com/mql/providers/alicloud"},"updated":{"name":"updated","type":"\t","is_mandatory":true,"title":"Time the node pool was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the nodes attach to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Service for Kubernetes node pool","desc":"A single node pool within an ACK cluster, keyed by nodePoolId. Exposes the node instance configuration, scaling and management policy, OS hardening flags, disk encryption, and the typed references to the security groups, vSwitches, RAM role, and KMS key the nodes use. Use it to audit node disk encryption, OS hardening, and automatic CVE patching.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs":{"id":"alicloud.ecs","name":"alicloud.ecs","fields":{"disk":{"name":"disk","type":"\u001balicloud.ecs.disk","title":"Elastic Compute Service disk","desc":"A single block-storage disk (cloud disk or local disk), keyed by the composite region and diskId. Exposes the disk category and size, its attachment to an instance, encryption state and KMS key, snapshot behavior, and the performance level.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"disks":{"name":"disks","type":"\u0019\u001balicloud.ecs.disk","title":"Block-storage disks across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Elastic Compute Service image","desc":"A single machine image visible to the account, keyed by the composite region and imageId. Exposes the operating system and architecture, the image size and version, its ownership and sharing state, and whether it is public or supports cloud-init.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"images":{"name":"images","type":"\u0019\u001balicloud.ecs.image","title":"Machine images visible to the account across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"instance":{"name":"instance","type":"\u001balicloud.ecs.instance","title":"Elastic Compute Service instance","desc":"A single ECS virtual machine, keyed by the composite region and instanceId. Exposes the lifecycle status, the instance type and zone, hardware sizing (vCPUs, memory, GPUs), billing and charge configuration, the private, public, and elastic IP addresses, the VPC and vSwitch it is attached to, and the security groups controlling its traffic.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.ecs.instance","title":"ECS instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairs":{"name":"keyPairs","type":"\u0019\u001balicloud.ecs.keypair","title":"SSH key pairs across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"keypair":{"name":"keypair","type":"\u001balicloud.ecs.keypair","title":"Elastic Compute Service SSH key pair","desc":"A single SSH key pair, keyed by the composite region and keyPairName. Exposes the public-key fingerprint, the creation time, and the resource group the key pair belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"prefixList":{"name":"prefixList","type":"\u001balicloud.ecs.prefixList","title":"Prefix list","desc":"A named set of CIDR blocks that security group rules reference in place of a literal address range, keyed by prefixListId. A rule scoped to a prefix list carries no source or destination CIDR of its own, so the blocks it actually admits live here and nowhere else. associationCount reports how many rules and route tables point at the list, which is how far a change to it reaches.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"prefixLists":{"name":"prefixLists","type":"\u0019\u001balicloud.ecs.prefixList","title":"Prefix lists across all enabled regions","desc":"A prefix list names a set of CIDR blocks that security group rules point at instead of writing the blocks out, so a rule scoped to a list shows no CIDR of its own until the list is read.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"securitygroup":{"name":"securitygroup","type":"\u001balicloud.ecs.securitygroup","title":"Elastic Compute Service security group","desc":"A single security group, keyed by the composite region and securityGroupId. Exposes the group name and type, the VPC it belongs to, its inbound and outbound rules, and the instances it is applied to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Elastic Compute Service (ECS)","desc":"Compute resources in a region, including virtual machine instances, their attached block-storage disks, machine images, SSH key pairs, and the security groups that filter instance traffic. Fans out over every region enabled on the account.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.disk":{"id":"alicloud.ecs.disk","name":"alicloud.ecs.disk","fields":{"attachedTime":{"name":"attachedTime","type":"\t","is_mandatory":true,"title":"Time when the disk was last attached","provider":"go.mondoo.com/mql/providers/alicloud"},"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Disk category","desc":"One of cloud, cloud_efficiency, cloud_ssd, cloud_essd, cloud_auto, cloud_essd_entry, ephemeral_ssd, or local disk categories.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the disk was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteAutoSnapshot":{"name":"deleteAutoSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether automatic snapshots are deleted together with the disk","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteWithInstance":{"name":"deleteWithInstance","type":"\u0004","is_mandatory":true,"title":"Whether the disk is released together with its instance","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Disk description","provider":"go.mondoo.com/mql/providers/alicloud"},"detachedTime":{"name":"detachedTime","type":"\t","is_mandatory":true,"title":"Time when the disk was last detached","provider":"go.mondoo.com/mql/providers/alicloud"},"device":{"name":"device","type":"\u0007","is_mandatory":true,"title":"Device name the disk is mounted as, for example /dev/xvda","provider":"go.mondoo.com/mql/providers/alicloud"},"diskChargeType":{"name":"diskChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the disk","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"diskId":{"name":"diskId","type":"\u0007","is_mandatory":true,"title":"Disk ID, for example d-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"diskName":{"name":"diskName","type":"\u0007","is_mandatory":true,"title":"Disk name","provider":"go.mondoo.com/mql/providers/alicloud"},"enableAutoSnapshot":{"name":"enableAutoSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether the automatic snapshot policy is enabled for the disk","provider":"go.mondoo.com/mql/providers/alicloud"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the disk is encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"instance":{"name":"instance","type":"\u001balicloud.ecs.instance","title":"Instance the disk is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"KMS key used to encrypt the disk, null when the disk is not encrypted","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKeyId":{"name":"kmsKeyId","type":"\u0007","is_mandatory":true,"title":"KMS key ID used to encrypt the disk","desc":"Deprecated in favor of kmsKey.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"performanceLevel":{"name":"performanceLevel","type":"\u0007","is_mandatory":true,"title":"Performance level of an ESSD disk","desc":"One of PL0, PL1, PL2, or PL3.","provider":"go.mondoo.com/mql/providers/alicloud"},"portable":{"name":"portable","type":"\u0004","is_mandatory":true,"title":"Whether the disk can be detached","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the disk","provider":"go.mondoo.com/mql/providers/alicloud"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Disk size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Disk status","desc":"One of In_use, Available, Attaching, Detaching, Creating, or ReIniting.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the disk, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Disk role","desc":"One of system or data.","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID of the disk","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service disk","desc":"A single block-storage disk (cloud disk or local disk), keyed by the composite region and diskId. Exposes the disk category and size, its attachment to an instance, encryption state and KMS key, snapshot behavior, and the performance level.","min_provider_version":"13.0.0","defaults":"diskId diskName category size status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.image":{"id":"alicloud.ecs.image","name":"alicloud.ecs.image","fields":{"architecture":{"name":"architecture","type":"\u0007","is_mandatory":true,"title":"CPU architecture of the image","desc":"One of i386 or x86_64.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the image was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Image description","provider":"go.mondoo.com/mql/providers/alicloud"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"Image ID, for example m-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"imageName":{"name":"imageName","type":"\u0007","is_mandatory":true,"title":"Image name","provider":"go.mondoo.com/mql/providers/alicloud"},"imageOwnerAlias":{"name":"imageOwnerAlias","type":"\u0007","is_mandatory":true,"title":"Alias of the image owner","desc":"One of system, self, others, or marketplace.","provider":"go.mondoo.com/mql/providers/alicloud"},"imageVersion":{"name":"imageVersion","type":"\u0007","is_mandatory":true,"title":"Image version","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","is_mandatory":true,"title":"Whether the image is public","provider":"go.mondoo.com/mql/providers/alicloud"},"isSelfShared":{"name":"isSelfShared","type":"\u0007","is_mandatory":true,"title":"Whether the image is shared to other accounts by the owner","provider":"go.mondoo.com/mql/providers/alicloud"},"isSupportCloudinit":{"name":"isSupportCloudinit","type":"\u0004","is_mandatory":true,"title":"Whether the image supports cloud-init","provider":"go.mondoo.com/mql/providers/alicloud"},"osName":{"name":"osName","type":"\u0007","is_mandatory":true,"title":"Name of the operating system in the image","provider":"go.mondoo.com/mql/providers/alicloud"},"osType":{"name":"osType","type":"\u0007","is_mandatory":true,"title":"Operating system family","desc":"One of windows or linux.","provider":"go.mondoo.com/mql/providers/alicloud"},"platform":{"name":"platform","type":"\u0007","is_mandatory":true,"title":"Platform of the operating system, for example CentOS or Ubuntu","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the image","provider":"go.mondoo.com/mql/providers/alicloud"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Image size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Image status","desc":"One of UnAvailable, Available, Creating, or CreateFailed.","provider":"go.mondoo.com/mql/providers/alicloud"},"usage":{"name":"usage","type":"\u0007","is_mandatory":true,"title":"How the image is used","desc":"One of instance, none, or reserved.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service image","desc":"A single machine image visible to the account, keyed by the composite region and imageId. Exposes the operating system and architecture, the image size and version, its ownership and sharing state, and whether it is public or supports cloud-init.","min_provider_version":"13.0.0","defaults":"imageId imageName osName status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.instance":{"id":"alicloud.ecs.instance","name":"alicloud.ecs.instance","fields":{"autoReleaseTime":{"name":"autoReleaseTime","type":"\t","is_mandatory":true,"title":"Automatic release time of a pay-as-you-go instance","provider":"go.mondoo.com/mql/providers/alicloud"},"cpu":{"name":"cpu","type":"\u0005","is_mandatory":true,"title":"Number of vCPUs","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"creditSpecification":{"name":"creditSpecification","type":"\u0007","is_mandatory":true,"title":"Performance mode of a burstable instance","desc":"One of Standard or Unlimited.","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether release protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"deploymentSetId":{"name":"deploymentSetId","type":"\u0007","is_mandatory":true,"title":"Deployment set ID the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Instance description","provider":"go.mondoo.com/mql/providers/alicloud"},"deviceAvailable":{"name":"deviceAvailable","type":"\u0004","is_mandatory":true,"title":"Whether data disks can be attached to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"eipAddress":{"name":"eipAddress","type":"\u0007","is_mandatory":true,"title":"Elastic IP address associated with the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"expiredTime":{"name":"expiredTime","type":"\t","is_mandatory":true,"title":"Expiration time of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"gpuAmount":{"name":"gpuAmount","type":"\u0005","is_mandatory":true,"title":"Number of GPUs attached to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"gpuSpec":{"name":"gpuSpec","type":"\u0007","is_mandatory":true,"title":"GPU model of the instance type, for example NVIDIA V100","provider":"go.mondoo.com/mql/providers/alicloud"},"hostName":{"name":"hostName","type":"\u0007","is_mandatory":true,"title":"Hostname of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Image the instance was created from","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the instance","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example i-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Instance type, for example ecs.g5.large","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceTypeFamily":{"name":"instanceTypeFamily","type":"\u0007","is_mandatory":true,"title":"Instance type family, for example ecs.g5","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method for network usage","desc":"One of PayByBandwidth or PayByTraffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetExposed":{"name":"internetExposed","type":"\u0004","title":"Whether the instance is reachable from the internet","desc":"True when the instance has a directly-assigned public IP address or an associated elastic IP address, indicating inbound reachability from the public internet before security-group rules are considered.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthIn":{"name":"internetMaxBandwidthIn","type":"\u0005","is_mandatory":true,"title":"Maximum inbound public bandwidth in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthOut":{"name":"internetMaxBandwidthOut","type":"\u0005","is_mandatory":true,"title":"Maximum outbound public bandwidth in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"ioOptimized":{"name":"ioOptimized","type":"\u0004","is_mandatory":true,"title":"Whether the instance is I/O optimized","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPair":{"name":"keyPair","type":"\u001balicloud.ecs.keypair","title":"SSH key pair used by the instance","desc":"Null on an instance launched without a key pair, and on one whose key pair has since been deleted.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairName":{"name":"keyPairName","type":"\u0007","is_mandatory":true,"title":"Name of the SSH key pair used by the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"localStorageAmount":{"name":"localStorageAmount","type":"\u0005","is_mandatory":true,"title":"Number of local disks attached to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"localStorageCapacity":{"name":"localStorageCapacity","type":"\u0005","is_mandatory":true,"title":"Capacity of local disks attached to the instance in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"memory":{"name":"memory","type":"\u0005","is_mandatory":true,"title":"Memory size in MiB","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataEndpointEnabled":{"name":"metadataEndpointEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the instance metadata service endpoint is reachable","desc":"False when the metadata endpoint is switched off entirely, which removes the instance RAM role credential path from the instance.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataHopLimit":{"name":"metadataHopLimit","type":"\u0005","is_mandatory":true,"title":"Maximum number of network hops a metadata response may travel","desc":"A limit of 1 keeps metadata responses on the instance itself, so a containerized workload on a bridged network cannot reach them.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataHttpTokens":{"name":"metadataHttpTokens","type":"\u0007","is_mandatory":true,"title":"Whether a session token is required to read instance metadata","desc":"Either optional, where a plain request to the metadata service returns credentials, or required, where the caller must obtain a token first. Requiring a token is what stops a server-side request forgery from reading the instance RAM role credentials.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type of the instance","desc":"One of classic or vpc.","provider":"go.mondoo.com/mql/providers/alicloud"},"osName":{"name":"osName","type":"\u0007","is_mandatory":true,"title":"Name of the operating system","provider":"go.mondoo.com/mql/providers/alicloud"},"osNameEn":{"name":"osNameEn","type":"\u0007","is_mandatory":true,"title":"English name of the operating system","provider":"go.mondoo.com/mql/providers/alicloud"},"osType":{"name":"osType","type":"\u0007","is_mandatory":true,"title":"Operating system family","desc":"One of windows or linux.","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIpAddresses":{"name":"privateIpAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Private IP addresses assigned to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"publicIpAddresses":{"name":"publicIpAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Public IP addresses assigned directly to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u001balicloud.ram.role","title":"Instance RAM role assumed by workloads on the instance","desc":"The role whose temporary credentials the instance metadata service hands to any process that can reach it. Traverse to attachedPolicies to see what a workload on this instance is authorized to do, and therefore what an attacker reaching the metadata service would inherit. Null when no instance RAM role is attached.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the instance, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupIds":{"name":"securityGroupIds","type":"\u0019\u0007","is_mandatory":true,"title":"Security group IDs applied to the instance","desc":"Deprecated in favor of securityGroups.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups controlling the instance's traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"spotDuration":{"name":"spotDuration","type":"\u0005","is_mandatory":true,"title":"Protection period of a preemptible instance in hours","provider":"go.mondoo.com/mql/providers/alicloud"},"spotPriceLimit":{"name":"spotPriceLimit","type":"\u0006","is_mandatory":true,"title":"Maximum hourly price for a preemptible instance","provider":"go.mondoo.com/mql/providers/alicloud"},"spotStrategy":{"name":"spotStrategy","type":"\u0007","is_mandatory":true,"title":"Bidding policy for a pay-as-you-go instance","desc":"One of NoSpot, SpotWithPriceLimit, or SpotAsPriceGo.","provider":"go.mondoo.com/mql/providers/alicloud"},"startTime":{"name":"startTime","type":"\t","is_mandatory":true,"title":"Time when the instance was last started","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending, Running, Starting, Stopping, or Stopped.","provider":"go.mondoo.com/mql/providers/alicloud"},"stoppedMode":{"name":"stoppedMode","type":"\u0007","is_mandatory":true,"title":"Stopped-instance billing mode","desc":"One of KeepCharging, StopCharging, or Not-applicable.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the instance, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"userData":{"name":"userData","type":"\u0007","title":"Startup script and cloud-init data supplied to the instance","desc":"The user data as plain text, decoded from the base64 form the API returns. Anything readable here is also readable by any process on the instance that can reach the metadata service, so it is where hardcoded passwords, API keys, and private registry credentials end up. Empty when the instance was launched without user data.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the instance is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the instance is connected to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID of the instance, for example cn-hangzhou-g","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service instance","desc":"A single ECS virtual machine, keyed by the composite region and instanceId. Exposes the lifecycle status, the instance type and zone, hardware sizing (vCPUs, memory, GPUs), billing and charge configuration, the private, public, and elastic IP addresses, the VPC and vSwitch it is attached to, and the security groups controlling its traffic.","min_provider_version":"13.0.0","defaults":"instanceId instanceName status instanceType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.keypair":{"id":"alicloud.ecs.keypair","name":"alicloud.ecs.keypair","fields":{"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the key pair was created","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairFingerPrint":{"name":"keyPairFingerPrint","type":"\u0007","is_mandatory":true,"title":"Fingerprint of the public key","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairName":{"name":"keyPairName","type":"\u0007","is_mandatory":true,"title":"Key pair name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the key pair","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the key pair","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the key pair belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the key pair, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service SSH key pair","desc":"A single SSH key pair, keyed by the composite region and keyPairName. Exposes the public-key fingerprint, the creation time, and the resource group the key pair belongs to.","min_provider_version":"13.0.0","defaults":"keyPairName","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.prefixList":{"id":"alicloud.ecs.prefixList","name":"alicloud.ecs.prefixList","fields":{"addressFamily":{"name":"addressFamily","type":"\u0007","is_mandatory":true,"title":"Address family of the entries","desc":"Either IPv4 or IPv6.","provider":"go.mondoo.com/mql/providers/alicloud"},"associationCount":{"name":"associationCount","type":"\u0005","is_mandatory":true,"title":"Number of resources that reference the list","desc":"Counts the security group rules and route entries pointing at the list, so a change to its blocks reaches every one of them.","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlocks":{"name":"cidrBlocks","type":"\u0019\u0007","title":"CIDR blocks the list admits","desc":"These are the addresses a rule scoped to this list actually matches. An entry of 0.0.0.0/0 opens every rule that points at the list.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the prefix list was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Prefix list description","provider":"go.mondoo.com/mql/providers/alicloud"},"maxEntries":{"name":"maxEntries","type":"\u0005","is_mandatory":true,"title":"Maximum number of entries the list can hold","provider":"go.mondoo.com/mql/providers/alicloud"},"prefixListId":{"name":"prefixListId","type":"\u0007","is_mandatory":true,"title":"Prefix list ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"prefixListName":{"name":"prefixListName","type":"\u0007","is_mandatory":true,"title":"Prefix list name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the prefix list lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the prefix list belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the prefix list belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the prefix list","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Prefix list","desc":"A named set of CIDR blocks that security group rules reference in place of a literal address range, keyed by prefixListId. A rule scoped to a prefix list carries no source or destination CIDR of its own, so the blocks it actually admits live here and nowhere else. associationCount reports how many rules and route tables point at the list, which is how far a change to it reaches.","min_provider_version":"13.4.1","defaults":"prefixListName prefixListId addressFamily associationCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.securitygroup":{"id":"alicloud.ecs.securitygroup","name":"alicloud.ecs.securitygroup","fields":{"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the security group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Security group description","provider":"go.mondoo.com/mql/providers/alicloud"},"instances":{"name":"instances","type":"\u0019\u001balicloud.ecs.instance","title":"Instances the security group is applied to","provider":"go.mondoo.com/mql/providers/alicloud"},"permission":{"name":"permission","type":"\u001balicloud.ecs.securitygroup.permission","title":"Elastic Compute Service security group rule","desc":"A single inbound or outbound rule of a security group, keyed by the security group ID, direction, and position. Exposes the protocol and port range, the source and destination CIDR blocks, referenced security groups, prefix lists, and the accept or drop policy.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"permissions":{"name":"permissions","type":"\u0019\u001balicloud.ecs.securitygroup.permission","title":"Inbound and outbound rules of the security group","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the security group","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the security group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the security group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupId":{"name":"securityGroupId","type":"\u0007","is_mandatory":true,"title":"Security group ID, for example sg-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupName":{"name":"securityGroupName","type":"\u0007","is_mandatory":true,"title":"Security group name","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupType":{"name":"securityGroupType","type":"\u0007","is_mandatory":true,"title":"Security group type","desc":"One of normal or enterprise.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the security group, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the security group belongs to","desc":"Null on a classic-network security group, which is not in a VPC.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcId":{"name":"vpcId","type":"\u0007","is_mandatory":true,"title":"VPC ID the security group belongs to","desc":"Deprecated in favor of vpc.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"}},"title":"Elastic Compute Service security group","desc":"A single security group, keyed by the composite region and securityGroupId. Exposes the group name and type, the VPC it belongs to, its inbound and outbound rules, and the instances it is applied to.","min_provider_version":"13.0.0","defaults":"securityGroupId securityGroupName securityGroupType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.securitygroup.permission":{"id":"alicloud.ecs.securitygroup.permission","name":"alicloud.ecs.securitygroup.permission","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/mql/providers/alicloud"},"destCidrIp":{"name":"destCidrIp","type":"\u0007","is_mandatory":true,"title":"Destination IPv4 CIDR block for an outbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"destPrefixList":{"name":"destPrefixList","type":"\u001balicloud.ecs.prefixList","title":"Destination prefix list for an outbound rule","desc":"Null unless the rule is scoped to a prefix list. When it is set, the rule has no destCidrIp of its own and the list's cidrBlocks are what the rule permits traffic to reach.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"destPrefixListId":{"name":"destPrefixListId","type":"\u0007","is_mandatory":true,"title":"Destination prefix list ID for an outbound rule","desc":"Deprecated in favor of destPrefixList.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"destSecurityGroup":{"name":"destSecurityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Destination security group for an outbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Rule direction","desc":"One of ingress or egress.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipProtocol":{"name":"ipProtocol","type":"\u0007","is_mandatory":true,"title":"Transport protocol the rule matches","desc":"One of TCP, UDP, ICMP, ICMPv6, GRE, or ALL.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6DestCidrIp":{"name":"ipv6DestCidrIp","type":"\u0007","is_mandatory":true,"title":"Destination IPv6 CIDR block for an outbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6SourceCidrIp":{"name":"ipv6SourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Source IPv6 CIDR block for an inbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"nicType":{"name":"nicType","type":"\u0007","is_mandatory":true,"title":"Network interface type the rule applies to","desc":"One of internet or intranet.","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","is_mandatory":true,"title":"Access policy of the rule","desc":"One of Accept or Drop.","provider":"go.mondoo.com/mql/providers/alicloud"},"portRange":{"name":"portRange","type":"\u0007","is_mandatory":true,"title":"Destination port range matched by the rule, for example 22/22 or 1/65535","provider":"go.mondoo.com/mql/providers/alicloud"},"priority":{"name":"priority","type":"\u0007","is_mandatory":true,"title":"Priority of the rule, from 1 (highest) to 100 (lowest)","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupRuleId":{"name":"securityGroupRuleId","type":"\u0007","is_mandatory":true,"title":"Rule ID","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCidrIp":{"name":"sourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Source IPv4 CIDR block for an inbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"sourcePortRange":{"name":"sourcePortRange","type":"\u0007","is_mandatory":true,"title":"Source port range matched by the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"sourcePrefixList":{"name":"sourcePrefixList","type":"\u001balicloud.ecs.prefixList","title":"Source prefix list for an inbound rule","desc":"Null unless the rule is scoped to a prefix list. When it is set, the rule has no sourceCidrIp of its own and the list's cidrBlocks are what the rule admits.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"sourcePrefixListId":{"name":"sourcePrefixListId","type":"\u0007","is_mandatory":true,"title":"Source prefix list ID for an inbound rule","desc":"Deprecated in favor of sourcePrefixList.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"sourceSecurityGroup":{"name":"sourceSecurityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Source security group for an inbound rule","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service security group rule","desc":"A single inbound or outbound rule of a security group, keyed by the security group ID, direction, and position. Exposes the protocol and port range, the source and destination CIDR blocks, referenced security groups, prefix lists, and the accept or drop policy.","min_provider_version":"13.0.0","defaults":"direction ipProtocol portRange policy","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.es":{"id":"alicloud.es","name":"alicloud.es","fields":{"instance":{"name":"instance","type":"\u001balicloud.es.instance","title":"Elasticsearch cluster","desc":"A single Elasticsearch cluster, keyed by instanceId. Reports the engine version and node layout, whether the transport is plain HTTP, whether disks are encrypted, and, through its detail accessors, whether the cluster and its Kibana console answer on a public endpoint and which address lists gate them.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.es.instance","title":"Elasticsearch clusters in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Elasticsearch","desc":"Elasticsearch clusters in the account. A cluster holds indexed copies of whatever was shipped into it, which is often log and application data, and it can be published on a public endpoint of its own alongside a Kibana console. Reports what each cluster accepts connections on and which addresses are allowed to reach it.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.es.instance":{"id":"alicloud.es.instance","name":"alicloud.es.instance","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the cluster was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dedicatedMaster":{"name":"dedicatedMaster","type":"\u0004","is_mandatory":true,"title":"Whether the cluster runs dedicated master nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Cluster description, which is the name shown in the console","provider":"go.mondoo.com/mql/providers/alicloud"},"diskEncrypted":{"name":"diskEncrypted","type":"\u0004","is_mandatory":true,"title":"Whether the data node disks are encrypted at rest","provider":"go.mondoo.com/mql/providers/alicloud"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Private domain the cluster answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"esVersion":{"name":"esVersion","type":"\u0007","is_mandatory":true,"title":"Elasticsearch version the cluster runs","desc":"An unsupported version stops receiving security fixes, so the version is part of the cluster's exposure and not only its capability.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceCategory":{"name":"instanceCategory","type":"\u0007","title":"Cluster edition","desc":"Values include x-pack for a standard commercial cluster and advanced for the enterprise edition.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"internetExposed":{"name":"internetExposed","type":"\u0004","title":"Whether the cluster is reachable from the internet","desc":"True when either the cluster endpoint or the Kibana console answers publicly. False means both are confined to the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"kibanaDomain":{"name":"kibanaDomain","type":"\u0007","title":"Public domain the Kibana console answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"kibanaIpWhitelist":{"name":"kibanaIpWhitelist","type":"\u0019\u0007","title":"Addresses allowed to reach the Kibana console","provider":"go.mondoo.com/mql/providers/alicloud"},"kibanaPublicNetworkEnabled":{"name":"kibanaPublicNetworkEnabled","type":"\u0004","title":"Whether the Kibana console answers on a public endpoint","desc":"Kibana reads everything the cluster holds, so a public console is a data exposure in its own right even when the cluster endpoint stays private.","provider":"go.mondoo.com/mql/providers/alicloud"},"nodeAmount":{"name":"nodeAmount","type":"\u0005","is_mandatory":true,"title":"Number of data nodes in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"paymentType":{"name":"paymentType","type":"\u0007","is_mandatory":true,"title":"Billing method","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the cluster answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIpWhitelist":{"name":"privateIpWhitelist","type":"\u0019\u0007","title":"Addresses allowed to reach the cluster from inside the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Protocol the cluster accepts connections on","desc":"HTTP or HTTPS. HTTP means credentials and query results cross the network in the clear, which matters most on a cluster that also answers publicly.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicDomain":{"name":"publicDomain","type":"\u0007","title":"Public domain the cluster answers on","desc":"Empty when no public endpoint is switched on.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicIpWhitelist":{"name":"publicIpWhitelist","type":"\u0019\u0007","title":"Addresses allowed to reach the public endpoint","desc":"An entry of 0.0.0.0/0 leaves the cluster open to the whole internet, which is the default the console offers when a public endpoint is switched on.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicNetworkEnabled":{"name":"publicNetworkEnabled","type":"\u0004","title":"Whether the cluster answers on a public endpoint","desc":"True means the cluster is reachable from outside its VPC, leaving publicIpWhitelist as the control over who may connect.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicPort":{"name":"publicPort","type":"\u0005","title":"Port the public endpoint answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the cluster lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Cluster status","desc":"One of active, activating, inactive, or invalid.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the cluster was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneCount":{"name":"zoneCount","type":"\u0005","is_mandatory":true,"title":"Number of zones the cluster spans","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elasticsearch cluster","desc":"A single Elasticsearch cluster, keyed by instanceId. Reports the engine version and node layout, whether the transport is plain HTTP, whether disks are encrypted, and, through its detail accessors, whether the cluster and its Kibana console answer on a public endpoint and which address lists gate them.","min_provider_version":"13.4.1","defaults":"description instanceId esVersion status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ess":{"id":"alicloud.ess","name":"alicloud.ess","fields":{"scalingConfiguration":{"name":"scalingConfiguration","type":"\u001balicloud.ess.scalingConfiguration","title":"Auto Scaling scaling configuration","desc":"The instance template a scaling group launches from: the image and instance type, the user data written into every instance, the RAM role and security groups each instance receives, the metadata service hardening, and the system disk encryption. The scalingConfigurationId and regionId fields together select a single configuration, for example `alicloud.ess.scalingConfiguration(scalingConfigurationId: \"asc-bp1abc\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"scalingConfigurations":{"name":"scalingConfigurations","type":"\u0019\u001balicloud.ess.scalingConfiguration","title":"Scaling configurations across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingGroup":{"name":"scalingGroup","type":"\u001balicloud.ess.scalingGroup","title":"Auto Scaling scaling group","desc":"A scaling group and the sizing, placement, and health-check settings that govern it, along with the scaling configurations it can launch from and the one currently active. The scalingGroupId and regionId fields together select a single group, for example `alicloud.ess.scalingGroup(scalingGroupId: \"asg-bp1abc\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"scalingGroups":{"name":"scalingGroups","type":"\u0019\u001balicloud.ess.scalingGroup","title":"Scaling groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Auto Scaling","desc":"Scaling groups and the scaling configurations they launch instances from, across every enabled region on the account. Instances created by a scaling group are transient, so the scaling configuration is the durable record of how they are built: the user data written into them, the RAM role and security groups they receive, the image they boot, and the metadata service hardening they inherit.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ess.scalingConfiguration":{"id":"alicloud.ess.scalingConfiguration","name":"alicloud.ess.scalingConfiguration","fields":{"confidentialComputingMode":{"name":"confidentialComputingMode","type":"\u0007","is_mandatory":true,"title":"Confidential computing mode of launched instances","desc":"Either Enclave or TDX when the instance builds a confidential computing environment. Empty when confidential computing is not configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the scaling configuration was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether launched instances are protected from deletion","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Image launched instances boot from","desc":"Null when the image has been deleted or is not visible to the account, which leaves the configuration unable to launch.","provider":"go.mondoo.com/mql/providers/alicloud"},"imageOwnerAlias":{"name":"imageOwnerAlias","type":"\u0007","is_mandatory":true,"title":"Where the image comes from","desc":"One of system for an Alibaba Cloud public image, self for a private image in the account, others for an image shared from another account, or marketplace.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Instance type launched from this configuration, for example ecs.g6.large","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthIn":{"name":"internetMaxBandwidthIn","type":"\u0005","is_mandatory":true,"title":"Maximum inbound public bandwidth in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthOut":{"name":"internetMaxBandwidthOut","type":"\u0005","is_mandatory":true,"title":"Maximum outbound public bandwidth in Mbit/s","desc":"A value above zero means every instance the group launches is assigned a public IP address, making it reachable from the internet subject to its security groups. Zero means instances get no public address.","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPair":{"name":"keyPair","type":"\u001balicloud.ecs.keypair","title":"Key pair installed on every instance the configuration launches","desc":"Null when the configuration installs no key pair, in which case logon depends on a password, and also when the named key pair has since been deleted.","provider":"go.mondoo.com/mql/providers/alicloud"},"lifecycleState":{"name":"lifecycleState","type":"\u0007","is_mandatory":true,"title":"Lifecycle state of the scaling configuration","desc":"Either Active, meaning the scaling group launches instances from this configuration, or Inactive.","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataEndpointEnabled":{"name":"metadataEndpointEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the instance metadata service endpoint is reachable","desc":"False when the metadata endpoint is switched off entirely, which removes the RAM role credential path from every instance the group launches.","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataHttpTokens":{"name":"metadataHttpTokens","type":"\u0007","is_mandatory":true,"title":"Whether a session token is required to read instance metadata","desc":"Either optional, where a plain request to the metadata service returns credentials, or required, where the caller must obtain a token first. Requiring a token is what stops a server-side request forgery on a launched instance from reading the RAM role credentials.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Scaling configuration name","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordInherit":{"name":"passwordInherit","type":"\u0004","is_mandatory":true,"title":"Whether launched instances keep the password baked into the image","desc":"True when the configuration inherits the image password rather than setting one, which leaves every instance sharing whatever credential the image was built with.","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordSet":{"name":"passwordSet","type":"\u0004","is_mandatory":true,"title":"Whether a logon password is configured","desc":"True when the configuration sets a password for the instance, enabling password logon alongside or instead of key-pair logon. The password itself is never returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u001balicloud.ram.role","title":"RAM role granted to every instance the configuration launches","desc":"The role whose temporary credentials the metadata service hands to any process on a launched instance. Traverse to attachedPolicies to see what a workload on those instances is authorized to do. Null when no instance RAM role is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the scaling configuration resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingConfigurationId":{"name":"scalingConfigurationId","type":"\u0007","is_mandatory":true,"title":"Scaling configuration ID","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingGroup":{"name":"scalingGroup","type":"\u001balicloud.ess.scalingGroup","title":"Scaling group the configuration belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityEnhancementStrategy":{"name":"securityEnhancementStrategy","type":"\u0007","is_mandatory":true,"title":"Hardening applied to the operating system at launch","desc":"Either Active, which installs the Security Center agent on each instance, or Deactive.","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to every instance the configuration launches","desc":"Traverse to permissions to see the inbound rules that will apply to each new instance, which is where a group launching into an open security group shows up.","provider":"go.mondoo.com/mql/providers/alicloud"},"spotStrategy":{"name":"spotStrategy","type":"\u0007","is_mandatory":true,"title":"Purchasing option for launched instances","desc":"One of NoSpot for pay-as-you-go, SpotWithPriceLimit, or SpotAsPriceGo.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskCategory":{"name":"systemDiskCategory","type":"\u0007","is_mandatory":true,"title":"System disk category","desc":"One of cloud, cloud_efficiency, cloud_ssd, cloud_essd, cloud_auto, or ephemeral_ssd.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskEncrypted":{"name":"systemDiskEncrypted","type":"\u0004","is_mandatory":true,"title":"Whether the system disk is encrypted at rest","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskKmsKey":{"name":"systemDiskKmsKey","type":"\u001balicloud.kms.key","title":"KMS key encrypting the system disk","desc":"Null when the system disk is unencrypted, or when it is encrypted with the service-managed key rather than a customer master key.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskSize":{"name":"systemDiskSize","type":"\u0005","is_mandatory":true,"title":"System disk size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"tenancy":{"name":"tenancy","type":"\u0007","is_mandatory":true,"title":"Tenancy of the underlying host","desc":"Either default for shared hosts or host for a dedicated host.","provider":"go.mondoo.com/mql/providers/alicloud"},"userData":{"name":"userData","type":"\u0007","is_mandatory":true,"title":"Startup script and cloud-init data written into every instance","desc":"The user data as plain text, decoded from the base64 form the API returns. Every instance the group launches receives it, and any process on those instances that can reach the metadata service can read it back, so a credential embedded here is exposed on every instance the group has ever created. Empty when the configuration carries no user data.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Auto Scaling scaling configuration","desc":"The instance template a scaling group launches from: the image and instance type, the user data written into every instance, the RAM role and security groups each instance receives, the metadata service hardening, and the system disk encryption. The scalingConfigurationId and regionId fields together select a single configuration, for example `alicloud.ess.scalingConfiguration(scalingConfigurationId: \"asc-bp1abc\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.2.5","defaults":"name scalingConfigurationId instanceType lifecycleState","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ess.scalingGroup":{"id":"alicloud.ess.scalingGroup","name":"alicloud.ess.scalingGroup","fields":{"activeCapacity":{"name":"activeCapacity","type":"\u0005","is_mandatory":true,"title":"Number of instances in the group that are serving traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"activeScalingConfiguration":{"name":"activeScalingConfiguration","type":"\u001balicloud.ess.scalingConfiguration","title":"Scaling configuration the group currently launches from","desc":"Null when the group has no active configuration, which is the case for a group that launches from a launch template.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the scaling group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultCooldown":{"name":"defaultCooldown","type":"\u0005","is_mandatory":true,"title":"Seconds after a scaling activity before another may start","provider":"go.mondoo.com/mql/providers/alicloud"},"desiredCapacity":{"name":"desiredCapacity","type":"\u0005","is_mandatory":true,"title":"Expected number of instances the group tries to hold","provider":"go.mondoo.com/mql/providers/alicloud"},"groupDeletionProtection":{"name":"groupDeletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether the group is protected from deletion","provider":"go.mondoo.com/mql/providers/alicloud"},"groupType":{"name":"groupType","type":"\u0007","is_mandatory":true,"title":"Kind of instance the group manages","desc":"Either ECS for Elastic Compute Service instances or ECI for elastic container instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckType":{"name":"healthCheckType","type":"\u0007","is_mandatory":true,"title":"How the group decides an instance is unhealthy","desc":"One of ECS, where the group replaces instances the ECS service reports as unhealthy, LOAD_BALANCER, or NONE, which disables replacement entirely.","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplateId":{"name":"launchTemplateId","type":"\u0007","is_mandatory":true,"title":"ID of the launch template the group creates instances from","desc":"Empty on a group that launches from a scaling configuration instead. When set, the instance shape lives in the launch template rather than in scalingConfigurations, so those settings are not visible here.","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplateVersion":{"name":"launchTemplateVersion","type":"\u0007","is_mandatory":true,"title":"Version of the launch template the group uses","desc":"A version number, or Latest or Default. Empty when the group launches from a scaling configuration.","provider":"go.mondoo.com/mql/providers/alicloud"},"lifecycleState":{"name":"lifecycleState","type":"\u0007","is_mandatory":true,"title":"Lifecycle state of the scaling group","desc":"One of Active, Inactive, or Deleting. Only an Active group launches and releases instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxInstanceLifetime":{"name":"maxInstanceLifetime","type":"\u0005","is_mandatory":true,"title":"Maximum seconds an instance may stay in the group before replacement","desc":"Zero when instances are never replaced on age alone, which lets a long-lived instance drift from the image the group launches today.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxSize":{"name":"maxSize","type":"\u0005","is_mandatory":true,"title":"Maximum number of instances the group may create","provider":"go.mondoo.com/mql/providers/alicloud"},"minSize":{"name":"minSize","type":"\u0005","is_mandatory":true,"title":"Minimum number of instances the group maintains","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationTime":{"name":"modificationTime","type":"\t","is_mandatory":true,"title":"Time the scaling group was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"multiAZPolicy":{"name":"multiAZPolicy","type":"\u0007","is_mandatory":true,"title":"How instances are spread across zones","desc":"One of PRIORITY, BALANCE, or COST_OPTIMIZED.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Scaling group name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the scaling group resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the scaling group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the scaling group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingConfigurations":{"name":"scalingConfigurations","type":"\u0019\u001balicloud.ess.scalingConfiguration","title":"Scaling configurations defined on the group","desc":"Every configuration attached to the group, active or not. An inactive configuration still ships whatever user data and permissions it holds the moment someone makes it active.","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingGroupId":{"name":"scalingGroupId","type":"\u0007","is_mandatory":true,"title":"Scaling group ID","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingPolicy":{"name":"scalingPolicy","type":"\u0007","is_mandatory":true,"title":"Reclaim mode applied when the group removes an instance","desc":"One of recycle, which stops the instance, release, which deletes it, or forcerelease.","provider":"go.mondoo.com/mql/providers/alicloud"},"suspendedProcesses":{"name":"suspendedProcesses","type":"\u0019\u0007","is_mandatory":true,"title":"Scaling processes the group has been told to stop running","desc":"Any of ScaleIn, ScaleOut, HealthCheck, AlarmNotification, or ScheduledAction. A suspended HealthCheck stops unhealthy instances being replaced, so a group can sit degraded without any activity recorded.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemSuspended":{"name":"systemSuspended","type":"\u0004","is_mandatory":true,"title":"Whether Auto Scaling itself has suspended the group","provider":"go.mondoo.com/mql/providers/alicloud"},"totalCapacity":{"name":"totalCapacity","type":"\u0005","is_mandatory":true,"title":"Number of instances currently in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the scaling group launches instances into","desc":"Null on a classic-network group.","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the scaling group may place instances in","desc":"The subnets available to the group, which determine the zones it can spread across. Empty on a classic-network group.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Auto Scaling scaling group","desc":"A scaling group and the sizing, placement, and health-check settings that govern it, along with the scaling configurations it can launch from and the one currently active. The scalingGroupId and regionId fields together select a single group, for example `alicloud.ess.scalingGroup(scalingGroupId: \"asg-bp1abc\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.2.5","defaults":"name scalingGroupId lifecycleState totalCapacity","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.fc":{"id":"alicloud.fc","name":"alicloud.fc","fields":{"function":{"name":"function","type":"\u001balicloud.fc.function","title":"Function Compute function","desc":"A single FC 3.0 function, keyed by functionName within its region. Exposes the runtime and resource configuration, the execution RAM role, the VPC and log configuration, public network egress, environment variables, and the function's triggers. Use it to audit the function's privilege and network exposure. For example alicloud.fc.function(functionName: \"my-fn\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"functions":{"name":"functions","type":"\u0019\u001balicloud.fc.function","title":"Functions across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"trigger":{"name":"trigger","type":"\u001balicloud.fc.trigger","title":"Function Compute trigger","desc":"A single trigger on an FC function, keyed by the owning functionName and triggerName. Exposes the trigger type and event source, the public and intranet HTTP endpoints for HTTP triggers, and the RAM role the event source assumes to invoke the function. Use it to audit whether a function is invocable from the internet.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Function Compute","desc":"Function Compute (FC 3.0) functions across an Alibaba Cloud account. Exposes the serverless functions in every enabled region, along with their triggers. Use it to audit function execution roles, network placement, public egress and invocation, and whether environment variables might carry secrets.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.fc.function":{"id":"alicloud.fc.function","name":"alicloud.fc.function","fields":{"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the function","provider":"go.mondoo.com/mql/providers/alicloud"},"codeChecksum":{"name":"codeChecksum","type":"\u0007","is_mandatory":true,"title":"CRC-64 checksum of the deployed code","provider":"go.mondoo.com/mql/providers/alicloud"},"codeSize":{"name":"codeSize","type":"\u0005","is_mandatory":true,"title":"Deployed code size in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"cpu":{"name":"cpu","type":"\u0006","is_mandatory":true,"title":"vCPU cores allocated to the function","provider":"go.mondoo.com/mql/providers/alicloud"},"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the function was created","provider":"go.mondoo.com/mql/providers/alicloud"},"customContainerImage":{"name":"customContainerImage","type":"\u0007","is_mandatory":true,"title":"Container image for a custom-container function, empty for other runtimes","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the function","provider":"go.mondoo.com/mql/providers/alicloud"},"diskSize":{"name":"diskSize","type":"\u0005","is_mandatory":true,"title":"Ephemeral disk size in MB, either 512 or 10240","provider":"go.mondoo.com/mql/providers/alicloud"},"environmentVariables":{"name":"environmentVariables","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Environment variables configured on the function","desc":"Audit these for plaintext secrets; values are returned as configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"executionRole":{"name":"executionRole","type":"\u001balicloud.ram.role","title":"RAM role the function assumes when it runs","desc":"Null when the function has no execution role. The role determines the permissions the function code runs with.","provider":"go.mondoo.com/mql/providers/alicloud"},"functionId":{"name":"functionId","type":"\u0007","is_mandatory":true,"title":"System-generated function ID","provider":"go.mondoo.com/mql/providers/alicloud"},"functionName":{"name":"functionName","type":"\u0007","is_mandatory":true,"title":"Function name, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"handler":{"name":"handler","type":"\u0007","is_mandatory":true,"title":"Request handler entry point, for example index.handler","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceConcurrency":{"name":"instanceConcurrency","type":"\u0005","is_mandatory":true,"title":"Maximum number of concurrent requests handled by one instance","provider":"go.mondoo.com/mql/providers/alicloud"},"internetAccess":{"name":"internetAccess","type":"\u0004","is_mandatory":true,"title":"Whether the function has public internet egress","desc":"True when the function may reach the public internet for outbound requests.","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifiedTime":{"name":"lastModifiedTime","type":"\t","is_mandatory":true,"title":"Time the function was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"logProject":{"name":"logProject","type":"\u001balicloud.log.project","title":"Log Service project that receives function logs, null when logging is not configured","provider":"go.mondoo.com/mql/providers/alicloud"},"logStore":{"name":"logStore","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service logstore that receives function logs","provider":"go.mondoo.com/mql/providers/alicloud"},"memorySize":{"name":"memorySize","type":"\u0005","is_mandatory":true,"title":"Memory allocated to the function in MB","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the function resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the function","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the function belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"runtime":{"name":"runtime","type":"\u0007","is_mandatory":true,"title":"Function runtime","desc":"For example nodejs18, python3.10, go1, java11, php7.2, custom, custom.debian10, or custom-container.","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroup":{"name":"securityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Security group applied to the function's VPC elastic network interface","provider":"go.mondoo.com/mql/providers/alicloud"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Function state, for example Active or Pending","provider":"go.mondoo.com/mql/providers/alicloud"},"stateReason":{"name":"stateReason","type":"\u0007","is_mandatory":true,"title":"Reason for the current state, empty when healthy","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the function","provider":"go.mondoo.com/mql/providers/alicloud"},"timeout":{"name":"timeout","type":"\u0005","is_mandatory":true,"title":"Maximum execution time in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"triggers":{"name":"triggers","type":"\u0019\u001balicloud.fc.trigger","title":"Triggers configured on the function","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the function is attached to, null when the function has no VPC configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the function's elastic network interfaces attach to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Function Compute function","desc":"A single FC 3.0 function, keyed by functionName within its region. Exposes the runtime and resource configuration, the execution RAM role, the VPC and log configuration, public network egress, environment variables, and the function's triggers. Use it to audit the function's privilege and network exposure. For example alicloud.fc.function(functionName: \"my-fn\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.fc.trigger":{"id":"alicloud.fc.trigger","name":"alicloud.fc.trigger","fields":{"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the trigger was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the trigger","provider":"go.mondoo.com/mql/providers/alicloud"},"function":{"name":"function","type":"\u001balicloud.fc.function","title":"Function the trigger belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"functionName":{"name":"functionName","type":"\u0007","is_mandatory":true,"title":"Name of the function the trigger belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"httpUrlInternet":{"name":"httpUrlInternet","type":"\u0007","is_mandatory":true,"title":"Public HTTP endpoint for an http trigger","desc":"Empty for non-http triggers or when the public URL is disabled. A non-empty value means the function can be invoked over the internet.","provider":"go.mondoo.com/mql/providers/alicloud"},"httpUrlIntranet":{"name":"httpUrlIntranet","type":"\u0007","is_mandatory":true,"title":"Intranet (VPC-only) HTTP endpoint for an http trigger","provider":"go.mondoo.com/mql/providers/alicloud"},"internetInvocable":{"name":"internetInvocable","type":"\u0004","title":"Whether the function is invocable from the public internet through this trigger","desc":"True when an http trigger exposes a public URL. Combine with the triggerConfig authType to determine whether anonymous invocation is allowed.","provider":"go.mondoo.com/mql/providers/alicloud"},"invocationRole":{"name":"invocationRole","type":"\u001balicloud.ram.role","title":"RAM role the event source assumes to invoke the function, null when none","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifiedTime":{"name":"lastModifiedTime","type":"\t","is_mandatory":true,"title":"Time the trigger was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"qualifier":{"name":"qualifier","type":"\u0007","is_mandatory":true,"title":"Version or alias the trigger invokes","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the trigger resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceArn":{"name":"sourceArn","type":"\u0007","is_mandatory":true,"title":"ARN of the event source that fires the trigger","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Trigger status, for example OK or Disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"targetArn":{"name":"targetArn","type":"\u0007","is_mandatory":true,"title":"ARN of the invocation target","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerConfig":{"name":"triggerConfig","type":"\n","is_mandatory":true,"title":"Type-specific trigger configuration","desc":"Parsed from the trigger's config document; the shape varies by type, for example authType and methods for an http trigger, or events for an oss trigger.","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerId":{"name":"triggerId","type":"\u0007","is_mandatory":true,"title":"System-generated trigger ID","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerName":{"name":"triggerName","type":"\u0007","is_mandatory":true,"title":"Trigger name, used with the function name as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Trigger type","desc":"One of http, oss, timer, log, mns_topic, cdn_events, or eventbridge.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Function Compute trigger","desc":"A single trigger on an FC function, keyed by the owning functionName and triggerName. Exposes the trigger type and event source, the public and intranet HTTP endpoints for HTTP triggers, and the RAM role the event source assumes to invoke the function. Use it to audit whether a function is invocable from the internet.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.kms":{"id":"alicloud.kms","name":"alicloud.kms","fields":{"key":{"name":"key","type":"\u001balicloud.kms.key","title":"Key Management Service customer master key","desc":"A single customer master key (CMK), keyed by keyId within its region. Exposes the key lifecycle state, cryptographic spec and usage, material origin, protection level, and the automatic-rotation configuration, along with the aliases that point at the key. Use it to audit whether keys rotate, whether deletion protection is on, and whether the key material lives in an HSM. For example `alicloud.kms.key(keyId: \"0d24xxxx\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"keys":{"name":"keys","type":"\u0019\u001balicloud.kms.key","title":"Customer master keys across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"secret":{"name":"secret","type":"\u001balicloud.kms.secret","title":"Key Management Service secret","desc":"A single secret held in Secrets Manager, keyed by secretName within its region. Exposes the secret metadata, type, rotation configuration, and the customer master key that encrypts the secret value. The secret value itself is never exposed. Use it to audit which secrets rotate and which key protects each one.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"secrets":{"name":"secrets","type":"\u0019\u001balicloud.kms.secret","title":"Secrets held in Secrets Manager across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Key Management Service","desc":"Encryption keys and secrets managed for an Alibaba Cloud account. Exposes the customer master keys across all enabled regions, including their lifecycle state, cryptographic spec, rotation configuration, and protection level, and the secrets held in Secrets Manager along with the master key that protects each one. Use it to audit key rotation, deletion protection, and whether keys are backed by a hardware security module.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.kms.key":{"id":"alicloud.kms.key","name":"alicloud.kms.key","fields":{"aliases":{"name":"aliases","type":"\u0019\u0007","title":"Alias names that point at the key, for example alias/my-key","provider":"go.mondoo.com/mql/providers/alicloud"},"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the key","provider":"go.mondoo.com/mql/providers/alicloud"},"automaticRotation":{"name":"automaticRotation","type":"\u0007","is_mandatory":true,"title":"Automatic key-rotation state","desc":"One of Enabled, Disabled, or Suspended. Suspended means rotation was enabled but KMS cannot rotate the key, for example after the key was disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationDate":{"name":"creationDate","type":"\t","is_mandatory":true,"title":"Time the key was created","provider":"go.mondoo.com/mql/providers/alicloud"},"creator":{"name":"creator","type":"\u0007","is_mandatory":true,"title":"Account (UID) or service that created the key","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteDate":{"name":"deleteDate","type":"\t","is_mandatory":true,"title":"Time the key is scheduled for deletion, null when no deletion is scheduled","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0007","is_mandatory":true,"title":"Deletion-protection state","desc":"Enabled when the key cannot be scheduled for deletion until protection is turned off.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the key","provider":"go.mondoo.com/mql/providers/alicloud"},"dkmsInstanceId":{"name":"dkmsInstanceId","type":"\u0007","is_mandatory":true,"title":"Dedicated KMS instance ID that holds the key, empty for the shared default KMS","provider":"go.mondoo.com/mql/providers/alicloud"},"keyId":{"name":"keyId","type":"\u0007","is_mandatory":true,"title":"Key ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"keySpec":{"name":"keySpec","type":"\u0007","is_mandatory":true,"title":"Cryptographic specification of the key","desc":"For example Aliyun_AES_256, Aliyun_SM4, RSA_2048, EC_P256, or EC_SM2.","provider":"go.mondoo.com/mql/providers/alicloud"},"keyState":{"name":"keyState","type":"\u0007","is_mandatory":true,"title":"Key lifecycle state","desc":"One of Enabled, Disabled, PendingDeletion, or PendingImport.","provider":"go.mondoo.com/mql/providers/alicloud"},"keyUsage":{"name":"keyUsage","type":"\u0007","is_mandatory":true,"title":"Cryptographic operations the key may perform","desc":"Either ENCRYPT/DECRYPT for encryption keys or SIGN/VERIFY for signing keys.","provider":"go.mondoo.com/mql/providers/alicloud"},"lastRotationDate":{"name":"lastRotationDate","type":"\t","is_mandatory":true,"title":"Time the key material was last rotated, null when never rotated","provider":"go.mondoo.com/mql/providers/alicloud"},"materialExpireTime":{"name":"materialExpireTime","type":"\t","is_mandatory":true,"title":"Time imported key material expires, null when it does not expire","provider":"go.mondoo.com/mql/providers/alicloud"},"nextRotationDate":{"name":"nextRotationDate","type":"\t","is_mandatory":true,"title":"Time the key is next scheduled to rotate, null when rotation is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Source of the key material","desc":"Aliyun_KMS when the material was generated by KMS, or EXTERNAL when it was imported.","provider":"go.mondoo.com/mql/providers/alicloud"},"primaryKeyVersion":{"name":"primaryKeyVersion","type":"\u0007","is_mandatory":true,"title":"Identifier of the current primary key version","provider":"go.mondoo.com/mql/providers/alicloud"},"protectionLevel":{"name":"protectionLevel","type":"\u0007","is_mandatory":true,"title":"Protection level of the key material","desc":"SOFTWARE for software-protected keys, or HSM when the material is stored in a hardware security module.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the key resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"rotationInterval":{"name":"rotationInterval","type":"\u0007","is_mandatory":true,"title":"Interval between automatic rotations, for example 31536000s","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Key Management Service customer master key","desc":"A single customer master key (CMK), keyed by keyId within its region. Exposes the key lifecycle state, cryptographic spec and usage, material origin, protection level, and the automatic-rotation configuration, along with the aliases that point at the key. Use it to audit whether keys rotate, whether deletion protection is on, and whether the key material lives in an HSM. For example `alicloud.kms.key(keyId: \"0d24xxxx\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.kms.secret":{"id":"alicloud.kms.secret","name":"alicloud.kms.secret","fields":{"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the secret","provider":"go.mondoo.com/mql/providers/alicloud"},"automaticRotation":{"name":"automaticRotation","type":"\u0007","is_mandatory":true,"title":"Automatic-rotation state","desc":"One of Enabled, Disabled, or Suspended.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the secret was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the secret","provider":"go.mondoo.com/mql/providers/alicloud"},"dkmsInstanceId":{"name":"dkmsInstanceId","type":"\u0007","is_mandatory":true,"title":"Dedicated KMS instance ID that holds the secret, empty for the shared default KMS","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionKey":{"name":"encryptionKey","type":"\u001balicloud.kms.key","title":"Customer master key that encrypts the secret value","provider":"go.mondoo.com/mql/providers/alicloud"},"extendedConfig":{"name":"extendedConfig","type":"\n","is_mandatory":true,"title":"Type-specific extended configuration","desc":"Parsed from the secret's extended-config document; the shape varies by secretType, for example the linked instance and account for an Rds secret. Null for Generic secrets.","provider":"go.mondoo.com/mql/providers/alicloud"},"lastRotationDate":{"name":"lastRotationDate","type":"\t","is_mandatory":true,"title":"Time the secret was last rotated, null when never rotated","provider":"go.mondoo.com/mql/providers/alicloud"},"nextRotationDate":{"name":"nextRotationDate","type":"\t","is_mandatory":true,"title":"Time the secret is next scheduled to rotate, null when rotation is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"owingService":{"name":"owingService","type":"\u0007","is_mandatory":true,"title":"Service that owns the secret, empty for user-managed secrets","provider":"go.mondoo.com/mql/providers/alicloud"},"plannedDeleteTime":{"name":"plannedDeleteTime","type":"\t","is_mandatory":true,"title":"Time the secret is scheduled for deletion, null when no deletion is scheduled","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the secret resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"rotationInterval":{"name":"rotationInterval","type":"\u0007","is_mandatory":true,"title":"Interval between automatic rotations, for example 604800s","provider":"go.mondoo.com/mql/providers/alicloud"},"secretName":{"name":"secretName","type":"\u0007","is_mandatory":true,"title":"Secret name, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"secretType":{"name":"secretType","type":"\u0007","is_mandatory":true,"title":"Secret type","desc":"One of Generic, Rds, RAMCredentials, or ECS. Managed types (Rds, ECS, RAMCredentials) are rotated by the owning service.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the secret","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the secret was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Key Management Service secret","desc":"A single secret held in Secrets Manager, keyed by secretName within its region. Exposes the secret metadata, type, rotation configuration, and the customer master key that encrypts the secret value. The secret value itself is never exposed. Use it to audit which secrets rotate and which key protects each one.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log":{"id":"alicloud.log","name":"alicloud.log","fields":{"logstore":{"name":"logstore","type":"\u001balicloud.log.logstore","title":"Log Service logstore","desc":"A single logstore within a Log Service project, keyed by the owning project name and logstore name. A logstore ingests, stores, and indexes a stream of logs. Exposes the retention period, shard layout, telemetry type, and the server-side encryption configuration. Use it to audit log retention and whether logs are encrypted with a customer master key.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Log Service project","desc":"A single Log Service project, keyed by name within its region. A project is the top-level container that groups logstores, dashboards, and alerts. Exposes the project metadata, endpoints, and the logstores it contains. For example `alicloud.log.project(name: \"my-project\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"projects":{"name":"projects","type":"\u0019\u001balicloud.log.project","title":"Log Service projects across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Log Service","desc":"Log Service (SLS) projects and their logstores across an Alibaba Cloud account. Exposes the projects in every enabled region and, within each, the logstores that ingest and store logs, including their retention period and server-side encryption configuration. Log Service is the delivery target for ActionTrail trails and VPC flow logs, so these resources anchor the account's logging posture.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log.logstore":{"id":"alicloud.log.logstore","name":"alicloud.log.logstore","fields":{"appendMeta":{"name":"appendMeta","type":"\u0004","title":"Whether the built-in reserved fields (for example __topic__) are recorded","provider":"go.mondoo.com/mql/providers/alicloud"},"autoSplit":{"name":"autoSplit","type":"\u0004","title":"Whether the logstore automatically splits shards under load","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","title":"Time the logstore was created","provider":"go.mondoo.com/mql/providers/alicloud"},"enableTracking":{"name":"enableTracking","type":"\u0004","title":"Whether WebTracking ingestion is enabled for the logstore","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionEnabled":{"name":"encryptionEnabled","type":"\u0004","title":"Whether server-side encryption is enabled for the logstore","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionKey":{"name":"encryptionKey","type":"\u001balicloud.kms.key","title":"Customer master key used for server-side encryption","desc":"Null when encryption is disabled or uses a service-managed key rather than a specific customer master key.","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionType":{"name":"encryptionType","type":"\u0007","title":"Server-side encryption algorithm","desc":"For example default or sm4. Empty when encryption is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"hotTtl":{"name":"hotTtl","type":"\u0005","title":"Number of days logs are kept in hot storage before moving to cold storage","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifyTime":{"name":"lastModifyTime","type":"\t","title":"Time the logstore was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"maxSplitShard":{"name":"maxSplitShard","type":"\u0005","title":"Maximum number of shards the logstore may auto-split into","provider":"go.mondoo.com/mql/providers/alicloud"},"mode":{"name":"mode","type":"\u0007","title":"Logstore mode, for example standard or query","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Logstore name, used with the project name as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Project that contains the logstore","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the project that contains the logstore","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the logstore resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"shardCount":{"name":"shardCount","type":"\u0005","title":"Number of read/write shards the logstore is split into","provider":"go.mondoo.com/mql/providers/alicloud"},"telemetryType":{"name":"telemetryType","type":"\u0007","title":"Telemetry type stored, for example None for logs or Metrics","provider":"go.mondoo.com/mql/providers/alicloud"},"ttl":{"name":"ttl","type":"\u0005","title":"Number of days ingested logs are retained; 3650 means permanent retention","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Log Service logstore","desc":"A single logstore within a Log Service project, keyed by the owning project name and logstore name. A logstore ingests, stores, and indexes a stream of logs. Exposes the retention period, shard layout, telemetry type, and the server-side encryption configuration. Use it to audit log retention and whether logs are encrypted with a customer master key.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log.project":{"id":"alicloud.log.project","name":"alicloud.log.project","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the project was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dataRedundancyType":{"name":"dataRedundancyType","type":"\u0007","is_mandatory":true,"title":"Data-redundancy type of the project storage, for example LRS or ZRS","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the project","provider":"go.mondoo.com/mql/providers/alicloud"},"internalEndpoint":{"name":"internalEndpoint","type":"\u0007","is_mandatory":true,"title":"Internal endpoint for access from within Alibaba Cloud","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpoint":{"name":"internetEndpoint","type":"\u0007","is_mandatory":true,"title":"Public endpoint for access over the Internet","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","title":"Whether the resource policy grants access to any principal","desc":"True when a granting statement names a wildcard principal, which opens the project's log data to callers outside the account. False when no policy is attached or every grant is scoped to named principals.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifyTime":{"name":"lastModifyTime","type":"\t","is_mandatory":true,"title":"Time the project was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"logstores":{"name":"logstores","type":"\u0019\u001balicloud.log.logstore","title":"Logstores contained in the project","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Project name, globally unique and used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"owner":{"name":"owner","type":"\u0007","is_mandatory":true,"title":"Account (UID) that owns the project","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","title":"Resource policy attached to the project","desc":"The JSON policy document that grants principals outside the owning account access to the project and everything in it. Empty when no policy is attached, which leaves access governed by RAM alone. Audit logs delivered into a project are only as protected as this policy allows.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"recycleBinEnabled":{"name":"recycleBinEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the recycle bin is enabled for the project","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the project resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the project","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the project belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Project status, for example Normal","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Log Service project","desc":"A single Log Service project, keyed by name within its region. A project is the top-level container that groups logstores, dashboards, and alerts. Exposes the project metadata, endpoints, and the logstores it contains. For example `alicloud.log.project(name: \"my-project\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.mongodb":{"id":"alicloud.mongodb","name":"alicloud.mongodb","fields":{"instance":{"name":"instance","type":"\u001balicloud.mongodb.instance","title":"ApsaraDB for MongoDB instance","desc":"A single ApsaraDB for MongoDB instance, keyed by dbInstanceId, for example dds-bp199659b178cef4. Exposes the deployment architecture, engine version, storage and network placement, maintenance window, and the security posture including TLS, transparent data encryption, the IP whitelist, the bound ECS security groups, and audit log status.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.mongodb.instance","title":"MongoDB instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for MongoDB","desc":"Managed MongoDB service in an Alibaba Cloud account. Exposes the MongoDB instances across every enabled region through instances, spanning replica set, sharded cluster, and serverless deployments together with their security posture.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.mongodb.instance":{"id":"alicloud.mongodb.instance","name":"alicloud.mongodb.instance","fields":{"auditPolicyEnabled":{"name":"auditPolicyEnabled","type":"\u0004","title":"Whether the audit log feature is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"backupRetentionPolicy":{"name":"backupRetentionPolicy","type":"\u0005","is_mandatory":true,"title":"Backup retention policy applied when the instance is released","desc":"One of 0 (all backup sets deleted immediately on release), 1 (one backup set retained long-term on release), or 2 (all backup sets retained long-term on release).","provider":"go.mondoo.com/mql/providers/alicloud"},"capacityUnit":{"name":"capacityUnit","type":"\u0007","is_mandatory":true,"title":"I/O throughput consumed by a serverless instance","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"currentKernelVersion":{"name":"currentKernelVersion","type":"\u0007","title":"Current minor kernel version of the database, for example 5.0.5-20220721143518_0","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceClass":{"name":"dbInstanceClass","type":"\u0007","is_mandatory":true,"title":"Instance type (specification), for example dds.mongo.mid","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceDescription":{"name":"dbInstanceDescription","type":"\u0007","is_mandatory":true,"title":"Instance name set by the user","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceId":{"name":"dbInstanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example dds-bp199659b178cef4","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStatus":{"name":"dbInstanceStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"Common values include Creating, Running, Deleting, Rebooting, DBInstanceClassChanging, and TransingToOthers. See the ApsaraDB for MongoDB instance state reference for the full set.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStorage":{"name":"dbInstanceStorage","type":"\u0005","is_mandatory":true,"title":"Storage capacity in GB","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceType":{"name":"dbInstanceType","type":"\u0007","is_mandatory":true,"title":"Deployment architecture","desc":"One of replicate (replica set or standalone), sharding (sharded cluster), or serverless.","provider":"go.mondoo.com/mql/providers/alicloud"},"destroyTime":{"name":"destroyTime","type":"\t","is_mandatory":true,"title":"Time when the released instance data is destroyed","provider":"go.mondoo.com/mql/providers/alicloud"},"encrypted":{"name":"encrypted","type":"\u0004","title":"Whether disk encryption is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionKey":{"name":"encryptionKey","type":"\u0007","title":"KMS key ID used for disk encryption, empty when disk encryption is disabled","desc":"Deprecated in favor of kmsKey.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"engine":{"name":"engine","type":"\u0007","is_mandatory":true,"title":"Database engine, for example MongoDB","provider":"go.mondoo.com/mql/providers/alicloud"},"engineVersion":{"name":"engineVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version","desc":"One of 7.0, 6.0, 5.0, 4.4, 4.2, 4.0, or 3.4.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Time when a subscription instance expires","provider":"go.mondoo.com/mql/providers/alicloud"},"hiddenZoneId":{"name":"hiddenZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the hidden (third) zone in a multi-zone deployment","provider":"go.mondoo.com/mql/providers/alicloud"},"kindCode":{"name":"kindCode","type":"\u0007","is_mandatory":true,"title":"Hardware kind code","desc":"One of 0 (physical machine), 1 (ECS instance), 2 (Docker cluster), or 18 (Kubernetes cluster).","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"KMS key used for disk encryption, null when disk encryption is disabled","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"lastDowngradeTime":{"name":"lastDowngradeTime","type":"\u0007","is_mandatory":true,"title":"Date of the last downgrade operation, for example 2021-05-08","provider":"go.mondoo.com/mql/providers/alicloud"},"lockMode":{"name":"lockMode","type":"\u0007","is_mandatory":true,"title":"Lock status","desc":"One of Unlock, ManualLock, LockByExpiration, LockByRestoration, LockByDiskQuota, or Released.","provider":"go.mondoo.com/mql/providers/alicloud"},"maintainEndTime":{"name":"maintainEndTime","type":"\u0007","title":"End of the maintenance window in UTC, for example 03:00Z","provider":"go.mondoo.com/mql/providers/alicloud"},"maintainStartTime":{"name":"maintainStartTime","type":"\u0007","title":"Start of the maintenance window in UTC, for example 18:00Z","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"One of Classic (classic network) or VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"protocolType":{"name":"protocolType","type":"\u0007","title":"Access protocol type of a sharded cluster instance","desc":"One of mongodb or dynamodb. Returned only for sharded cluster instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"readonlyReplicas":{"name":"readonlyReplicas","type":"\u0007","title":"Number of read-only nodes in the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the instance, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"releaseProtection":{"name":"releaseProtection","type":"\u0004","title":"Whether release protection is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"releaseTime":{"name":"releaseTime","type":"\t","is_mandatory":true,"title":"Time when the instance was released","provider":"go.mondoo.com/mql/providers/alicloud"},"replicationFactor":{"name":"replicationFactor","type":"\u0007","is_mandatory":true,"title":"Number of nodes in a replica set instance","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"secondaryZoneId":{"name":"secondaryZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the secondary zone in a multi-zone deployment","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupIds":{"name":"securityGroupIds","type":"\u0019\u0007","title":"IDs of the ECS security groups bound to the instance","desc":"Deprecated in favor of securityGroups.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"ECS security groups bound to the instance","desc":"The groups whose rules govern which sources may reach the instance. Traverse to permissions to see the allowed source ranges and ports alongside securityIPList, which controls the instance whitelist separately.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"securityIPList":{"name":"securityIPList","type":"\u0019\u0007","title":"IP addresses and CIDR blocks in the instance whitelist","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether TLS/SSL is enabled for client connections","provider":"go.mondoo.com/mql/providers/alicloud"},"sslExpireTime":{"name":"sslExpireTime","type":"\t","title":"Time when the current SSL certificate expires","provider":"go.mondoo.com/mql/providers/alicloud"},"storageEngine":{"name":"storageEngine","type":"\u0007","title":"Storage engine, for example WiredTiger or RocksDB","provider":"go.mondoo.com/mql/providers/alicloud"},"storageType":{"name":"storageType","type":"\u0007","is_mandatory":true,"title":"Disk storage type","desc":"One of cloud_essd, cloud_essd1, cloud_essd2, cloud_essd3, local_ssd, or cloud_essd_dbfs_s.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the instance, keyed by tag key","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether transparent data encryption (TDE) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC hosting the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcAuthMode":{"name":"vpcAuthMode","type":"\u0007","is_mandatory":true,"title":"Password-free access over VPC","desc":"One of Open (password-free access within the VPC is enabled), Close (a password is required), or NotSupport.","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch hosting the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Primary zone ID of the instance, for example cn-hangzhou-g","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for MongoDB instance","desc":"A single ApsaraDB for MongoDB instance, keyed by dbInstanceId, for example dds-bp199659b178cef4. Exposes the deployment architecture, engine version, storage and network placement, maintenance window, and the security posture including TLS, transparent data encryption, the IP whitelist, the bound ECS security groups, and audit log status.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas":{"id":"alicloud.nas","name":"alicloud.nas","fields":{"accessGroup":{"name":"accessGroup","type":"\u001balicloud.nas.accessGroup","title":"NAS access group","desc":"A single NAS access group, keyed by accessGroupName within its region. An access group is a named set of access rules that govern which client IP ranges may mount the file systems bound to it. Exposes the group metadata and its access rules. Use it to audit the client ranges permitted to mount.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"accessGroups":{"name":"accessGroups","type":"\u0019\u001balicloud.nas.accessGroup","title":"NAS access groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"accessRule":{"name":"accessRule","type":"\u001balicloud.nas.accessRule","title":"NAS access rule","desc":"A single access rule within a NAS access group, keyed by accessRuleId. A rule permits a client IP range to mount with a given read/write and user-squash policy. Exposes the allowed CIDR, access mode, and squash setting. Use it to find rules that open a file system to broad client ranges or disable root squashing.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"fileSystem":{"name":"fileSystem","type":"\u001balicloud.nas.fileSystem","title":"NAS file system","desc":"A single NAS file system, keyed by fileSystemId within its region. Exposes the storage and protocol type, the encryption state and key, capacity and used size, and the mount targets that expose it to clients. Use it to audit encryption at rest and the network exposure of the mount targets. For example alicloud.nas.fileSystem(fileSystemId: \"1a2b3c\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"fileSystems":{"name":"fileSystems","type":"\u0019\u001balicloud.nas.fileSystem","title":"NAS file systems across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"mountTarget":{"name":"mountTarget","type":"\u001balicloud.nas.mountTarget","title":"NAS mount target","desc":"A single mount target of a NAS file system, keyed by mountTargetDomain. A mount target is the network endpoint clients mount, bound to a VPC and access group. Exposes the network placement and the access group that controls which clients may mount it. Use it to audit whether a file system is reachable from a classic (non-VPC) network.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud NAS file storage","desc":"Apsara File Storage NAS file systems and access controls across an Alibaba Cloud account. Exposes the file systems in every enabled region, their mount targets, and the access groups and rules that govern which clients may mount them. Use it to audit whether file systems are encrypted and whether their exports are open to overly broad client ranges.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.accessGroup":{"id":"alicloud.nas.accessGroup","name":"alicloud.nas.accessGroup","fields":{"accessGroupName":{"name":"accessGroupName","type":"\u0007","is_mandatory":true,"title":"Access group name, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"accessGroupType":{"name":"accessGroupType","type":"\u0007","is_mandatory":true,"title":"Access group network type, either Vpc or Classic","provider":"go.mondoo.com/mql/providers/alicloud"},"accessRules":{"name":"accessRules","type":"\u0019\u001balicloud.nas.accessRule","title":"Access rules that govern which clients may mount","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the access group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the access group","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemType":{"name":"fileSystemType","type":"\u0007","is_mandatory":true,"title":"File system type the access group applies to","provider":"go.mondoo.com/mql/providers/alicloud"},"mountTargetCount":{"name":"mountTargetCount","type":"\u0005","is_mandatory":true,"title":"Number of mount targets bound to the group","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the access group resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"ruleCount":{"name":"ruleCount","type":"\u0005","is_mandatory":true,"title":"Number of access rules in the group","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS access group","desc":"A single NAS access group, keyed by accessGroupName within its region. An access group is a named set of access rules that govern which client IP ranges may mount the file systems bound to it. Exposes the group metadata and its access rules. Use it to audit the client ranges permitted to mount.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.accessRule":{"id":"alicloud.nas.accessRule","name":"alicloud.nas.accessRule","fields":{"accessGroupName":{"name":"accessGroupName","type":"\u0007","is_mandatory":true,"title":"Name of the access group the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"accessRuleId":{"name":"accessRuleId","type":"\u0007","is_mandatory":true,"title":"Access rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6SourceCidrIp":{"name":"ipv6SourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Allowed IPv6 client CIDR, empty when no IPv6 rule is set","desc":"The IPv6 client range permitted to mount. ::/0 permits every IPv6 client.","provider":"go.mondoo.com/mql/providers/alicloud"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Rule priority, 1 (highest) to 100 (lowest)","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the access rule resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"rwAccess":{"name":"rwAccess","type":"\u0007","is_mandatory":true,"title":"Read/write access granted, either RDWR (read-write) or RDONLY (read-only)","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCidrIp":{"name":"sourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Allowed IPv4 client CIDR","desc":"The client address range permitted to mount. 0.0.0.0/0 permits every IPv4 client.","provider":"go.mondoo.com/mql/providers/alicloud"},"userAccess":{"name":"userAccess","type":"\u0007","is_mandatory":true,"title":"Root-squash policy","desc":"One of no_squash (root is not squashed), root_squash (root maps to an anonymous user), or all_squash (every user maps to anonymous). no_squash gives mounting clients full root access to the file system.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS access rule","desc":"A single access rule within a NAS access group, keyed by accessRuleId. A rule permits a client IP range to mount with a given read/write and user-squash policy. Exposes the allowed CIDR, access mode, and squash setting. Use it to find rules that open a file system to broad client ranges or disable root squashing.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.fileSystem":{"id":"alicloud.nas.fileSystem","name":"alicloud.nas.fileSystem","fields":{"capacity":{"name":"capacity","type":"\u0005","is_mandatory":true,"title":"Provisioned capacity in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method, either PayAsYouGo or Subscription","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the file system was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the file system","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptType":{"name":"encryptType","type":"\u0005","is_mandatory":true,"title":"Server-side encryption type","desc":"One of 0 (no encryption), 1 (NAS-managed service key), or 2 (a customer master key from KMS).","provider":"go.mondoo.com/mql/providers/alicloud"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the file system is encrypted at rest","desc":"True when the encryption type is 1 or 2. When false, data is stored unencrypted.","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemId":{"name":"fileSystemId","type":"\u0007","is_mandatory":true,"title":"File system ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemType":{"name":"fileSystemType","type":"\u0007","is_mandatory":true,"title":"File system type, one of standard, extreme, cpfs, or cpfsse","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"Customer master key used for encryption","desc":"Null unless the encryption type is 2 (a specific KMS key). The NAS-managed service key (type 1) is not a queryable KMS key.","provider":"go.mondoo.com/mql/providers/alicloud"},"meteredSize":{"name":"meteredSize","type":"\u0005","is_mandatory":true,"title":"Used (metered) size in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"mountTargets":{"name":"mountTargets","type":"\u0019\u001balicloud.nas.mountTarget","title":"Mount targets that expose the file system to clients","provider":"go.mondoo.com/mql/providers/alicloud"},"protocolType":{"name":"protocolType","type":"\u0007","is_mandatory":true,"title":"Access protocol, one of NFS, SMB, or cpfs","provider":"go.mondoo.com/mql/providers/alicloud"},"redundancyType":{"name":"redundancyType","type":"\u0007","is_mandatory":true,"title":"Storage redundancy type, for example LRS","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the file system resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the file system","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the file system belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"File system status, for example Running, Pending, or Stopped","provider":"go.mondoo.com/mql/providers/alicloud"},"storageType":{"name":"storageType","type":"\u0007","is_mandatory":true,"title":"Storage class, for example Performance, Capacity, standard, or advance","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the file system","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the file system resides in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS file system","desc":"A single NAS file system, keyed by fileSystemId within its region. Exposes the storage and protocol type, the encryption state and key, capacity and used size, and the mount targets that expose it to clients. Use it to audit encryption at rest and the network exposure of the mount targets. For example alicloud.nas.fileSystem(fileSystemId: \"1a2b3c\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.mountTarget":{"id":"alicloud.nas.mountTarget","name":"alicloud.nas.mountTarget","fields":{"accessGroup":{"name":"accessGroup","type":"\u001balicloud.nas.accessGroup","title":"Access group that controls which clients may mount the target","provider":"go.mondoo.com/mql/providers/alicloud"},"accessGroupName":{"name":"accessGroupName","type":"\u0007","is_mandatory":true,"title":"Name of the access group that controls which clients may mount the target","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystem":{"name":"fileSystem","type":"\u001balicloud.nas.fileSystem","title":"File system the mount target belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemId":{"name":"fileSystemId","type":"\u0007","is_mandatory":true,"title":"ID of the file system the mount target belongs to","desc":"Deprecated in favor of fileSystem.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"mountTargetDomain":{"name":"mountTargetDomain","type":"\u0007","is_mandatory":true,"title":"Mount target domain (the mount address), used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"Either Vpc (isolated to a VPC) or Classic (the legacy shared network).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the mount target resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Mount target status, for example Active or Inactive","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the mount target is attached to, null for a classic-network mount target","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the mount target attaches to, null for a classic-network mount target","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS mount target","desc":"A single mount target of a NAS file system, keyed by mountTargetDomain. A mount target is the network endpoint clients mount, bound to a VPC and access group. Exposes the network placement and the access group that controls which clients may mount it. Use it to audit whether a file system is reachable from a classic (non-VPC) network.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb":{"id":"alicloud.nlb","name":"alicloud.nlb","fields":{"listener":{"name":"listener","type":"\u001balicloud.nlb.listener","title":"Network Load Balancer listener","desc":"A single listener on an NLB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy and certificates for TCPSSL listeners, and the server group it forwards to. Use it to audit whether a TCPSSL listener enforces a strong TLS policy.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.nlb.loadBalancer","title":"Network Load Balancer instance","desc":"A single NLB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC, vSwitches, and security groups it runs in, and its listeners. Unlike an ALB, an NLB can enforce security groups directly. For example alicloud.nlb.loadBalancer(loadBalancerId: \"nlb-xxx\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001balicloud.nlb.loadBalancer","title":"Network load balancers across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroup":{"name":"serverGroup","type":"\u001balicloud.nlb.serverGroup","title":"Network Load Balancer server group","desc":"A single NLB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward traffic to. Exposes the backend protocol, scheduling algorithm, client-IP preservation, health-check configuration, and the VPC the group belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverGroups":{"name":"serverGroups","type":"\u0019\u001balicloud.nlb.serverGroup","title":"NLB server groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Network Load Balancer","desc":"NLB (Layer-4) load balancers across an Alibaba Cloud account. Exposes the network load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether security groups are applied, and whether TCPSSL listeners use a strong TLS policy.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.listener":{"id":"alicloud.nlb.listener","name":"alicloud.nlb.listener","fields":{"alpnEnabled":{"name":"alpnEnabled","type":"\u0004","is_mandatory":true,"title":"Whether ALPN is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alpnPolicy":{"name":"alpnPolicy","type":"\u0007","is_mandatory":true,"title":"ALPN policy applied when ALPN is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"caCertificateIds":{"name":"caCertificateIds","type":"\u0019\u0007","is_mandatory":true,"title":"CA certificate IDs used for mutual TLS on a TCPSSL listener","provider":"go.mondoo.com/mql/providers/alicloud"},"caEnabled":{"name":"caEnabled","type":"\u0004","is_mandatory":true,"title":"Whether mutual TLS (client certificate authentication) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"certificateIds":{"name":"certificateIds","type":"\u0019\u0007","is_mandatory":true,"title":"Server certificate IDs presented by a TCPSSL listener","provider":"go.mondoo.com/mql/providers/alicloud"},"cps":{"name":"cps","type":"\u0005","is_mandatory":true,"title":"Connections-per-second limit for the listener, 0 when unlimited","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"idleTimeout":{"name":"idleTimeout","type":"\u0005","is_mandatory":true,"title":"Idle connection timeout in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"listenerId":{"name":"listenerId","type":"\u0007","is_mandatory":true,"title":"Listener ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.nlb.loadBalancer","title":"Load balancer the listener belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the load balancer the listener belongs to","desc":"Deprecated in favor of loadBalancer.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the listener serves on","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Listener protocol, one of TCP, UDP, or TCPSSL","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyProtocolEnabled":{"name":"proxyProtocolEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the Proxy Protocol is enabled to pass client information to backends","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the listener resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyId":{"name":"securityPolicyId","type":"\u0007","is_mandatory":true,"title":"TLS security policy applied to the listener, meaningful for TCPSSL listeners","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroup":{"name":"serverGroup","type":"\u001balicloud.nlb.serverGroup","title":"Server group the listener forwards traffic to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Listener status, for example Running, Configuring, or Stopped","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the listener","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network Load Balancer listener","desc":"A single listener on an NLB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy and certificates for TCPSSL listeners, and the server group it forwards to. Use it to audit whether a TCPSSL listener enforces a strong TLS policy.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.loadBalancer":{"id":"alicloud.nlb.loadBalancer","name":"alicloud.nlb.loadBalancer","fields":{"addressIpVersion":{"name":"addressIpVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the address, either Ipv4 or DualStack","provider":"go.mondoo.com/mql/providers/alicloud"},"addressType":{"name":"addressType","type":"\u0007","is_mandatory":true,"title":"Address type","desc":"Either Internet (internet-facing) or Intranet (internal only).","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageId":{"name":"bandwidthPackageId","type":"\u0007","is_mandatory":true,"title":"ID of the bandwidth package bound to the load balancer, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (billing) status, either Normal or Abnormal","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the load balancer was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossZoneEnabled":{"name":"crossZoneEnabled","type":"\u0004","is_mandatory":true,"title":"Whether cross-zone load balancing is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtectionEnabled":{"name":"deletionProtectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"dnsName":{"name":"dnsName","type":"\u0007","is_mandatory":true,"title":"DNS name assigned to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"internetFacing":{"name":"internetFacing","type":"\u0004","title":"Whether the load balancer serves traffic from the public internet","desc":"True when the address type is Internet. An internet-facing load balancer is reachable from outside the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6AddressType":{"name":"ipv6AddressType","type":"\u0007","is_mandatory":true,"title":"IPv6 address type, either Internet or Intranet","provider":"go.mondoo.com/mql/providers/alicloud"},"listeners":{"name":"listeners","type":"\u0019\u001balicloud.nlb.listener","title":"Listeners configured on the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"Load balancer ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionStatus":{"name":"modificationProtectionStatus","type":"\u0007","is_mandatory":true,"title":"Modification-protection status, either NonProtection or ConsoleProtection","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Load balancer name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the load balancer resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the load balancer","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the load balancer belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to the load balancer","desc":"NLB enforces these security groups on traffic to the load balancer. An empty result means no security-group filtering is applied at the load balancer.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Load balancer status","desc":"For example Active, Inactive, Provisioning, or Configuring.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Load balancer type, always Network for NLB","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the load balancer runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the load balancer attaches to across its zones","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network Load Balancer instance","desc":"A single NLB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC, vSwitches, and security groups it runs in, and its listeners. Unlike an ALB, an NLB can enforce security groups directly. For example alicloud.nlb.loadBalancer(loadBalancerId: \"nlb-xxx\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.serverGroup":{"id":"alicloud.nlb.serverGroup","name":"alicloud.nlb.serverGroup","fields":{"addressIpVersion":{"name":"addressIpVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the backends, either Ipv4 or DualStack","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionDrainEnabled":{"name":"connectionDrainEnabled","type":"\u0004","is_mandatory":true,"title":"Whether connection draining is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckConnectPort":{"name":"healthCheckConnectPort","type":"\u0005","is_mandatory":true,"title":"Health-check connection port","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckEnabled":{"name":"healthCheckEnabled","type":"\u0004","is_mandatory":true,"title":"Whether health checks are enabled for the group","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckType":{"name":"healthCheckType","type":"\u0007","is_mandatory":true,"title":"Health-check protocol, one of TCP, HTTP, or UDP","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Server group name","provider":"go.mondoo.com/mql/providers/alicloud"},"preserveClientIpEnabled":{"name":"preserveClientIpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether client source IP preservation is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Backend protocol, one of TCP, UDP, or TCPSSL","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the server group resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the server group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduler":{"name":"scheduler","type":"\u0007","is_mandatory":true,"title":"Scheduling algorithm, for example Wrr, rr, sch, tch, or qch","provider":"go.mondoo.com/mql/providers/alicloud"},"server":{"name":"server","type":"\u001balicloud.nlb.serverGroup.server","title":"NLB backend server","desc":"One server an NLB server group forwards traffic to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverCount":{"name":"serverCount","type":"\u0005","is_mandatory":true,"title":"Number of backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroupId":{"name":"serverGroupId","type":"\u0007","is_mandatory":true,"title":"Server group ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"servers":{"name":"servers","type":"\u0019\u001balicloud.nlb.serverGroup.server","title":"Servers in the group","desc":"What the load balancer forwards to. An internet-facing NLB makes every one of these reachable from the public internet on the listener's port.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Server group status","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the server group","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Server group type, either Instance or Ip","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network Load Balancer server group","desc":"A single NLB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward traffic to. Exposes the backend protocol, scheduling algorithm, client-IP preservation, health-check configuration, and the VPC the group belongs to.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.serverGroup.server":{"id":"alicloud.nlb.serverGroup.server","name":"alicloud.nlb.serverGroup.server","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Backend server description","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the backend","desc":"Null unless serverType is Ecs, or when the instance can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"ID of the backend server","desc":"An ECS instance ID, an elastic network interface ID, or an IP address, depending on serverType.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverIp":{"name":"serverIp","type":"\u0007","is_mandatory":true,"title":"IP address the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverType":{"name":"serverType","type":"\u0007","is_mandatory":true,"title":"Kind of backend","desc":"One of Ecs, Eni, or Ip.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Backend server status","provider":"go.mondoo.com/mql/providers/alicloud"},"weight":{"name":"weight","type":"\u0005","is_mandatory":true,"title":"Share of traffic the server receives","desc":"A weight of 0 takes the server out of rotation without detaching it.","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone the backend server sits in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NLB backend server","desc":"One server an NLB server group forwards traffic to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","min_provider_version":"13.4.1","defaults":"serverType serverId serverIp port weight","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss":{"id":"alicloud.oss","name":"alicloud.oss","fields":{"bucket":{"name":"bucket","type":"\u001balicloud.oss.bucket","title":"Object Storage Service bucket","desc":"A single OSS bucket, keyed by name (bucket names are globally unique). The summary fields (region, storageClass, creationDate, endpoints, resourceGroupId) come from the account bucket listing. The remaining accessors call the per-bucket configuration APIs to expose the access control policy, default server-side encryption, versioning state, access logging target, bucket policy document, tags, and the block-public-access posture used to audit exposure.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"buckets":{"name":"buckets","type":"\u0019\u001balicloud.oss.bucket","title":"Buckets owned by the account across all regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Object Storage Service","desc":"Entry point for the Object Storage Service (OSS) in an Alibaba Cloud account. Exposes every bucket the credential can list across all regions through buckets, from which per-bucket access control, encryption, versioning, logging, tagging, and public-access posture are reachable.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss.bucket":{"id":"alicloud.oss.bucket","name":"alicloud.oss.bucket","fields":{"acl":{"name":"acl","type":"\u0007","title":"Access control list grant","desc":"The canned ACL applied to the bucket. One of private, public-read, or public-read-write. public-read and public-read-write expose bucket contents to anonymous callers.","provider":"go.mondoo.com/mql/providers/alicloud"},"allowEmptyReferer":{"name":"allowEmptyReferer","type":"\u0004","title":"Whether requests carrying no Referer header are allowed","desc":"True by default. Combined with an otherwise restrictive referer list, this being true leaves the restriction trivially bypassed, since the client chooses whether to send the header.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"blockPublicAccess":{"name":"blockPublicAccess","type":"\u0004","title":"Whether block public access is enabled for the bucket","provider":"go.mondoo.com/mql/providers/alicloud"},"bucketInfo":{"name":"bucketInfo","type":"\n","title":"Full bucket information","desc":"The complete bucket detail record, including access monitoring, data redundancy type, cross-region replication, transfer acceleration, the server-side encryption rule, the log bucket policy, owner, comment, and the block-public-access flag.","provider":"go.mondoo.com/mql/providers/alicloud"},"corsRule":{"name":"corsRule","type":"\u001balicloud.oss.bucket.corsRule","title":"OSS bucket cross-origin resource sharing rule","desc":"One CORS rule, deciding which origins a browser may read the bucket from and with which methods and headers. An allowed origin of `*` lets a page on any site read whatever the requesting browser is allowed to read.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"corsRules":{"name":"corsRules","type":"\u0019\u001balicloud.oss.bucket.corsRule","title":"Cross-origin resource sharing rules","desc":"Which other origins a browser may read the bucket from. Empty when CORS is not configured, which refuses every cross-origin browser request.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"creationDate":{"name":"creationDate","type":"\t","is_mandatory":true,"title":"Time the bucket was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossRegionReplication":{"name":"crossRegionReplication","type":"\u0007","title":"Cross-region replication state","desc":"Whether cross-region replication is enabled for the bucket. One of Enabled or Disabled. Empty when the setting is not returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"dataRedundancyType":{"name":"dataRedundancyType","type":"\u0007","title":"Data redundancy type","desc":"The redundancy model for stored data. One of LRS (locally redundant) or ZRS (zone redundant). Empty when the setting is not returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"encryption":{"name":"encryption","type":"\n","title":"Default server-side encryption rule","desc":"The default encryption applied to new objects, with the SSEAlgorithm (KMS, AES256, or SM4), the KMSMasterKeyID when a specific key is used, and the KMSDataEncryption algorithm. Null when no default encryption rule is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"extranetEndpoint":{"name":"extranetEndpoint","type":"\u0007","is_mandatory":true,"title":"Public endpoint for access over the Internet","provider":"go.mondoo.com/mql/providers/alicloud"},"intranetEndpoint":{"name":"intranetEndpoint","type":"\u0007","is_mandatory":true,"title":"Internal endpoint for access from ECS instances in the same region","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","title":"Whether the bucket is readable from the internet without credentials","desc":"True when the bucket reaches anonymous callers, either through a public-read or public-read-write canned acl or through a bucket policy that allows a `*` principal. False whenever blockPublicAccess is on, which overrides both. Use it to find buckets exposed to the internet regardless of which of the two mechanisms opened them.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"KMS key used for default server-side encryption","desc":"The customer master key named by the bucket's default encryption rule. Null when the bucket has no default encryption or uses the AES256/SM4 built-in keys rather than a specific KMS key.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"location":{"name":"location","type":"\u0007","is_mandatory":true,"title":"Data center that stores the bucket, for example oss-cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"logging":{"name":"logging","type":"\n","title":"Access logging configuration","desc":"The access-logging target when logging is enabled, with TargetBucket, TargetPrefix, and LoggingRole. Null when access logging is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Bucket name, globally unique across Alibaba Cloud","provider":"go.mondoo.com/mql/providers/alicloud"},"objectLockRetentionDays":{"name":"objectLockRetentionDays","type":"\u0005","title":"Days objects are retained under the retention policy","desc":"Zero when no retention policy is configured.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"objectLockState":{"name":"objectLockState","type":"\u0007","title":"State of the retention policy applied to the bucket","desc":"InProgress for a policy that can still be withdrawn, Locked for one that cannot. Empty when no retention policy is configured, meaning objects can be deleted or overwritten at any time. A locked policy is what makes stored objects survive an attacker holding valid credentials.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","title":"Bucket policy document","desc":"The raw JSON bucket policy that grants cross-account or anonymous permissions. Empty when no bucket policy is attached.","provider":"go.mondoo.com/mql/providers/alicloud"},"policyAllowsPublicAccess":{"name":"policyAllowsPublicAccess","type":"\u0004","title":"Whether the bucket policy allows public access","desc":"Object Storage Service's own verdict on the attached policy, independent of the ACL. False when no policy is attached.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"publicAccessBlock":{"name":"publicAccessBlock","type":"\n","title":"Block public access configuration","desc":"The block-public-access setting, with BlockPublicAccess indicating whether public access is blocked. Null when never configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"refererAllowList":{"name":"refererAllowList","type":"\u0019\u0007","title":"Referer values allowed to reach the bucket","desc":"Empty when no referer restriction is configured.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"refererDenyList":{"name":"refererDenyList","type":"\u0019\u0007","title":"Referer values refused by the bucket","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region ID the bucket resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"replicationRule":{"name":"replicationRule","type":"\u001balicloud.oss.bucket.replicationRule","title":"OSS bucket replication rule","desc":"One rule copying objects to another bucket, keyed by its rule ID. Reports where the copies land and what is copied, so a rule sending object data to another region or another account is visible as one.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"replicationRules":{"name":"replicationRules","type":"\u0019\u001balicloud.oss.bucket.replicationRule","title":"Rules that copy objects to another bucket","desc":"Replication moves object data out of this bucket, and the destination can be in another region or owned by another account.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the bucket","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the bucket belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"sseAlgorithm":{"name":"sseAlgorithm","type":"\u0007","title":"Default server-side encryption algorithm","desc":"The SSEAlgorithm from the default encryption rule (KMS, AES256, or SM4), flattened for auditing. Empty when no default encryption is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"storageClass":{"name":"storageClass","type":"\u0007","is_mandatory":true,"title":"Storage class","desc":"One of Standard, IA, Archive, ColdArchive, or DeepColdArchive.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","title":"Bucket tags as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsEnforced":{"name":"tlsEnforced","type":"\u0004","title":"Whether the bucket restricts which TLS versions clients may use","desc":"False means every TLS version the service accepts is allowed, including versions no longer considered safe.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsVersions":{"name":"tlsVersions","type":"\u0019\u0007","title":"TLS versions clients may use","desc":"For example TLSv1.2 and TLSv1.3. Empty when tlsEnforced is false, which does not mean TLS is off, only that the bucket sets no floor of its own.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"transferAcceleration":{"name":"transferAcceleration","type":"\u0007","title":"Transfer acceleration state","desc":"Whether transfer acceleration is enabled for the bucket. One of Enabled or Disabled. Empty when the setting is not returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"versioning":{"name":"versioning","type":"\u0007","title":"Versioning state","desc":"One of Enabled or Suspended. Empty when versioning was never configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"websiteEnabled":{"name":"websiteEnabled","type":"\u0004","title":"Whether the bucket serves a static website","desc":"Static hosting is an intentional public surface, so a bucket with it enabled is meant to be read anonymously.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"websiteErrorDocument":{"name":"websiteErrorDocument","type":"\u0007","title":"Page served for errors on the static website","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"websiteIndexDocument":{"name":"websiteIndexDocument","type":"\u0007","title":"Default page served for the static website","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Object Storage Service bucket","desc":"A single OSS bucket, keyed by name (bucket names are globally unique). The summary fields (region, storageClass, creationDate, endpoints, resourceGroupId) come from the account bucket listing. The remaining accessors call the per-bucket configuration APIs to expose the access control policy, default server-side encryption, versioning state, access logging target, bucket policy document, tags, and the block-public-access posture used to audit exposure.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss.bucket.corsRule":{"id":"alicloud.oss.bucket.corsRule","name":"alicloud.oss.bucket.corsRule","fields":{"allowedHeaders":{"name":"allowedHeaders","type":"\u0019\u0007","is_mandatory":true,"title":"Request headers allowed in a cross-origin request","desc":"A value of `*` allows every header.","provider":"go.mondoo.com/mql/providers/alicloud"},"allowedMethods":{"name":"allowedMethods","type":"\u0019\u0007","is_mandatory":true,"title":"Methods allowed in a cross-origin request","provider":"go.mondoo.com/mql/providers/alicloud"},"allowedOrigins":{"name":"allowedOrigins","type":"\u0019\u0007","is_mandatory":true,"title":"Origins a browser may issue cross-origin requests from","desc":"A value of `*` allows every site.","provider":"go.mondoo.com/mql/providers/alicloud"},"exposeHeaders":{"name":"exposeHeaders","type":"\u0019\u0007","is_mandatory":true,"title":"Response headers exposed to the requesting page","provider":"go.mondoo.com/mql/providers/alicloud"},"maxAgeSeconds":{"name":"maxAgeSeconds","type":"\u0005","is_mandatory":true,"title":"Seconds a browser may cache the preflight response","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"OSS bucket cross-origin resource sharing rule","desc":"One CORS rule, deciding which origins a browser may read the bucket from and with which methods and headers. An allowed origin of `*` lets a page on any site read whatever the requesting browser is allowed to read.","min_provider_version":"13.4.1","defaults":"allowedOrigins allowedMethods maxAgeSeconds","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss.bucket.replicationRule":{"id":"alicloud.oss.bucket.replicationRule","name":"alicloud.oss.bucket.replicationRule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Operations copied to the destination","desc":"ALL covers writes, deletes and aborted uploads. PUT covers writes only, so an object deleted here survives at the destination.","provider":"go.mondoo.com/mql/providers/alicloud"},"historicalObjectReplication":{"name":"historicalObjectReplication","type":"\u0007","is_mandatory":true,"title":"Whether objects that predate the rule are copied","desc":"Either enabled or disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Replication rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"prefixes":{"name":"prefixes","type":"\u0019\u0007","is_mandatory":true,"title":"Object name prefixes the rule covers","desc":"Empty when the rule covers the whole bucket.","provider":"go.mondoo.com/mql/providers/alicloud"},"replicaKmsKeyId":{"name":"replicaKmsKeyId","type":"\u0007","is_mandatory":true,"title":"KMS key ID used to encrypt the replicated objects","desc":"Empty when the destination objects are not encrypted with a customer key.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Replication status","desc":"One of starting, doing, or closing.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRole":{"name":"syncRole","type":"\u0007","is_mandatory":true,"title":"RAM role Object Storage Service assumes to perform the replication","provider":"go.mondoo.com/mql/providers/alicloud"},"targetBucket":{"name":"targetBucket","type":"\u0007","is_mandatory":true,"title":"Bucket objects are copied to","provider":"go.mondoo.com/mql/providers/alicloud"},"targetLocation":{"name":"targetLocation","type":"\u0007","is_mandatory":true,"title":"Region the destination bucket sits in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"OSS bucket replication rule","desc":"One rule copying objects to another bucket, keyed by its rule ID. Reports where the copies land and what is copied, so a rule sending object data to another region or another account is visible as one.","min_provider_version":"13.4.1","defaults":"id targetBucket targetLocation status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb":{"id":"alicloud.polardb","name":"alicloud.polardb","fields":{"cluster":{"name":"cluster","type":"\u001balicloud.polardb.cluster","title":"PolarDB cluster","desc":"A single ApsaraDB for PolarDB cluster, keyed by dbClusterId. Exposes the cluster lifecycle status, database engine and version, node class and count, storage usage, network placement, billing, and the security-posture controls that govern it: SSL/TLS encryption in transit, Transparent Data Encryption (TDE) at rest, the IP access whitelist, deletion protection, and the connection endpoints. Select a cluster with alicloud.polardb.cluster(dbClusterId: \"pc-xxxxxxxx\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"clusters":{"name":"clusters","type":"\u0019\u001balicloud.polardb.cluster","title":"PolarDB clusters across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"PolarDB","desc":"Entry point for querying ApsaraDB for PolarDB, the cloud-native relational database service. Exposes the PolarDB clusters provisioned across every enabled region through clusters.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb.cluster":{"id":"alicloud.polardb.cluster","name":"alicloud.polardb.cluster","fields":{"accessWhitelist":{"name":"accessWhitelist","type":"\u0019\u0007","title":"IP access whitelist entries","desc":"The flattened set of CIDR entries permitted to connect to the cluster, gathered across every whitelist group. An entry of 0.0.0.0/0 means the cluster accepts connections from any source.","provider":"go.mondoo.com/mql/providers/alicloud"},"aiType":{"name":"aiType","type":"\u0007","is_mandatory":true,"title":"AI feature type of the cluster","desc":"One of SearchNode, DLNode, or an empty string when no AI node is attached.","provider":"go.mondoo.com/mql/providers/alicloud"},"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Product edition","desc":"One of Normal (Cluster Edition), Basic (Single Node Edition), ArchiveNormal (X-Engine), or SENormal (Standard Edition).","provider":"go.mondoo.com/mql/providers/alicloud"},"cpuCores":{"name":"cpuCores","type":"\u0007","is_mandatory":true,"title":"Number of CPU cores per node","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Creation time","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterDescription":{"name":"dbClusterDescription","type":"\u0007","is_mandatory":true,"title":"User-defined cluster description","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterId":{"name":"dbClusterId","type":"\u0007","is_mandatory":true,"title":"Cluster ID, for example pc-bp1234567890abc","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterNetworkType":{"name":"dbClusterNetworkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"One of VPC or Classic.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterStatus":{"name":"dbClusterStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"For example Creating, Running, Deleting, Rebooting, DBNodeCreating, DBNodeDeleting, ClassChanging, NetAddressCreating, NetAddressDeleting, or NetAddressModifying.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbNodeClass":{"name":"dbNodeClass","type":"\u0007","is_mandatory":true,"title":"Node specification class, for example polar.mysql.x4.medium","provider":"go.mondoo.com/mql/providers/alicloud"},"dbNodeNumber":{"name":"dbNodeNumber","type":"\u0005","is_mandatory":true,"title":"Number of nodes in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"dbNodes":{"name":"dbNodes","type":"\u0019\n","is_mandatory":true,"title":"Database nodes in the cluster","desc":"One entry per node with dbNodeId, dbNodeClass, dbNodeRole (Writer or Reader), zoneId, regionId, imciSwitch (columnar index state), hotReplicaMode, and serverless.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbType":{"name":"dbType","type":"\u0007","is_mandatory":true,"title":"Database engine family","desc":"One of MySQL, PostgreSQL, or Oracle.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbVersion":{"name":"dbVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version, for example 8.0, 5.7, 5.6, 11, or 14","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionLock":{"name":"deletionLock","type":"\u0005","is_mandatory":true,"title":"Deletion protection flag","desc":"1 when release/deletion protection is enabled, 0 when it is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"endpoints":{"name":"endpoints","type":"\u0019\n","title":"Connection endpoints of the cluster","desc":"One entry per network address with endpointType (Cluster, Primary, or Custom), dbEndpointId, addressType (the network type, Public or Private), connectionString, port, readWriteMode, and nodes.","provider":"go.mondoo.com/mql/providers/alicloud"},"engine":{"name":"engine","type":"\u0007","is_mandatory":true,"title":"Storage engine of the cluster","desc":"One of POLARDB (compute-storage separated) or MySQL.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Expiration time (null for pay-as-you-go clusters)","provider":"go.mondoo.com/mql/providers/alicloud"},"expired":{"name":"expired","type":"\u0007","is_mandatory":true,"title":"Whether the subscription cluster has expired, as a string","desc":"One of true or false. Empty for pay-as-you-go clusters.","provider":"go.mondoo.com/mql/providers/alicloud"},"hotStandbyCluster":{"name":"hotStandbyCluster","type":"\u0007","is_mandatory":true,"title":"Whether the cluster is a hot-standby (multi-zone) cluster","desc":"One of ON or OFF.","provider":"go.mondoo.com/mql/providers/alicloud"},"lockMode":{"name":"lockMode","type":"\u0007","is_mandatory":true,"title":"Lock state of the cluster","desc":"One of Unlock, ManualLock, LockByExpiration, or LockByDiskQuota.","provider":"go.mondoo.com/mql/providers/alicloud"},"memorySize":{"name":"memorySize","type":"\u0007","is_mandatory":true,"title":"Memory size per node, in MB","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method","desc":"One of Prepaid (subscription) or Postpaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the cluster resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the cluster","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverlessType":{"name":"serverlessType","type":"\u0007","is_mandatory":true,"title":"Serverless cluster type, for example AgileServerless or SteadyServerless (empty for non-serverless clusters)","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether SSL/TLS encryption in transit is enabled on any endpoint","desc":"True when at least one endpoint reports SSLEnabled as Enabled. False when SSL is disabled on all endpoints.","provider":"go.mondoo.com/mql/providers/alicloud"},"storageMax":{"name":"storageMax","type":"\u0005","title":"Maximum storage capacity, in bytes","desc":"For PSL5/PSL4 (compute-storage separated) clusters this is the auto-scaling ceiling. Resolved from the cluster attribute detail.","provider":"go.mondoo.com/mql/providers/alicloud"},"storagePayType":{"name":"storagePayType","type":"\u0007","is_mandatory":true,"title":"Storage billing method","desc":"One of Prepaid (subscription) or Postpaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"storageSpace":{"name":"storageSpace","type":"\u0005","is_mandatory":true,"title":"Provisioned storage space, in GB (0 when storage auto-scales)","provider":"go.mondoo.com/mql/providers/alicloud"},"storageType":{"name":"storageType","type":"\u0007","is_mandatory":true,"title":"Storage type","desc":"For example HighPerformance, PSL5, PSL4, or ESSDAUTOPL.","provider":"go.mondoo.com/mql/providers/alicloud"},"storageUsed":{"name":"storageUsed","type":"\u0005","is_mandatory":true,"title":"Used storage, in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"strictConsistency":{"name":"strictConsistency","type":"\u0007","is_mandatory":true,"title":"Whether multi-node strict consistency is enabled","desc":"One of ON or OFF.","provider":"go.mondoo.com/mql/providers/alicloud"},"subCategory":{"name":"subCategory","type":"\u0007","is_mandatory":true,"title":"Product sub-edition, for example Exclusive or General","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the cluster, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether Transparent Data Encryption (TDE) at rest is enabled","desc":"True when the cluster TDE status is Enabled. False when TDE is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the primary node resides in, for example cn-hangzhou-i","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"PolarDB cluster","desc":"A single ApsaraDB for PolarDB cluster, keyed by dbClusterId. Exposes the cluster lifecycle status, database engine and version, node class and count, storage usage, network placement, billing, and the security-posture controls that govern it: SSL/TLS encryption in transit, Transparent Data Encryption (TDE) at rest, the IP access whitelist, deletion protection, and the connection endpoints. Select a cluster with alicloud.polardb.cluster(dbClusterId: \"pc-xxxxxxxx\").","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram":{"id":"alicloud.ram","name":"alicloud.ram","fields":{"accessKey":{"name":"accessKey","type":"\u001balicloud.ram.accessKey","title":"Resource Access Management access key","desc":"An access key credential belonging to a RAM user, keyed by the owning userName and accessKeyId. Exposes the key status and creation time. The secret access key is never exposed.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"group":{"name":"group","type":"\u001balicloud.ram.group","title":"Resource Access Management user group","desc":"A collection of RAM users, keyed by groupName. Exposes the group metadata and lifecycle timestamps, plus the member users and the policies attached to the group.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"groups":{"name":"groups","type":"\u0019\u001balicloud.ram.group","title":"RAM user groups in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordPolicy":{"name":"passwordPolicy","type":"\u001balicloud.ram.passwordPolicy","title":"Account-wide password policy for RAM users","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\u001balicloud.ram.policy","title":"Permission policies in the account, both system and custom","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u001balicloud.ram.policy","title":"Resource Access Management permission policy","desc":"A permission policy. Exposes the policy metadata, attachment count, and default version, along with the policy document of the default version. System policies are managed by Alibaba Cloud; custom policies are defined in the account. The policyName and policyType fields together select a single policy, for example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"role":{"name":"role","type":"\u001balicloud.ram.role","title":"Resource Access Management role","desc":"A RAM role that trusted identities can assume, keyed by roleName. Exposes the role identifiers, description, session limits, and tags, along with the trust policy that governs who may assume it and the permission policies attached to it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"roles":{"name":"roles","type":"\u0019\u001balicloud.ram.role","title":"RAM roles in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPreference":{"name":"securityPreference","type":"\n","title":"Console and credential security preferences for the account","desc":"Nested preferences controlling whether RAM users may manage their own access keys, MFA devices, and public keys, whether they may change their own password, the console login network masks, and the login session duration.","provider":"go.mondoo.com/mql/providers/alicloud"},"user":{"name":"user","type":"\u001balicloud.ram.user","title":"Resource Access Management user","desc":"A single RAM identity, keyed by userName. Exposes the user profile (display name, email, mobile phone, comments) and lifecycle timestamps, plus the user's access keys, group memberships, attached policies, MFA device binding, and console login profile.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"users":{"name":"users","type":"\u0019\u001balicloud.ram.user","title":"RAM users in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Resource Access Management","desc":"Identity and access configuration for an Alibaba Cloud account. Exposes the RAM users, user groups, roles, and permission policies defined in the account, along with the account-wide password policy and the console and credential security preferences.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.accessKey":{"id":"alicloud.ram.accessKey","name":"alicloud.ram.accessKey","fields":{"accessKeyId":{"name":"accessKeyId","type":"\u0007","is_mandatory":true,"title":"Access key ID","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the access key was created","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Key status","desc":"Either Active or Inactive.","provider":"go.mondoo.com/mql/providers/alicloud"},"user":{"name":"user","type":"\u001balicloud.ram.user","title":"RAM user that owns the access key","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"User name that owns the access key","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management access key","desc":"An access key credential belonging to a RAM user, keyed by the owning userName and accessKeyId. Exposes the key status and creation time. The secret access key is never exposed.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.group":{"id":"alicloud.ram.group","name":"alicloud.ram.group","fields":{"attachedPolicies":{"name":"attachedPolicies","type":"\u0019\u001balicloud.ram.policy","title":"Policies attached to the group","desc":"The permission policies every member of the group inherits. Traverse to policyDocument to inspect the permission statements granted through group membership.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"comments":{"name":"comments","type":"\u0007","is_mandatory":true,"title":"Comments describing the group","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"groupId":{"name":"groupId","type":"\u0007","is_mandatory":true,"title":"Group ID","provider":"go.mondoo.com/mql/providers/alicloud"},"groupName":{"name":"groupName","type":"\u0007","is_mandatory":true,"title":"Group name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\n","title":"Policy attachment records for policies attached to the group","desc":"Each entry lists the policyName, policyType (System or Custom), defaultVersion, description, and attachDate of a policy attached to the group. Use attachedPolicies to reach the policy itself, including its permission statements.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the group was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"users":{"name":"users","type":"\u0019\u001balicloud.ram.user","title":"Users that belong to the group","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management user group","desc":"A collection of RAM users, keyed by groupName. Exposes the group metadata and lifecycle timestamps, plus the member users and the policies attached to the group.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.passwordPolicy":{"id":"alicloud.ram.passwordPolicy","name":"alicloud.ram.passwordPolicy","fields":{"hardExpiry":{"name":"hardExpiry","type":"\u0004","is_mandatory":true,"title":"Whether an expired password blocks console sign-in until an administrator resets it","desc":"When true, a user whose password has expired cannot sign in and an administrator must reset the password. When false, the user may change the expired password at sign-in.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxLoginAttempts":{"name":"maxLoginAttempts","type":"\u0005","is_mandatory":true,"title":"Number of consecutive failed sign-in attempts before the user is locked out","provider":"go.mondoo.com/mql/providers/alicloud"},"maxPasswordAge":{"name":"maxPasswordAge","type":"\u0005","is_mandatory":true,"title":"Maximum password age in days before it must be changed, or 0 when passwords never expire","provider":"go.mondoo.com/mql/providers/alicloud"},"minimumPasswordLength":{"name":"minimumPasswordLength","type":"\u0005","is_mandatory":true,"title":"Minimum number of characters required in a password","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordReusePrevention":{"name":"passwordReusePrevention","type":"\u0005","is_mandatory":true,"title":"Number of previous passwords that cannot be reused","provider":"go.mondoo.com/mql/providers/alicloud"},"requireLowercaseCharacters":{"name":"requireLowercaseCharacters","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain a lowercase letter","provider":"go.mondoo.com/mql/providers/alicloud"},"requireNumbers":{"name":"requireNumbers","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain a number","provider":"go.mondoo.com/mql/providers/alicloud"},"requireSymbols":{"name":"requireSymbols","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain a symbol","provider":"go.mondoo.com/mql/providers/alicloud"},"requireUppercaseCharacters":{"name":"requireUppercaseCharacters","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain an uppercase letter","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management password policy","desc":"Account-wide password requirements for RAM users. Exposes the minimum length, character-class requirements, expiration and reuse rules, and the failed-login lockout threshold.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.policy":{"id":"alicloud.ram.policy","name":"alicloud.ram.policy","fields":{"allowsAdminAccess":{"name":"allowsAdminAccess","type":"\u0004","title":"Whether the policy grants every action on every resource","desc":"True when a statement allows action `*` on resource `*`, or on the fully wildcarded `acs:*:*:*:*`, with no NotAction or NotResource exception carved out of it. A condition on the statement does not clear the flag, because the grant is still unrestricted wherever that condition holds.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"attachmentCount":{"name":"attachmentCount","type":"\u0005","is_mandatory":true,"title":"Number of entities the policy is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the policy was created","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultVersion":{"name":"defaultVersion","type":"\u0007","is_mandatory":true,"title":"Version ID of the default policy version, for example v1","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"hasUnscopedResource":{"name":"hasUnscopedResource","type":"\u0004","title":"Whether a granting statement applies to a whole service","desc":"True when any Allow statement names `*`, or an ACS resource name whose relative ID is `*`, such as `acs:oss:*:*:*`. Only the relative ID counts: the region and account fields are wildcarded in most real policies, so `acs:oss:*:*:mybucket/*` names one bucket and does not set the flag. Deny statements are ignored.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"hasWildcardAction":{"name":"hasWildcardAction","type":"\u0004","title":"Whether a granting statement names an action by wildcard","desc":"True when any Allow statement names an action containing `*`, covering both the full `*` and prefix forms such as `ecs:Describe*`. A prefix wildcard is worth surfacing because it also grants actions the service has not shipped yet. Deny statements are ignored.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"policyDocument":{"name":"policyDocument","type":"\u0007","title":"Policy document of the default version","desc":"The permission statements of the default version as a JSON string.","provider":"go.mondoo.com/mql/providers/alicloud"},"policyName":{"name":"policyName","type":"\u0007","is_mandatory":true,"title":"Policy name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"policyType":{"name":"policyType","type":"\u0007","is_mandatory":true,"title":"Policy type","desc":"Either System for an Alibaba Cloud managed policy or Custom for an account-defined policy.","provider":"go.mondoo.com/mql/providers/alicloud"},"statement":{"name":"statement","type":"\u001balicloud.ram.policy.statement","title":"Statement of a Resource Access Management permission policy","desc":"A single permission statement out of a policy's default version. Exposes the effect, the actions and resources the statement names or excludes, and the condition constraining the grant. For example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\").statements`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"statements":{"name":"statements","type":"\u0019\u001balicloud.ram.policy.statement","title":"Permission statements of the default policy version","desc":"The statements of policyDocument broken out one by one, each carrying the effect, the actions and resources it names, and any condition placed on the grant. Query into them to audit what a policy actually permits, for example `alicloud.ram.policies.where(policyType == \"Custom\") { policyName statements { effect action resource } }`.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the policy was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management permission policy","desc":"A permission policy. Exposes the policy metadata, attachment count, and default version, along with the policy document of the default version. System policies are managed by Alibaba Cloud; custom policies are defined in the account. The policyName and policyType fields together select a single policy, for example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\")`.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.policy.statement":{"id":"alicloud.ram.policy.statement","name":"alicloud.ram.policy.statement","fields":{"action":{"name":"action","type":"\u0019\u0007","is_mandatory":true,"title":"Actions the statement applies to","desc":"Each entry is either `service:Action`, a prefix wildcard such as `ecs:Describe*`, or the full wildcard `*`. Empty when the statement uses notAction instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"condition":{"name":"condition","type":"\n","is_mandatory":true,"title":"Condition constraining the grant","desc":"The condition block keyed by operator, for example `{\"StringEquals\": {\"acs:SourceVpc\": [\"vpc-1\"]}}` or `{\"IpAddress\": {\"acs:SourceIp\": [\"10.0.0.0/8\"]}}`. Null when the statement grants unconditionally.","provider":"go.mondoo.com/mql/providers/alicloud"},"effect":{"name":"effect","type":"\u0007","is_mandatory":true,"title":"Effect of the statement","desc":"Either Allow or Deny.","provider":"go.mondoo.com/mql/providers/alicloud"},"notAction":{"name":"notAction","type":"\u0019\u0007","is_mandatory":true,"title":"Actions excluded from the statement","desc":"The statement applies to every action except these. Empty on the usual statement, which names its actions through action.","provider":"go.mondoo.com/mql/providers/alicloud"},"notResource":{"name":"notResource","type":"\u0019\u0007","is_mandatory":true,"title":"Resources excluded from the statement","desc":"The statement applies to every resource except these. Empty on the usual statement, which names its resources through resource.","provider":"go.mondoo.com/mql/providers/alicloud"},"resource":{"name":"resource","type":"\u0019\u0007","is_mandatory":true,"title":"Resources the statement applies to","desc":"Each entry is either the full wildcard `*` or an ACS resource name of the form `acs:\u003cservice\u003e:\u003cregion\u003e:\u003caccount\u003e:\u003crelative-id\u003e`. Empty when the statement uses notResource instead, and on statements that name no resource at all, such as a role trust statement.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Statement of a Resource Access Management permission policy","desc":"A single permission statement out of a policy's default version. Exposes the effect, the actions and resources the statement names or excludes, and the condition constraining the grant. For example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\").statements`.","min_provider_version":"13.2.5","defaults":"effect action resource","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.role":{"id":"alicloud.ram.role","name":"alicloud.ram.role","fields":{"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the role","provider":"go.mondoo.com/mql/providers/alicloud"},"assumeRolePolicyDocument":{"name":"assumeRolePolicyDocument","type":"\u0007","title":"Trust policy document controlling which identities may assume the role","desc":"The assume-role policy as a JSON string, naming the principals permitted to assume this role and the conditions on that trust.","provider":"go.mondoo.com/mql/providers/alicloud"},"attachedPolicies":{"name":"attachedPolicies","type":"\u0019\u001balicloud.ram.policy","title":"Policies attached to the role","desc":"The permission policies a session that assumes this role receives. Traverse to policyDocument alongside assumeRolePolicyDocument to see both who may assume the role and what the assumed session is allowed to do.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the role was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the role","provider":"go.mondoo.com/mql/providers/alicloud"},"maxSessionDuration":{"name":"maxSessionDuration","type":"\u0005","is_mandatory":true,"title":"Maximum session duration in seconds allowed when assuming the role","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\n","title":"Policy attachment records for policies attached to the role","desc":"Each entry lists the policyName, policyType (System or Custom), defaultVersion, description, and attachDate of a policy attached to the role. Use attachedPolicies to reach the policy itself, including its permission statements.","provider":"go.mondoo.com/mql/providers/alicloud"},"roleId":{"name":"roleId","type":"\u0007","is_mandatory":true,"title":"Role ID","provider":"go.mondoo.com/mql/providers/alicloud"},"roleName":{"name":"roleName","type":"\u0007","is_mandatory":true,"title":"Role name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the role","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the role was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management role","desc":"A RAM role that trusted identities can assume, keyed by roleName. Exposes the role identifiers, description, session limits, and tags, along with the trust policy that governs who may assume it and the permission policies attached to it.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.user":{"id":"alicloud.ram.user","name":"alicloud.ram.user","fields":{"accessKeys":{"name":"accessKeys","type":"\u0019\u001balicloud.ram.accessKey","title":"Access keys belonging to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"attachedPolicies":{"name":"attachedPolicies","type":"\u0019\u001balicloud.ram.policy","title":"Policies attached directly to the user","desc":"The permission policies granted to the user by direct attachment, not counting policies the user inherits through group membership. Traverse to policyDocument to inspect the permission statements a user holds, for example to find users granted the AdministratorAccess system policy.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"comments":{"name":"comments","type":"\u0007","is_mandatory":true,"title":"Comments describing the user","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the user was created","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name","provider":"go.mondoo.com/mql/providers/alicloud"},"effectivePolicies":{"name":"effectivePolicies","type":"\u0019\u001balicloud.ram.policy","title":"Every policy the user holds, directly or through a group","desc":"The union of attachedPolicies and the policies attached to each group the user belongs to, with a policy held by both routes listed once. This is the set that decides what a user can actually do, which attachedPolicies alone understates whenever permissions are granted through groups. For example `alicloud.ram.users.where(effectivePolicies.any(allowsAdminAccess))` finds every administrator in the account.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email address bound to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"groups":{"name":"groups","type":"\u0019\u001balicloud.ram.group","title":"Groups the user belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"lastLoginDate":{"name":"lastLoginDate","type":"\t","title":"Time the user last signed in to the console","provider":"go.mondoo.com/mql/providers/alicloud"},"loginProfile":{"name":"loginProfile","type":"\n","title":"Console login profile for the user","desc":"Presence indicates the user can sign in to the console. Exposes userName, mfaBindRequired, passwordResetRequired, and createDate, or null when the user has no console login enabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaDevice":{"name":"mfaDevice","type":"\n","title":"Multi-factor authentication device bound to the user","desc":"The serialNumber and type of the bound MFA device, or null when the user has no MFA device.","provider":"go.mondoo.com/mql/providers/alicloud"},"mobilePhone":{"name":"mobilePhone","type":"\u0007","is_mandatory":true,"title":"Mobile phone number bound to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\n","title":"Policy attachment records for policies attached directly to the user","desc":"Each entry lists the policyName, policyType (System or Custom), defaultVersion, description, and attachDate of a policy attached to the user. Use attachedPolicies to reach the policy itself, including its permission statements.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the user was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"userId":{"name":"userId","type":"\u0007","is_mandatory":true,"title":"User ID","provider":"go.mondoo.com/mql/providers/alicloud"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"User name, used as the console sign-in name and the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management user","desc":"A single RAM identity, keyed by userName. Exposes the user profile (display name, email, mobile phone, comments) and lifecycle timestamps, plus the user's access keys, group memberships, attached policies, MFA device binding, and console login profile.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.rds":{"id":"alicloud.rds","name":"alicloud.rds","fields":{"instance":{"name":"instance","type":"\u001balicloud.rds.instance","title":"ApsaraDB RDS instance","desc":"A single ApsaraDB relational database instance, keyed by dbInstanceId (for example rm-uf6wjk5xxxxxxx). Exposes the database engine and version, the instance class and storage, the network placement and connection endpoint, the billing and lock state, and the security posture: whether SSL/TLS and TDE encryption are enabled, the IP address whitelist, and the attached ECS security groups.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.rds.instance","title":"RDS instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB RDS","desc":"ApsaraDB relational database instances in an Alibaba Cloud account. Exposes the RDS instances discovered across every enabled region through instances, from which the database engine and version, the network placement, and the security posture (SSL/TLS, TDE encryption, public accessibility, and IP address whitelist) can be audited.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.rds.instance":{"id":"alicloud.rds.instance","name":"alicloud.rds.instance","fields":{"blueGreenDeploymentName":{"name":"blueGreenDeploymentName","type":"\u0007","title":"Name of the blue-green deployment the instance takes part in","desc":"Empty when the instance is not part of one. A blue-green deployment runs a second instance holding the same data as the one serving traffic, so both halves have to be hardened alike: the standby is a live copy of production data that a whitelist or encryption setting applied only to the original does not cover.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"blueInstanceName":{"name":"blueInstanceName","type":"\u0007","title":"Name of the blue instance in the deployment, empty when not part of one","desc":"The blue instance is the one currently serving traffic.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"RDS edition of the instance","desc":"One of Basic, HighAvailability, cluster, Finance, or serverless_basic.","provider":"go.mondoo.com/mql/providers/alicloud"},"computeBurstEnabled":{"name":"computeBurstEnabled","type":"\u0004","title":"Whether compute burst is enabled for the instance","desc":"A burst-enabled instance may exceed its purchased compute for short periods, so its effective capacity is not the class alone.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionMode":{"name":"connectionMode","type":"\u0007","is_mandatory":true,"title":"Connection mode of the instance","desc":"One of Standard (standard mode) or Safe (database proxy mode).","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionString":{"name":"connectionString","type":"\u0007","is_mandatory":true,"title":"Endpoint used to connect to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceClass":{"name":"dbInstanceClass","type":"\u0007","is_mandatory":true,"title":"Instance type (class), for example rds.mys2.small","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceDescription":{"name":"dbInstanceDescription","type":"\u0007","is_mandatory":true,"title":"Description of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceId":{"name":"dbInstanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example rm-uf6wjk5xxxxxxx","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceNetType":{"name":"dbInstanceNetType","type":"\u0007","is_mandatory":true,"title":"Network connection type of the instance","desc":"One of Internet (public) or Intranet (internal).","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStatus":{"name":"dbInstanceStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the instance, for example Running or Creating","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStorage":{"name":"dbInstanceStorage","type":"\u0005","title":"Storage capacity of the instance in GB","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStorageType":{"name":"dbInstanceStorageType","type":"\u0007","is_mandatory":true,"title":"Storage type of the instance","desc":"One of local_ssd, cloud_ssd, cloud_essd, cloud_essd2, or cloud_essd3.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceType":{"name":"dbInstanceType","type":"\u0007","is_mandatory":true,"title":"Role of the instance","desc":"One of Primary (primary instance), Readonly (read-only instance), Guard (disaster recovery instance), or Temp (temporary instance).","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether release (deletion) protection is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"engine":{"name":"engine","type":"\u0007","is_mandatory":true,"title":"Database engine","desc":"One of MySQL, SQLServer, PostgreSQL, or MariaDB.","provider":"go.mondoo.com/mql/providers/alicloud"},"engineVersion":{"name":"engineVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version, for example 5.7","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Time when the instance expires (subscription instances only)","provider":"go.mondoo.com/mql/providers/alicloud"},"greenInstanceName":{"name":"greenInstanceName","type":"\u0007","title":"Name of the green instance in the deployment, empty when not part of one","desc":"The green instance is the standby the deployment will switch to.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceNetworkType":{"name":"instanceNetworkType","type":"\u0007","is_mandatory":true,"title":"Network type of the instance","desc":"One of VPC or Classic.","provider":"go.mondoo.com/mql/providers/alicloud"},"lockMode":{"name":"lockMode","type":"\u0007","is_mandatory":true,"title":"Lock state of the instance","desc":"One of Unlock, ManualLock, LockByExpiration, LockByRestoration, or LockByDiskQuota.","provider":"go.mondoo.com/mql/providers/alicloud"},"lockReason":{"name":"lockReason","type":"\u0007","is_mandatory":true,"title":"Reason the instance is locked","provider":"go.mondoo.com/mql/providers/alicloud"},"masterInstance":{"name":"masterInstance","type":"\u001balicloud.rds.instance","title":"Primary instance, set for read-only and disaster recovery instances","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method of the instance","desc":"One of Postpaid (pay-as-you-go) or Prepaid (subscription).","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","title":"Port on which the instance listens for connections","provider":"go.mondoo.com/mql/providers/alicloud"},"readOnlyStatus":{"name":"readOnlyStatus","type":"\u0007","title":"Read-only state of the instance, empty when it reports none","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID where the instance is deployed, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupIds":{"name":"securityGroupIds","type":"\u0019\u0007","title":"IDs of the ECS security groups attached to the instance","desc":"Deprecated in favor of securityGroups.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"ECS security groups attached to the instance","desc":"The groups whose rules govern which sources may reach the instance. Traverse to permissions to see the allowed source ranges and ports alongside securityIPList, which controls the database whitelist separately.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"securityIPList":{"name":"securityIPList","type":"\u0019\u0007","title":"IP address whitelist","desc":"The IP addresses and CIDR blocks allowed to connect to the instance. A whitelist entry of 0.0.0.0/0 exposes the instance to the entire internet.","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether SSL/TLS encryption is enabled for client connections","provider":"go.mondoo.com/mql/providers/alicloud"},"sslExpireTime":{"name":"sslExpireTime","type":"\t","title":"Expiration time of the server certificate used for SSL/TLS","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","title":"Tags attached to the instance as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether Transparent Data Encryption (TDE) is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"vectorSupportStatus":{"name":"vectorSupportStatus","type":"\u0007","title":"Whether the instance supports vector storage and search","desc":"Reports the state of the vector extension, which turns the instance into a store for embeddings and therefore a data surface an AI application reads from. Empty when the engine does not report it.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC that the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch that the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID where the instance is deployed, for example cn-hangzhou-a","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB RDS instance","desc":"A single ApsaraDB relational database instance, keyed by dbInstanceId (for example rm-uf6wjk5xxxxxxx). Exposes the database engine and version, the instance class and storage, the network placement and connection endpoint, the billing and lock state, and the security posture: whether SSL/TLS and TDE encryption are enabled, the IP address whitelist, and the attached ECS security groups.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.redis":{"id":"alicloud.redis","name":"alicloud.redis","fields":{"instance":{"name":"instance","type":"\u001balicloud.redis.instance","title":"ApsaraDB for Redis instance","desc":"A single ApsaraDB for Redis or Tair instance, keyed by instanceId (for example r-bp1zxszhcgatnx). Exposes the instance class and architecture, the engine version, the network placement, and the security posture (TLS encryption, transparent data encryption, the IP whitelist, attached ECS security groups, and whether password authentication is enforced).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.redis.instance","title":"ApsaraDB for Redis (Tair) instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for Redis","desc":"Entry point for the ApsaraDB for Redis (Tair) instances in an Alibaba Cloud account. Enumerates every Redis and Tair instance across the enabled regions through instances, each of which exposes its configuration and security posture.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.redis.instance":{"id":"alicloud.redis.instance","name":"alicloud.redis.instance","fields":{"architectureType":{"name":"architectureType","type":"\u0007","is_mandatory":true,"title":"Deployment architecture","desc":"One of cluster (cluster architecture), standard (standard architecture), or rwsplit (read/write splitting architecture).","provider":"go.mondoo.com/mql/providers/alicloud"},"authEnabled":{"name":"authEnabled","type":"\u0004","title":"Whether password authentication is enforced","desc":"True when password authentication is required. False when password-free access is enabled, allowing connections from within the VPC without a password.","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Maximum internal bandwidth of the instance, in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"capacity":{"name":"capacity","type":"\u0005","is_mandatory":true,"title":"Storage capacity of the instance, in MB","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionDomain":{"name":"connectionDomain","type":"\u0007","is_mandatory":true,"title":"Internal endpoint (connection domain) of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"connections":{"name":"connections","type":"\u0005","is_mandatory":true,"title":"Maximum number of concurrent connections the instance supports","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"editionType":{"name":"editionType","type":"\u0007","is_mandatory":true,"title":"Edition","desc":"One of Community (Redis Open-Source Edition) or Enterprise (Tair Enterprise Edition).","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"Time the subscription instance expires","provider":"go.mondoo.com/mql/providers/alicloud"},"engineVersion":{"name":"engineVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version, for example 4.0, 5.0, 6.0, or 7.0","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceClass":{"name":"instanceClass","type":"\u0007","is_mandatory":true,"title":"Instance type, for example redis.master.small.default","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example r-bp1zxszhcgatnx","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceStatus":{"name":"instanceStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Normal, Creating, Changing, Inactive, Flushing, Released, Transforming, Unavailable, Error, Migrating, BackupRecovering, MinorVersionUpgrading, NetworkModifying, SSLModifying, or MajorVersionUpgrading.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Database engine","desc":"One of Redis (Redis Open-Source Edition), Tair (Tair Enterprise Edition), or Memcache.","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"One of CLASSIC (classic network) or VPC (virtual private cloud).","provider":"go.mondoo.com/mql/providers/alicloud"},"nodeType":{"name":"nodeType","type":"\u0007","is_mandatory":true,"title":"Node type","desc":"One of double (master-replica) or single (standalone).","provider":"go.mondoo.com/mql/providers/alicloud"},"packageType":{"name":"packageType","type":"\u0007","is_mandatory":true,"title":"Package type","desc":"One of standard (standard package) or customized (custom package).","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Service port the instance listens on, for example 6379","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIp":{"name":"privateIp","type":"\u0007","is_mandatory":true,"title":"Private IP address of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"qps":{"name":"qps","type":"\u0005","is_mandatory":true,"title":"Maximum number of queries per second the instance can serve","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the instance is deployed in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"secondaryZoneId":{"name":"secondaryZoneId","type":"\u0007","is_mandatory":true,"title":"Secondary zone ID for a zone-redundant instance","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupIds":{"name":"securityGroupIds","type":"\u0019\u0007","title":"IDs of the ECS security groups associated with the instance","desc":"Deprecated in favor of securityGroups.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"ECS security groups associated with the instance","desc":"The groups whose rules govern which sources may reach the instance. Traverse to permissions to see the allowed source ranges and ports alongside securityIPList, which controls the instance whitelist separately.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"securityIPList":{"name":"securityIPList","type":"\u0019\u0007","title":"IP addresses and CIDR blocks allowed by the instance whitelists","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether TLS (SSL) encryption is enabled for in-transit traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the instance, as key/value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether transparent data encryption (TDE) is enabled for data at rest","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the instance is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the instance is deployed in, for example cn-hangzhou-b","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for Redis instance","desc":"A single ApsaraDB for Redis or Tair instance, keyed by instanceId (for example r-bp1zxszhcgatnx). Exposes the instance class and architecture, the engine version, the network placement, and the security posture (TLS encryption, transparent data encryption, the IP whitelist, attached ECS security groups, and whether password authentication is enforced).","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager":{"id":"alicloud.resourceManager","name":"alicloud.resourceManager","fields":{"account":{"name":"account","type":"\u001balicloud.resourceManager.account","title":"Resource Directory account","desc":"A single member or management account in the resource directory, keyed by accountId. Exposes the account profile, its position in the folder hierarchy, how it joined the directory, and its lifecycle timestamps.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"accounts":{"name":"accounts","type":"\u0019\u001balicloud.resourceManager.account","title":"Member and management accounts in the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPolicies":{"name":"controlPolicies","type":"\u0019\u001balicloud.resourceManager.controlPolicy","title":"Control policies in the resource directory, both system and custom","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPolicy":{"name":"controlPolicy","type":"\u001balicloud.resourceManager.controlPolicy","title":"Resource Directory control policy","desc":"A single control policy in the resource directory, keyed by policyId. A control policy sets the maximum permissions available to the accounts and folders it is attached to. Exposes the policy metadata and how many entities it is attached to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"controlPolicyStatus":{"name":"controlPolicyStatus","type":"\u0007","title":"Control-policy enablement state","desc":"Enabled when control policies may be attached to restrict member-account permissions.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","title":"Time the resource directory was created","provider":"go.mondoo.com/mql/providers/alicloud"},"folder":{"name":"folder","type":"\u001balicloud.resourceManager.folder","title":"Resource Directory folder","desc":"A single folder in the resource directory hierarchy, keyed by folderId. A folder groups member accounts and can nest other folders. Exposes the folder name, its parent, and creation time.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"folders":{"name":"folders","type":"\u0019\u001balicloud.resourceManager.folder","title":"Folders in the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"},"masterAccountId":{"name":"masterAccountId","type":"\u0007","title":"Management (master) account ID","provider":"go.mondoo.com/mql/providers/alicloud"},"masterAccountName":{"name":"masterAccountName","type":"\u0007","title":"Management (master) account name","provider":"go.mondoo.com/mql/providers/alicloud"},"memberDeletionStatus":{"name":"memberDeletionStatus","type":"\u0007","title":"Member-account deletion state","desc":"Enabled when member accounts may be deleted from the directory.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceDirectoryId":{"name":"resourceDirectoryId","type":"\u0007","title":"Resource directory (organization) ID","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group","desc":"A single resource group in an Alibaba Cloud account, keyed by resourceGroupId, for example `alicloud.resourceManager.resourceGroups.where(name == \"production\")`. A resource group is the ownership and billing boundary that most Alibaba Cloud resources are placed into, and RAM policies are commonly scoped to one. Exposes the group identifier, its display name, lifecycle status, owning account, and tags. Resources across the provider reach their group through a resourceGroup field, so an audit can select or exclude an environment by group rather than by an opaque identifier.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"resourceGroups":{"name":"resourceGroups","type":"\u0019\u001balicloud.resourceManager.resourceGroup","title":"Resource groups in the account","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"rootFolderId":{"name":"rootFolderId","type":"\u0007","title":"Root folder ID of the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Resource Directory","desc":"Multi-account governance structure for an Alibaba Cloud account. Exposes the resource directory (the organization), the management and member accounts it contains, the folder hierarchy that groups them, and the control policies available to restrict member-account permissions. Use it to audit organization membership and whether control policies are enabled.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.account":{"id":"alicloud.resourceManager.account","name":"alicloud.resourceManager.account","fields":{"accountId":{"name":"accountId","type":"\u0007","is_mandatory":true,"title":"Account (UID)","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name of the account","provider":"go.mondoo.com/mql/providers/alicloud"},"folder":{"name":"folder","type":"\u001balicloud.resourceManager.folder","title":"Folder that contains the account","provider":"go.mondoo.com/mql/providers/alicloud"},"folderId":{"name":"folderId","type":"\u0007","is_mandatory":true,"title":"ID of the folder that contains the account","provider":"go.mondoo.com/mql/providers/alicloud"},"joinMethod":{"name":"joinMethod","type":"\u0007","is_mandatory":true,"title":"How the account joined the directory","desc":"Either created or invited.","provider":"go.mondoo.com/mql/providers/alicloud"},"joinTime":{"name":"joinTime","type":"\t","is_mandatory":true,"title":"Time the account joined the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"modifyTime":{"name":"modifyTime","type":"\t","is_mandatory":true,"title":"Time the account was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceDirectoryId":{"name":"resourceDirectoryId","type":"\u0007","is_mandatory":true,"title":"Resource directory (organization) ID","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Account status, for example CreateSuccess or InviteSuccess","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Account type","desc":"ResourceAccount for an account created in the directory, or CloudAccount for an existing account invited into it.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Directory account","desc":"A single member or management account in the resource directory, keyed by accountId. Exposes the account profile, its position in the folder hierarchy, how it joined the directory, and its lifecycle timestamps.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.controlPolicy":{"id":"alicloud.resourceManager.controlPolicy","name":"alicloud.resourceManager.controlPolicy","fields":{"attachmentCount":{"name":"attachmentCount","type":"\u0005","is_mandatory":true,"title":"Number of accounts and folders the policy is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the policy was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"effectScope":{"name":"effectScope","type":"\u0007","is_mandatory":true,"title":"Identity types the policy governs, for example RAM","provider":"go.mondoo.com/mql/providers/alicloud"},"policyId":{"name":"policyId","type":"\u0007","is_mandatory":true,"title":"Policy ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"policyName":{"name":"policyName","type":"\u0007","is_mandatory":true,"title":"Policy name","provider":"go.mondoo.com/mql/providers/alicloud"},"policyType":{"name":"policyType","type":"\u0007","is_mandatory":true,"title":"Policy type","desc":"Either System for an Alibaba Cloud-managed policy or Custom for a user-defined one.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the policy was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Directory control policy","desc":"A single control policy in the resource directory, keyed by policyId. A control policy sets the maximum permissions available to the accounts and folders it is attached to. Exposes the policy metadata and how many entities it is attached to.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.folder":{"id":"alicloud.resourceManager.folder","name":"alicloud.resourceManager.folder","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the folder was created","provider":"go.mondoo.com/mql/providers/alicloud"},"folderId":{"name":"folderId","type":"\u0007","is_mandatory":true,"title":"Folder ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"folderName":{"name":"folderName","type":"\u0007","is_mandatory":true,"title":"Folder name","provider":"go.mondoo.com/mql/providers/alicloud"},"parentFolder":{"name":"parentFolder","type":"\u001balicloud.resourceManager.folder","title":"Parent folder in the resource directory hierarchy","desc":"Null on the root folder, which has no parent.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"parentFolderId":{"name":"parentFolderId","type":"\u0007","is_mandatory":true,"title":"ID of the parent folder, empty for the root folder","desc":"Deprecated in favor of parentFolder.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"}},"title":"Resource Directory folder","desc":"A single folder in the resource directory hierarchy, keyed by folderId. A folder groups member accounts and can nest other folders. Exposes the folder name, its parent, and creation time.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.resourceGroup":{"id":"alicloud.resourceManager.resourceGroup","name":"alicloud.resourceManager.resourceGroup","fields":{"accountId":{"name":"accountId","type":"\u0007","is_mandatory":true,"title":"ID of the account that owns the resource group","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the resource group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name of the resource group","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the resource group within the account","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Creating, OK, PendingDelete, or Deleting.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the resource group","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource group","desc":"A single resource group in an Alibaba Cloud account, keyed by resourceGroupId, for example `alicloud.resourceManager.resourceGroups.where(name == \"production\")`. A resource group is the ownership and billing boundary that most Alibaba Cloud resources are placed into, and RAM policies are commonly scoped to one. Exposes the group identifier, its display name, lifecycle status, owning account, and tags. Resources across the provider reach their group through a resourceGroup field, so an audit can select or exclude an environment by group rather than by an opaque identifier.","min_provider_version":"13.3.2","defaults":"resourceGroupId name displayName status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas":{"id":"alicloud.sas","name":"alicloud.sas","fields":{"alarmEvent":{"name":"alarmEvent","type":"\u001balicloud.sas.alarmEvent","title":"Alert raised by Security Center threat detection","desc":"A single alert, keyed by its event ID. Exposes what was detected, where, and whether it has been handled, along with the container and Kubernetes context when the alert came from a containerized workload.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"alarmEvents":{"name":"alarmEvents","type":"\u0019\u001balicloud.sas.alarmEvent","title":"Alerts raised by threat detection","provider":"go.mondoo.com/mql/providers/alicloud"},"assetLevel":{"name":"assetLevel","type":"\u0005","title":"Number of assets the subscription covers","desc":"Protection stops applying to assets beyond this quota, so a machine count above it means part of the fleet is unprotected.","provider":"go.mondoo.com/mql/providers/alicloud"},"baselineCheck":{"name":"baselineCheck","type":"\u001balicloud.sas.baselineCheck","title":"Baseline check failure found by Security Center","desc":"A configuration baseline check that machines are failing, keyed by riskId. Exposes how many machines fail the check and the severity split of those failures, so a check with a high warningMachineCount is a systemic misconfiguration rather than a one-off.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"baselineChecks":{"name":"baselineChecks","type":"\u0019\u001balicloud.sas.baselineCheck","title":"Baseline check failures found across the protected machines, grouped by check","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","title":"Whether Security Center is active for the account","desc":"False when the service has never been subscribed. The free tier still reports true, so pair this with version to tell the tiers apart.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","title":"Time the subscription expires","provider":"go.mondoo.com/mql/providers/alicloud"},"machine":{"name":"machine","type":"\u001balicloud.sas.machine","title":"Machine protected by Security Center","desc":"A single asset in the Security Center inventory, keyed by uuid. Exposes the agent state, the vulnerability and risk counts attributed to the machine, and its network addresses. The clientStatus field is the coverage audit: an offline or unbound agent means the machine is in the inventory but not actually being protected.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"machines":{"name":"machines","type":"\u0019\u001balicloud.sas.machine","title":"Machines Security Center is protecting","provider":"go.mondoo.com/mql/providers/alicloud"},"openTime":{"name":"openTime","type":"\t","title":"Time the subscription was activated","provider":"go.mondoo.com/mql/providers/alicloud"},"postPay":{"name":"postPay","type":"\u0004","title":"Whether the subscription is billed pay-as-you-go","provider":"go.mondoo.com/mql/providers/alicloud"},"trialVersion":{"name":"trialVersion","type":"\u0004","title":"Whether the current subscription is a trial","provider":"go.mondoo.com/mql/providers/alicloud"},"version":{"name":"version","type":"\u0005","title":"Subscription edition code","desc":"Higher codes carry more detection capability, with 1 for the free basic edition. Zero when the service has never been subscribed.","provider":"go.mondoo.com/mql/providers/alicloud"},"vulnerabilities":{"name":"vulnerabilities","type":"\u0019\u001balicloud.sas.vulnerability","title":"Vulnerabilities found across the protected machines, grouped by vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"vulnerability":{"name":"vulnerability","type":"\u001balicloud.sas.vulnerability","title":"Vulnerability found by Security Center","desc":"A vulnerability seen across the protected machines, keyed by its type and name. The counts break the affected machines down by remediation urgency, so asapCount is the number that Security Center judges must be fixed immediately.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Security Center","desc":"Threat detection and posture management for the account. Exposes the subscription edition and quota, the protected machines and whether their agents are reporting, the vulnerabilities and baseline check failures found across them, and the alerts raised by threat detection.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.alarmEvent":{"id":"alicloud.sas.alarmEvent","name":"alicloud.sas.alarmEvent","fields":{"alarmEventName":{"name":"alarmEventName","type":"\u0007","is_mandatory":true,"title":"Alert name","provider":"go.mondoo.com/mql/providers/alicloud"},"alarmEventType":{"name":"alarmEventType","type":"\u0007","is_mandatory":true,"title":"Alert type","provider":"go.mondoo.com/mql/providers/alicloud"},"autoBreaking":{"name":"autoBreaking","type":"\u0004","is_mandatory":true,"title":"Whether the alert triggered automatic containment","provider":"go.mondoo.com/mql/providers/alicloud"},"canBeDealOnLine":{"name":"canBeDealOnLine","type":"\u0004","is_mandatory":true,"title":"Whether the alert can be handled from the console","provider":"go.mondoo.com/mql/providers/alicloud"},"containerId":{"name":"containerId","type":"\u0007","is_mandatory":true,"title":"ID of the affected container","provider":"go.mondoo.com/mql/providers/alicloud"},"containerImageName":{"name":"containerImageName","type":"\u0007","is_mandatory":true,"title":"Image the affected container was started from","provider":"go.mondoo.com/mql/providers/alicloud"},"dataSource":{"name":"dataSource","type":"\u0007","is_mandatory":true,"title":"Detection engine that raised the alert","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of what was detected","provider":"go.mondoo.com/mql/providers/alicloud"},"eventStatus":{"name":"eventStatus","type":"\u0005","is_mandatory":true,"title":"Handling state of the alert","desc":"A non-zero value marks the alert as still outstanding.","provider":"go.mondoo.com/mql/providers/alicloud"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Event ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the affected instance","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Name of the affected instance","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address of the affected machine","provider":"go.mondoo.com/mql/providers/alicloud"},"intranetIp":{"name":"intranetIp","type":"\u0007","is_mandatory":true,"title":"Private IP address of the affected machine","provider":"go.mondoo.com/mql/providers/alicloud"},"k8sClusterId":{"name":"k8sClusterId","type":"\u0007","is_mandatory":true,"title":"ID of the Kubernetes cluster the alert came from","provider":"go.mondoo.com/mql/providers/alicloud"},"k8sNamespace":{"name":"k8sNamespace","type":"\u0007","is_mandatory":true,"title":"Kubernetes namespace the alert came from","provider":"go.mondoo.com/mql/providers/alicloud"},"k8sPodName":{"name":"k8sPodName","type":"\u0007","is_mandatory":true,"title":"Kubernetes pod the alert came from","provider":"go.mondoo.com/mql/providers/alicloud"},"lastTime":{"name":"lastTime","type":"\t","is_mandatory":true,"title":"Time the activity behind the alert was last seen","provider":"go.mondoo.com/mql/providers/alicloud"},"level":{"name":"level","type":"\u0007","is_mandatory":true,"title":"Alert severity","desc":"One of serious, suspicious, or remind.","provider":"go.mondoo.com/mql/providers/alicloud"},"machine":{"name":"machine","type":"\u001balicloud.sas.machine","title":"Machine the alert was raised against","desc":"Null when the alert carries no asset UUID, which is the case for alerts raised against the account rather than a specific machine.","provider":"go.mondoo.com/mql/providers/alicloud"},"occurrenceTime":{"name":"occurrenceTime","type":"\t","is_mandatory":true,"title":"Time the activity behind the alert first occurred","provider":"go.mondoo.com/mql/providers/alicloud"},"stages":{"name":"stages","type":"\u0007","is_mandatory":true,"title":"Attack stages the alert maps to","provider":"go.mondoo.com/mql/providers/alicloud"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Security Center asset UUID of the affected machine","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alert raised by Security Center threat detection","desc":"A single alert, keyed by its event ID. Exposes what was detected, where, and whether it has been handled, along with the container and Kubernetes context when the alert came from a containerized workload.","min_provider_version":"13.2.5","defaults":"alarmEventName level eventStatus instanceName","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.baselineCheck":{"id":"alicloud.sas.baselineCheck","name":"alicloud.sas.baselineCheck","fields":{"checkCount":{"name":"checkCount","type":"\u0005","is_mandatory":true,"title":"Number of times the check has been run","provider":"go.mondoo.com/mql/providers/alicloud"},"checkExploit":{"name":"checkExploit","type":"\u0004","is_mandatory":true,"title":"Whether a known exploit exists for the condition the check detects","provider":"go.mondoo.com/mql/providers/alicloud"},"containerRisk":{"name":"containerRisk","type":"\u0004","is_mandatory":true,"title":"Whether the check applies to container workloads","provider":"go.mondoo.com/mql/providers/alicloud"},"databaseRisk":{"name":"databaseRisk","type":"\u0004","is_mandatory":true,"title":"Whether the check applies to databases","provider":"go.mondoo.com/mql/providers/alicloud"},"highWarningCount":{"name":"highWarningCount","type":"\u0005","is_mandatory":true,"title":"Number of high-severity failures of the check","provider":"go.mondoo.com/mql/providers/alicloud"},"lastFoundTime":{"name":"lastFoundTime","type":"\t","is_mandatory":true,"title":"Time the failure was last observed","provider":"go.mondoo.com/mql/providers/alicloud"},"level":{"name":"level","type":"\u0007","is_mandatory":true,"title":"Severity of the check","desc":"One of high, medium, or low.","provider":"go.mondoo.com/mql/providers/alicloud"},"lowWarningCount":{"name":"lowWarningCount","type":"\u0005","is_mandatory":true,"title":"Number of low-severity failures of the check","provider":"go.mondoo.com/mql/providers/alicloud"},"mediumWarningCount":{"name":"mediumWarningCount","type":"\u0005","is_mandatory":true,"title":"Number of medium-severity failures of the check","provider":"go.mondoo.com/mql/providers/alicloud"},"riskId":{"name":"riskId","type":"\u0005","is_mandatory":true,"title":"Baseline check ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"riskName":{"name":"riskName","type":"\u0007","is_mandatory":true,"title":"Name of the baseline check","provider":"go.mondoo.com/mql/providers/alicloud"},"subTypeAlias":{"name":"subTypeAlias","type":"\u0007","is_mandatory":true,"title":"Subcategory of the baseline check","provider":"go.mondoo.com/mql/providers/alicloud"},"typeAlias":{"name":"typeAlias","type":"\u0007","is_mandatory":true,"title":"Category of the baseline check","provider":"go.mondoo.com/mql/providers/alicloud"},"warningMachineCount":{"name":"warningMachineCount","type":"\u0005","is_mandatory":true,"title":"Number of machines currently failing the check","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Baseline check failure found by Security Center","desc":"A configuration baseline check that machines are failing, keyed by riskId. Exposes how many machines fail the check and the severity split of those failures, so a check with a high warningMachineCount is a systemic misconfiguration rather than a one-off.","min_provider_version":"13.2.5","defaults":"riskName level warningMachineCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.machine":{"id":"alicloud.sas.machine","name":"alicloud.sas.machine","fields":{"alarmStatus":{"name":"alarmStatus","type":"\u0007","is_mandatory":true,"title":"Whether the machine has outstanding alerts","provider":"go.mondoo.com/mql/providers/alicloud"},"assetTypeName":{"name":"assetTypeName","type":"\u0007","is_mandatory":true,"title":"Asset type, for example ECS or a non-Alibaba Cloud server","provider":"go.mondoo.com/mql/providers/alicloud"},"authVersionName":{"name":"authVersionName","type":"\u0007","is_mandatory":true,"title":"Protection edition applied to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"bind":{"name":"bind","type":"\u0004","is_mandatory":true,"title":"Whether the machine is bound to the Security Center subscription","desc":"False when the machine falls outside the purchased asset quota, so its findings are reported but protection is not applied.","provider":"go.mondoo.com/mql/providers/alicloud"},"clientStatus":{"name":"clientStatus","type":"\u0007","is_mandatory":true,"title":"Security Center agent state","desc":"Online when the agent is reporting, Offline when it has stopped, and Uninstalled when no agent is present. Anything other than Online means the machine is in the inventory without being protected.","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterId":{"name":"clusterId","type":"\u0007","is_mandatory":true,"title":"ID of the Kubernetes cluster the machine belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the machine was added to the inventory","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the machine","desc":"Null when the machine is not an Alibaba Cloud ECS instance, which is the case for servers onboarded from another cloud or from on-premises.","provider":"go.mondoo.com/mql/providers/alicloud"},"exposedStatus":{"name":"exposedStatus","type":"\u0005","is_mandatory":true,"title":"Whether the machine is exposed to the internet","desc":"Non-zero when Security Center's exposure analysis found an internet-facing path to the machine.","provider":"go.mondoo.com/mql/providers/alicloud"},"groupTrace":{"name":"groupTrace","type":"\u0007","is_mandatory":true,"title":"Group the machine is filed under in the Security Center console","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckCount":{"name":"healthCheckCount","type":"\u0005","is_mandatory":true,"title":"Number of baseline check failures on the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"importance":{"name":"importance","type":"\u0005","is_mandatory":true,"title":"Asset importance, where higher values mark more critical assets","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the underlying instance","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Name of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address of the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"intranetIp":{"name":"intranetIp","type":"\u0007","is_mandatory":true,"title":"Private IP address of the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"lastLoginTime":{"name":"lastLoginTime","type":"\t","is_mandatory":true,"title":"Time of the last recorded sign-in to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"os":{"name":"os","type":"\u0007","is_mandatory":true,"title":"Operating system family, for example linux or windows","provider":"go.mondoo.com/mql/providers/alicloud"},"osName":{"name":"osName","type":"\u0007","is_mandatory":true,"title":"Operating system name and version","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the machine runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"riskCount":{"name":"riskCount","type":"\u0007","is_mandatory":true,"title":"Number of outstanding risks attributed to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"riskStatus":{"name":"riskStatus","type":"\u0007","is_mandatory":true,"title":"Whether the machine has outstanding risks","provider":"go.mondoo.com/mql/providers/alicloud"},"safeEventCount":{"name":"safeEventCount","type":"\u0005","is_mandatory":true,"title":"Number of security events recorded against the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Security Center asset UUID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vendorName":{"name":"vendorName","type":"\u0007","is_mandatory":true,"title":"Cloud vendor hosting the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"vulCount":{"name":"vulCount","type":"\u0005","is_mandatory":true,"title":"Number of unfixed vulnerabilities attributed to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"vulStatus":{"name":"vulStatus","type":"\u0007","is_mandatory":true,"title":"Whether the machine has outstanding vulnerabilities","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Machine protected by Security Center","desc":"A single asset in the Security Center inventory, keyed by uuid. Exposes the agent state, the vulnerability and risk counts attributed to the machine, and its network addresses. The clientStatus field is the coverage audit: an offline or unbound agent means the machine is in the inventory but not actually being protected.","min_provider_version":"13.2.5","defaults":"instanceName clientStatus vulCount riskCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.vulnerability":{"id":"alicloud.sas.vulnerability","name":"alicloud.sas.vulnerability","fields":{"aliasName":{"name":"aliasName","type":"\u0007","is_mandatory":true,"title":"Human-readable vulnerability title","provider":"go.mondoo.com/mql/providers/alicloud"},"asapCount":{"name":"asapCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines Security Center rates fix-immediately","provider":"go.mondoo.com/mql/providers/alicloud"},"handledCount":{"name":"handledCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines where the vulnerability has been handled","provider":"go.mondoo.com/mql/providers/alicloud"},"lastFoundTime":{"name":"lastFoundTime","type":"\t","is_mandatory":true,"title":"Time the vulnerability was last seen","provider":"go.mondoo.com/mql/providers/alicloud"},"laterCount":{"name":"laterCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines Security Center rates fix-later","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Vulnerability identifier, for example a CVE or advisory ID","provider":"go.mondoo.com/mql/providers/alicloud"},"nntfCount":{"name":"nntfCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines Security Center rates no-fix-required","provider":"go.mondoo.com/mql/providers/alicloud"},"raspDefend":{"name":"raspDefend","type":"\u0005","is_mandatory":true,"title":"Whether application self-protection can defend the vulnerability at runtime","desc":"Non-zero when runtime defense covers the vulnerability, which mitigates it without a patch.","provider":"go.mondoo.com/mql/providers/alicloud"},"related":{"name":"related","type":"\u0007","is_mandatory":true,"title":"Related vulnerability identifiers","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u0007","is_mandatory":true,"title":"Tags describing the vulnerability, for example whether an exploit exists","provider":"go.mondoo.com/mql/providers/alicloud"},"totalFixCount":{"name":"totalFixCount","type":"\u0005","is_mandatory":true,"title":"Total number of successful fixes recorded for the vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Vulnerability category","desc":"One of cve for Linux software vulnerabilities, sys for Windows system vulnerabilities, cms for web content management vulnerabilities, app for application vulnerabilities, emg for urgent vulnerabilities, or sca for software component analysis findings.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Vulnerability found by Security Center","desc":"A vulnerability seen across the protected machines, keyed by its type and name. The counts break the affected machines down by remediation urgency, so asapCount is the number that Security Center judges must be fixed immediately.","min_provider_version":"13.2.5","defaults":"name aliasName type asapCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb":{"id":"alicloud.slb","name":"alicloud.slb","fields":{"backendServer":{"name":"backendServer","type":"\u001balicloud.slb.backendServer","title":"CLB backend server","desc":"One server a CLB forwards traffic to, whether attached directly to the load balancer or through a vServer group. An internet-facing CLB makes its backends reachable from the public internet on the listener's port, regardless of what the backend's own security groups say about its address, which is why the load balancer and not the instance is where that exposure becomes visible.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"listener":{"name":"listener","type":"\u001balicloud.slb.listener","title":"Server Load Balancer (CLB) listener","desc":"A single listener configured on a CLB instance, keyed by the composite of loadBalancerId, protocol, and listenerPort. Exposes the protocol and port mapping, the scheduling algorithm, the access-control (ACL) settings, and, for HTTPS listeners, the TLS cipher policy and the server and CA certificates. Protocol-specific health-check and forwarding settings are available through config.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.slb.loadBalancer","title":"Server Load Balancer (CLB) instance","desc":"A single Classic Load Balancer instance, keyed by loadBalancerId (for example lb-bp1b6c719dfa08ex). Exposes the instance addressing and network placement, the internet or intranet exposure signalled by addressType, the billing and specification settings, the deletion and modification protection flags, and the configured listeners and backend servers.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001balicloud.slb.loadBalancer","title":"CLB instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroup":{"name":"vServerGroup","type":"\u001balicloud.slb.vServerGroup","title":"CLB vServer group","desc":"A named set of backend servers that a CLB listener or forwarding rule sends traffic to, keyed by vServerGroupId. A group lets one load balancer serve several backend sets, so the servers behind a listener are found here rather than on the load balancer itself.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Server Load Balancer","desc":"Classic Load Balancer (CLB) resources in an Alibaba Cloud account. Exposes the CLB instances discovered across every enabled region through loadBalancers, from which listeners, backend servers, addressing, and protection settings can be audited.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.backendServer":{"id":"alicloud.slb.backendServer","name":"alicloud.slb.backendServer","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Backend server description","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the backend","desc":"Null when the backend is an elastic network interface or the instance can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the load balancer forwards to","desc":"Zero for a backend attached directly to the load balancer, where the port comes from the listener instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"ID of the backend server","desc":"An ECS instance ID or an elastic network interface ID, depending on type.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverIp":{"name":"serverIp","type":"\u0007","is_mandatory":true,"title":"IP address the load balancer forwards to","desc":"Set when the backend is an elastic network interface or is addressed by IP.","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Kind of backend","desc":"Either ecs for an instance or eni for an elastic network interface.","provider":"go.mondoo.com/mql/providers/alicloud"},"weight":{"name":"weight","type":"\u0005","is_mandatory":true,"title":"Share of traffic the server receives","desc":"A weight of 0 takes the server out of rotation without detaching it.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CLB backend server","desc":"One server a CLB forwards traffic to, whether attached directly to the load balancer or through a vServer group. An internet-facing CLB makes its backends reachable from the public internet on the listener's port, regardless of what the backend's own security groups say about its address, which is why the load balancer and not the instance is where that exposure becomes visible.","min_provider_version":"13.4.1","defaults":"type serverId serverIp port weight","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.listener":{"id":"alicloud.slb.listener","name":"alicloud.slb.listener","fields":{"aclId":{"name":"aclId","type":"\u0007","is_mandatory":true,"title":"ID of the access control list bound to the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"aclIds":{"name":"aclIds","type":"\u0019\u0007","is_mandatory":true,"title":"IDs of the access control lists bound to the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"aclStatus":{"name":"aclStatus","type":"\u0007","is_mandatory":true,"title":"Whether access control is enabled for the listener","desc":"One of on or off.","provider":"go.mondoo.com/mql/providers/alicloud"},"aclType":{"name":"aclType","type":"\u0007","is_mandatory":true,"title":"Type of access control applied when aclStatus is on","desc":"One of white (only requests from allowlisted addresses are forwarded) or black (requests from blocklisted addresses are denied).","provider":"go.mondoo.com/mql/providers/alicloud"},"backendServerPort":{"name":"backendServerPort","type":"\u0005","is_mandatory":true,"title":"Backend server port that the listener forwards requests to","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Maximum bandwidth of the listener, in Mbit/s (-1 indicates unlimited)","provider":"go.mondoo.com/mql/providers/alicloud"},"caCertificateId":{"name":"caCertificateId","type":"\u0007","is_mandatory":true,"title":"ID of the CA certificate used for mutual TLS on an HTTPS listener","provider":"go.mondoo.com/mql/providers/alicloud"},"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Protocol-specific listener configuration","desc":"The health-check, session-persistence, connection-drain, and request-header settings for the listener. The available keys vary by protocol (HTTP, HTTPS, TCP, or UDP).","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"enableHttp2":{"name":"enableHttp2","type":"\u0007","is_mandatory":true,"title":"Whether HTTP/2 is enabled on an HTTPS listener","desc":"One of on or off. Null for non-HTTPS listeners.","provider":"go.mondoo.com/mql/providers/alicloud"},"listenerPort":{"name":"listenerPort","type":"\u0005","is_mandatory":true,"title":"Frontend port on which the listener accepts requests","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.slb.loadBalancer","title":"CLB instance that the listener belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the CLB instance that the listener belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Protocol used by the listener","desc":"One of http, https, tcp, or udp.","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduler":{"name":"scheduler","type":"\u0007","is_mandatory":true,"title":"Scheduling algorithm used to distribute requests","desc":"One of wrr (weighted round-robin), rr (round-robin), sch (source-IP consistent hashing), tch (four-tuple consistent hashing), or qch (QUIC-ID consistent hashing).","provider":"go.mondoo.com/mql/providers/alicloud"},"serverCertificateId":{"name":"serverCertificateId","type":"\u0007","is_mandatory":true,"title":"ID of the server certificate bound to an HTTPS listener","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the listener","desc":"One of running or stopped.","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsCipherPolicy":{"name":"tlsCipherPolicy","type":"\u0007","is_mandatory":true,"title":"TLS security policy applied to an HTTPS listener","desc":"One of tls_cipher_policy_1_0, tls_cipher_policy_1_1, tls_cipher_policy_1_2, tls_cipher_policy_1_2_strict, or tls_cipher_policy_1_2_strict_with_1_3, each enabling a different set of TLS versions and cipher suites. Null for non-HTTPS listeners.","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroup":{"name":"vServerGroup","type":"\u001balicloud.slb.vServerGroup","title":"vServer group the listener forwards to","desc":"Null when the listener forwards to the load balancer's default backend servers rather than a group.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroupId":{"name":"vServerGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the vServer group associated with the listener","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Server Load Balancer (CLB) listener","desc":"A single listener configured on a CLB instance, keyed by the composite of loadBalancerId, protocol, and listenerPort. Exposes the protocol and port mapping, the scheduling algorithm, the access-control (ACL) settings, and, for HTTPS listeners, the TLS cipher policy and the server and CA certificates. Protocol-specific health-check and forwarding settings are available through config.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.loadBalancer":{"id":"alicloud.slb.loadBalancer","name":"alicloud.slb.loadBalancer","fields":{"address":{"name":"address","type":"\u0007","is_mandatory":true,"title":"Service IP address that the CLB instance uses to provide services","provider":"go.mondoo.com/mql/providers/alicloud"},"addressIPVersion":{"name":"addressIPVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the service address","desc":"One of ipv4 or ipv6.","provider":"go.mondoo.com/mql/providers/alicloud"},"addressType":{"name":"addressType","type":"\u0007","is_mandatory":true,"title":"Network exposure of the CLB instance","desc":"One of internet (a public IP address is assigned and requests are forwarded over the internet) or intranet (a private IP address is assigned and requests are forwarded only over internal networks).","provider":"go.mondoo.com/mql/providers/alicloud"},"backendServers":{"name":"backendServers","type":"\u0019\n","title":"Backend server summaries","desc":"Deprecated in favor of backends. Each entry carries the serverId, serverIp, weight, type (ecs or eni), and an optional description.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"backends":{"name":"backends","type":"\u0019\u001balicloud.slb.backendServer","title":"Backend servers attached directly to the CLB instance","desc":"What the load balancer forwards to. An internet-facing CLB makes every one of these reachable from the public internet on the listener's port, whatever the backend's own security groups say about its address.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Maximum bandwidth of a pay-by-bandwidth internet-facing instance, in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the CLB instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteProtection":{"name":"deleteProtection","type":"\u0007","is_mandatory":true,"title":"Whether deletion protection is enabled","desc":"One of on or off.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method of the CLB instance","desc":"One of PayBySpec or PayByCLCU. Takes effect only for pay-as-you-go instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method of internet data transfer","desc":"One of paybybandwidth (pay-by-bandwidth) or paybytraffic (pay-by-data-transfer).","provider":"go.mondoo.com/mql/providers/alicloud"},"internetFacing":{"name":"internetFacing","type":"\u0004","title":"Whether the load balancer is reachable from the internet","desc":"True when addressType is internet, meaning the CLB has a public IP address and forwards requests from the public internet to its backend servers.","provider":"go.mondoo.com/mql/providers/alicloud"},"listeners":{"name":"listeners","type":"\u0019\u001balicloud.slb.listener","title":"Listeners configured on the CLB instance","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"CLB instance ID, for example lb-bp1b6c719dfa08ex","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerName":{"name":"loadBalancerName","type":"\u0007","is_mandatory":true,"title":"Name of the CLB instance","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerSpec":{"name":"loadBalancerSpec","type":"\u0007","is_mandatory":true,"title":"Specification of the CLB instance, for example slb.s1.small","desc":"Pay-as-you-go instances are not subject to specifications and report slb.lcu.elastic by default.","provider":"go.mondoo.com/mql/providers/alicloud"},"masterZoneId":{"name":"masterZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the primary zone, for example cn-hangzhou-b","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionReason":{"name":"modificationProtectionReason","type":"\u0007","is_mandatory":true,"title":"Reason recorded when the configuration read-only mode is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionStatus":{"name":"modificationProtectionStatus","type":"\u0007","is_mandatory":true,"title":"Whether the configuration read-only (modification protection) mode is enabled","desc":"One of NonProtection (disabled) or ConsoleProtection (enabled, instance configuration cannot be changed in the console).","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type of an internal-facing CLB instance","desc":"One of vpc or classic.","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method of the CLB instance","desc":"One of PayOnDemand (pay-as-you-go) or PrePay (subscription).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID where the CLB instance is deployed, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the load balancer","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group that the CLB instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"slaveZoneId":{"name":"slaveZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the secondary zone, for example cn-hangzhou-d","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the CLB instance","desc":"One of active (running as expected), inactive (disabled, does not forward traffic), or locked (locked, for example after expiration or non-payment).","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the CLB instance, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroups":{"name":"vServerGroups","type":"\u0019\u001balicloud.slb.vServerGroup","title":"vServer groups defined on the CLB instance","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC that the CLB instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch that the CLB instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Server Load Balancer (CLB) instance","desc":"A single Classic Load Balancer instance, keyed by loadBalancerId (for example lb-bp1b6c719dfa08ex). Exposes the instance addressing and network placement, the internet or intranet exposure signalled by addressType, the billing and specification settings, the deletion and modification protection flags, and the configured listeners and backend servers.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.vServerGroup":{"id":"alicloud.slb.vServerGroup","name":"alicloud.slb.vServerGroup","fields":{"backends":{"name":"backends","type":"\u0019\u001balicloud.slb.backendServer","title":"Backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the CLB instance the group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the group lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"serverCount":{"name":"serverCount","type":"\u0005","is_mandatory":true,"title":"Number of backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the group","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroupId":{"name":"vServerGroupId","type":"\u0007","is_mandatory":true,"title":"vServer group ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroupName":{"name":"vServerGroupName","type":"\u0007","is_mandatory":true,"title":"vServer group name","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CLB vServer group","desc":"A named set of backend servers that a CLB listener or forwarding rule sends traffic to, keyed by vServerGroupId. A group lets one load balancer serve several backend sets, so the servers behind a listener are found here rather than on the load balancer itself.","min_provider_version":"13.4.1","defaults":"vServerGroupName vServerGroupId serverCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc":{"id":"alicloud.vpc","name":"alicloud.vpc","fields":{"eipAddress":{"name":"eipAddress","type":"\u001balicloud.vpc.eipAddress","title":"Elastic IP address (EIP)","desc":"A single elastic IP address, keyed by allocationId, for example eip-2zeerraiwb7uabc. Exposes the public IP address, the bandwidth and billing configuration, the ISP line, the lifecycle status, and the instance the EIP is bound to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"eipAddresses":{"name":"eipAddresses","type":"\u0019\u001balicloud.vpc.eipAddress","title":"Elastic IP addresses across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLog":{"name":"flowLog","type":"\u001balicloud.vpc.flowLog","title":"VPC flow log","desc":"A single flow log that captures traffic metadata for a VPC, vSwitch, or elastic network interface, keyed by flowLogId within its region. Exposes the monitored resource, the traffic direction and path captured, and the Log Service project and logstore that receive the records. Use it to audit whether flow logging is enabled for a network and where the records are delivered. For example `alicloud.vpc.flowLog(flowLogId: \"fl-xxx\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"flowLogs":{"name":"flowLogs","type":"\u0019\u001balicloud.vpc.flowLog","title":"Flow logs across all enabled regions","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"natGateway":{"name":"natGateway","type":"\u001balicloud.vpc.natGateway","title":"VPC NAT gateway","desc":"A single NAT gateway, keyed by natGatewayId, for example ngw-bp1uewa15k4abc. Exposes the specification, the NAT type and network type, the lifecycle and billing status, the SNAT and DNAT table IDs, and the private-network placement.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"natGateways":{"name":"natGateways","type":"\u0019\u001balicloud.vpc.natGateway","title":"NAT gateways across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"network":{"name":"network","type":"\u001balicloud.vpc.network","title":"Virtual Private Cloud network","desc":"A single VPC, keyed by vpcId, for example vpc-bp1qpo0kug3a20qqe0abc. Exposes the primary and secondary CIDR blocks, the IPv6 configuration, the lifecycle status, the default-VPC flag, the vRouter, and the vSwitches, route tables, and NAT gateways associated with the network.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"networkAcl":{"name":"networkAcl","type":"\u001balicloud.vpc.networkAcl","title":"VPC network ACL","desc":"A single network ACL, keyed by networkAclId, for example nacl-a2do9e413e0spzasx. Exposes the lifecycle status, the ingress and egress rule entries, and the vSwitches the ACL is bound to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"networkAcls":{"name":"networkAcls","type":"\u0019\u001balicloud.vpc.networkAcl","title":"Network ACLs across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"networks":{"name":"networks","type":"\u0019\u001balicloud.vpc.network","title":"VPC networks across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTable":{"name":"routeTable","type":"\u001balicloud.vpc.routeTable","title":"VPC route table","desc":"A single route table, keyed by routeTableId, for example vtb-bp1e123abc. Exposes the route table type, the bound vSwitches and gateways, the lifecycle status, and the individual route entries through routeEntries.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"routeTables":{"name":"routeTables","type":"\u0019\u001balicloud.vpc.routeTable","title":"Route tables across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnConnection":{"name":"vpnConnection","type":"\u001balicloud.vpc.vpnConnection","title":"VPN connection","desc":"A single IPsec tunnel terminating on a VPN gateway, keyed by vpnConnectionId. The local and remote subnets are the reachability this connection creates: traffic from the remote subnet reaches the local one without crossing an internet gateway. The negotiated algorithms and lifetimes are exposed so weak cipher suites can be found, but the pre-shared key is deliberately not.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpnConnections":{"name":"vpnConnections","type":"\u0019\u001balicloud.vpc.vpnConnection","title":"VPN connections across all enabled regions","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGateway":{"name":"vpnGateway","type":"\u001balicloud.vpc.vpnGateway","title":"VPN gateway","desc":"A VPN gateway attached to a VPC, keyed by vpnGatewayId. Exposes the IPsec and SSL capabilities, the public address traffic arrives on, and the connections terminating on it. A gateway is how traffic reaches the VPC from outside Alibaba Cloud, so its connections describe reachability that security groups alone do not explain.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpnGateways":{"name":"vpnGateways","type":"\u0019\u001balicloud.vpc.vpnGateway","title":"VPN gateways across all enabled regions","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch (VPC subnet)","desc":"A single vSwitch, keyed by vSwitchId, for example vsw-25bcdxs7pv1abc. Exposes the CIDR blocks, the zone, the number of free IP addresses, the associated route table and network ACL, and the parent VPC.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches (subnets) across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Virtual Private Cloud (VPC)","desc":"Entry point for the Alibaba Cloud VPC networking service. Exposes the VPCs, vSwitches, route tables, NAT gateways, elastic IP addresses, and network ACLs defined across every enabled region on the account.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.eipAddress":{"id":"alicloud.vpc.eipAddress","name":"alicloud.vpc.eipAddress","fields":{"allocationId":{"name":"allocationId","type":"\u0007","is_mandatory":true,"title":"Allocation ID of the EIP, for example eip-2zeerraiwb7uabc","provider":"go.mondoo.com/mql/providers/alicloud"},"allocationTime":{"name":"allocationTime","type":"\t","is_mandatory":true,"title":"Time when the EIP was allocated","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0007","is_mandatory":true,"title":"Peak bandwidth of the EIP in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageBandwidth":{"name":"bandwidthPackageBandwidth","type":"\u0007","is_mandatory":true,"title":"Maximum bandwidth of the bandwidth plan in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageId":{"name":"bandwidthPackageId","type":"\u0007","is_mandatory":true,"title":"ID of the bandwidth plan (shared bandwidth) the EIP joined","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageType":{"name":"bandwidthPackageType","type":"\u0007","is_mandatory":true,"title":"Type of the bandwidth plan the EIP joined","provider":"go.mondoo.com/mql/providers/alicloud"},"bizType":{"name":"bizType","type":"\u0007","is_mandatory":true,"title":"Business type of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (payment) status of the EIP","desc":"One of Normal or FinancialLocked.","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the EIP","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"eipBandwidth":{"name":"eipBandwidth","type":"\u0007","is_mandatory":true,"title":"Maximum bandwidth of the EIP in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"expiredTime":{"name":"expiredTime","type":"\t","is_mandatory":true,"title":"Time when the EIP expires","provider":"go.mondoo.com/mql/providers/alicloud"},"hasReservationData":{"name":"hasReservationData","type":"\u0007","is_mandatory":true,"title":"Whether the EIP has renewal (reservation) data","provider":"go.mondoo.com/mql/providers/alicloud"},"hdMonitorStatus":{"name":"hdMonitorStatus","type":"\u0007","is_mandatory":true,"title":"High-definition monitoring status of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance the EIP is bound to","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceRegionId":{"name":"instanceRegionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the instance the EIP is bound to","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Type of the instance the EIP is bound to","desc":"One of EcsInstance, SlbInstance, Nat, HaVip, NetworkInterface, or IpAddress.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method for internet data transfer","desc":"One of PayByBandwidth or PayByTraffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipAddress":{"name":"ipAddress","type":"\u0007","is_mandatory":true,"title":"Public IP address of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"isp":{"name":"isp","type":"\u0007","is_mandatory":true,"title":"ISP line of the EIP","desc":"One of BGP, BGP_PRO, ChinaTelecom, ChinaUnicom, or ChinaMobile.","provider":"go.mondoo.com/mql/providers/alicloud"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Association mode of the EIP","desc":"One of NAT, MULTI_BINDED, or BINDED.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"netmode":{"name":"netmode","type":"\u0007","is_mandatory":true,"title":"Network mode of the EIP","desc":"One of public or a private network mode.","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIpAddress":{"name":"privateIpAddress","type":"\u0007","is_mandatory":true,"title":"Private IP address of the instance the EIP is bound to","provider":"go.mondoo.com/mql/providers/alicloud"},"publicIpAddressPoolId":{"name":"publicIpAddressPoolId","type":"\u0007","is_mandatory":true,"title":"ID of the IP address pool the EIP was drawn from","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the elastic IP address","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"secondLimited":{"name":"secondLimited","type":"\u0004","is_mandatory":true,"title":"Whether second-level (fine-grained) monitoring is limited","provider":"go.mondoo.com/mql/providers/alicloud"},"securityProtectionTypes":{"name":"securityProtectionTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Firewall (security protection) types enabled on the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"segmentInstanceId":{"name":"segmentInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the contiguous EIP group the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"serviceManaged":{"name":"serviceManaged","type":"\u0005","is_mandatory":true,"title":"Whether the EIP is managed by an Alibaba Cloud service","desc":"0 indicates the EIP is user-managed, 1 indicates it is managed by a service.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Associating, Unassociating, InUse, or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the EIP is associated with","provider":"go.mondoo.com/mql/providers/alicloud"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Zone the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic IP address (EIP)","desc":"A single elastic IP address, keyed by allocationId, for example eip-2zeerraiwb7uabc. Exposes the public IP address, the bandwidth and billing configuration, the ISP line, the lifecycle status, and the instance the EIP is bound to.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.flowLog":{"id":"alicloud.vpc.flowLog","name":"alicloud.vpc.flowLog","fields":{"aggregationInterval":{"name":"aggregationInterval","type":"\u0005","is_mandatory":true,"title":"Interval in seconds over which records are aggregated, for example 600","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (billing) state of the flow log","desc":"For example Normal, or FinancialLocked when the flow log is locked for overdue payment.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the flow log was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deliverErrorMessage":{"name":"deliverErrorMessage","type":"\u0007","is_mandatory":true,"title":"Most recent delivery error, empty when delivery is healthy","provider":"go.mondoo.com/mql/providers/alicloud"},"deliverStatus":{"name":"deliverStatus","type":"\u0007","is_mandatory":true,"title":"Delivery state of the records to Log Service","desc":"For example FlowLogDeliverStarted when records are being delivered, or a failure state when delivery is not succeeding.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the flow log","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLogId":{"name":"flowLogId","type":"\u0007","is_mandatory":true,"title":"Flow log ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLogName":{"name":"flowLogName","type":"\u0007","is_mandatory":true,"title":"Flow log name","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version captured","desc":"One of IPv4, IPv6, or all.","provider":"go.mondoo.com/mql/providers/alicloud"},"logStoreName":{"name":"logStoreName","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service logstore that receives the records","provider":"go.mondoo.com/mql/providers/alicloud"},"logstore":{"name":"logstore","type":"\u001balicloud.log.logstore","title":"Log Service logstore that receives the records","provider":"go.mondoo.com/mql/providers/alicloud"},"network":{"name":"network","type":"\u001balicloud.vpc.network","title":"VPC network monitored by the flow log","desc":"Null when the monitored resource is a vSwitch or an elastic network interface rather than a VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Log Service project that receives the records","desc":"Null when the flow log names no project, and when the project lives in another account that the scan cannot read.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service project that receives the records","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the flow log resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the flow log","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the flow log belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceId":{"name":"resourceId","type":"\u0007","is_mandatory":true,"title":"ID of the monitored resource (a VPC, vSwitch, or elastic network interface)","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceType":{"name":"resourceType","type":"\u0007","is_mandatory":true,"title":"Type of the monitored resource","desc":"One of VPC, VSwitch, or NetworkInterface.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Flow log state","desc":"One of Active or Inactive. A flow log only captures traffic while Active.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the flow log","provider":"go.mondoo.com/mql/providers/alicloud"},"trafficPath":{"name":"trafficPath","type":"\u0019\u0007","is_mandatory":true,"title":"Traffic path captured","desc":"The network paths the flow log records, for example full for all paths or a subset such as internetGateway. Empty when no path filter is applied.","provider":"go.mondoo.com/mql/providers/alicloud"},"trafficType":{"name":"trafficType","type":"\u0007","is_mandatory":true,"title":"Traffic direction captured","desc":"One of All, Allow (accepted traffic), or Drop (rejected traffic).","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch monitored by the flow log","desc":"Null when the monitored resource is a VPC or an elastic network interface rather than a vSwitch.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC flow log","desc":"A single flow log that captures traffic metadata for a VPC, vSwitch, or elastic network interface, keyed by flowLogId within its region. Exposes the monitored resource, the traffic direction and path captured, and the Log Service project and logstore that receive the records. Use it to audit whether flow logging is enabled for a network and where the records are delivered. For example `alicloud.vpc.flowLog(flowLogId: \"fl-xxx\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.natGateway":{"id":"alicloud.vpc.natGateway","name":"alicloud.vpc.natGateway","fields":{"accessMode":{"name":"accessMode","type":"\n","is_mandatory":true,"title":"Access mode of the NAT gateway","desc":"Carries modeValue and tunnelType.","provider":"go.mondoo.com/mql/providers/alicloud"},"autoPay":{"name":"autoPay","type":"\u0004","is_mandatory":true,"title":"Whether the order is automatically paid for a subscription NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (payment) status of the NAT gateway","desc":"One of Normal or FinancialLocked.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the NAT gateway was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsMetricEnabled":{"name":"ecsMetricEnabled","type":"\u0004","is_mandatory":true,"title":"Whether flow monitoring (ECS metrics) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"eipBindMode":{"name":"eipBindMode","type":"\u0007","is_mandatory":true,"title":"EIP binding mode of the NAT gateway","desc":"One of MULTI_BINDED or NAT.","provider":"go.mondoo.com/mql/providers/alicloud"},"enableSessionLog":{"name":"enableSessionLog","type":"\u0007","is_mandatory":true,"title":"Whether NAT session logging is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"expiredTime":{"name":"expiredTime","type":"\t","is_mandatory":true,"title":"Time when the NAT gateway expires","provider":"go.mondoo.com/mql/providers/alicloud"},"forwardTableIds":{"name":"forwardTableIds","type":"\u0019\u0007","is_mandatory":true,"title":"DNAT (forward) table IDs of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"fullNatTableIds":{"name":"fullNatTableIds","type":"\u0019\u0007","is_mandatory":true,"title":"FULLNAT table IDs of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"icmpReplyEnabled":{"name":"icmpReplyEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the NAT gateway replies to ICMP (ping) requests","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the NAT gateway","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method for internet data transfer","desc":"One of PayByLcu or PayBySpec.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipLists":{"name":"ipLists","type":"\u0019\n","is_mandatory":true,"title":"Elastic IP addresses associated with the NAT gateway","desc":"Each entry carries allocationId, ipAddress, privateIpAddress, snatEntryEnabled, and usingStatus.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"NAT gateway name","provider":"go.mondoo.com/mql/providers/alicloud"},"natGatewayId":{"name":"natGatewayId","type":"\u0007","is_mandatory":true,"title":"NAT gateway ID, for example ngw-bp1uewa15k4abc","provider":"go.mondoo.com/mql/providers/alicloud"},"natGatewayPrivateInfo":{"name":"natGatewayPrivateInfo","type":"\n","is_mandatory":true,"title":"Private-network placement of an enhanced NAT gateway","desc":"Carries vswitchId, privateIpAddress, eniInstanceId, eniType, izNo, maxBandwidth, maxSessionEstablishRate, and maxSessionQuota.","provider":"go.mondoo.com/mql/providers/alicloud"},"natType":{"name":"natType","type":"\u0007","is_mandatory":true,"title":"NAT gateway type","desc":"One of Normal or Enhanced.","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type of the NAT gateway","desc":"One of internet for a public gateway or intranet for a private gateway.","provider":"go.mondoo.com/mql/providers/alicloud"},"privateLinkEnabled":{"name":"privateLinkEnabled","type":"\u0004","is_mandatory":true,"title":"Whether PrivateLink is enabled for the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"privateLinkMode":{"name":"privateLinkMode","type":"\u0007","is_mandatory":true,"title":"PrivateLink mode of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the NAT gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the NAT gateway","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the NAT gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityProtectionEnabled":{"name":"securityProtectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether firewall (security protection) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"snatTableIds":{"name":"snatTableIds","type":"\u0019\u0007","is_mandatory":true,"title":"SNAT table IDs of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"spec":{"name":"spec","type":"\u0007","is_mandatory":true,"title":"Specification of the NAT gateway","desc":"One of Small, Middle, Large, or XLarge.1 for a standard NAT gateway.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Creating, Available, Modifying, Deleting, or Converting.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the NAT gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC NAT gateway","desc":"A single NAT gateway, keyed by natGatewayId, for example ngw-bp1uewa15k4abc. Exposes the specification, the NAT type and network type, the lifecycle and billing status, the SNAT and DNAT table IDs, and the private-network placement.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.network":{"id":"alicloud.vpc.network","name":"alicloud.vpc.network","fields":{"cenStatus":{"name":"cenStatus","type":"\u0007","is_mandatory":true,"title":"Cloud Enterprise Network (CEN) attachment status","desc":"Returned as Attached only when the VPC is attached to a CEN instance.","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlock":{"name":"cidrBlock","type":"\u0007","is_mandatory":true,"title":"Primary IPv4 CIDR block of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlocks":{"name":"cidrBlocks","type":"\u0019\u0007","is_mandatory":true,"title":"Secondary IPv4 CIDR blocks of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the VPC was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"dhcpOptionsSetId":{"name":"dhcpOptionsSetId","type":"\u0007","is_mandatory":true,"title":"DHCP options set ID bound to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"dhcpOptionsSetStatus":{"name":"dhcpOptionsSetStatus","type":"\u0007","is_mandatory":true,"title":"DHCP options set status","desc":"One of Available, InUse, Deleted, or Pending.","provider":"go.mondoo.com/mql/providers/alicloud"},"dnsHostnameStatus":{"name":"dnsHostnameStatus","type":"\u0007","is_mandatory":true,"title":"DNS hostname feature status","desc":"Indicates whether the DNS hostname feature is enabled, for example ENABLED or DISABLED.","provider":"go.mondoo.com/mql/providers/alicloud"},"enabledIpv6":{"name":"enabledIpv6","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 is enabled for the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLogs":{"name":"flowLogs","type":"\u0019\u001balicloud.vpc.flowLog","title":"Flow logs monitoring this VPC","desc":"Flow logs whose monitored resource is the VPC itself. A flow log only captures traffic while its status is Active. Flow logs scoped to a vSwitch or an elastic network interface inside the VPC are not included.","min_provider_version":"13.2.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6CidrBlock":{"name":"ipv6CidrBlock","type":"\u0007","is_mandatory":true,"title":"IPv6 CIDR block of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6CidrBlocks":{"name":"ipv6CidrBlocks","type":"\u0019\n","is_mandatory":true,"title":"IPv6 CIDR blocks with their ISP line type","desc":"Each entry carries the ipv6CidrBlock and its ipv6Isp line type (for example BGP, ChinaMobile, ChinaUnicom, or ChinaTelecom).","provider":"go.mondoo.com/mql/providers/alicloud"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether this is the default VPC in the region","provider":"go.mondoo.com/mql/providers/alicloud"},"natGateways":{"name":"natGateways","type":"\u0019\u001balicloud.vpc.natGateway","title":"NAT gateways attached to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the VPC belongs to, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the VPC","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the VPC belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTables":{"name":"routeTables","type":"\u0019\u001balicloud.vpc.routeTable","title":"Route tables associated with the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"userCidrs":{"name":"userCidrs","type":"\u0019\u0007","is_mandatory":true,"title":"User CIDR blocks associated with the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"vRouterId":{"name":"vRouterId","type":"\u0007","is_mandatory":true,"title":"vRouter ID of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcId":{"name":"vpcId","type":"\u0007","is_mandatory":true,"title":"VPC ID, for example vpc-bp1qpo0kug3a20qqe0abc","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcName":{"name":"vpcName","type":"\u0007","is_mandatory":true,"title":"VPC name","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGateways":{"name":"vpnGateways","type":"\u0019\u001balicloud.vpc.vpnGateway","title":"VPN gateways attached to the VPC","desc":"Each gateway terminates connections that reach the VPC from outside Alibaba Cloud, so this is reachability that security-group rules alone do not explain.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches in the VPC","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Virtual Private Cloud network","desc":"A single VPC, keyed by vpcId, for example vpc-bp1qpo0kug3a20qqe0abc. Exposes the primary and secondary CIDR blocks, the IPv6 configuration, the lifecycle status, the default-VPC flag, the vRouter, and the vSwitches, route tables, and NAT gateways associated with the network.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.networkAcl":{"id":"alicloud.vpc.networkAcl","name":"alicloud.vpc.networkAcl","fields":{"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the network ACL was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the network ACL","provider":"go.mondoo.com/mql/providers/alicloud"},"egressAclEntries":{"name":"egressAclEntries","type":"\u0019\n","is_mandatory":true,"title":"Outbound rule summaries","desc":"Deprecated in favor of egressEntries. Each entry carries protocol, port, destinationCidrIp, policy, description, entryType, ipVersion, networkAclEntryId, and networkAclEntryName.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"egressEntries":{"name":"egressEntries","type":"\u0019\u001balicloud.vpc.networkAcl.entry","is_mandatory":true,"title":"Outbound rules of the network ACL","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"entry":{"name":"entry","type":"\u001balicloud.vpc.networkAcl.entry","title":"Network ACL rule","desc":"A single inbound or outbound rule, keyed by entryId. Network ACLs are evaluated before security groups, so an accept rule here decides what reaches the security groups at all and a drop rule overrides whatever they allow. Ports arrive as a range string such as 22/22 or -1/-1 for every port.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ingressAclEntries":{"name":"ingressAclEntries","type":"\u0019\n","is_mandatory":true,"title":"Inbound rule summaries","desc":"Deprecated in favor of ingressEntries. Each entry carries protocol, port, sourceCidrIp, policy, description, entryType, ipVersion, networkAclEntryId, and networkAclEntryName.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"ingressEntries":{"name":"ingressEntries","type":"\u0019\u001balicloud.vpc.networkAcl.entry","is_mandatory":true,"title":"Inbound rules of the network ACL","desc":"Evaluated before security groups on traffic entering the attached vSwitches, so a rule here can admit traffic no security group was ever asked about.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"networkAclId":{"name":"networkAclId","type":"\u0007","is_mandatory":true,"title":"Network ACL ID, for example nacl-a2do9e413e0spzasx","provider":"go.mondoo.com/mql/providers/alicloud"},"networkAclName":{"name":"networkAclName","type":"\u0007","is_mandatory":true,"title":"Network ACL name","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the network ACL","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the network ACL belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resources":{"name":"resources","type":"\u0019\n","is_mandatory":true,"title":"Resources the network ACL is bound to","desc":"Each entry carries resourceId, resourceType, and status.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Available or Modifying.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the network ACL","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the network ACL belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC network ACL","desc":"A single network ACL, keyed by networkAclId, for example nacl-a2do9e413e0spzasx. Exposes the lifecycle status, the ingress and egress rule entries, and the vSwitches the ACL is bound to.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.networkAcl.entry":{"id":"alicloud.vpc.networkAcl.entry","name":"alicloud.vpc.networkAcl.entry","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationCidrIp":{"name":"destinationCidrIp","type":"\u0007","is_mandatory":true,"title":"Destination addresses an outbound rule matches","desc":"Empty on an ingress rule.","provider":"go.mondoo.com/mql/providers/alicloud"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Which way the rule applies","desc":"Either ingress or egress.","provider":"go.mondoo.com/mql/providers/alicloud"},"entryId":{"name":"entryId","type":"\u0007","is_mandatory":true,"title":"Rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"entryType":{"name":"entryType","type":"\u0007","is_mandatory":true,"title":"How the rule was created","desc":"custom for a rule added deliberately, system for one created with the ACL.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version the rule applies to","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","is_mandatory":true,"title":"What the rule does with matching traffic","desc":"Either accept or drop.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0007","is_mandatory":true,"title":"Port range the rule matches","desc":"Written as first/last, for example 22/22. A value of -1/-1 matches every port, which is the form a rule takes when the protocol is not tcp or udp.","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Protocol the rule matches","desc":"One of icmp, gre, tcp, udp, or all.","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCidrIp":{"name":"sourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Source addresses an inbound rule matches","desc":"Empty on an egress rule. A value of 0.0.0.0/0 matches the whole internet.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network ACL rule","desc":"A single inbound or outbound rule, keyed by entryId. Network ACLs are evaluated before security groups, so an accept rule here decides what reaches the security groups at all and a drop rule overrides whatever they allow. Ports arrive as a range string such as 22/22 or -1/-1 for every port.","min_provider_version":"13.4.1","defaults":"direction policy protocol port","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.routeTable":{"id":"alicloud.vpc.routeTable","name":"alicloud.vpc.routeTable","fields":{"associateType":{"name":"associateType","type":"\u0007","is_mandatory":true,"title":"Type of resource the route table is associated with","desc":"One of VSwitch or Gateway.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the route table was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"gatewayIds":{"name":"gatewayIds","type":"\u0019\u0007","is_mandatory":true,"title":"Gateway IDs associated with the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the route table","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the route table belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"route":{"name":"route","type":"\u001balicloud.vpc.routeTable.route","title":"Route in a VPC route table","desc":"A single route, keyed by routeEntryId. Reports the destination it matches and the next hop traffic is handed to. A system route is created with the VPC and a custom route was added deliberately, which the type field distinguishes.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"routeEntries":{"name":"routeEntries","type":"\u0019\n","title":"Route entry summaries","desc":"Deprecated in favor of routes. Each entry carries destinationCidrBlock, nextHopType, nextHopId, status, type, routeEntryId, routeEntryName, description, ipVersion, and origin.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"routePropagationEnable":{"name":"routePropagationEnable","type":"\u0004","is_mandatory":true,"title":"Whether route propagation is enabled for the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableId":{"name":"routeTableId","type":"\u0007","is_mandatory":true,"title":"Route table ID, for example vtb-bp1e123abc","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableName":{"name":"routeTableName","type":"\u0007","is_mandatory":true,"title":"Route table name","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableType":{"name":"routeTableType","type":"\u0007","is_mandatory":true,"title":"Route table type","desc":"One of System or Custom.","provider":"go.mondoo.com/mql/providers/alicloud"},"routerId":{"name":"routerId","type":"\u0007","is_mandatory":true,"title":"ID of the router the route table belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"routerType":{"name":"routerType","type":"\u0007","is_mandatory":true,"title":"Type of router the route table belongs to","desc":"One of VRouter or VBR.","provider":"go.mondoo.com/mql/providers/alicloud"},"routes":{"name":"routes","type":"\u0019\u001balicloud.vpc.routeTable.route","title":"Routes in the route table","desc":"Where traffic leaving the attached vSwitches is sent. A route for 0.0.0.0/0 is the one that decides whether a subnet reaches the internet at all, and which gateway it leaves through.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the route table belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches associated with the route table","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC route table","desc":"A single route table, keyed by routeTableId, for example vtb-bp1e123abc. Exposes the route table type, the bound vSwitches and gateways, the lifecycle status, and the individual route entries through routeEntries.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.routeTable.route":{"id":"alicloud.vpc.routeTable.route","name":"alicloud.vpc.routeTable.route","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Route description","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationCidrBlock":{"name":"destinationCidrBlock","type":"\u0007","is_mandatory":true,"title":"Destination the route matches","desc":"A CIDR block. 0.0.0.0/0 is the default route, which catches everything not matched by a more specific entry.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the destination","provider":"go.mondoo.com/mql/providers/alicloud"},"nextHopId":{"name":"nextHopId","type":"\u0007","is_mandatory":true,"title":"ID of the next hop","provider":"go.mondoo.com/mql/providers/alicloud"},"nextHopType":{"name":"nextHopType","type":"\u0007","is_mandatory":true,"title":"Kind of next hop traffic is handed to","desc":"Values include Instance, NatGateway, VpnGateway, RouterInterface, NetworkInterface, IPv6Gateway, and Attachment. The kind decides whether the route leads out of the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Origin of the route","provider":"go.mondoo.com/mql/providers/alicloud"},"routeEntryId":{"name":"routeEntryId","type":"\u0007","is_mandatory":true,"title":"Route entry ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"routeEntryName":{"name":"routeEntryName","type":"\u0007","is_mandatory":true,"title":"Route entry name","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Route status","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"How the route was created","desc":"System for a route created with the VPC, Custom for one added afterwards.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Route in a VPC route table","desc":"A single route, keyed by routeEntryId. Reports the destination it matches and the next hop traffic is handed to. A system route is created with the VPC and a custom route was added deliberately, which the type field distinguishes.","min_provider_version":"13.4.1","defaults":"destinationCidrBlock nextHopType nextHopId status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.vpnConnection":{"id":"alicloud.vpc.vpnConnection","name":"alicloud.vpc.vpnConnection","fields":{"attachInstanceId":{"name":"attachInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the gateway or transit router the connection attaches to","provider":"go.mondoo.com/mql/providers/alicloud"},"attachType":{"name":"attachType","type":"\u0007","is_mandatory":true,"title":"Whether the connection attaches to a VPN gateway or a transit router","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the connection was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossAccountAuthorized":{"name":"crossAccountAuthorized","type":"\u0004","is_mandatory":true,"title":"Whether the connection is authorized across accounts","desc":"True when the tunnel joins networks owned by different accounts.","provider":"go.mondoo.com/mql/providers/alicloud"},"customerGatewayId":{"name":"customerGatewayId","type":"\u0007","is_mandatory":true,"title":"ID of the customer gateway representing the remote end","desc":"The remote end is not modeled as a resource, so this stays a raw ID.","provider":"go.mondoo.com/mql/providers/alicloud"},"effectImmediately":{"name":"effectImmediately","type":"\u0004","is_mandatory":true,"title":"Whether configuration changes take effect immediately","provider":"go.mondoo.com/mql/providers/alicloud"},"enableDpd":{"name":"enableDpd","type":"\u0004","is_mandatory":true,"title":"Whether dead peer detection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"enableNatTraversal":{"name":"enableNatTraversal","type":"\u0004","is_mandatory":true,"title":"Whether NAT traversal is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"enableTunnelsBgp":{"name":"enableTunnelsBgp","type":"\u0004","is_mandatory":true,"title":"Whether the tunnel exchanges routes over BGP","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeAuthenticationAlgorithm":{"name":"ikeAuthenticationAlgorithm","type":"\u0007","is_mandatory":true,"title":"Authentication algorithm negotiated for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeEncryptionAlgorithm":{"name":"ikeEncryptionAlgorithm","type":"\u0007","is_mandatory":true,"title":"Encryption algorithm negotiated for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeLifetime":{"name":"ikeLifetime","type":"\u0005","is_mandatory":true,"title":"Lifetime of the key-exchange security association in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeMode":{"name":"ikeMode","type":"\u0007","is_mandatory":true,"title":"IKE negotiation mode, either main or aggressive","desc":"Aggressive mode completes in fewer exchanges but sends identity information before the channel is encrypted.","provider":"go.mondoo.com/mql/providers/alicloud"},"ikePfs":{"name":"ikePfs","type":"\u0007","is_mandatory":true,"title":"Diffie-Hellman group used for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeVersion":{"name":"ikeVersion","type":"\u0007","is_mandatory":true,"title":"IKE protocol version, either ikev1 or ikev2","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address of the remote peer","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecAuthenticationAlgorithm":{"name":"ipsecAuthenticationAlgorithm","type":"\u0007","is_mandatory":true,"title":"Authentication algorithm protecting the tunnel payload","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecEncryptionAlgorithm":{"name":"ipsecEncryptionAlgorithm","type":"\u0007","is_mandatory":true,"title":"Encryption algorithm protecting the tunnel payload","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecLifetime":{"name":"ipsecLifetime","type":"\u0005","is_mandatory":true,"title":"Lifetime of the tunnel security association in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecPfs":{"name":"ipsecPfs","type":"\u0007","is_mandatory":true,"title":"Diffie-Hellman group used to rekey the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"localSubnet":{"name":"localSubnet","type":"\u0007","is_mandatory":true,"title":"CIDR blocks on the Alibaba Cloud side reachable through the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the connection","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the connection lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"remoteSubnet":{"name":"remoteSubnet","type":"\u0007","is_mandatory":true,"title":"CIDR blocks on the remote side reachable through the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Negotiation state of the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Connection status, for example ike_sa_established or active","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnConnectionId":{"name":"vpnConnectionId","type":"\u0007","is_mandatory":true,"title":"VPN connection ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGateway":{"name":"vpnGateway","type":"\u001balicloud.vpc.vpnGateway","title":"VPN gateway the connection terminates on","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPN connection","desc":"A single IPsec tunnel terminating on a VPN gateway, keyed by vpnConnectionId. The local and remote subnets are the reachability this connection creates: traffic from the remote subnet reaches the local one without crossing an internet gateway. The negotiated algorithms and lifetimes are exposed so weak cipher suites can be found, but the pre-shared key is deliberately not.","min_provider_version":"13.2.5","defaults":"vpnConnectionId name status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.vpnGateway":{"id":"alicloud.vpc.vpnGateway","name":"alicloud.vpc.vpnGateway","fields":{"autoPropagate":{"name":"autoPropagate","type":"\u0004","is_mandatory":true,"title":"Whether the gateway automatically propagates learned routes to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Billing status of the gateway, for example Normal or FinancialLocked","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"connections":{"name":"connections","type":"\u0019\u001balicloud.vpc.vpnConnection","title":"Connections terminating on the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the gateway was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"enableBgp":{"name":"enableBgp","type":"\u0004","is_mandatory":true,"title":"Whether the gateway exchanges routes over BGP","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"Time the gateway subscription ends","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address the gateway terminates tunnels on","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecVpnEnabled":{"name":"ipsecVpnEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the gateway accepts IPsec connections","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Whether the gateway is reachable over the internet or only privately","desc":"public for an internet-facing gateway, private for one reachable only from within Alibaba Cloud.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the gateway runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the VPN gateway","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"spec":{"name":"spec","type":"\u0007","is_mandatory":true,"title":"Gateway bandwidth specification","provider":"go.mondoo.com/mql/providers/alicloud"},"sslMaxConnections":{"name":"sslMaxConnections","type":"\u0005","is_mandatory":true,"title":"Maximum number of concurrent SSL clients the gateway accepts","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnEnabled":{"name":"sslVpnEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the gateway accepts SSL client connections","desc":"An SSL gateway lets individual clients dial into the VPC rather than joining a fixed network, so it widens reachability to anyone holding a client certificate.","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnInternetIp":{"name":"sslVpnInternetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address SSL clients connect to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Gateway status, for example active or provisioning","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the gateway, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the gateway is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGatewayId":{"name":"vpnGatewayId","type":"\u0007","is_mandatory":true,"title":"VPN gateway ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnType":{"name":"vpnType","type":"\u0007","is_mandatory":true,"title":"Gateway type, for example Normal or National-Standard","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the gateway is placed in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPN gateway","desc":"A VPN gateway attached to a VPC, keyed by vpnGatewayId. Exposes the IPsec and SSL capabilities, the public address traffic arrives on, and the connections terminating on it. A gateway is how traffic reaches the VPC from outside Alibaba Cloud, so its connections describe reachability that security groups alone do not explain.","min_provider_version":"13.2.5","defaults":"vpnGatewayId name status internetIp","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.vswitch":{"id":"alicloud.vpc.vswitch","name":"alicloud.vpc.vswitch","fields":{"availableIpAddressCount":{"name":"availableIpAddressCount","type":"\u0005","is_mandatory":true,"title":"Number of available IP addresses in the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlock":{"name":"cidrBlock","type":"\u0007","is_mandatory":true,"title":"IPv4 CIDR block of the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the vSwitch was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"enabledIpv6":{"name":"enabledIpv6","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 is enabled for the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6CidrBlock":{"name":"ipv6CidrBlock","type":"\u0007","is_mandatory":true,"title":"IPv6 CIDR block of the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether the vSwitch is the default vSwitch in its zone","provider":"go.mondoo.com/mql/providers/alicloud"},"networkAcl":{"name":"networkAcl","type":"\u001balicloud.vpc.networkAcl","title":"Network ACL bound to the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the vSwitch","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the vSwitch belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTable":{"name":"routeTable","type":"\u001balicloud.vpc.routeTable","title":"Route table associated with the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableType":{"name":"routeTableType","type":"\u0007","is_mandatory":true,"title":"Type of the associated route table, for example System or Custom","provider":"go.mondoo.com/mql/providers/alicloud"},"shareType":{"name":"shareType","type":"\u0007","is_mandatory":true,"title":"vSwitch sharing status","desc":"Empty for a regular vSwitch, Shared once the vSwitch is shared, or Sharing while sharing is in progress.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"vSwitchId":{"name":"vSwitchId","type":"\u0007","is_mandatory":true,"title":"vSwitch ID, for example vsw-25bcdxs7pv1abc","provider":"go.mondoo.com/mql/providers/alicloud"},"vSwitchName":{"name":"vSwitchName","type":"\u0007","is_mandatory":true,"title":"vSwitch name","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the vSwitch belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the vSwitch belongs to, for example cn-hangzhou-d","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"vSwitch (VPC subnet)","desc":"A single vSwitch, keyed by vSwitchId, for example vsw-25bcdxs7pv1abc. Exposes the CIDR blocks, the zone, the number of free IP addresses, the associated route table and network ACL, and the parent VPC.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf":{"id":"alicloud.waf","name":"alicloud.waf","fields":{"defenseResource":{"name":"defenseResource","type":"\u001balicloud.waf.defenseResource","title":"Web Application Firewall protected resource","desc":"A single protected object of a WAF instance, keyed by the owning instanceId and resource name. A protected object is a CNAME domain or an attached cloud-native resource (ALB, CLB, MSE). Exposes the backing product, protection mode, and provisioning health. Use it to enumerate what WAF is protecting and whether protection is active.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"domain":{"name":"domain","type":"\u001balicloud.waf.domain","title":"Web Application Firewall protected domain","desc":"A single CNAME-access domain protected by a WAF instance, keyed by domain. Exposes the WAF-assigned CNAME, listen ports, and the TLS configuration (certificate, minimum TLS version) of the HTTPS listener. Use it to audit whether an HTTPS domain enforces a strong TLS version and presents a non-expired certificate.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instance":{"name":"instance","type":"\u001balicloud.waf.instance","title":"Web Application Firewall instance","desc":"A single WAF 3.0 instance, keyed by instanceId. WAF provisions one instance per account per center. Exposes the edition, subscription window, and status, and is the parent of the protected resources and domains. Use it to confirm WAF is provisioned and not expired.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.waf.instance","title":"WAF instances across the China and international centers","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Web Application Firewall","desc":"WAF 3.0 instances and the resources they protect for an Alibaba Cloud account. WAF is a center service with one instance per account in each of the China and international centers. Exposes the instance edition and subscription state, the protected objects (domains and cloud-native resources), and the CNAME domains with their TLS configuration. Use it to audit which web assets are behind WAF and whether their listeners terminate TLS.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.defenseResource":{"id":"alicloud.waf.defenseResource","name":"alicloud.waf.defenseResource","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the protected object was created","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the WAF instance protecting the resource","provider":"go.mondoo.com/mql/providers/alicloud"},"pattern":{"name":"pattern","type":"\u0007","is_mandatory":true,"title":"Protection mode of the object, for example domain","provider":"go.mondoo.com/mql/providers/alicloud"},"product":{"name":"product","type":"\u0007","is_mandatory":true,"title":"Cloud service backing the resource, for example alb, clb, or mse; empty for a CNAME domain","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the resource belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resource":{"name":"resource","type":"\u0007","is_mandatory":true,"title":"Protected object name, for example a domain or a cloud resource id","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u0007","is_mandatory":true,"title":"WAF protection-group the resource belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceStatus":{"name":"resourceStatus","type":"\u0007","is_mandatory":true,"title":"Provisioning status","desc":"active when protection is running, or initializing / init_failed while it is being set up.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall protected resource","desc":"A single protected object of a WAF instance, keyed by the owning instanceId and resource name. A protected object is a CNAME domain or an attached cloud-native resource (ALB, CLB, MSE). Exposes the backing product, protection mode, and provisioning health. Use it to enumerate what WAF is protecting and whether protection is active.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.domain":{"id":"alicloud.waf.domain","name":"alicloud.waf.domain","fields":{"certExpireTime":{"name":"certExpireTime","type":"\t","title":"Expiry time of the bound certificate, null when no certificate is configured","provider":"go.mondoo.com/mql/providers/alicloud"},"certId":{"name":"certId","type":"\u0007","title":"ID of the certificate bound to the HTTPS listener, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"cname":{"name":"cname","type":"\u0007","is_mandatory":true,"title":"WAF-assigned CNAME that traffic must resolve to","provider":"go.mondoo.com/mql/providers/alicloud"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Protected hostname, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"httpPorts":{"name":"httpPorts","type":"\u0019\u0005","is_mandatory":true,"title":"HTTP listener ports","provider":"go.mondoo.com/mql/providers/alicloud"},"httpsEnabled":{"name":"httpsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the domain serves HTTPS","desc":"True when at least one HTTPS listener port is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"httpsPorts":{"name":"httpsPorts","type":"\u0019\u0005","is_mandatory":true,"title":"HTTPS listener ports","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the WAF instance protecting the domain","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the domain belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Domain status","desc":"1 (normal), 2 (creating), 3 (modifying), 4 (releasing), or 5 (forwarding disabled).","provider":"go.mondoo.com/mql/providers/alicloud"},"tls13Enabled":{"name":"tls13Enabled","type":"\u0004","title":"Whether TLS 1.3 is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsVersion":{"name":"tlsVersion","type":"\u0007","title":"Minimum TLS version accepted, for example tlsv1.2","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall protected domain","desc":"A single CNAME-access domain protected by a WAF instance, keyed by domain. Exposes the WAF-assigned CNAME, listen ports, and the TLS configuration (certificate, minimum TLS version) of the HTTPS listener. Use it to audit whether an HTTPS domain enforces a strong TLS version and presents a non-expired certificate.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.instance":{"id":"alicloud.waf.instance","name":"alicloud.waf.instance","fields":{"defenseResources":{"name":"defenseResources","type":"\u0019\u001balicloud.waf.defenseResource","title":"Protected objects (domains and cloud-native resources) behind the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"domains":{"name":"domains","type":"\u0019\u001balicloud.waf.domain","title":"CNAME-access domains protected by the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"edition":{"name":"edition","type":"\u0007","is_mandatory":true,"title":"Instance edition or plan","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"End of the subscription window","provider":"go.mondoo.com/mql/providers/alicloud"},"inDebt":{"name":"inDebt","type":"\u0007","is_mandatory":true,"title":"Whether the instance is in debt (overdue payment)","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"WAF instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method, for example POSTPAY or SUBSCRIPTION","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the instance belongs to, either cn-hangzhou or ap-southeast-1","provider":"go.mondoo.com/mql/providers/alicloud"},"startTime":{"name":"startTime","type":"\t","is_mandatory":true,"title":"Start of the subscription window","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Instance status","desc":"1 (Normal), 2 (Expired), or 3 (Released). Only a Normal instance is actively protecting traffic.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall instance","desc":"A single WAF 3.0 instance, keyed by instanceId. WAF provisions one instance per account per center. Exposes the edition, subscription window, and status, and is the parent of the protected resources and domains. Use it to confirm WAF is provisioned and not expired.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"}}}