{"resources":{"alicloud":{"id":"alicloud","name":"alicloud","fields":{"accountId":{"name":"accountId","type":"\u0007","title":"Account (UID) that the active credential belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"acr":{"name":"acr","type":"\u001balicloud.acr","title":"Alibaba Cloud Container Registry","desc":"Container Registry (ACR) instances in the account and what is published through them: the namespaces that group repositories, the repositories themselves and whether each is readable without credentials, the replication rules that copy images to other regions or accounts, and the scan rules that decide whether an image is examined before it runs. The images an ACK cluster pulls come from here, so this is where a container supply chain begins.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"actiontrail":{"name":"actiontrail","type":"\u001balicloud.actiontrail","title":"Alibaba Cloud ActionTrail","desc":"Audit trail configuration for an Alibaba Cloud account. Exposes the trails that record management and data-plane API events, including where each trail delivers events (an OSS bucket or a Log Service project), whether it spans the resource directory, and its live logging and delivery health. Use it to audit whether API activity is being recorded and successfully delivered.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"alb":{"name":"alb","type":"\u001balicloud.alb","title":"Alibaba Cloud Application Load Balancer","desc":"ALB (Layer-7) load balancers across an Alibaba Cloud account. Exposes the application load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether HTTPS listeners use a strong TLS policy, and whether access logging is enabled.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"antiddos":{"name":"antiddos","type":"\u001balicloud.antiddos","title":"Alibaba Cloud Anti-DDoS","desc":"Anti-DDoS Pro and Premium instances and the assets they protect for an Alibaba Cloud account. Anti-DDoS is a center service. Exposes the scrubbing instances, their subscription health, and the web domains and forwarding ports under protection. Use it to audit which assets are protected and whether an instance's protection has lapsed (expired, disabled, or in debt).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"asset":{"name":"asset","type":"\u001basset","title":"Asset this root belongs to","desc":"Platform, version, identity and labels of the asset this root describes.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cen":{"name":"cen","type":"\u001balicloud.cen","title":"Cloud Enterprise Network","desc":"Transit networking for the account. Exposes the CEN instances, each of which joins the networks attached to it into one routing domain, so a workload in one attached VPC can reach a workload in another regardless of region.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cloudFirewall":{"name":"cloudFirewall","type":"\u001balicloud.cloudFirewall","title":"Alibaba Cloud Cloud Firewall","desc":"Cloud Firewall access-control state for an Alibaba Cloud account. Cloud Firewall is a center service. Exposes whether the firewall service is active, its edition, and the internet-boundary control policies (the allow and deny rules). Use it to audit whether the firewall is enabled and whether any rule broadly permits inbound traffic.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cloudsso":{"name":"cloudsso","type":"\u001balicloud.cloudsso","title":"CloudSSO","desc":"Workforce identity and account access for an Alibaba Cloud resource directory. Exposes the CloudSSO directories in the account, and through them the workforce users and groups, the access configurations that define what a session may do, and the assignments that grant those configurations on individual member accounts.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"config":{"name":"config","type":"\u001balicloud.config","title":"Alibaba Cloud Cloud Config","desc":"Configuration-compliance state for an Alibaba Cloud account. Exposes the Config rules that continuously evaluate resource configuration, the account-wide compliance summary, and whether the configuration recorder and its delivery channels are active. Use it to audit whether configuration recording is enabled and how many resources are non-compliant.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cs":{"name":"cs","type":"\u001balicloud.cs","title":"Alibaba Cloud Container Service for Kubernetes","desc":"ACK clusters across an Alibaba Cloud account. Exposes the Kubernetes clusters in every enabled region, including their type and version, network layout, API server exposure, control-plane audit logging, workload-identity (RRSA) settings, node pools, and installed addons. Use it to audit whether a cluster's API server is reachable from the internet and whether audit logging is enabled.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ecs":{"name":"ecs","type":"\u001balicloud.ecs","title":"Elastic Compute Service (ECS)","desc":"Compute resources in a region, including virtual machine instances, their attached block-storage disks, machine images, SSH key pairs, and the security groups that filter instance traffic. Fans out over every region enabled on the account.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"es":{"name":"es","type":"\u001balicloud.es","title":"Alibaba Cloud Elasticsearch","desc":"Elasticsearch clusters in the account. A cluster holds indexed copies of whatever was shipped into it, which is often log and application data, and it can be published on a public endpoint of its own alongside a Kibana console. Reports what each cluster accepts connections on and which addresses are allowed to reach it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ess":{"name":"ess","type":"\u001balicloud.ess","title":"Auto Scaling","desc":"Scaling groups and the scaling configurations they launch instances from, across every enabled region on the account. Instances created by a scaling group are transient, so the scaling configuration is the durable record of how they are built: the user data written into them, the RAM role and security groups they receive, the image they boot, and the metadata service hardening they inherit.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"fc":{"name":"fc","type":"\u001balicloud.fc","title":"Alibaba Cloud Function Compute","desc":"Function Compute (FC 3.0) functions across an Alibaba Cloud account. Exposes the serverless functions in every enabled region, along with their triggers. Use it to audit function execution roles, network placement, public egress and invocation, and whether environment variables might carry secrets.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"kms":{"name":"kms","type":"\u001balicloud.kms","title":"Alibaba Cloud Key Management Service","desc":"Encryption keys and secrets managed for an Alibaba Cloud account. Exposes the customer master keys across all enabled regions, including their lifecycle state, cryptographic spec, rotation configuration, and protection level, and the secrets held in Secrets Manager along with the master key that protects each one. Use it to audit key rotation, deletion protection, and whether keys are backed by a hardware security module.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"log":{"name":"log","type":"\u001balicloud.log","title":"Alibaba Cloud Log Service","desc":"Log Service (SLS) projects and their logstores across an Alibaba Cloud account. Exposes the projects in every enabled region and, within each, the logstores that ingest and store logs, including their retention period and server-side encryption configuration. Log Service is the delivery target for ActionTrail trails and VPC flow logs, so these resources anchor the account's logging posture.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"mongodb":{"name":"mongodb","type":"\u001balicloud.mongodb","title":"ApsaraDB for MongoDB","desc":"Managed MongoDB service in an Alibaba Cloud account. Exposes the MongoDB instances across every enabled region through instances, spanning replica set, sharded cluster, and serverless deployments together with their security posture.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"nas":{"name":"nas","type":"\u001balicloud.nas","title":"Alibaba Cloud NAS file storage","desc":"Apsara File Storage NAS file systems and access controls across an Alibaba Cloud account. Exposes the file systems in every enabled region, their mount targets, and the access groups and rules that govern which clients may mount them. Use it to audit whether file systems are encrypted and whether their exports are open to overly broad client ranges.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"nlb":{"name":"nlb","type":"\u001balicloud.nlb","title":"Alibaba Cloud Network Load Balancer","desc":"NLB (Layer-4) load balancers across an Alibaba Cloud account. Exposes the network load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether security groups are applied, and whether TCPSSL listeners use a strong TLS policy.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"oss":{"name":"oss","type":"\u001balicloud.oss","title":"Object Storage Service","desc":"Entry point for the Object Storage Service (OSS) in an Alibaba Cloud account. Exposes every bucket the credential can list across all regions through buckets, from which per-bucket access control, encryption, versioning, logging, tagging, and public-access posture are reachable.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"polardb":{"name":"polardb","type":"\u001balicloud.polardb","title":"PolarDB","desc":"Entry point for querying ApsaraDB for PolarDB, the cloud-native relational database service. Exposes the PolarDB clusters provisioned across every enabled region through clusters, and the retrieval-augmented generation corpora built on them through knowledgeBases and knowledgeSpaces.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ram":{"name":"ram","type":"\u001balicloud.ram","title":"Alibaba Cloud Resource Access Management","desc":"Identity and access configuration for an Alibaba Cloud account. Exposes the RAM users, user groups, roles, and permission policies defined in the account, along with the account-wide password policy and the console and credential security preferences.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"rds":{"name":"rds","type":"\u001balicloud.rds","title":"ApsaraDB RDS","desc":"ApsaraDB relational database instances in an Alibaba Cloud account. Exposes the RDS instances discovered across every enabled region through instances, from which the database engine and version, the network placement, and the security posture (SSL/TLS, TDE encryption, public accessibility, and IP address whitelist) can be audited.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"redis":{"name":"redis","type":"\u001balicloud.redis","title":"ApsaraDB for Redis","desc":"Entry point for the ApsaraDB for Redis (Tair) instances in an Alibaba Cloud account. Enumerates every Redis and Tair instance across the enabled regions through instances, each of which exposes its configuration and security posture.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"regions":{"name":"regions","type":"\u0019\u0007","title":"Region IDs enabled on the account, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceManager":{"name":"resourceManager","type":"\u001balicloud.resourceManager","title":"Alibaba Cloud Resource Directory","desc":"Multi-account governance structure for an Alibaba Cloud account. Exposes the resource directory (the organization), the management and member accounts it contains, the folder hierarchy that groups them, and the control policies available to restrict member-account permissions. Use it to audit organization membership and whether control policies are enabled.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"sas":{"name":"sas","type":"\u001balicloud.sas","title":"Security Center","desc":"Threat detection and posture management for the account. Exposes the subscription edition and quota, the protected machines and whether their agents are reporting, the vulnerabilities and baseline check failures found across them, and the alerts raised by threat detection.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"slb":{"name":"slb","type":"\u001balicloud.slb","title":"Server Load Balancer","desc":"Classic Load Balancer (CLB) resources in an Alibaba Cloud account. Exposes the CLB instances discovered across every enabled region through loadBalancers, from which listeners, backend servers, addressing, and protection settings can be audited.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpc":{"name":"vpc","type":"\u001balicloud.vpc","title":"Virtual Private Cloud (VPC)","desc":"Entry point for the Alibaba Cloud VPC networking service. Exposes the VPCs, vSwitches, route tables, NAT gateways, elastic IP addresses, and network ACLs defined across every enabled region on the account.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"waf":{"name":"waf","type":"\u001balicloud.waf","title":"Alibaba Cloud Web Application Firewall","desc":"WAF 3.0 instances and the resources they protect for an Alibaba Cloud account. WAF is a center service with one instance per account in each of the China and international centers. Exposes the instance edition and subscription state, the protected objects (domains and cloud-native resources), and the CNAME domains with their TLS configuration. Use it to audit which web assets are behind WAF and whether their listeners terminate TLS.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud","desc":"Entry point for querying an Alibaba Cloud account. Exposes the account identity and the region IDs enabled on the account, and is the root from which the RAM, ECS, Auto Scaling, VPC, OSS, SLB, ALB, NLB, and managed-database resources are reached, along with the Container Service for Kubernetes, Function Compute, NAS file storage, Web Application Firewall, Cloud Firewall, Anti-DDoS, Security Center, Key Management Service, ActionTrail, Log Service, Cloud Config, CloudSSO, Cloud Enterprise Network, and Resource Directory resources.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud","root":true},"alicloud.acr":{"id":"alicloud.acr","name":"alicloud.acr","fields":{"instance":{"name":"instance","type":"\u001balicloud.acr.instance","title":"Container Registry instance","desc":"A single Enterprise Edition registry, keyed by instanceId. Reports the edition and state of the instance, whether its internet endpoint is switched on and which addresses that endpoint accepts, and the namespaces, repositories, replication rules and scan rules it holds.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.acr.instance","title":"Container Registry Enterprise Edition instances in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"namespace":{"name":"namespace","type":"\u001balicloud.acr.namespace","title":"Container Registry namespace","desc":"A namespace groups repositories inside one registry and sets the defaults new repositories inherit. Selected by namespaceName within an instance. The defaults matter on their own: a namespace that creates repositories on push and hands them public visibility turns a mistyped image name into a world-readable repository.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"repository":{"name":"repository","type":"\u001balicloud.acr.repository","title":"Container Registry repository","desc":"One image repository, keyed by repoId. Reports whether the repository is readable without credentials, whether its tags can be overwritten after they have been deployed, and which namespace holds it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"repositoryTag":{"name":"repositoryTag","type":"\u001balicloud.acr.repositoryTag","title":"Container Registry image tag","desc":"A single tag in a Container Registry repository, keyed by the owning repoId and tag name. Exposes the image content the tag points at (digest, size, push time) and the vulnerability scan of that content. Use it to answer whether a cluster pulls an image carrying known high-severity vulnerabilities, which the scan rule alone cannot say because it configures the scan rather than reporting its findings.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"scanRule":{"name":"scanRule","type":"\u001balicloud.acr.scanRule","title":"Container Registry scan rule","desc":"A rule that decides which images are examined and when, keyed by scanRuleId. A registry with no scan rule only examines an image when someone asks it to, so an image can be pulled and run without ever having been looked at.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"syncRule":{"name":"syncRule","type":"\u001balicloud.acr.syncRule","title":"Container Registry replication rule","desc":"A rule that copies images between registries, keyed by syncRuleId. Reports what the rule matches and where the copies land, so a rule that moves images into another account or region is visible as one.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vulnerability":{"name":"vulnerability","type":"\u001balicloud.acr.vulnerability","title":"Vulnerability found in a Container Registry image","desc":"A single scan finding for one image tag. Exposes the CVE, its severity, the package that carries it, and the version that fixes it. Use it to find images running a package with a known fix available.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Container Registry","desc":"Container Registry (ACR) instances in the account and what is published through them: the namespaces that group repositories, the repositories themselves and whether each is readable without credentials, the replication rules that copy images to other regions or accounts, and the scan rules that decide whether an image is examined before it runs. The images an ACK cluster pulls come from here, so this is where a container supply chain begins.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.instance":{"id":"alicloud.acr.instance","name":"alicloud.acr.instance","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceSpecification":{"name":"instanceSpecification","type":"\u0007","is_mandatory":true,"title":"Enterprise Edition specification","desc":"The purchased edition, such as Enterprise_Basic, Enterprise_Standard, or Enterprise_Advanced. Vulnerability scanning and some replication features are only available above the basic edition.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceStatus":{"name":"instanceStatus","type":"\u0007","is_mandatory":true,"title":"Instance status","desc":"RUNNING for an instance serving traffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointAclEnabled":{"name":"internetEndpointAclEnabled","type":"\u0004","title":"Whether an address list gates the internet endpoint","desc":"False on an enabled internet endpoint means every source address may reach the registry, leaving repository visibility as the only control.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointAclEntries":{"name":"internetEndpointAclEntries","type":"\u0019\u0007","title":"Addresses allowed to reach the internet endpoint","desc":"The CIDR entries of the endpoint's address list. Empty when no list is configured, which is not a restriction: an enabled endpoint with no entries and no list enforcement accepts every source.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointDomains":{"name":"internetEndpointDomains","type":"\u0019\u0007","title":"Public domains the instance answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpointEnabled":{"name":"internetEndpointEnabled","type":"\u0004","title":"Whether the instance is reachable over the internet","desc":"False means images can only be pulled from inside a linked VPC. True means the registry answers on a public domain, and internetEndpointAclEnabled decides whether anything narrows who may reach it.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","is_mandatory":true,"title":"Time the instance was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaces":{"name":"namespaces","type":"\u0019\u001balicloud.acr.namespace","title":"Namespaces defined in the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the instance lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"repositories":{"name":"repositories","type":"\u0019\u001balicloud.acr.repository","title":"Repositories held in the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scanRules":{"name":"scanRules","type":"\u0019\u001balicloud.acr.scanRule","title":"Rules that decide which images are scanned and when","desc":"Empty when no scan rule is configured, in which case images are only examined if someone starts a scan by hand.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRules":{"name":"syncRules","type":"\u0019\u001balicloud.acr.syncRule","title":"Replication rules that copy images in or out of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the instance","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry instance","desc":"A single Enterprise Edition registry, keyed by instanceId. Reports the edition and state of the instance, whether its internet endpoint is switched on and which addresses that endpoint accepts, and the namespaces, repositories, replication rules and scan rules it holds.","min_provider_version":"13.4.1","defaults":"instanceName instanceSpecification instanceStatus regionId","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.namespace":{"id":"alicloud.acr.namespace","name":"alicloud.acr.namespace","fields":{"autoCreateRepo":{"name":"autoCreateRepo","type":"\u0004","is_mandatory":true,"title":"Whether pushing an unknown repository name creates it","desc":"True means a push to a name that does not exist yet creates the repository with the namespace defaults rather than failing, so a typo or an unreviewed push lands a new repository.","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultRepoType":{"name":"defaultRepoType","type":"\u0007","is_mandatory":true,"title":"Visibility given to a repository created in this namespace","desc":"Either PUBLIC or PRIVATE. PUBLIC together with autoCreateRepo means an automatically created repository is readable without credentials.","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultTagImmutability":{"name":"defaultTagImmutability","type":"\u0004","is_mandatory":true,"title":"Tag immutability given to a repository created in this namespace","desc":"False means new repositories allow an existing tag to be repointed at different content.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance holding the namespace","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceId":{"name":"namespaceId","type":"\u0007","is_mandatory":true,"title":"Namespace ID","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceName":{"name":"namespaceName","type":"\u0007","is_mandatory":true,"title":"Namespace name, used as the selection key within an instance","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceStatus":{"name":"namespaceStatus","type":"\u0007","is_mandatory":true,"title":"Namespace status","desc":"Either NORMAL or DELETING.","provider":"go.mondoo.com/mql/providers/alicloud"},"repositories":{"name":"repositories","type":"\u0019\u001balicloud.acr.repository","title":"Repositories in the namespace","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the namespace belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the namespace belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry namespace","desc":"A namespace groups repositories inside one registry and sets the defaults new repositories inherit. Selected by namespaceName within an instance. The defaults matter on their own: a namespace that creates repositories on push and hands them public visibility turns a mistyped image name into a world-readable repository.","min_provider_version":"13.4.1","defaults":"namespaceName defaultRepoType autoCreateRepo","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.repository":{"id":"alicloud.acr.repository","name":"alicloud.acr.repository","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the repository was created","provider":"go.mondoo.com/mql/providers/alicloud"},"imageTags":{"name":"imageTags","type":"\u0019\u001balicloud.acr.repositoryTag","title":"Image tags held in the repository","desc":"Each tag names the image content a deployment pulls when it references this repository by tag, and carries the scan findings for that content.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance holding the repository","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","title":"Whether the repository can be pulled from the internet without credentials","desc":"True only when the repository is PUBLIC and its instance answers on the internet: a public repository inside an instance with no internet endpoint is still reachable only from a linked VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","is_mandatory":true,"title":"Time the repository was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"namespace":{"name":"namespace","type":"\u001balicloud.acr.namespace","title":"Namespace holding the repository","provider":"go.mondoo.com/mql/providers/alicloud"},"repoBuildType":{"name":"repoBuildType","type":"\u0007","is_mandatory":true,"title":"How images reach the repository","desc":"MANUAL for images pushed by a client, AUTO for images produced by a build rule in the registry.","provider":"go.mondoo.com/mql/providers/alicloud"},"repoId":{"name":"repoId","type":"\u0007","is_mandatory":true,"title":"Repository ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"repoName":{"name":"repoName","type":"\u0007","is_mandatory":true,"title":"Repository name","provider":"go.mondoo.com/mql/providers/alicloud"},"repoNamespaceName":{"name":"repoNamespaceName","type":"\u0007","is_mandatory":true,"title":"Name of the namespace holding the repository","provider":"go.mondoo.com/mql/providers/alicloud"},"repoStatus":{"name":"repoStatus","type":"\u0007","is_mandatory":true,"title":"Repository status","provider":"go.mondoo.com/mql/providers/alicloud"},"repoType":{"name":"repoType","type":"\u0007","is_mandatory":true,"title":"Repository visibility","desc":"Either PUBLIC, which needs no credentials to pull, or PRIVATE.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the repository belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the repository belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"summary":{"name":"summary","type":"\u0007","is_mandatory":true,"title":"Repository summary","provider":"go.mondoo.com/mql/providers/alicloud"},"tagImmutability":{"name":"tagImmutability","type":"\u0004","is_mandatory":true,"title":"Whether an existing tag can be overwritten","desc":"False means a tag can be repointed at different content after it has been deployed, so the image reviewed at build time is not necessarily the one that runs.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry repository","desc":"One image repository, keyed by repoId. Reports whether the repository is readable without credentials, whether its tags can be overwritten after they have been deployed, and which namespace holds it.","min_provider_version":"13.4.1","defaults":"repoNamespaceName repoName repoType tagImmutability","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.repositoryTag":{"id":"alicloud.acr.repositoryTag","name":"alicloud.acr.repositoryTag","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the image was pushed","provider":"go.mondoo.com/mql/providers/alicloud"},"digest":{"name":"digest","type":"\u0007","is_mandatory":true,"title":"Content digest the tag points at, for example sha256:abc123","desc":"The digest, not the tag, identifies the bytes that run. On a repository with tagImmutability off, the same tag can point at a different digest tomorrow.","provider":"go.mondoo.com/mql/providers/alicloud"},"hasHighSeverityVulnerabilities":{"name":"hasHighSeverityVulnerabilities","type":"\u0004","title":"Whether the image carries a high-severity vulnerability","desc":"False on an image that has never been scanned, which is a different fact from a clean image; read scanned to tell them apart.","provider":"go.mondoo.com/mql/providers/alicloud"},"highSeverityCount":{"name":"highSeverityCount","type":"\u0005","title":"Number of high-severity vulnerabilities found in the image","provider":"go.mondoo.com/mql/providers/alicloud"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"Registry-assigned image ID","provider":"go.mondoo.com/mql/providers/alicloud"},"imageSize":{"name":"imageSize","type":"\u0005","is_mandatory":true,"title":"Size of the image in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the registry instance holding the image","provider":"go.mondoo.com/mql/providers/alicloud"},"lowSeverityCount":{"name":"lowSeverityCount","type":"\u0005","title":"Number of low-severity vulnerabilities found in the image","provider":"go.mondoo.com/mql/providers/alicloud"},"mediumSeverityCount":{"name":"mediumSeverityCount","type":"\u0005","title":"Number of medium-severity vulnerabilities found in the image","provider":"go.mondoo.com/mql/providers/alicloud"},"repoId":{"name":"repoId","type":"\u0007","is_mandatory":true,"title":"ID of the repository holding the tag","provider":"go.mondoo.com/mql/providers/alicloud"},"scanStatus":{"name":"scanStatus","type":"\u0007","title":"Scan status of the image","desc":"One of SCANNING, COMPLETE, FAILED, or RETRYING. Empty when the registry has never scanned the image, or when the scan status cannot be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"scanned":{"name":"scanned","type":"\u0004","title":"Whether a vulnerability scan of this image has completed","desc":"False when the image has never been scanned, when a scan is still running, and when the last scan failed. An unscanned image reports no vulnerabilities, which must not be read as a clean image.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the image, for example NORMAL","provider":"go.mondoo.com/mql/providers/alicloud"},"tag":{"name":"tag","type":"\u0007","is_mandatory":true,"title":"Tag name, for example latest or v1.2.3","provider":"go.mondoo.com/mql/providers/alicloud"},"unknownSeverityCount":{"name":"unknownSeverityCount","type":"\u0005","title":"Number of vulnerabilities the scanner could not rate","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the image was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"vulnerabilities":{"name":"vulnerabilities","type":"\u0019\u001balicloud.acr.vulnerability","title":"Vulnerabilities the registry found in the image","desc":"Empty on an image that has not been scanned as well as on a clean one, so read scanned alongside this.","provider":"go.mondoo.com/mql/providers/alicloud"},"vulnerabilityCount":{"name":"vulnerabilityCount","type":"\u0005","title":"Total number of vulnerabilities found in the image","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry image tag","desc":"A single tag in a Container Registry repository, keyed by the owning repoId and tag name. Exposes the image content the tag points at (digest, size, push time) and the vulnerability scan of that content. Use it to answer whether a cluster pulls an image carrying known high-severity vulnerabilities, which the scan rule alone cannot say because it configures the scan rather than reporting its findings.","min_provider_version":"13.5.1","defaults":"tag status vulnerabilityCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.scanRule":{"id":"alicloud.acr.scanRule","name":"alicloud.acr.scanRule","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance the rule applies to","provider":"go.mondoo.com/mql/providers/alicloud"},"repoTagFilterPattern":{"name":"repoTagFilterPattern","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which tags are scanned","desc":"Empty when the rule covers every tag in scope.","provider":"go.mondoo.com/mql/providers/alicloud"},"ruleName":{"name":"ruleName","type":"\u0007","is_mandatory":true,"title":"Scan rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"scanRuleId":{"name":"scanRuleId","type":"\u0007","is_mandatory":true,"title":"Scan rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"scanScope":{"name":"scanScope","type":"\u0007","is_mandatory":true,"title":"What the rule covers","desc":"REPO for a single repository, or the wider scope the rule was created with.","provider":"go.mondoo.com/mql/providers/alicloud"},"scanType":{"name":"scanType","type":"\u0007","is_mandatory":true,"title":"What the scan looks for","desc":"VUL runs the cloud security scanner for vulnerabilities, SBOM runs content analysis to inventory what an image contains.","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerType":{"name":"triggerType","type":"\u0007","is_mandatory":true,"title":"How the scan fires","desc":"AUTO for a scan triggered by a push, so an image is examined as it arrives rather than on request.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the rule was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry scan rule","desc":"A rule that decides which images are examined and when, keyed by scanRuleId. A registry with no scan rule only examines an image when someone asks it to, so an image can be pulled and run without ever having been looked at.","min_provider_version":"13.4.1","defaults":"ruleName scanType scanScope triggerType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.syncRule":{"id":"alicloud.acr.syncRule","name":"alicloud.acr.syncRule","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossUser":{"name":"crossUser","type":"\u0004","is_mandatory":true,"title":"Whether the rule crosses an account boundary","desc":"True means the other end of the rule belongs to a different Alibaba Cloud account, so images leave this account entirely.","provider":"go.mondoo.com/mql/providers/alicloud"},"localInstanceId":{"name":"localInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance the rule was defined on","provider":"go.mondoo.com/mql/providers/alicloud"},"localNamespaceName":{"name":"localNamespaceName","type":"\u0007","is_mandatory":true,"title":"Namespace the rule reads from","provider":"go.mondoo.com/mql/providers/alicloud"},"localRegionId":{"name":"localRegionId","type":"\u0007","is_mandatory":true,"title":"Region of the instance the rule was defined on","provider":"go.mondoo.com/mql/providers/alicloud"},"localRepoName":{"name":"localRepoName","type":"\u0007","is_mandatory":true,"title":"Repository the rule reads from","desc":"Empty for a rule scoped to a whole namespace.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","is_mandatory":true,"title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"namespaceNameFilter":{"name":"namespaceNameFilter","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which namespaces the rule covers","provider":"go.mondoo.com/mql/providers/alicloud"},"repoNameFilter":{"name":"repoNameFilter","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which repositories the rule covers","provider":"go.mondoo.com/mql/providers/alicloud"},"syncDirection":{"name":"syncDirection","type":"\u0007","is_mandatory":true,"title":"Direction images move","desc":"FROM copies from the source instance to the target instance, TO copies from the target instance back to the source.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRuleId":{"name":"syncRuleId","type":"\u0007","is_mandatory":true,"title":"Replication rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRuleName":{"name":"syncRuleName","type":"\u0007","is_mandatory":true,"title":"Replication rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"syncScope":{"name":"syncScope","type":"\u0007","is_mandatory":true,"title":"What the rule matches","desc":"NAMESPACE replicates a whole namespace, REPO replicates a single repository. A NAMESPACE rule keeps applying to repositories created after the rule was written.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncTrigger":{"name":"syncTrigger","type":"\u0007","is_mandatory":true,"title":"How the rule fires","desc":"INITIATIVE for a replication started on purpose, PASSIVE for one triggered by a push.","provider":"go.mondoo.com/mql/providers/alicloud"},"tagFilter":{"name":"tagFilter","type":"\u0007","is_mandatory":true,"title":"Regular expression selecting which tags the rule copies","provider":"go.mondoo.com/mql/providers/alicloud"},"targetInstanceId":{"name":"targetInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance images are copied to","desc":"The target can belong to another account, which has no resource here, so this is the only view of it.","provider":"go.mondoo.com/mql/providers/alicloud"},"targetNamespaceName":{"name":"targetNamespaceName","type":"\u0007","is_mandatory":true,"title":"Namespace images are copied into","provider":"go.mondoo.com/mql/providers/alicloud"},"targetRegionId":{"name":"targetRegionId","type":"\u0007","is_mandatory":true,"title":"Region images are copied to","provider":"go.mondoo.com/mql/providers/alicloud"},"targetRepoName":{"name":"targetRepoName","type":"\u0007","is_mandatory":true,"title":"Repository images are copied into","desc":"Empty for a rule scoped to a whole namespace.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Registry replication rule","desc":"A rule that copies images between registries, keyed by syncRuleId. Reports what the rule matches and where the copies land, so a rule that moves images into another account or region is visible as one.","min_provider_version":"13.4.1","defaults":"syncRuleName syncDirection targetRegionId crossUser","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.acr.vulnerability":{"id":"alicloud.acr.vulnerability","name":"alicloud.acr.vulnerability","fields":{"addedBy":{"name":"addedBy","type":"\u0007","is_mandatory":true,"title":"Image layer that introduced the affected component","provider":"go.mondoo.com/mql/providers/alicloud"},"aliasName":{"name":"aliasName","type":"\u0007","is_mandatory":true,"title":"Alternative name the scanner uses for the vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"cveLink":{"name":"cveLink","type":"\u0007","is_mandatory":true,"title":"Reference URL for the vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"cveLocation":{"name":"cveLocation","type":"\u0007","is_mandatory":true,"title":"Path inside the image where the affected component was found","provider":"go.mondoo.com/mql/providers/alicloud"},"cveName":{"name":"cveName","type":"\u0007","is_mandatory":true,"title":"CVE identifier, for example CVE-2021-3711","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"feature":{"name":"feature","type":"\u0007","is_mandatory":true,"title":"Package or component carrying the vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"fixCmd":{"name":"fixCmd","type":"\u0007","is_mandatory":true,"title":"Command that installs the fixed version, empty when no fix is published","provider":"go.mondoo.com/mql/providers/alicloud"},"scanType":{"name":"scanType","type":"\u0007","is_mandatory":true,"title":"Kind of finding, cve for a system package or sca for an application dependency","provider":"go.mondoo.com/mql/providers/alicloud"},"severity":{"name":"severity","type":"\u0007","is_mandatory":true,"title":"Severity rating","desc":"One of High, Medium, Low, or Unknown.","provider":"go.mondoo.com/mql/providers/alicloud"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Version of the package present in the image","provider":"go.mondoo.com/mql/providers/alicloud"},"versionFixed":{"name":"versionFixed","type":"\u0007","is_mandatory":true,"title":"Version that fixes the vulnerability, empty when no fix is published","desc":"A non-empty value means the image can be rebuilt to remove the finding today.","provider":"go.mondoo.com/mql/providers/alicloud"},"versionFormat":{"name":"versionFormat","type":"\u0007","is_mandatory":true,"title":"Packaging format the version numbers follow, for example dpkg or rpm","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Vulnerability found in a Container Registry image","desc":"A single scan finding for one image tag. Exposes the CVE, its severity, the package that carries it, and the version that fixes it. Use it to find images running a package with a known fix available.","min_provider_version":"13.5.1","defaults":"cveName severity feature version","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.actiontrail":{"id":"alicloud.actiontrail","name":"alicloud.actiontrail","fields":{"trail":{"name":"trail","type":"\u001balicloud.actiontrail.trail","title":"ActionTrail trail","desc":"A single audit trail, keyed by name. Exposes the event categories it captures (read, write, or all), the OSS bucket and Log Service project it delivers to, the delivery roles, whether it is an organization trail, and its live logging and delivery status. Use it to confirm a trail is actively logging and delivering events without errors.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"trails":{"name":"trails","type":"\u0019\u001balicloud.actiontrail.trail","title":"Trails configured in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud ActionTrail","desc":"Audit trail configuration for an Alibaba Cloud account. Exposes the trails that record management and data-plane API events, including where each trail delivers events (an OSS bucket or a Log Service project), whether it spans the resource directory, and its live logging and delivery health. Use it to audit whether API activity is being recorded and successfully delivered.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.actiontrail.trail":{"id":"alicloud.actiontrail.trail","name":"alicloud.actiontrail.trail","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the trail was created","provider":"go.mondoo.com/mql/providers/alicloud"},"eventRW":{"name":"eventRW","type":"\u0007","is_mandatory":true,"title":"Event categories the trail records","desc":"One of Write, Read, or All.","provider":"go.mondoo.com/mql/providers/alicloud"},"homeRegion":{"name":"homeRegion","type":"\u0007","is_mandatory":true,"title":"Region the trail was created in","provider":"go.mondoo.com/mql/providers/alicloud"},"isLogging":{"name":"isLogging","type":"\u0004","title":"Whether the trail is actively logging events","desc":"The live logging state reported by ActionTrail, which can differ from the configured status.","provider":"go.mondoo.com/mql/providers/alicloud"},"isOrganizationTrail":{"name":"isOrganizationTrail","type":"\u0004","is_mandatory":true,"title":"Whether the trail records events across all accounts in the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryError":{"name":"latestDeliveryError","type":"\u0007","title":"Most recent event-delivery error, empty when the last delivery succeeded","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryLogServiceError":{"name":"latestDeliveryLogServiceError","type":"\u0007","title":"Most recent Log Service delivery error, empty when the last delivery succeeded","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryLogServiceTime":{"name":"latestDeliveryLogServiceTime","type":"\t","title":"Time of the most recent successful delivery to Log Service, null when none","provider":"go.mondoo.com/mql/providers/alicloud"},"latestDeliveryTime":{"name":"latestDeliveryTime","type":"\t","title":"Time of the most recent successful event delivery, null when none","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Trail name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"organizationId":{"name":"organizationId","type":"\u0007","is_mandatory":true,"title":"Resource directory (organization) ID for an organization trail, empty otherwise","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucket":{"name":"ossBucket","type":"\u001balicloud.oss.bucket","title":"OSS bucket that receives delivered events","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucketLocation":{"name":"ossBucketLocation","type":"\u0007","is_mandatory":true,"title":"Region of the OSS bucket, for example oss-cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucketName":{"name":"ossBucketName","type":"\u0007","is_mandatory":true,"title":"Name of the OSS bucket that receives delivered events, empty when not delivering to OSS","provider":"go.mondoo.com/mql/providers/alicloud"},"ossKeyPrefix":{"name":"ossKeyPrefix","type":"\u0007","is_mandatory":true,"title":"Object-name prefix applied to delivered event files","provider":"go.mondoo.com/mql/providers/alicloud"},"ossWriteRoleArn":{"name":"ossWriteRoleArn","type":"\u0007","is_mandatory":true,"title":"RAM role ARN ActionTrail assumes to write to the OSS bucket","provider":"go.mondoo.com/mql/providers/alicloud"},"slsProject":{"name":"slsProject","type":"\u001balicloud.log.project","title":"Log Service project that receives delivered events","provider":"go.mondoo.com/mql/providers/alicloud"},"slsProjectArn":{"name":"slsProjectArn","type":"\u0007","is_mandatory":true,"title":"ARN of the Log Service project that receives delivered events, empty when not delivering to SLS","provider":"go.mondoo.com/mql/providers/alicloud"},"slsWriteRoleArn":{"name":"slsWriteRoleArn","type":"\u0007","is_mandatory":true,"title":"RAM role ARN ActionTrail assumes to write to the Log Service project","provider":"go.mondoo.com/mql/providers/alicloud"},"startLoggingTime":{"name":"startLoggingTime","type":"\t","is_mandatory":true,"title":"Time the trail most recently started logging","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Configuration state of the trail","desc":"One of Enable, Disable, or Fresh. Fresh means the trail was created but has never started logging.","provider":"go.mondoo.com/mql/providers/alicloud"},"stopLoggingTime":{"name":"stopLoggingTime","type":"\t","is_mandatory":true,"title":"Time the trail most recently stopped logging, empty while logging","provider":"go.mondoo.com/mql/providers/alicloud"},"trailArn":{"name":"trailArn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the trail","provider":"go.mondoo.com/mql/providers/alicloud"},"trailRegion":{"name":"trailRegion","type":"\u0007","is_mandatory":true,"title":"Region whose events the trail records, or All for a multi-region trail","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the trail was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ActionTrail trail","desc":"A single audit trail, keyed by name. Exposes the event categories it captures (read, write, or all), the OSS bucket and Log Service project it delivers to, the delivery roles, whether it is an organization trail, and its live logging and delivery status. Use it to confirm a trail is actively logging and delivering events without errors.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb":{"id":"alicloud.alb","name":"alicloud.alb","fields":{"listener":{"name":"listener","type":"\u001balicloud.alb.listener","title":"Application Load Balancer listener","desc":"A single listener on an ALB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy for HTTPS/QUIC listeners, and the server groups it forwards to. Use it to audit whether an HTTPS listener enforces a strong TLS policy and presents certificates.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.alb.loadBalancer","title":"Application Load Balancer instance","desc":"A single ALB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC and security groups it runs in, its access-logging configuration, and its listeners. Use it to audit public exposure and access logging. For example alicloud.alb.loadBalancer(loadBalancerId: \"alb-xxx\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001balicloud.alb.loadBalancer","title":"Application load balancers across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicies":{"name":"securityPolicies","type":"\u0019\u001balicloud.alb.securityPolicy","title":"Custom TLS security policies across all enabled regions","desc":"A security policy fixes the TLS versions and cipher suites a listener accepts. Only custom policies are listed; a listener using one of the built-in policies names it by id and has no entry here.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicy":{"name":"securityPolicy","type":"\u001balicloud.alb.securityPolicy","title":"Application Load Balancer TLS security policy","desc":"A custom TLS security policy, keyed by securityPolicyId within its region. Exposes the TLS versions and cipher suites the policy permits. Use it to find a listener that still accepts TLS 1.0 or 1.1.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverGroup":{"name":"serverGroup","type":"\u001balicloud.alb.serverGroup","title":"Application Load Balancer server group","desc":"A single ALB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward requests to. Exposes the backend protocol, scheduling algorithm, health-check configuration, and the VPC the group belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverGroups":{"name":"serverGroups","type":"\u0019\u001balicloud.alb.serverGroup","title":"ALB server groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Application Load Balancer","desc":"ALB (Layer-7) load balancers across an Alibaba Cloud account. Exposes the application load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether HTTPS listeners use a strong TLS policy, and whether access logging is enabled.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.listener":{"id":"alicloud.alb.listener","name":"alicloud.alb.listener","fields":{"certificateIds":{"name":"certificateIds","type":"\u0019\u0007","title":"Server certificate IDs presented by the listener","desc":"Empty for non-TLS listeners. A populated list confirms the HTTPS/QUIC listener presents a server certificate.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"gzipEnabled":{"name":"gzipEnabled","type":"\u0004","is_mandatory":true,"title":"Whether response gzip compression is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"http2Enabled":{"name":"http2Enabled","type":"\u0004","is_mandatory":true,"title":"Whether HTTP/2 is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"idleTimeout":{"name":"idleTimeout","type":"\u0005","is_mandatory":true,"title":"Idle connection timeout in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"listenerId":{"name":"listenerId","type":"\u0007","is_mandatory":true,"title":"Listener ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.alb.loadBalancer","title":"Load balancer the listener belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the load balancer the listener belongs to","desc":"Deprecated in favor of loadBalancer.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.alb.listener.loadBalancer"},"mutualTlsEnabled":{"name":"mutualTlsEnabled","type":"\u0004","title":"Whether mutual TLS (client certificate authentication) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the listener serves on","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Listener protocol, one of HTTP, HTTPS, or QUIC","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the listener resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"requestTimeout":{"name":"requestTimeout","type":"\u0005","is_mandatory":true,"title":"Request timeout in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicy":{"name":"securityPolicy","type":"\u001balicloud.alb.securityPolicy","title":"TLS security policy applied to the listener","desc":"Null for a non-TLS listener and for a listener using one of the built-in policies, which are not enumerable; securityPolicyId names those.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyId":{"name":"securityPolicyId","type":"\u0007","is_mandatory":true,"title":"TLS security policy applied to the listener, empty for non-TLS listeners","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroups":{"name":"serverGroups","type":"\u0019\u001balicloud.alb.serverGroup","title":"Server groups the listener forwards requests to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Listener status, for example Running, Configuring, or Stopped","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the listener","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Application Load Balancer listener","desc":"A single listener on an ALB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy for HTTPS/QUIC listeners, and the server groups it forwards to. Use it to audit whether an HTTPS listener enforces a strong TLS policy and presents certificates.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.loadBalancer":{"id":"alicloud.alb.loadBalancer","name":"alicloud.alb.loadBalancer","fields":{"accessLogProject":{"name":"accessLogProject","type":"\u001balicloud.log.project","title":"Log Service project that receives access logs, null when access logging is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"accessLogStore":{"name":"accessLogStore","type":"\u001balicloud.log.logstore","title":"Log Service logstore that receives access logs, null when access logging is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"accessLoggingEnabled":{"name":"accessLoggingEnabled","type":"\u0004","is_mandatory":true,"title":"Whether access logging to Log Service is enabled","desc":"True when the load balancer delivers access logs to a Log Service project and logstore. When false, request-level access logs are not retained.","provider":"go.mondoo.com/mql/providers/alicloud"},"addressAllocatedMode":{"name":"addressAllocatedMode","type":"\u0007","is_mandatory":true,"title":"Address allocation mode, either Fixed or Dynamic","provider":"go.mondoo.com/mql/providers/alicloud"},"addressIpVersion":{"name":"addressIpVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the address, either IPv4 or DualStack","provider":"go.mondoo.com/mql/providers/alicloud"},"addressType":{"name":"addressType","type":"\u0007","is_mandatory":true,"title":"Address type","desc":"Either Internet (internet-facing) or Intranet (internal only).","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageId":{"name":"bandwidthPackageId","type":"\u0007","is_mandatory":true,"title":"ID of the bandwidth package bound to the load balancer, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (billing) status of the load balancer, for example Normal","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the load balancer was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtectionEnabled":{"name":"deletionProtectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"dnsName":{"name":"dnsName","type":"\u0007","is_mandatory":true,"title":"DNS name assigned to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"edition":{"name":"edition","type":"\u0007","is_mandatory":true,"title":"Load balancer edition, one of Basic, Standard, or StandardWithWaf","provider":"go.mondoo.com/mql/providers/alicloud"},"internetFacing":{"name":"internetFacing","type":"\u0004","title":"Whether the load balancer serves traffic from the public internet","desc":"True when the address type is Internet. An internet-facing load balancer is reachable from outside the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6AddressType":{"name":"ipv6AddressType","type":"\u0007","is_mandatory":true,"title":"IPv6 address type, either Internet or Intranet","provider":"go.mondoo.com/mql/providers/alicloud"},"listeners":{"name":"listeners","type":"\u0019\u001balicloud.alb.listener","title":"Listeners configured on the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"Load balancer ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionStatus":{"name":"modificationProtectionStatus","type":"\u0007","is_mandatory":true,"title":"Modification-protection status, either NonProtection or ConsoleProtection","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Load balancer name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the load balancer resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the load balancer","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the load balancer belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Load balancer status","desc":"For example Active, Inactive, Provisioning, or Configuring.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the load balancer runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the load balancer attaches to across its zones","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Application Load Balancer instance","desc":"A single ALB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC and security groups it runs in, its access-logging configuration, and its listeners. Use it to audit public exposure and access logging. For example alicloud.alb.loadBalancer(loadBalancerId: \"alb-xxx\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.securityPolicy":{"id":"alicloud.alb.securityPolicy","name":"alicloud.alb.securityPolicy","fields":{"allowsLegacyTls":{"name":"allowsLegacyTls","type":"\u0004","is_mandatory":true,"title":"Whether the policy still accepts TLS 1.0 or TLS 1.1","desc":"Both versions are deprecated and carry known weaknesses, so a listener bound to such a policy accepts connections that a current client would refuse to make.","provider":"go.mondoo.com/mql/providers/alicloud"},"ciphers":{"name":"ciphers","type":"\u0019\u0007","is_mandatory":true,"title":"Cipher suites the policy permits","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the policy resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the policy belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyId":{"name":"securityPolicyId","type":"\u0007","is_mandatory":true,"title":"Security policy ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyName":{"name":"securityPolicyName","type":"\u0007","is_mandatory":true,"title":"Name of the security policy","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the policy, for example Available or Configuring","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsVersions":{"name":"tlsVersions","type":"\u0019\u0007","is_mandatory":true,"title":"TLS versions the policy accepts, for example TLSv1.2 and TLSv1.3","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Application Load Balancer TLS security policy","desc":"A custom TLS security policy, keyed by securityPolicyId within its region. Exposes the TLS versions and cipher suites the policy permits. Use it to find a listener that still accepts TLS 1.0 or 1.1.","min_provider_version":"13.5.1","defaults":"securityPolicyName tlsVersions status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.serverGroup":{"id":"alicloud.alb.serverGroup","name":"alicloud.alb.serverGroup","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the server group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossZoneEnabled":{"name":"crossZoneEnabled","type":"\u0004","is_mandatory":true,"title":"Whether cross-zone load balancing is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckEnabled":{"name":"healthCheckEnabled","type":"\u0004","is_mandatory":true,"title":"Whether health checks are enabled for the group","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckPath":{"name":"healthCheckPath","type":"\u0007","is_mandatory":true,"title":"Health-check request path, for HTTP health checks","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckProtocol":{"name":"healthCheckProtocol","type":"\u0007","is_mandatory":true,"title":"Health-check protocol, one of HTTP, TCP, or gRPC","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Server group name","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Backend protocol, one of HTTP, HTTPS, or gRPC","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the server group resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the server group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduler":{"name":"scheduler","type":"\u0007","is_mandatory":true,"title":"Scheduling algorithm, one of Wrr, Wlc, or Sch","provider":"go.mondoo.com/mql/providers/alicloud"},"server":{"name":"server","type":"\u001balicloud.alb.serverGroup.server","title":"ALB backend server","desc":"One server an ALB server group forwards requests to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverCount":{"name":"serverCount","type":"\u0005","is_mandatory":true,"title":"Number of backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroupId":{"name":"serverGroupId","type":"\u0007","is_mandatory":true,"title":"Server group ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"servers":{"name":"servers","type":"\u0019\u001balicloud.alb.serverGroup.server","title":"Servers in the group","desc":"What the load balancer forwards to. An internet-facing ALB makes every one of these reachable from the public internet on the listener's port.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Server group status","provider":"go.mondoo.com/mql/providers/alicloud"},"stickySessionEnabled":{"name":"stickySessionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether session stickiness is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"stickySessionType":{"name":"stickySessionType","type":"\u0007","is_mandatory":true,"title":"Session stickiness type, either Insert or Server","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the server group","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Server group type, one of Instance, Ip, or Fc","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Application Load Balancer server group","desc":"A single ALB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward requests to. Exposes the backend protocol, scheduling algorithm, health-check configuration, and the VPC the group belongs to.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.alb.serverGroup.server":{"id":"alicloud.alb.serverGroup.server","name":"alicloud.alb.serverGroup.server","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Backend server description","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the backend","desc":"Null unless serverType is Ecs, or when the instance can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"remoteIpEnabled":{"name":"remoteIpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the client IP is preserved to the backend","desc":"False means the backend sees the load balancer's address instead of the caller's, which affects any allowlist or log the backend keeps.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"ID of the backend server","desc":"An ECS instance ID, an elastic network interface ID, an IP address, or a Function Compute function, depending on serverType.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverIp":{"name":"serverIp","type":"\u0007","is_mandatory":true,"title":"IP address the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverType":{"name":"serverType","type":"\u0007","is_mandatory":true,"title":"Kind of backend","desc":"One of Ecs, Eni, Ip, or Fc.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Backend server status","provider":"go.mondoo.com/mql/providers/alicloud"},"weight":{"name":"weight","type":"\u0005","is_mandatory":true,"title":"Share of traffic the server receives","desc":"A weight of 0 takes the server out of rotation without detaching it.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ALB backend server","desc":"One server an ALB server group forwards requests to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","min_provider_version":"13.4.1","defaults":"serverType serverId serverIp port weight","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos":{"id":"alicloud.antiddos","name":"alicloud.antiddos","fields":{"instance":{"name":"instance","type":"\u001balicloud.antiddos.instance","title":"Anti-DDoS instance","desc":"A single Anti-DDoS Pro or Premium instance, keyed by instanceId. Exposes the mitigation edition, forwarding state, and subscription window, and is the parent of the protected web domains and forwarding ports. Use it to confirm an instance is enabled and not expired. Protection is effectively off when the instance is expired or not forwarding traffic.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.antiddos.instance","title":"Anti-DDoS Pro and Premium instances across the China and international centers","provider":"go.mondoo.com/mql/providers/alicloud"},"networkRule":{"name":"networkRule","type":"\u001balicloud.antiddos.networkRule","title":"Anti-DDoS protected forwarding port","desc":"A single non-web (Layer-4) forwarding rule on an Anti-DDoS instance, keyed by the instanceId, protocol, and frontend port. Exposes the frontend and backend ports and the origin servers. Use it to enumerate the TCP and UDP ports under Anti-DDoS protection.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"webRule":{"name":"webRule","type":"\u001balicloud.antiddos.webRule","title":"Anti-DDoS protected web domain","desc":"A single web domain protected by an Anti-DDoS instance, keyed by the owning instanceId and domain. Exposes the scrubbing CNAME, the HTTP flood (CC) protection state, the certificate, and the origin servers. Use it to audit whether a protected domain has CC protection and a non-expired certificate.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Anti-DDoS","desc":"Anti-DDoS Pro and Premium instances and the assets they protect for an Alibaba Cloud account. Anti-DDoS is a center service. Exposes the scrubbing instances, their subscription health, and the web domains and forwarding ports under protection. Use it to audit which assets are protected and whether an instance's protection has lapsed (expired, disabled, or in debt).","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos.instance":{"id":"alicloud.antiddos.instance","name":"alicloud.antiddos.instance","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"debtStatus":{"name":"debtStatus","type":"\u0005","is_mandatory":true,"title":"Overdue-payment status, 0 when there is no overdue payment","provider":"go.mondoo.com/mql/providers/alicloud"},"edition":{"name":"edition","type":"\u0005","is_mandatory":true,"title":"Mitigation edition","desc":"0 (Premium Insurance), 1 (Premium Unlimited), 2 (Premium mainland acceleration), or 9 (Pro Profession).","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the instance is forwarding (protecting) traffic","desc":"False when the instance is not forwarding service traffic, which means its protection is effectively off.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Time the instance subscription expires","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Anti-DDoS instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"Anti-DDoS instance IP that scrubbed traffic is delivered from","provider":"go.mondoo.com/mql/providers/alicloud"},"ipMode":{"name":"ipMode","type":"\u0007","is_mandatory":true,"title":"Forwarding mode of the instance IP, for example fnat","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the instance, either Ipv4 or Ipv6","provider":"go.mondoo.com/mql/providers/alicloud"},"networkRules":{"name":"networkRules","type":"\u0019\u001balicloud.antiddos.networkRule","title":"Non-web (TCP/UDP) forwarding ports protected by the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the instance belongs to, either cn-hangzhou or ap-southeast-1","provider":"go.mondoo.com/mql/providers/alicloud"},"remark":{"name":"remark","type":"\u0007","is_mandatory":true,"title":"Instance remark","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Instance status","desc":"1 (Normal) or 2 (Expired). An expired instance no longer scrubs traffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"webRules":{"name":"webRules","type":"\u0019\u001balicloud.antiddos.webRule","title":"Web (HTTP/HTTPS) domains protected by the instance","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Anti-DDoS instance","desc":"A single Anti-DDoS Pro or Premium instance, keyed by instanceId. Exposes the mitigation edition, forwarding state, and subscription window, and is the parent of the protected web domains and forwarding ports. Use it to confirm an instance is enabled and not expired. Protection is effectively off when the instance is expired or not forwarding traffic.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos.networkRule":{"id":"alicloud.antiddos.networkRule","name":"alicloud.antiddos.networkRule","fields":{"backendPort":{"name":"backendPort","type":"\u0005","is_mandatory":true,"title":"Backend (origin) port traffic is forwarded to","provider":"go.mondoo.com/mql/providers/alicloud"},"frontendPort":{"name":"frontendPort","type":"\u0005","is_mandatory":true,"title":"Frontend (listener) port scrubbed traffic arrives on","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the Anti-DDoS instance the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Forwarding protocol, either tcp or udp","provider":"go.mondoo.com/mql/providers/alicloud"},"realServers":{"name":"realServers","type":"\u0019\u0007","is_mandatory":true,"title":"Origin servers traffic is forwarded to after scrubbing","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Anti-DDoS protected forwarding port","desc":"A single non-web (Layer-4) forwarding rule on an Anti-DDoS instance, keyed by the instanceId, protocol, and frontend port. Exposes the frontend and backend ports and the origin servers. Use it to enumerate the TCP and UDP ports under Anti-DDoS protection.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.antiddos.webRule":{"id":"alicloud.antiddos.webRule","name":"alicloud.antiddos.webRule","fields":{"ccEnabled":{"name":"ccEnabled","type":"\u0004","is_mandatory":true,"title":"Whether HTTP flood (CC) protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"ccRuleEnabled":{"name":"ccRuleEnabled","type":"\u0004","is_mandatory":true,"title":"Whether a CC protection rule is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"certExpireTime":{"name":"certExpireTime","type":"\t","is_mandatory":true,"title":"Expiry time of the bound certificate, null when no certificate is configured","provider":"go.mondoo.com/mql/providers/alicloud"},"certName":{"name":"certName","type":"\u0007","is_mandatory":true,"title":"Name of the certificate bound to the domain, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"cname":{"name":"cname","type":"\u0007","is_mandatory":true,"title":"Anti-DDoS scrubbing CNAME that traffic must resolve to","provider":"go.mondoo.com/mql/providers/alicloud"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Protected hostname, used with the instance ID as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the Anti-DDoS instance protecting the domain","provider":"go.mondoo.com/mql/providers/alicloud"},"logDeliveryEnabled":{"name":"logDeliveryEnabled","type":"\u0004","title":"Whether access and attack logs for the domain are delivered to Log Service","desc":"Anti-DDoS keeps a searchable record of the traffic it scrubbed only while this is on, so an attack on a domain with it off leaves nothing to investigate afterwards. The switch is per protected domain rather than per instance, so one domain having it on says nothing about the others.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logLogstoreName":{"name":"logLogstoreName","type":"\u0007","title":"Name of the Log Service logstore the domain's logs are delivered to","desc":"Empty when log delivery is off.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logProject":{"name":"logProject","type":"\u001balicloud.log.project","title":"Log Service project the domain's logs are delivered to","desc":"Null when log delivery is off or the project can no longer be read. Traverse to it for the retention and the access policy of the store that holds the scrubbing records.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logProjectName":{"name":"logProjectName","type":"\u0007","title":"Name of the Log Service project the domain's logs are delivered to","desc":"Empty when log delivery is off.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"penalized":{"name":"penalized","type":"\u0004","is_mandatory":true,"title":"Whether the domain is currently penalized (blocked) for abnormal traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyTypes":{"name":"proxyTypes","type":"\u0019\n","is_mandatory":true,"title":"Protocols and listener ports the domain serves","desc":"Each entry lists the proxyType (http, https, websocket, or websockets) and the proxyPorts it listens on.","provider":"go.mondoo.com/mql/providers/alicloud"},"realServers":{"name":"realServers","type":"\u0019\n","is_mandatory":true,"title":"Origin servers traffic is forwarded to after scrubbing","desc":"Each entry lists the realServer (an IP or hostname) and its rsType (0 for an IP, 1 for a domain).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the domain belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Anti-DDoS protected web domain","desc":"A single web domain protected by an Anti-DDoS instance, keyed by the owning instanceId and domain. Exposes the scrubbing CNAME, the HTTP flood (CC) protection state, the certificate, and the origin servers. Use it to audit whether a protected domain has CC protection and a non-expired certificate.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cen":{"id":"alicloud.cen","name":"alicloud.cen","fields":{"attachment":{"name":"attachment","type":"\u001balicloud.cen.attachment","title":"Network attached to a Cloud Enterprise Network","desc":"A single network joined to a CEN, keyed by the cenId and the attached network's ID. The childInstanceType names what kind of network it is, and childInstanceOwnerId reveals attachments owned by another account, which extend reachability outside the account boundary.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instance":{"name":"instance","type":"\u001balicloud.cen.instance","title":"Cloud Enterprise Network instance","desc":"A single CEN, keyed by cenId. Every network attached to it can route to every other attached network, so the attachments list is the reachability boundary: a VPC attached here is reachable from every other attached VPC, across regions and across accounts, before security-group and ACL rules are considered.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.cen.instance","title":"Cloud Enterprise Network instances in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Enterprise Network","desc":"Transit networking for the account. Exposes the CEN instances, each of which joins the networks attached to it into one routing domain, so a workload in one attached VPC can reach a workload in another regardless of region.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cen.attachment":{"id":"alicloud.cen.attachment","name":"alicloud.cen.attachment","fields":{"attachTime":{"name":"attachTime","type":"\t","is_mandatory":true,"title":"Time the network was attached","provider":"go.mondoo.com/mql/providers/alicloud"},"cenId":{"name":"cenId","type":"\u0007","is_mandatory":true,"title":"ID of the CEN the network is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceId":{"name":"childInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the attached network","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceOwnerId":{"name":"childInstanceOwnerId","type":"\u0005","is_mandatory":true,"title":"Account (UID) that owns the attached network","desc":"A value other than the scanned account means the CEN reaches into another account, extending the routing domain past the account boundary.","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceRegionId":{"name":"childInstanceRegionId","type":"\u0007","is_mandatory":true,"title":"Region the attached network lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"childInstanceType":{"name":"childInstanceType","type":"\u0007","is_mandatory":true,"title":"Kind of attached network","desc":"One of VPC, VBR for a virtual border router carrying an Express Connect circuit, or CCN for a Cloud Connect Network.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Attachment status, for example Attached or Attaching","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC behind a VPC attachment","desc":"Null for a VBR or CCN attachment, and for a VPC owned by another account, which the scanned credential cannot read.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network attached to a Cloud Enterprise Network","desc":"A single network joined to a CEN, keyed by the cenId and the attached network's ID. The childInstanceType names what kind of network it is, and childInstanceOwnerId reveals attachments owned by another account, which extend reachability outside the account boundary.","min_provider_version":"13.2.5","defaults":"childInstanceId childInstanceType childInstanceRegionId status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cen.instance":{"id":"alicloud.cen.instance","name":"alicloud.cen.instance","fields":{"attachments":{"name":"attachments","type":"\u0019\u001balicloud.cen.attachment","title":"Networks attached to the CEN","provider":"go.mondoo.com/mql/providers/alicloud"},"cenId":{"name":"cenId","type":"\u0007","is_mandatory":true,"title":"CEN instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the CEN was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the CEN instance","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6Level":{"name":"ipv6Level","type":"\u0007","is_mandatory":true,"title":"Whether the CEN carries IPv6 traffic","desc":"ENABLE when IPv6 routing is on, DISABLE when the CEN carries IPv4 only.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the CEN instance","provider":"go.mondoo.com/mql/providers/alicloud"},"protectionLevel":{"name":"protectionLevel","type":"\u0007","is_mandatory":true,"title":"Level of DDoS protection applied to the CEN","desc":"FULL when protection covers every attached network, or REDUCE for the basic level.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the CEN instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the CEN belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Instance status, for example Creating or Active","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the CEN, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Enterprise Network instance","desc":"A single CEN, keyed by cenId. Every network attached to it can route to every other attached network, so the attachments list is the reachability boundary: a VPC attached here is reachable from every other attached VPC, across regions and across accounts, before security-group and ACL rules are considered.","min_provider_version":"13.2.5","defaults":"cenId name status protectionLevel","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall":{"id":"alicloud.cloudFirewall","name":"alicloud.cloudFirewall","fields":{"controlPolicies":{"name":"controlPolicies","type":"\u0019\u001balicloud.cloudFirewall.controlPolicy","title":"Internet-boundary control policies in both the inbound and outbound directions","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPolicy":{"name":"controlPolicy","type":"\u001balicloud.cloudFirewall.controlPolicy","title":"Cloud Firewall control policy","desc":"A single internet-boundary access-control rule, keyed by aclUuid. A rule permits or denies traffic between a source and destination on given ports and protocols. Exposes the action, source, destination, and whether it is enabled. Use it to find enabled rules that broadly accept inbound traffic (for example an accept rule with source 0.0.0.0/0).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"edition":{"name":"edition","type":"\u0005","title":"Cloud Firewall edition","desc":"2 (Premium), 3 (Enterprise), 4 (Ultimate), or 10 (pay-as-you-go). 0 when the service is not provisioned.","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","title":"Whether the Cloud Firewall service is active for the account","provider":"go.mondoo.com/mql/providers/alicloud"},"logDeliveryEnabled":{"name":"logDeliveryEnabled","type":"\u0004","title":"Whether Cloud Firewall delivers its traffic logs to Log Service","desc":"Reports whether a Log Service logstore is provisioned to receive the firewall's logs. This is the log-analysis feature and is separate from enabled: a firewall that is running with log analysis off keeps no searchable record of the traffic it allowed or denied, so a control policy cannot be shown to have ever matched.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logProject":{"name":"logProject","type":"\u001balicloud.log.project","title":"Log Service project holding the firewall logs","desc":"Null when log analysis is off or the project can no longer be read.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logProjectName":{"name":"logProjectName","type":"\u0007","title":"Name of the Log Service project holding the firewall logs","desc":"Empty when log analysis is off.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logRegionId":{"name":"logRegionId","type":"\u0007","title":"Region the firewall logs are delivered to","desc":"Empty when log analysis is off.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logRetentionDays":{"name":"logRetentionDays","type":"\u0005","title":"Days the firewall logs are retained","desc":"Zero when log analysis is off. Logs older than this are dropped, which bounds how far back an investigation can reach.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logStoreName":{"name":"logStoreName","type":"\u0007","title":"Name of the Log Service logstore holding the firewall logs","desc":"Empty when log analysis is off.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"natControlPolicy":{"name":"natControlPolicy","type":"\u001balicloud.cloudFirewall.natControlPolicy","title":"Cloud Firewall NAT firewall control policy","desc":"A single NAT-boundary access-control rule, keyed by aclUuid. A rule permits or denies traffic leaving (or entering) a NAT gateway on given ports and protocols. Exposes the direction, action, both endpoints, and whether the rule is enforced. Use it to find egress rules that permit unrestricted outbound traffic from a private subnet.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"natFirewall":{"name":"natFirewall","type":"\u001balicloud.cloudFirewall.natFirewall","title":"Cloud Firewall NAT firewall","desc":"A single NAT firewall, keyed by proxyId. A NAT firewall inspects the traffic a private subnet sends through a NAT gateway. Exposes the guarded gateway and VPC, the firewall health, strict mode, and the access-control rules on the egress path. Use it to find NAT gateways whose outbound traffic passes uninspected.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"natFirewalls":{"name":"natFirewalls","type":"\u0019\u001balicloud.cloudFirewall.natFirewall","title":"NAT firewalls guarding outbound traffic through a NAT gateway","desc":"A NAT firewall inspects the egress path of a private subnet. Without one, an instance with no public address still reaches the internet through the NAT gateway unfiltered.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcControlPolicy":{"name":"vpcControlPolicy","type":"\u001balicloud.cloudFirewall.vpcControlPolicy","title":"Cloud Firewall VPC firewall control policy","desc":"A single east-west access-control rule of a VPC firewall, keyed by aclUuid. A rule permits or denies traffic between a source and a destination on given ports and protocols. Exposes the action, both endpoints, the resolved address-book members, and whether the rule is enforced. Use it to find enabled rules that broadly permit traffic between VPCs (for example an accept rule whose source is 0.0.0.0/0).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpcFirewall":{"name":"vpcFirewall","type":"\u001balicloud.cloudFirewall.vpcFirewall","title":"Cloud Firewall VPC firewall","desc":"A single VPC firewall, keyed by vpcFirewallId. A VPC firewall guards the east-west path between two VPCs joined by CEN, VPC peering, or Express Connect. Exposes both ends of the pair, whether the firewall is switched on, the strict-mode and intrusion-prevention settings, and the access-control rules it enforces. Use it to find VPC pairs that carry traffic with no firewall in the path, or with a firewall that only observes.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpcFirewalls":{"name":"vpcFirewalls","type":"\u0019\u001balicloud.cloudFirewall.vpcFirewall","title":"VPC firewalls guarding traffic between VPCs","desc":"A VPC firewall sits on an east-west path (a CEN attachment, a VPC peering, or an Express Connect circuit) rather than on the internet boundary, so controlPolicies says nothing about it. A VPC pair with no VPC firewall, or one whose firewall is switched off, moves traffic between networks with nothing inspecting it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Cloud Firewall","desc":"Cloud Firewall access-control state for an Alibaba Cloud account. Cloud Firewall is a center service. Exposes whether the firewall service is active, its edition, and the internet-boundary control policies (the allow and deny rules). Use it to audit whether the firewall is enabled and whether any rule broadly permits inbound traffic.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall.controlPolicy":{"id":"alicloud.cloudFirewall.controlPolicy","name":"alicloud.cloudFirewall.controlPolicy","fields":{"aclUuid":{"name":"aclUuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action taken on matching traffic","desc":"One of accept (allow), drop (deny), or log (monitor only).","provider":"go.mondoo.com/mql/providers/alicloud"},"applicationName":{"name":"applicationName","type":"\u0007","is_mandatory":true,"title":"Application-layer protocol the rule matches, for example HTTP or ANY","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"destPort":{"name":"destPort","type":"\u0007","is_mandatory":true,"title":"Destination port or port range","provider":"go.mondoo.com/mql/providers/alicloud"},"destination":{"name":"destination","type":"\u0007","is_mandatory":true,"title":"Destination address, CIDR, domain, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationType":{"name":"destinationType","type":"\u0007","is_mandatory":true,"title":"Destination type, for example net, group, domain, or location","provider":"go.mondoo.com/mql/providers/alicloud"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Traffic direction the rule applies to, either in (inbound) or out (outbound)","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is enabled","desc":"A disabled rule is configured but not enforced.","provider":"go.mondoo.com/mql/providers/alicloud"},"hitTimes":{"name":"hitTimes","type":"\u0005","is_mandatory":true,"title":"Cumulative number of times the rule has matched traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"order":{"name":"order","type":"\u0005","is_mandatory":true,"title":"Rule priority order","provider":"go.mondoo.com/mql/providers/alicloud"},"proto":{"name":"proto","type":"\u0007","is_mandatory":true,"title":"Protocol, one of ANY, TCP, UDP, or ICMP","provider":"go.mondoo.com/mql/providers/alicloud"},"source":{"name":"source","type":"\u0007","is_mandatory":true,"title":"Source address, CIDR, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceType":{"name":"sourceType","type":"\u0007","is_mandatory":true,"title":"Source type, for example net (CIDR), group (address book), or location","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Firewall control policy","desc":"A single internet-boundary access-control rule, keyed by aclUuid. A rule permits or denies traffic between a source and destination on given ports and protocols. Exposes the action, source, destination, and whether it is enabled. Use it to find enabled rules that broadly accept inbound traffic (for example an accept rule with source 0.0.0.0/0).","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall.natControlPolicy":{"id":"alicloud.cloudFirewall.natControlPolicy","name":"alicloud.cloudFirewall.natControlPolicy","fields":{"aclUuid":{"name":"aclUuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action taken on matching traffic","desc":"One of accept (allow), drop (deny), or log (monitor only).","provider":"go.mondoo.com/mql/providers/alicloud"},"applicationNames":{"name":"applicationNames","type":"\u0019\u0007","is_mandatory":true,"title":"Application-layer protocols the rule matches, for example HTTP or ANY","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"destPort":{"name":"destPort","type":"\u0007","is_mandatory":true,"title":"Destination port or port range","provider":"go.mondoo.com/mql/providers/alicloud"},"destPortGroupPorts":{"name":"destPortGroupPorts","type":"\u0019\u0007","is_mandatory":true,"title":"Ports behind a destination port address book","provider":"go.mondoo.com/mql/providers/alicloud"},"destPortType":{"name":"destPortType","type":"\u0007","is_mandatory":true,"title":"Destination port type, either port (a literal port) or group (a port address book)","provider":"go.mondoo.com/mql/providers/alicloud"},"destination":{"name":"destination","type":"\u0007","is_mandatory":true,"title":"Destination address, CIDR, domain, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationGroupCidrs":{"name":"destinationGroupCidrs","type":"\u0019\u0007","is_mandatory":true,"title":"CIDRs behind a destination address book, empty when the destination is a plain CIDR","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationType":{"name":"destinationType","type":"\u0007","is_mandatory":true,"title":"Destination type, one of net, group, or domain","provider":"go.mondoo.com/mql/providers/alicloud"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Traffic direction the rule applies to, either in (inbound) or out (outbound)","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is enforced","desc":"A disabled rule is configured but not applied.","provider":"go.mondoo.com/mql/providers/alicloud"},"hitTimes":{"name":"hitTimes","type":"\u0005","is_mandatory":true,"title":"Cumulative number of times the rule has matched traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"lastHitTime":{"name":"lastHitTime","type":"\t","is_mandatory":true,"title":"Time the rule last matched traffic, null when it never has","provider":"go.mondoo.com/mql/providers/alicloud"},"natGatewayId":{"name":"natGatewayId","type":"\u0007","is_mandatory":true,"title":"ID of the NAT gateway the rule applies to","provider":"go.mondoo.com/mql/providers/alicloud"},"order":{"name":"order","type":"\u0005","is_mandatory":true,"title":"Rule priority order","provider":"go.mondoo.com/mql/providers/alicloud"},"proto":{"name":"proto","type":"\u0007","is_mandatory":true,"title":"Protocol, one of ANY, TCP, UDP, or ICMP","provider":"go.mondoo.com/mql/providers/alicloud"},"source":{"name":"source","type":"\u0007","is_mandatory":true,"title":"Source address, CIDR, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceGroupCidrs":{"name":"sourceGroupCidrs","type":"\u0019\u0007","is_mandatory":true,"title":"CIDRs behind a source address book, empty when the source is a plain CIDR","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceType":{"name":"sourceType","type":"\u0007","is_mandatory":true,"title":"Source type, either net (a CIDR) or group (an address book)","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Firewall NAT firewall control policy","desc":"A single NAT-boundary access-control rule, keyed by aclUuid. A rule permits or denies traffic leaving (or entering) a NAT gateway on given ports and protocols. Exposes the direction, action, both endpoints, and whether the rule is enforced. Use it to find egress rules that permit unrestricted outbound traffic from a private subnet.","min_provider_version":"13.5.1","defaults":"direction action source destination destPort enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall.natFirewall":{"id":"alicloud.cloudFirewall.natFirewall","name":"alicloud.cloudFirewall.natFirewall","fields":{"controlPolicies":{"name":"controlPolicies","type":"\u0019\u001balicloud.cloudFirewall.natControlPolicy","title":"Access-control rules enforced on the egress path","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the NAT firewall is inspecting traffic","desc":"True only while proxyStatus reads normal. Every other state, including abnormal, leaves egress traffic uninspected.","provider":"go.mondoo.com/mql/providers/alicloud"},"errorDetail":{"name":"errorDetail","type":"\u0007","is_mandatory":true,"title":"Detail of the failure when the firewall is in an abnormal state, empty otherwise","provider":"go.mondoo.com/mql/providers/alicloud"},"natGateway":{"name":"natGateway","type":"\u001balicloud.vpc.natGateway","title":"NAT gateway the firewall guards","desc":"Null when the gateway lies outside the scanned regions or has been deleted.","provider":"go.mondoo.com/mql/providers/alicloud"},"natGatewayName":{"name":"natGatewayName","type":"\u0007","is_mandatory":true,"title":"Name of the guarded NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyId":{"name":"proxyId","type":"\u0007","is_mandatory":true,"title":"NAT firewall (proxy) ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyName":{"name":"proxyName","type":"\u0007","is_mandatory":true,"title":"Name of the NAT firewall","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyStatus":{"name":"proxyStatus","type":"\u0007","is_mandatory":true,"title":"Health of the NAT firewall","desc":"One of configuring, deleting, normal, abnormal, opening, closing, or closed.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the NAT firewall runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"strictMode":{"name":"strictMode","type":"\u0004","is_mandatory":true,"title":"Whether strict mode is enabled","desc":"In strict mode outbound traffic is denied unless a policy allows it. With strict mode off the default is to allow.","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the guarded NAT gateway belongs to","desc":"Null when the VPC lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcName":{"name":"vpcName","type":"\u0007","is_mandatory":true,"title":"Name of the VPC the guarded NAT gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Firewall NAT firewall","desc":"A single NAT firewall, keyed by proxyId. A NAT firewall inspects the traffic a private subnet sends through a NAT gateway. Exposes the guarded gateway and VPC, the firewall health, strict mode, and the access-control rules on the egress path. Use it to find NAT gateways whose outbound traffic passes uninspected.","min_provider_version":"13.5.1","defaults":"proxyName proxyStatus enabled strictMode","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall.vpcControlPolicy":{"id":"alicloud.cloudFirewall.vpcControlPolicy","name":"alicloud.cloudFirewall.vpcControlPolicy","fields":{"aclUuid":{"name":"aclUuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action taken on matching traffic","desc":"One of accept (allow), drop (deny), or log (monitor only).","provider":"go.mondoo.com/mql/providers/alicloud"},"applicationNames":{"name":"applicationNames","type":"\u0019\u0007","is_mandatory":true,"title":"Application-layer protocols the rule matches, for example HTTP or ANY","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"destPort":{"name":"destPort","type":"\u0007","is_mandatory":true,"title":"Destination port or port range","provider":"go.mondoo.com/mql/providers/alicloud"},"destPortGroupPorts":{"name":"destPortGroupPorts","type":"\u0019\u0007","is_mandatory":true,"title":"Ports behind a destination port address book","provider":"go.mondoo.com/mql/providers/alicloud"},"destPortType":{"name":"destPortType","type":"\u0007","is_mandatory":true,"title":"Destination port type, either port (a literal port) or group (a port address book)","provider":"go.mondoo.com/mql/providers/alicloud"},"destination":{"name":"destination","type":"\u0007","is_mandatory":true,"title":"Destination address, CIDR, domain, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationGroupCidrs":{"name":"destinationGroupCidrs","type":"\u0019\u0007","is_mandatory":true,"title":"CIDRs behind a destination address book, empty when the destination is a plain CIDR","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationType":{"name":"destinationType","type":"\u0007","is_mandatory":true,"title":"Destination type, one of net, group, or domain","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is enforced","desc":"A disabled rule is configured but not applied.","provider":"go.mondoo.com/mql/providers/alicloud"},"hitTimes":{"name":"hitTimes","type":"\u0005","is_mandatory":true,"title":"Cumulative number of times the rule has matched traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"lastHitTime":{"name":"lastHitTime","type":"\t","is_mandatory":true,"title":"Time the rule last matched traffic, null when it never has","provider":"go.mondoo.com/mql/providers/alicloud"},"order":{"name":"order","type":"\u0005","is_mandatory":true,"title":"Rule priority order","provider":"go.mondoo.com/mql/providers/alicloud"},"proto":{"name":"proto","type":"\u0007","is_mandatory":true,"title":"Protocol, one of ANY, TCP, UDP, or ICMP","provider":"go.mondoo.com/mql/providers/alicloud"},"source":{"name":"source","type":"\u0007","is_mandatory":true,"title":"Source address, CIDR, or address-book reference","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceGroupCidrs":{"name":"sourceGroupCidrs","type":"\u0019\u0007","is_mandatory":true,"title":"CIDRs behind a source address book, empty when the source is a plain CIDR","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceType":{"name":"sourceType","type":"\u0007","is_mandatory":true,"title":"Source type, either net (a CIDR) or group (an address book)","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcFirewallId":{"name":"vpcFirewallId","type":"\u0007","is_mandatory":true,"title":"ID of the VPC firewall the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Firewall VPC firewall control policy","desc":"A single east-west access-control rule of a VPC firewall, keyed by aclUuid. A rule permits or denies traffic between a source and a destination on given ports and protocols. Exposes the action, both endpoints, the resolved address-book members, and whether the rule is enforced. Use it to find enabled rules that broadly permit traffic between VPCs (for example an accept rule whose source is 0.0.0.0/0).","min_provider_version":"13.5.1","defaults":"action source destination destPort proto enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudFirewall.vpcFirewall":{"id":"alicloud.cloudFirewall.vpcFirewall","name":"alicloud.cloudFirewall.vpcFirewall","fields":{"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Throughput of the firewall in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"connectSubType":{"name":"connectSubType","type":"\u0007","is_mandatory":true,"title":"Sub-type of the connection, for further detail on the connect type","provider":"go.mondoo.com/mql/providers/alicloud"},"connectType":{"name":"connectType","type":"\u0007","is_mandatory":true,"title":"Kind of connection the firewall guards","desc":"One of cen (a Cloud Enterprise Network attachment), vpcpeer (a VPC peering connection), or expressconnect (a leased-line circuit).","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPolicies":{"name":"controlPolicies","type":"\u0019\u001balicloud.cloudFirewall.vpcControlPolicy","title":"Access-control rules enforced on the guarded path","provider":"go.mondoo.com/mql/providers/alicloud"},"crossAccount":{"name":"crossAccount","type":"\u0004","is_mandatory":true,"title":"Whether the peer VPC belongs to a different account","desc":"A cross-account pair carries traffic out of this account's control, so the rules on it are worth reading even when both ends look internal.","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the firewall is switched on","desc":"True only while firewallSwitchStatus reads opened. A configured but closed firewall enforces none of its control policies.","provider":"go.mondoo.com/mql/providers/alicloud"},"firewallSwitchStatus":{"name":"firewallSwitchStatus","type":"\u0007","is_mandatory":true,"title":"Raw switch status of the firewall","desc":"One of opened, closed, or notconfigured.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsBasicRulesEnabled":{"name":"ipsBasicRulesEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the intrusion-prevention basic rule set is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsBlocking":{"name":"ipsBlocking","type":"\u0004","is_mandatory":true,"title":"Whether the intrusion-prevention system blocks rather than observes","desc":"False when IPS runs in monitor mode, where a detected intrusion is recorded and still delivered.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsMode":{"name":"ipsMode","type":"\u0005","is_mandatory":true,"title":"Raw intrusion-prevention mode, 0 (monitor) or 1 (block)","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsRuleClass":{"name":"ipsRuleClass","type":"\u0005","is_mandatory":true,"title":"Intrusion-prevention rule group, 1 (loose), 2 (medium), or 3 (strict)","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsVirtualPatchEnabled":{"name":"ipsVirtualPatchEnabled","type":"\u0004","is_mandatory":true,"title":"Whether virtual patching is enabled","desc":"Virtual patching blocks exploitation of a known vulnerability at the firewall while the workload behind it is still unpatched.","provider":"go.mondoo.com/mql/providers/alicloud"},"localRegionId":{"name":"localRegionId","type":"\u0007","is_mandatory":true,"title":"Region of the local VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"localVpc":{"name":"localVpc","type":"\u001balicloud.vpc.network","title":"Local VPC of the guarded pair","desc":"Null when the VPC lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"localVpcName":{"name":"localVpcName","type":"\u0007","is_mandatory":true,"title":"Name of the local VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"peerRegionId":{"name":"peerRegionId","type":"\u0007","is_mandatory":true,"title":"Region of the peer VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"peerVpc":{"name":"peerVpc","type":"\u001balicloud.vpc.network","title":"Peer VPC of the guarded pair","desc":"Null when the peer belongs to another account or lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"peerVpcId":{"name":"peerVpcId","type":"\u0007","is_mandatory":true,"title":"ID of the peer VPC","desc":"Kept as a raw value as well as a reference because the peer may belong to another Alibaba Cloud account, in which case peerVpc cannot be resolved and this is the only record of what the pair reaches.","provider":"go.mondoo.com/mql/providers/alicloud"},"peerVpcName":{"name":"peerVpcName","type":"\u0007","is_mandatory":true,"title":"Name of the peer VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"peerVpcOwnerId":{"name":"peerVpcOwnerId","type":"\u0007","is_mandatory":true,"title":"Account that owns the peer VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"regionStatus":{"name":"regionStatus","type":"\u0007","is_mandatory":true,"title":"Whether the firewall region is available","provider":"go.mondoo.com/mql/providers/alicloud"},"strictMode":{"name":"strictMode","type":"\u0004","is_mandatory":true,"title":"Whether strict mode is enabled","desc":"In strict mode traffic is denied unless a policy allows it. With strict mode off the default is to allow, so an empty policy list means the pair is wide open rather than closed.","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcFirewallId":{"name":"vpcFirewallId","type":"\u0007","is_mandatory":true,"title":"VPC firewall ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcFirewallName":{"name":"vpcFirewallName","type":"\u0007","is_mandatory":true,"title":"Name of the VPC firewall","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Firewall VPC firewall","desc":"A single VPC firewall, keyed by vpcFirewallId. A VPC firewall guards the east-west path between two VPCs joined by CEN, VPC peering, or Express Connect. Exposes both ends of the pair, whether the firewall is switched on, the strict-mode and intrusion-prevention settings, and the access-control rules it enforces. Use it to find VPC pairs that carry traffic with no firewall in the path, or with a firewall that only observes.","min_provider_version":"13.5.1","defaults":"vpcFirewallName connectType enabled strictMode","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso":{"id":"alicloud.cloudsso","name":"alicloud.cloudsso","fields":{"accessAssignment":{"name":"accessAssignment","type":"\u001balicloud.cloudsso.accessAssignment","title":"CloudSSO access assignment","desc":"A grant binding a CloudSSO user or group to an access configuration on one member account. This is the edge that turns a permission set into effective access: it names who (principal), what (access configuration), and where (target account).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"accessConfiguration":{"name":"accessConfiguration","type":"\u001balicloud.cloudsso.accessConfiguration","title":"CloudSSO access configuration","desc":"A named set of permissions that a CloudSSO user assumes on a member account, keyed by the directoryId and accessConfigurationId. The permission policies determine what a session created from this configuration may do, and the session duration determines how long it lasts. An access configuration grants nothing until an assignment binds it to a principal and an account.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"directories":{"name":"directories","type":"\u0019\u001balicloud.cloudsso.directory","title":"CloudSSO directories in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"directory":{"name":"directory","type":"\u001balicloud.cloudsso.directory","title":"CloudSSO directory","desc":"A CloudSSO directory, the container for a workforce identity population and the access it holds on the resource directory. The directoryId selects the directory, for example `alicloud.cloudsso.directory(directoryId: \"d-00example\")`. Exposes the users and groups in the directory, the access configurations and their assignments, the password policy, and the multi-factor and credential-retrieval settings that govern how members sign in.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"enabled":{"name":"enabled","type":"\u0004","title":"Whether CloudSSO is enabled for the account","desc":"False when the service has never been enabled, in which case the account manages access through RAM users and roles alone.","provider":"go.mondoo.com/mql/providers/alicloud"},"group":{"name":"group","type":"\u001balicloud.cloudsso.group","title":"CloudSSO group","desc":"A group of workforce users in a CloudSSO directory, keyed by the directoryId and groupId. Access assignments made to a group apply to every member, so the members list is what turns a group-level grant into the set of people who actually hold it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"mfaDevice":{"name":"mfaDevice","type":"\u001balicloud.cloudsso.mfaDevice","title":"CloudSSO multi-factor authentication device","desc":"A second-factor device bound to a CloudSSO user, keyed by deviceId. Exposes the device type and when it became effective.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"passwordPolicy":{"name":"passwordPolicy","type":"\u001balicloud.cloudsso.passwordPolicy","title":"CloudSSO password policy","desc":"Password requirements applied to users in a CloudSSO directory. Exposes the length, character-class, reuse, and expiration rules, along with the failed-sign-in lockout threshold.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"permissionPolicy":{"name":"permissionPolicy","type":"\u001balicloud.cloudsso.permissionPolicy","title":"CloudSSO permission policy","desc":"A permission policy attached to a CloudSSO access configuration. A System policy is one of the Alibaba Cloud managed policies, reachable through ramPolicy; an Inline policy carries its statements in policyDocument on this resource. Between them they define everything a session created from the access configuration is allowed to do.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"samlIdentityProvider":{"name":"samlIdentityProvider","type":"\u001balicloud.cloudsso.samlIdentityProvider","title":"CloudSSO external SAML identity provider","desc":"The SAML identity provider federated with a CloudSSO directory, keyed by the directoryId. Exposes the provider entity, the sign-in endpoint, the request binding and signing settings, and whether federated sign-in is switched on. Use it to confirm that sign-in is authenticated by the corporate identity provider rather than by CloudSSO's local user store.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"task":{"name":"task","type":"\u001balicloud.cloudsso.task","title":"CloudSSO access-provisioning task","desc":"A single grant or revocation of an access configuration on a member account, keyed by taskId. Exposes what was granted to whom on which target and whether the operation succeeded. Use it to find a failed revocation, which leaves access in place after it was meant to be withdrawn.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"user":{"name":"user","type":"\u001balicloud.cloudsso.user","title":"CloudSSO user","desc":"A workforce user in a CloudSSO directory, keyed by the directoryId and userId. Exposes the user profile, whether the account was created directly or synchronized from an external identity provider, the multi-factor devices bound to it, and the groups it belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"CloudSSO","desc":"Workforce identity and account access for an Alibaba Cloud resource directory. Exposes the CloudSSO directories in the account, and through them the workforce users and groups, the access configurations that define what a session may do, and the assignments that grant those configurations on individual member accounts.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.accessAssignment":{"id":"alicloud.cloudsso.accessAssignment","name":"alicloud.cloudsso.accessAssignment","fields":{"accessConfiguration":{"name":"accessConfiguration","type":"\u001balicloud.cloudsso.accessConfiguration","title":"Access configuration the assignment grants","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationId":{"name":"accessConfigurationId","type":"\u0007","is_mandatory":true,"title":"ID of the access configuration the assignment grants","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationName":{"name":"accessConfigurationName","type":"\u0007","is_mandatory":true,"title":"Name of the access configuration the assignment grants","provider":"go.mondoo.com/mql/providers/alicloud"},"account":{"name":"account","type":"\u001balicloud.resourceManager.account","title":"Member account the assignment grants access on","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the assignment was created","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the assignment belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"group":{"name":"group","type":"\u001balicloud.cloudsso.group","title":"Group the assignment was made to","desc":"Null when the assignment was made to a single user.","provider":"go.mondoo.com/mql/providers/alicloud"},"principalId":{"name":"principalId","type":"\u0007","is_mandatory":true,"title":"ID of the principal the assignment grants access to","provider":"go.mondoo.com/mql/providers/alicloud"},"principalName":{"name":"principalName","type":"\u0007","is_mandatory":true,"title":"Name of the principal","provider":"go.mondoo.com/mql/providers/alicloud"},"principalType":{"name":"principalType","type":"\u0007","is_mandatory":true,"title":"Principal type","desc":"Either User for an assignment made to a single user, or Group for one made to a group, in which case every member of the group holds the access.","provider":"go.mondoo.com/mql/providers/alicloud"},"targetId":{"name":"targetId","type":"\u0007","is_mandatory":true,"title":"ID of the account the assignment grants access on","provider":"go.mondoo.com/mql/providers/alicloud"},"targetName":{"name":"targetName","type":"\u0007","is_mandatory":true,"title":"Name of the account the assignment grants access on","provider":"go.mondoo.com/mql/providers/alicloud"},"targetPath":{"name":"targetPath","type":"\u0007","is_mandatory":true,"title":"Path of the target account in the resource directory hierarchy","provider":"go.mondoo.com/mql/providers/alicloud"},"targetType":{"name":"targetType","type":"\u0007","is_mandatory":true,"title":"Target type, for example RD-Account for a resource directory member account","provider":"go.mondoo.com/mql/providers/alicloud"},"user":{"name":"user","type":"\u001balicloud.cloudsso.user","title":"User the assignment was made to","desc":"Null when the assignment was made to a group.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO access assignment","desc":"A grant binding a CloudSSO user or group to an access configuration on one member account. This is the edge that turns a permission set into effective access: it names who (principal), what (access configuration), and where (target account).","min_provider_version":"13.2.5","defaults":"principalName accessConfigurationName targetName","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.accessConfiguration":{"id":"alicloud.cloudsso.accessConfiguration","name":"alicloud.cloudsso.accessConfiguration","fields":{"accessConfigurationId":{"name":"accessConfigurationId","type":"\u0007","is_mandatory":true,"title":"Access configuration ID, used with directoryId as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationName":{"name":"accessConfigurationName","type":"\u0007","is_mandatory":true,"title":"Name of the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the access configuration was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the access configuration belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"permissionPolicies":{"name":"permissionPolicies","type":"\u0019\u001balicloud.cloudsso.permissionPolicy","title":"Permission policies attached to the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"relayState":{"name":"relayState","type":"\u0007","is_mandatory":true,"title":"Initial console page a session lands on","provider":"go.mondoo.com/mql/providers/alicloud"},"sessionDuration":{"name":"sessionDuration","type":"\u0005","is_mandatory":true,"title":"Maximum length of a session created from this configuration, in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the access configuration was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO access configuration","desc":"A named set of permissions that a CloudSSO user assumes on a member account, keyed by the directoryId and accessConfigurationId. The permission policies determine what a session created from this configuration may do, and the session duration determines how long it lasts. An access configuration grants nothing until an assignment binds it to a principal and an account.","min_provider_version":"13.2.5","defaults":"accessConfigurationName sessionDuration","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.directory":{"id":"alicloud.cloudsso.directory","name":"alicloud.cloudsso.directory","fields":{"accessAssignments":{"name":"accessAssignments","type":"\u0019\u001balicloud.cloudsso.accessAssignment","title":"Assignments granting access configurations on member accounts","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurations":{"name":"accessConfigurations","type":"\u0019\u001balicloud.cloudsso.accessConfiguration","title":"Access configurations defined in the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"allowUserToGetCredentials":{"name":"allowUserToGetCredentials","type":"\u0004","title":"Whether users may retrieve long-lived access credentials for themselves","desc":"True lets a signed-in user mint credentials that outlive the sign-in session, widening the window in which a compromised session is useful.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the directory was created","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"Directory ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryName":{"name":"directoryName","type":"\u0007","is_mandatory":true,"title":"Name of the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"groups":{"name":"groups","type":"\u0019\u001balicloud.cloudsso.group","title":"Groups in the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"loginNetworkMasks":{"name":"loginNetworkMasks","type":"\u0007","title":"Network ranges users may sign in from","desc":"Semicolon-separated CIDR blocks restricting where sign-ins are accepted. Empty when sign-in is accepted from anywhere.","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaAuthenticationStatus":{"name":"mfaAuthenticationStatus","type":"\u0007","title":"When multi-factor authentication is demanded of users signing in","desc":"One of Enabled, where every sign-in requires a second factor, Byp, where it is required only for sign-ins the service judges risky, or Disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordPolicy":{"name":"passwordPolicy","type":"\u001balicloud.cloudsso.passwordPolicy","title":"Password requirements for users in the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the directory is hosted in","provider":"go.mondoo.com/mql/providers/alicloud"},"samlIdentityProvider":{"name":"samlIdentityProvider","type":"\u001balicloud.cloudsso.samlIdentityProvider","title":"External SAML identity provider federated with the directory","desc":"Null when no identity provider has been configured, in which case sign-in is authenticated by CloudSSO's own user store and the controls of the corporate identity provider (conditional access, device posture, deprovisioning on termination) do not apply.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"scimSynchronizationEnabled":{"name":"scimSynchronizationEnabled","type":"\u0004","title":"Whether SCIM synchronization from an external identity provider is enabled","desc":"When enabled, the user and group population is managed by the external provider, so accounts deactivated there stop being usable here.","provider":"go.mondoo.com/mql/providers/alicloud"},"ssoEnabled":{"name":"ssoEnabled","type":"\u0004","title":"Whether single sign-on through an external identity provider is enabled","desc":"False both when no provider is configured and when one is configured but switched off, which are the two ways sign-in falls back to the local user store.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"tasks":{"name":"tasks","type":"\u0019\u001balicloud.cloudsso.task","title":"Access-provisioning tasks recorded for the directory","desc":"Each task is one grant or revocation of an access configuration on a member account. Use it to find a revocation that failed, which leaves access in place after it was meant to be withdrawn.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the directory was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"users":{"name":"users","type":"\u0019\u001balicloud.cloudsso.user","title":"Users in the directory","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO directory","desc":"A CloudSSO directory, the container for a workforce identity population and the access it holds on the resource directory. The directoryId selects the directory, for example `alicloud.cloudsso.directory(directoryId: \"d-00example\")`. Exposes the users and groups in the directory, the access configurations and their assignments, the password policy, and the multi-factor and credential-retrieval settings that govern how members sign in.","min_provider_version":"13.2.5","defaults":"directoryId directoryName region","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.group":{"id":"alicloud.cloudsso.group","name":"alicloud.cloudsso.group","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the group","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"groupId":{"name":"groupId","type":"\u0007","is_mandatory":true,"title":"Group ID, used with directoryId as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"groupName":{"name":"groupName","type":"\u0007","is_mandatory":true,"title":"Name of the group","provider":"go.mondoo.com/mql/providers/alicloud"},"members":{"name":"members","type":"\u0019\u001balicloud.cloudsso.user","title":"Users that belong to the group","provider":"go.mondoo.com/mql/providers/alicloud"},"provisionType":{"name":"provisionType","type":"\u0007","is_mandatory":true,"title":"How the group came to exist","desc":"Either Manual for a group created directly in the directory, or Synchronized for one provisioned from an external identity provider.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the group was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO group","desc":"A group of workforce users in a CloudSSO directory, keyed by the directoryId and groupId. Access assignments made to a group apply to every member, so the members list is what turns a group-level grant into the set of people who actually hold it.","min_provider_version":"13.2.5","defaults":"groupName provisionType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.mfaDevice":{"id":"alicloud.cloudsso.mfaDevice","name":"alicloud.cloudsso.mfaDevice","fields":{"deviceId":{"name":"deviceId","type":"\u0007","is_mandatory":true,"title":"Device ID","provider":"go.mondoo.com/mql/providers/alicloud"},"deviceName":{"name":"deviceName","type":"\u0007","is_mandatory":true,"title":"Name of the device","provider":"go.mondoo.com/mql/providers/alicloud"},"deviceType":{"name":"deviceType","type":"\u0007","is_mandatory":true,"title":"Device type, for example TOTP for an authenticator application","provider":"go.mondoo.com/mql/providers/alicloud"},"effectiveTime":{"name":"effectiveTime","type":"\t","is_mandatory":true,"title":"Time the device became effective","provider":"go.mondoo.com/mql/providers/alicloud"},"userId":{"name":"userId","type":"\u0007","is_mandatory":true,"title":"ID of the user the device is bound to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO multi-factor authentication device","desc":"A second-factor device bound to a CloudSSO user, keyed by deviceId. Exposes the device type and when it became effective.","min_provider_version":"13.2.5","defaults":"deviceName deviceType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.passwordPolicy":{"id":"alicloud.cloudsso.passwordPolicy","name":"alicloud.cloudsso.passwordPolicy","fields":{"hardExpire":{"name":"hardExpire","type":"\u0004","is_mandatory":true,"title":"Whether an expired password blocks sign-in outright","desc":"True locks the user out until an administrator resets the password, rather than prompting for a change at the next sign-in.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxLoginAttempts":{"name":"maxLoginAttempts","type":"\u0005","is_mandatory":true,"title":"Number of consecutive failed sign-ins before the account is locked","provider":"go.mondoo.com/mql/providers/alicloud"},"maxPasswordAge":{"name":"maxPasswordAge","type":"\u0005","is_mandatory":true,"title":"Number of days a password remains valid","provider":"go.mondoo.com/mql/providers/alicloud"},"maxPasswordLength":{"name":"maxPasswordLength","type":"\u0005","is_mandatory":true,"title":"Maximum number of characters a password may contain","provider":"go.mondoo.com/mql/providers/alicloud"},"minPasswordDifferentChars":{"name":"minPasswordDifferentChars","type":"\u0005","is_mandatory":true,"title":"Minimum number of characters that must differ from the previous password","provider":"go.mondoo.com/mql/providers/alicloud"},"minPasswordLength":{"name":"minPasswordLength","type":"\u0005","is_mandatory":true,"title":"Minimum number of characters a password must contain","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordNotContainUsername":{"name":"passwordNotContainUsername","type":"\u0004","is_mandatory":true,"title":"Whether the password is barred from containing the user name","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordReusePrevention":{"name":"passwordReusePrevention","type":"\u0005","is_mandatory":true,"title":"Number of previous passwords that may not be reused","provider":"go.mondoo.com/mql/providers/alicloud"},"requireLowerCaseChars":{"name":"requireLowerCaseChars","type":"\u0004","is_mandatory":true,"title":"Whether a lowercase letter is required","provider":"go.mondoo.com/mql/providers/alicloud"},"requireNumbers":{"name":"requireNumbers","type":"\u0004","is_mandatory":true,"title":"Whether a digit is required","provider":"go.mondoo.com/mql/providers/alicloud"},"requireSymbols":{"name":"requireSymbols","type":"\u0004","is_mandatory":true,"title":"Whether a symbol is required","provider":"go.mondoo.com/mql/providers/alicloud"},"requireUpperCaseChars":{"name":"requireUpperCaseChars","type":"\u0004","is_mandatory":true,"title":"Whether an uppercase letter is required","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO password policy","desc":"Password requirements applied to users in a CloudSSO directory. Exposes the length, character-class, reuse, and expiration rules, along with the failed-sign-in lockout threshold.","min_provider_version":"13.2.5","defaults":"minPasswordLength maxLoginAttempts","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.permissionPolicy":{"id":"alicloud.cloudsso.permissionPolicy","name":"alicloud.cloudsso.permissionPolicy","fields":{"accessConfigurationId":{"name":"accessConfigurationId","type":"\u0007","is_mandatory":true,"title":"ID of the access configuration the policy is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"addTime":{"name":"addTime","type":"\t","is_mandatory":true,"title":"Time the policy was attached to the access configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the access configuration belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"policyDocument":{"name":"policyDocument","type":"\u0007","is_mandatory":true,"title":"Permission statements of an inline policy, as a JSON string","desc":"Empty for a System policy, whose statements are exposed through ramPolicy instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"policyName":{"name":"policyName","type":"\u0007","is_mandatory":true,"title":"Name of the permission policy","provider":"go.mondoo.com/mql/providers/alicloud"},"policyType":{"name":"policyType","type":"\u0007","is_mandatory":true,"title":"Policy type","desc":"Either System for an Alibaba Cloud managed policy or Inline for a policy defined on the access configuration itself.","provider":"go.mondoo.com/mql/providers/alicloud"},"ramPolicy":{"name":"ramPolicy","type":"\u001balicloud.ram.policy","title":"Managed policy behind a System permission policy","desc":"The Alibaba Cloud managed policy of the same name, so its statements can be read the same way as for a RAM identity. Null for an Inline policy.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO permission policy","desc":"A permission policy attached to a CloudSSO access configuration. A System policy is one of the Alibaba Cloud managed policies, reachable through ramPolicy; an Inline policy carries its statements in policyDocument on this resource. Between them they define everything a session created from the access configuration is allowed to do.","min_provider_version":"13.2.5","defaults":"policyName policyType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.samlIdentityProvider":{"id":"alicloud.cloudsso.samlIdentityProvider","name":"alicloud.cloudsso.samlIdentityProvider","fields":{"bindingType":{"name":"bindingType","type":"\u0007","is_mandatory":true,"title":"Binding used to send SAML requests, either Post or Redirect","provider":"go.mondoo.com/mql/providers/alicloud"},"certificateIds":{"name":"certificateIds","type":"\u0019\u0007","is_mandatory":true,"title":"IDs of the SAML signing certificates configured for the provider","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the provider was first configured","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the provider is federated with","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether federated sign-in is switched on","desc":"A provider configured but left disabled means sign-in still falls back to the local user store.","provider":"go.mondoo.com/mql/providers/alicloud"},"entityId":{"name":"entityId","type":"\u0007","is_mandatory":true,"title":"Entity ID of the identity provider, for example http://www.okta.com/exk3qwgt","provider":"go.mondoo.com/mql/providers/alicloud"},"loginUrl":{"name":"loginUrl","type":"\u0007","is_mandatory":true,"title":"Sign-in URL users are redirected to","provider":"go.mondoo.com/mql/providers/alicloud"},"ssoStatus":{"name":"ssoStatus","type":"\u0007","is_mandatory":true,"title":"Raw single sign-on status, either Enabled or Disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the provider configuration was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"wantRequestSigned":{"name":"wantRequestSigned","type":"\u0004","is_mandatory":true,"title":"Whether CloudSSO signs the SAML requests it sends","desc":"Signed requests let the identity provider reject an authentication request that did not originate from this directory.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO external SAML identity provider","desc":"The SAML identity provider federated with a CloudSSO directory, keyed by the directoryId. Exposes the provider entity, the sign-in endpoint, the request binding and signing settings, and whether federated sign-in is switched on. Use it to confirm that sign-in is authenticated by the corporate identity provider rather than by CloudSSO's local user store.","min_provider_version":"13.5.1","defaults":"entityId ssoStatus bindingType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.task":{"id":"alicloud.cloudsso.task","name":"alicloud.cloudsso.task","fields":{"accessConfiguration":{"name":"accessConfiguration","type":"\u001balicloud.cloudsso.accessConfiguration","title":"Access configuration the task granted or revoked","desc":"Null when the configuration has since been deleted.","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationId":{"name":"accessConfigurationId","type":"\u0007","is_mandatory":true,"title":"ID of the access configuration the task granted or revoked","desc":"Kept as a raw value alongside accessConfiguration because a task is a historical record: the configuration it names may since have been deleted, in which case the reference resolves to null and this is all that remains.","provider":"go.mondoo.com/mql/providers/alicloud"},"accessConfigurationName":{"name":"accessConfigurationName","type":"\u0007","is_mandatory":true,"title":"Name of the access configuration the task granted or revoked","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"Time the task finished, null while it is still running","provider":"go.mondoo.com/mql/providers/alicloud"},"failureReason":{"name":"failureReason","type":"\u0007","is_mandatory":true,"title":"Reason the task failed, empty when it did not","provider":"go.mondoo.com/mql/providers/alicloud"},"principalId":{"name":"principalId","type":"\u0007","is_mandatory":true,"title":"ID of the user or group the task acted on","provider":"go.mondoo.com/mql/providers/alicloud"},"principalName":{"name":"principalName","type":"\u0007","is_mandatory":true,"title":"Name of the user or group the task acted on","provider":"go.mondoo.com/mql/providers/alicloud"},"principalType":{"name":"principalType","type":"\u0007","is_mandatory":true,"title":"Kind of principal, either User or Group","provider":"go.mondoo.com/mql/providers/alicloud"},"startTime":{"name":"startTime","type":"\t","is_mandatory":true,"title":"Time the task started","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Outcome of the task","desc":"One of InProgress, Success, or Failed.","provider":"go.mondoo.com/mql/providers/alicloud"},"succeeded":{"name":"succeeded","type":"\u0004","is_mandatory":true,"title":"Whether the task completed successfully","desc":"False for a task still running as well as for a failed one. A failed DeleteAccessAssignment means the access it was withdrawing is still granted.","provider":"go.mondoo.com/mql/providers/alicloud"},"targetId":{"name":"targetId","type":"\u0007","is_mandatory":true,"title":"ID of the account the access was granted on or revoked from","provider":"go.mondoo.com/mql/providers/alicloud"},"targetName":{"name":"targetName","type":"\u0007","is_mandatory":true,"title":"Name of the account the access was granted on or revoked from","provider":"go.mondoo.com/mql/providers/alicloud"},"targetPath":{"name":"targetPath","type":"\u0007","is_mandatory":true,"title":"Resource-directory path of the target","provider":"go.mondoo.com/mql/providers/alicloud"},"targetPathName":{"name":"targetPathName","type":"\u0007","is_mandatory":true,"title":"Resource-directory path name of the target","provider":"go.mondoo.com/mql/providers/alicloud"},"targetType":{"name":"targetType","type":"\u0007","is_mandatory":true,"title":"Kind of target, for example RD-Account","provider":"go.mondoo.com/mql/providers/alicloud"},"taskId":{"name":"taskId","type":"\u0007","is_mandatory":true,"title":"Task ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"taskType":{"name":"taskType","type":"\u0007","is_mandatory":true,"title":"Kind of operation","desc":"For example ProvisionAccessConfiguration, DeprovisionAccessConfiguration, CreateAccessAssignment, or DeleteAccessAssignment.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO access-provisioning task","desc":"A single grant or revocation of an access configuration on a member account, keyed by taskId. Exposes what was granted to whom on which target and whether the operation succeeded. Use it to find a failed revocation, which leaves access in place after it was meant to be withdrawn.","min_provider_version":"13.5.1","defaults":"taskType status principalName targetName","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cloudsso.user":{"id":"alicloud.cloudsso.user","name":"alicloud.cloudsso.user","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the user was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"directoryId":{"name":"directoryId","type":"\u0007","is_mandatory":true,"title":"ID of the directory the user belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email address of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"firstName":{"name":"firstName","type":"\u0007","is_mandatory":true,"title":"First name of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"groups":{"name":"groups","type":"\u0019\u001balicloud.cloudsso.group","title":"Groups the user belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"lastName":{"name":"lastName","type":"\u0007","is_mandatory":true,"title":"Last name of the user","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaDevices":{"name":"mfaDevices","type":"\u0019\u001balicloud.cloudsso.mfaDevice","title":"Multi-factor authentication devices bound to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"provisionType":{"name":"provisionType","type":"\u0007","is_mandatory":true,"title":"How the user account came to exist","desc":"Either Manual for a user created directly in the directory, or Synchronized for one provisioned from an external identity provider. A manual user survives deprovisioning at the identity provider.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"User status","desc":"Either Enabled or Disabled. A disabled user cannot sign in but keeps its group memberships and assignments.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the user was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"userId":{"name":"userId","type":"\u0007","is_mandatory":true,"title":"User ID, used with directoryId as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"Sign-in name of the user","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CloudSSO user","desc":"A workforce user in a CloudSSO directory, keyed by the directoryId and userId. Exposes the user profile, whether the account was created directly or synchronized from an external identity provider, the multi-factor devices bound to it, and the groups it belongs to.","min_provider_version":"13.2.5","defaults":"userName displayName status provisionType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config":{"id":"alicloud.config","name":"alicloud.config","fields":{"aggregator":{"name":"aggregator","type":"\u001balicloud.config.aggregator","title":"Cloud Config aggregator","desc":"An account group that collects configuration and compliance data from other accounts into this one, keyed by aggregatorId. An RD aggregator covers a folder of the resource directory and grows as accounts join it, while a CUSTOM aggregator covers a fixed list of accounts and silently omits any account added afterwards.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"aggregators":{"name":"aggregators","type":"\u0019\u001balicloud.config.aggregator","title":"Account groups that aggregate configuration data from member accounts","desc":"An aggregator collects configuration and compliance data from other accounts into this one, either from the whole resource directory or from a hand-picked set of accounts.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePack":{"name":"compliancePack","type":"\u001balicloud.config.compliancePack","title":"Cloud Config compliance pack","desc":"A named bundle of Config rules evaluated together, keyed by compliancePackId. Reports the pack definition, the template it was built from, the risk level assigned to it, and the rules it carries, so a pack that is present but not yet evaluating is distinguishable from one that is active.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"compliancePacks":{"name":"compliancePacks","type":"\u0019\u001balicloud.config.compliancePack","title":"Compliance packs applied in the account","desc":"A compliance pack bundles Config rules into a single evaluated set. Reports the pack inventory, the risk level assigned to each, and the rules a pack carries.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceSummary":{"name":"complianceSummary","type":"\n","title":"Account-wide compliance summary","desc":"Counts of compliant and non-compliant rules and resources. Keys include compliantRuleCount, nonCompliantRuleCount, totalRuleCount, compliantResourceCount, nonCompliantResourceCount, totalResourceCount, and the highRisk, mediumRisk, and lowRisk non-compliant resource counts.","provider":"go.mondoo.com/mql/providers/alicloud"},"deliveryChannel":{"name":"deliveryChannel","type":"\u001balicloud.config.deliveryChannel","title":"Cloud Config delivery channel","desc":"A destination Cloud Config writes configuration snapshots, configuration change notifications, and compliance results to, keyed by channelId. The destination is an OSS bucket, a Log Service logstore, or a Message Service topic, reached through ossBucket and logstore where the destination has a resource of its own. The enabled flag reports whether delivery is running, and the four notification toggles report which payload kinds are sent, so a channel that exists but delivers nothing an audit pipeline reads is distinguishable from one that is working.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"deliveryChannels":{"name":"deliveryChannels","type":"\u0019\u001balicloud.config.deliveryChannel","title":"Delivery channels that export configuration data and compliance results","desc":"A recording account that has no enabled delivery channel keeps its configuration history only inside the Cloud Config console, so nothing reaches the OSS bucket, logstore, or message topic an audit pipeline reads. Empty when no delivery channel is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"evaluationResult":{"name":"evaluationResult","type":"\u001balicloud.config.evaluationResult","title":"Cloud Config rule evaluation result","desc":"The outcome of one Config rule examining one resource. Reports the compliance verdict, the annotation naming what failed, the rule and compliance pack that produced it, and when the resource last failed and was last brought back into compliance. Where rules describes the checks that exist, this describes what they actually found.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"nonCompliantResults":{"name":"nonCompliantResults","type":"\u0019\u001balicloud.config.evaluationResult","title":"Non-compliant evaluation results across every rule in the account","desc":"The resources that currently fail a Config rule, each carrying the rule that flagged it, the annotation explaining why, and the risk level. This is the evaluated outcome, whereas rules reports only which rules exist.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"recordedResourceTypes":{"name":"recordedResourceTypes","type":"\u0019\u0007","title":"Resource types the configuration recorder captures","provider":"go.mondoo.com/mql/providers/alicloud"},"recorderEnabled":{"name":"recorderEnabled","type":"\u0004","title":"Whether the configuration recorder is registered and actively recording","desc":"True when the recorder status is REGISTERED. When false, resource configuration changes are not being captured.","provider":"go.mondoo.com/mql/providers/alicloud"},"recorderStatus":{"name":"recorderStatus","type":"\u0007","title":"Configuration-recorder status","desc":"One of REGISTRABLE, BUILDING, REGISTERED, or REBUILDING. REGISTERED means recording is active.","provider":"go.mondoo.com/mql/providers/alicloud"},"rule":{"name":"rule","type":"\u001balicloud.config.rule","title":"Cloud Config rule","desc":"A single Config rule, keyed by configRuleId. A rule continuously evaluates whether resources of a given type meet a configuration requirement and reports each resource as compliant or non-compliant. Exposes the rule definition, risk level, evaluation source, and current compliance result.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"rules":{"name":"rules","type":"\u0019\u001balicloud.config.rule","title":"Config rules defined in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Cloud Config","desc":"Configuration-compliance state for an Alibaba Cloud account. Exposes the Config rules that continuously evaluate resource configuration, the account-wide compliance summary, and whether the configuration recorder and its delivery channels are active. Use it to audit whether configuration recording is enabled and how many resources are non-compliant.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.aggregator":{"id":"alicloud.config.aggregator","name":"alicloud.config.aggregator","fields":{"accountCount":{"name":"accountCount","type":"\u0005","is_mandatory":true,"title":"Number of member accounts the aggregator collects from","provider":"go.mondoo.com/mql/providers/alicloud"},"aggregatorId":{"name":"aggregatorId","type":"\u0007","is_mandatory":true,"title":"Aggregator ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"aggregatorName":{"name":"aggregatorName","type":"\u0007","is_mandatory":true,"title":"Aggregator name","provider":"go.mondoo.com/mql/providers/alicloud"},"aggregatorType":{"name":"aggregatorType","type":"\u0007","is_mandatory":true,"title":"Aggregator type","desc":"Either RD, covering a resource directory folder, or CUSTOM, covering a fixed set of accounts.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the aggregator was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Aggregator description","provider":"go.mondoo.com/mql/providers/alicloud"},"folder":{"name":"folder","type":"\u001balicloud.resourceManager.folder","title":"Resource directory folder the aggregator covers","desc":"Null for a CUSTOM aggregator, which names accounts rather than a folder.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Aggregator status","desc":"0 while the account group is being created, and 1 once it is created.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the aggregator","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config aggregator","desc":"An account group that collects configuration and compliance data from other accounts into this one, keyed by aggregatorId. An RD aggregator covers a folder of the resource directory and grows as accounts join it, while a CUSTOM aggregator covers a fixed list of accounts and silently omits any account added afterwards.","min_provider_version":"13.4.1","defaults":"aggregatorName aggregatorType accountCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.compliancePack":{"id":"alicloud.config.compliancePack","name":"alicloud.config.compliancePack","fields":{"compliancePackId":{"name":"compliancePackId","type":"\u0007","is_mandatory":true,"title":"Compliance pack ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePackName":{"name":"compliancePackName","type":"\u0007","is_mandatory":true,"title":"Compliance pack name","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePackTemplateId":{"name":"compliancePackTemplateId","type":"\u0007","is_mandatory":true,"title":"ID of the template the pack was built from","desc":"Empty for a pack assembled from individual rules rather than a template.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the pack was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Compliance pack description","provider":"go.mondoo.com/mql/providers/alicloud"},"riskLevel":{"name":"riskLevel","type":"\u0005","is_mandatory":true,"title":"Risk level assigned to the pack","desc":"One of 1 (high), 2 (medium), or 3 (low).","provider":"go.mondoo.com/mql/providers/alicloud"},"rules":{"name":"rules","type":"\u0019\u001balicloud.config.rule","title":"Config rules the pack evaluates","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Compliance pack status","desc":"Either ACTIVE, meaning the pack is evaluating, or CREATING.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the pack","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config compliance pack","desc":"A named bundle of Config rules evaluated together, keyed by compliancePackId. Reports the pack definition, the template it was built from, the risk level assigned to it, and the rules it carries, so a pack that is present but not yet evaluating is distinguishable from one that is active.","min_provider_version":"13.4.1","defaults":"compliancePackName status riskLevel","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.deliveryChannel":{"id":"alicloud.config.deliveryChannel","name":"alicloud.config.deliveryChannel","fields":{"assumeRole":{"name":"assumeRole","type":"\u001balicloud.ram.role","title":"RAM role Cloud Config assumes to write to the destination","desc":"Null when the channel is configured without an assume-role ARN.","provider":"go.mondoo.com/mql/providers/alicloud"},"channelId":{"name":"channelId","type":"\u0007","is_mandatory":true,"title":"Delivery channel ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"compliantSnapshot":{"name":"compliantSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether compliant evaluation results are delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"condition":{"name":"condition","type":"\u0007","is_mandatory":true,"title":"Filter that limits which resources the channel delivers","desc":"A JSON expression evaluated against each configuration item. Empty when the channel delivers every item.","provider":"go.mondoo.com/mql/providers/alicloud"},"configurationItemChangeNotification":{"name":"configurationItemChangeNotification","type":"\u0004","is_mandatory":true,"title":"Whether configuration change notifications are delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"configurationSnapshot":{"name":"configurationSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether the scheduled resource snapshot is delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Delivery channel description","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the channel is delivering","desc":"False when the channel exists but is disabled, in which case nothing reaches the destination.","provider":"go.mondoo.com/mql/providers/alicloud"},"logstore":{"name":"logstore","type":"\u001balicloud.log.logstore","title":"Log Service logstore the channel delivers to","desc":"Null when the channel targets an OSS bucket or a Message Service topic.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Delivery channel name","provider":"go.mondoo.com/mql/providers/alicloud"},"nonCompliantNotification":{"name":"nonCompliantNotification","type":"\u0004","is_mandatory":true,"title":"Whether non-compliant evaluation results are delivered","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucket":{"name":"ossBucket","type":"\u001balicloud.oss.bucket","title":"OSS bucket the channel delivers to","desc":"Null when the channel targets a Log Service logstore or a Message Service topic.","provider":"go.mondoo.com/mql/providers/alicloud"},"oversizedDataOssTargetArn":{"name":"oversizedDataOssTargetArn","type":"\u0007","is_mandatory":true,"title":"ARN of the OSS bucket that receives payloads too large for the channel","desc":"Empty when no oversized-data bucket is configured, in which case an oversized payload is dropped rather than delivered elsewhere.","provider":"go.mondoo.com/mql/providers/alicloud"},"snapshotTime":{"name":"snapshotTime","type":"\u0007","is_mandatory":true,"title":"Delivery time of the scheduled resource snapshot","desc":"An ISO 8601 timestamp whose hour selects the daily delivery time, for example 2021-09-15T16:00:00Z. Empty when snapshot delivery is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"targetArn":{"name":"targetArn","type":"\u0007","is_mandatory":true,"title":"ARN of the destination the channel writes to","desc":"An OSS bucket, a Message Service topic, or a Log Service logstore. Message Service topics have no resource of their own, so this is the only complete view of the destination.","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Destination service","desc":"One of OSS, MNS, or SLS.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config delivery channel","desc":"A destination Cloud Config writes configuration snapshots, configuration change notifications, and compliance results to, keyed by channelId. The destination is an OSS bucket, a Log Service logstore, or a Message Service topic, reached through ossBucket and logstore where the destination has a resource of its own. The enabled flag reports whether delivery is running, and the four notification toggles report which payload kinds are sent, so a channel that exists but delivers nothing an audit pipeline reads is distinguishable from one that is working.","min_provider_version":"13.4.1","defaults":"name type enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.evaluationResult":{"id":"alicloud.config.evaluationResult","name":"alicloud.config.evaluationResult","fields":{"annotation":{"name":"annotation","type":"\u0007","is_mandatory":true,"title":"Explanation of the verdict","desc":"Names the setting that failed, such as the ports a security group leaves open. Empty for a compliant resource.","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePack":{"name":"compliancePack","type":"\u001balicloud.config.compliancePack","title":"Compliance pack the rule was evaluated under","desc":"Null when the rule does not belong to a pack.","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceType":{"name":"complianceType","type":"\u0007","is_mandatory":true,"title":"Compliance verdict","desc":"One of COMPLIANT, NON_COMPLIANT, NOT_APPLICABLE, INSUFFICIENT_DATA, or IGNORED.","provider":"go.mondoo.com/mql/providers/alicloud"},"configRule":{"name":"configRule","type":"\u001balicloud.config.rule","title":"Config rule that produced the result","provider":"go.mondoo.com/mql/providers/alicloud"},"ignoreDate":{"name":"ignoreDate","type":"\u0007","is_mandatory":true,"title":"Date the result was set to be ignored","desc":"Formatted as yyyy-MM-dd. Empty unless the result has been ignored, which suppresses it from the compliance summary without fixing the resource.","provider":"go.mondoo.com/mql/providers/alicloud"},"invokedTime":{"name":"invokedTime","type":"\t","is_mandatory":true,"title":"Time the rule last evaluated the resource","provider":"go.mondoo.com/mql/providers/alicloud"},"lastCompliantFixedTime":{"name":"lastCompliantFixedTime","type":"\t","is_mandatory":true,"title":"Time the resource was last brought back into compliance","provider":"go.mondoo.com/mql/providers/alicloud"},"lastNonCompliantTime":{"name":"lastNonCompliantTime","type":"\t","is_mandatory":true,"title":"Time the resource was last recorded as non-compliant","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the evaluated resource lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"remediationEnabled":{"name":"remediationEnabled","type":"\u0004","is_mandatory":true,"title":"Whether a remediation is configured for the rule","desc":"False means a failing resource stays failing until someone acts on it.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the evaluated resource belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceId":{"name":"resourceId","type":"\u0007","is_mandatory":true,"title":"ID of the evaluated resource","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceName":{"name":"resourceName","type":"\u0007","is_mandatory":true,"title":"Name of the evaluated resource","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceType":{"name":"resourceType","type":"\u0007","is_mandatory":true,"title":"Type of the evaluated resource","desc":"An Alibaba Cloud resource type such as ACS::ECS::Instance.","provider":"go.mondoo.com/mql/providers/alicloud"},"resultRecordedTime":{"name":"resultRecordedTime","type":"\t","is_mandatory":true,"title":"Time the result was recorded","provider":"go.mondoo.com/mql/providers/alicloud"},"riskLevel":{"name":"riskLevel","type":"\u0005","is_mandatory":true,"title":"Risk level of the rule that produced the result","desc":"One of 1 (high), 2 (medium), or 3 (low).","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config rule evaluation result","desc":"The outcome of one Config rule examining one resource. Reports the compliance verdict, the annotation naming what failed, the rule and compliance pack that produced it, and when the resource last failed and was last brought back into compliance. Where rules describes the checks that exist, this describes what they actually found.","min_provider_version":"13.4.1","defaults":"resourceName resourceType complianceType riskLevel","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.config.rule":{"id":"alicloud.config.rule","name":"alicloud.config.rule","fields":{"automationType":{"name":"automationType","type":"\u0007","is_mandatory":true,"title":"Automation type applied to non-compliant resources, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceCount":{"name":"complianceCount","type":"\u0005","is_mandatory":true,"title":"Number of resources in the current compliance result","provider":"go.mondoo.com/mql/providers/alicloud"},"compliancePackId":{"name":"compliancePackId","type":"\u0007","is_mandatory":true,"title":"ID of the compliance pack the rule belongs to, empty when the rule is standalone","provider":"go.mondoo.com/mql/providers/alicloud"},"complianceType":{"name":"complianceType","type":"\u0007","is_mandatory":true,"title":"Compliance result type","desc":"One of COMPLIANT, NON_COMPLIANT, NOT_APPLICABLE, or INSUFFICIENT_DATA.","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleArn":{"name":"configRuleArn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleId":{"name":"configRuleId","type":"\u0007","is_mandatory":true,"title":"Config rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleName":{"name":"configRuleName","type":"\u0007","is_mandatory":true,"title":"Config rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"configRuleState":{"name":"configRuleState","type":"\u0007","is_mandatory":true,"title":"Rule state","desc":"One of ACTIVE, INACTIVE, EVALUATING, or DELETING.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"evaluationResults":{"name":"evaluationResults","type":"\u0019\u001balicloud.config.evaluationResult","title":"Resources the rule has evaluated and the verdict for each","desc":"The evaluated outcome of the rule, one entry per resource it examined, carrying the compliance verdict and the annotation explaining it.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"maximumExecutionFrequency":{"name":"maximumExecutionFrequency","type":"\u0007","title":"Maximum interval at which a periodic rule re-evaluates","desc":"One of One_Hour, Three_Hours, Six_Hours, Twelve_Hours, or TwentyFour_Hours. Empty for change-triggered rules.","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceTypesScope":{"name":"resourceTypesScope","type":"\u0019\u0007","is_mandatory":true,"title":"Resource types the rule evaluates","provider":"go.mondoo.com/mql/providers/alicloud"},"riskLevel":{"name":"riskLevel","type":"\u0005","is_mandatory":true,"title":"Risk level of a non-compliant result","desc":"1 for high, 2 for medium, 3 for low.","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceIdentifier":{"name":"sourceIdentifier","type":"\u0007","is_mandatory":true,"title":"Identifier of the managed rule or custom evaluation function","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceOwner":{"name":"sourceOwner","type":"\u0007","is_mandatory":true,"title":"Owner of the rule's evaluation logic","desc":"ALIYUN for a managed rule, or a custom source such as CUSTOM_FC for a Function Compute-backed rule.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the rule","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Cloud Config rule","desc":"A single Config rule, keyed by configRuleId. A rule continuously evaluates whether resources of a given type meet a configuration requirement and reports each resource as compliant or non-compliant. Exposes the rule definition, risk level, evaluation source, and current compliance result.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs":{"id":"alicloud.cs","name":"alicloud.cs","fields":{"cluster":{"name":"cluster","type":"\u001balicloud.cs.cluster","title":"Container Service for Kubernetes cluster","desc":"A single ACK cluster, keyed by clusterId within its region. Exposes the cluster type and Kubernetes version, the VPC, vSwitches, and security group it runs in, the pod and service CIDRs, the public and intranet API server endpoints, and the derived internet-exposure of the API server. Node pools, installed addons, control-plane audit logging, and workload-identity (RRSA) settings are reached from here. For example alicloud.cs.cluster(clusterId: \"c1a2b3\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"clusters":{"name":"clusters","type":"\u0019\u001balicloud.cs.cluster","title":"Kubernetes clusters across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"grant":{"name":"grant","type":"\u001balicloud.cs.grant","title":"Container Service cluster access grant","desc":"A single cluster access grant held by a RAM user or role, keyed by the principal together with the scope and role it confers. Exposes what the grant covers (one cluster, one namespace of a cluster, or every cluster in the account), which preset role it confers, and whether it is the cluster creator's implicit administrator right. This is the answer to who can reach a cluster's API server and with what rights, which cluster settings alone do not show.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"grants":{"name":"grants","type":"\u0019\u001balicloud.cs.grant","title":"Cluster access grants held by the account's RAM users and roles","desc":"Every grant in the account, across all clusters. Container Service reports grants per principal rather than per cluster, so reading these costs one call for each RAM user and each RAM role in the account. A credential that is itself a RAM user or role only sees the clusters it administers, so the result can be incomplete for anything other than the account owner.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePool":{"name":"nodePool","type":"\u001balicloud.cs.nodePool","title":"Container Service for Kubernetes node pool","desc":"A single node pool within an ACK cluster, keyed by nodePoolId. Exposes the node instance configuration, scaling and management policy, OS hardening flags, disk encryption, and the typed references to the security groups, vSwitches, RAM role, and KMS key the nodes use. Use it to audit node disk encryption, OS hardening, and automatic CVE patching.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Container Service for Kubernetes","desc":"ACK clusters across an Alibaba Cloud account. Exposes the Kubernetes clusters in every enabled region, including their type and version, network layout, API server exposure, control-plane audit logging, workload-identity (RRSA) settings, node pools, and installed addons. Use it to audit whether a cluster's API server is reachable from the internet and whether audit logging is enabled.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs.cluster":{"id":"alicloud.cs.cluster","name":"alicloud.cs.cluster","fields":{"addons":{"name":"addons","type":"\u0019\n","title":"Addons installed in the cluster","desc":"Each entry lists the name, version, and state of an installed addon, for example security-inspector, logtail-ds, terway-eniip, or csi-plugin. Use it to audit which security and observability addons are present.","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerAuditEnabled":{"name":"apiServerAuditEnabled","type":"\u0004","title":"Whether Kubernetes API server audit logging is enabled","desc":"True when cluster auditing records API server activity to Log Service. Null when the cluster auditing configuration does not report the setting.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerAuditLogProject":{"name":"apiServerAuditLogProject","type":"\u001balicloud.log.project","title":"Log Service project that receives the API server audit logs","desc":"Null when cluster auditing is not configured.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerInternetExposed":{"name":"apiServerInternetExposed","type":"\u0004","is_mandatory":true,"title":"Whether the Kubernetes API server is reachable from the internet","desc":"True when the cluster exposes a public API server endpoint. A publicly reachable API server broadens the attack surface of the control plane.","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerIntranetEndpoint":{"name":"apiServerIntranetEndpoint","type":"\u0007","is_mandatory":true,"title":"Intranet (private) API server endpoint","provider":"go.mondoo.com/mql/providers/alicloud"},"apiServerPublicEndpoint":{"name":"apiServerPublicEndpoint","type":"\u0007","is_mandatory":true,"title":"Public (internet) API server endpoint","desc":"The internet-facing Kubernetes API server URL. Empty when the API server has no public endpoint.","provider":"go.mondoo.com/mql/providers/alicloud"},"auditLogEnabled":{"name":"auditLogEnabled","type":"\u0004","title":"Whether Kubernetes API server audit logging is enabled","desc":"Deprecated in favor of alicloud.cs.cluster.apiServerAuditEnabled. This reports whether control-plane log collection lists a component named audit, which is not one of the components ACK collects.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.cs.cluster.apiServerAuditEnabled"},"check":{"name":"check","type":"\u001balicloud.cs.cluster.check","title":"Container Service cluster inspection run","desc":"A single cluster check run, keyed by checkId. Exposes the kind of check, how it finished, and when it started and completed.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"checks":{"name":"checks","type":"\u0019\u001balicloud.cs.cluster.check","title":"Cluster inspection runs","desc":"The cluster check runs recorded for the cluster, most recent first. Each carries when it ran and how it finished, so a cluster that has never been inspected reports an empty list and one whose last run is old is visible from finishedAt.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterDomain":{"name":"clusterDomain","type":"\u0007","is_mandatory":true,"title":"Cluster local DNS domain, for example cluster.local","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterId":{"name":"clusterId","type":"\u0007","is_mandatory":true,"title":"Cluster ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterSpec":{"name":"clusterSpec","type":"\u0007","is_mandatory":true,"title":"Managed-tier specification","desc":"For example ack.pro.small or ack.standard. Empty for dedicated Kubernetes clusters.","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterType":{"name":"clusterType","type":"\u0007","is_mandatory":true,"title":"Cluster type","desc":"One of Kubernetes (dedicated), ManagedKubernetes, Ask (serverless), or ExternalKubernetes.","provider":"go.mondoo.com/mql/providers/alicloud"},"containerCidr":{"name":"containerCidr","type":"\u0007","is_mandatory":true,"title":"Pod CIDR block","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPlaneLogComponents":{"name":"controlPlaneLogComponents","type":"\u0019\u0007","title":"Control-plane components shipping logs to Log Service","desc":"For example kube-apiserver, kube-controller-manager, kube-scheduler, ccm (cloud-controller-manager), or controlplane-events. Empty when control-plane logging is off. API server audit logs are a separate feature, reported by apiServerAuditEnabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPlaneLogProject":{"name":"controlPlaneLogProject","type":"\u001balicloud.log.project","title":"Log Service project that receives the control-plane logs","desc":"Null when control-plane logging is not configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPlaneLogTtl":{"name":"controlPlaneLogTtl","type":"\u0005","title":"Retention in days of the control-plane logs, 0 when logging is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Time the cluster was created","provider":"go.mondoo.com/mql/providers/alicloud"},"currentVersion":{"name":"currentVersion","type":"\u0007","is_mandatory":true,"title":"Running Kubernetes version","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled for the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"grants":{"name":"grants","type":"\u0019\u001balicloud.cs.grant","title":"Cluster access grants that reach this cluster","desc":"The grants naming this cluster or a namespace within it, together with the account-wide grants that cover every cluster. Shares one sweep with the grants on the parent service, so reading it for a second cluster costs no further calls.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"initVersion":{"name":"initVersion","type":"\u0007","is_mandatory":true,"title":"Kubernetes version the cluster was created with","provider":"go.mondoo.com/mql/providers/alicloud"},"ipStack":{"name":"ipStack","type":"\u0007","is_mandatory":true,"title":"IP stack of the cluster","desc":"One of ipv4, ipv6, or dual.","provider":"go.mondoo.com/mql/providers/alicloud"},"maintenanceWindow":{"name":"maintenanceWindow","type":"\n","is_mandatory":true,"title":"Maintenance window configuration","desc":"The scheduled maintenance window, with enable, duration, maintenanceTime, recurrence, and weeklyPeriod. Null when no window is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Cluster name","provider":"go.mondoo.com/mql/providers/alicloud"},"networkMode":{"name":"networkMode","type":"\u0007","is_mandatory":true,"title":"Cluster network mode, for example vpc or overlay","provider":"go.mondoo.com/mql/providers/alicloud"},"nextVersion":{"name":"nextVersion","type":"\u0007","is_mandatory":true,"title":"Next Kubernetes version available for upgrade, empty when up to date","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePools":{"name":"nodePools","type":"\u0019\u001balicloud.cs.nodePool","title":"Node pools in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"oidcIssuerUrl":{"name":"oidcIssuerUrl","type":"\u0007","title":"OIDC issuer URL for workload identity, empty when RRSA is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"privateZone":{"name":"privateZone","type":"\u0004","is_mandatory":true,"title":"Whether PrivateZone (private DNS) is enabled for the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"profile":{"name":"profile","type":"\u0007","is_mandatory":true,"title":"Cluster profile, for example Default, Serverless, or Edge","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyMode":{"name":"proxyMode","type":"\u0007","is_mandatory":true,"title":"kube-proxy mode, either iptables or ipvs","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the cluster resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the cluster","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"rrsaEnabled":{"name":"rrsaEnabled","type":"\u0004","title":"Whether RAM Roles for Service Accounts (RRSA) workload identity is enabled","desc":"True when the cluster issues OIDC tokens for pod-level RAM authorization instead of relying on the shared worker node role.","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroup":{"name":"securityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Security group applied to the cluster nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"serviceCidr":{"name":"serviceCidr","type":"\u0007","is_mandatory":true,"title":"Service CIDR block","provider":"go.mondoo.com/mql/providers/alicloud"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Total number of nodes in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Cluster lifecycle state","desc":"For example running, initial, failed, or deleting.","provider":"go.mondoo.com/mql/providers/alicloud"},"subnetCidr":{"name":"subnetCidr","type":"\u0007","is_mandatory":true,"title":"Node subnet CIDR block","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"timezone":{"name":"timezone","type":"\u0007","is_mandatory":true,"title":"Time zone configured for the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"updated":{"name":"updated","type":"\t","is_mandatory":true,"title":"Time the cluster was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the cluster runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the cluster's control plane and nodes attach to","provider":"go.mondoo.com/mql/providers/alicloud"},"workerRamRole":{"name":"workerRamRole","type":"\u001balicloud.ram.role","title":"Worker node RAM role, null when the cluster has no worker RAM role","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the cluster's managed resources reside in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Service for Kubernetes cluster","desc":"A single ACK cluster, keyed by clusterId within its region. Exposes the cluster type and Kubernetes version, the VPC, vSwitches, and security group it runs in, the pod and service CIDRs, the public and intranet API server endpoints, and the derived internet-exposure of the API server. Node pools, installed addons, control-plane audit logging, and workload-identity (RRSA) settings are reached from here. For example alicloud.cs.cluster(clusterId: \"c1a2b3\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs.cluster.check":{"id":"alicloud.cs.cluster.check","name":"alicloud.cs.cluster.check","fields":{"checkId":{"name":"checkId","type":"\u0007","is_mandatory":true,"title":"Check run ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the run was created","provider":"go.mondoo.com/mql/providers/alicloud"},"finishedAt":{"name":"finishedAt","type":"\t","is_mandatory":true,"title":"Time the run completed","desc":"Null while the run is still in progress.","provider":"go.mondoo.com/mql/providers/alicloud"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Status message the run reported","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Outcome of the run, for example Succeeded, Failed, or Running","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Kind of check that ran, for example ClusterUpgrade or NodePoolUpgrade","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Service cluster inspection run","desc":"A single cluster check run, keyed by checkId. Exposes the kind of check, how it finished, and when it started and completed.","min_provider_version":"13.5.1","defaults":"type status finishedAt","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs.grant":{"id":"alicloud.cs.grant","name":"alicloud.cs.grant","fields":{"cluster":{"name":"cluster","type":"\u001balicloud.cs.cluster","title":"Cluster the grant applies to","desc":"Null for a grant that covers every cluster rather than a named one, and null when the named cluster can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"owner":{"name":"owner","type":"\u0004","is_mandatory":true,"title":"Whether the grant is the cluster creator's implicit administrator right","desc":"A creator grant is not one somebody assigned, so it does not appear in a review of assigned permissions.","provider":"go.mondoo.com/mql/providers/alicloud"},"principalName":{"name":"principalName","type":"\u0007","is_mandatory":true,"title":"Name of the RAM user or role holding the grant","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u0004","is_mandatory":true,"title":"Whether the grant is held by a RAM role rather than a RAM user","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceId":{"name":"resourceId","type":"\u0007","is_mandatory":true,"title":"Resource the grant applies to","desc":"The cluster ID for a cluster-scoped grant, clusterId/namespace for a namespace-scoped grant, or all-clusters for a grant covering every cluster in the account.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceType":{"name":"resourceType","type":"\u0007","is_mandatory":true,"title":"Scope the grant applies at","desc":"One of cluster (a single cluster), namespace (one namespace of a single cluster), or console (every cluster in the account).","provider":"go.mondoo.com/mql/providers/alicloud"},"role":{"name":"role","type":"\u001balicloud.ram.role","title":"RAM role holding the grant","desc":"Null when the grant is held by a RAM user.","provider":"go.mondoo.com/mql/providers/alicloud"},"roleName":{"name":"roleName","type":"\u0007","is_mandatory":true,"title":"Name of the custom cluster role the grant confers","desc":"Empty unless roleType is custom.","provider":"go.mondoo.com/mql/providers/alicloud"},"roleType":{"name":"roleType","type":"\u0007","is_mandatory":true,"title":"Preset role the grant confers","desc":"One of admin (administrator), ops (operations), dev (developer), restricted (limited), or custom, where the rights come from the cluster role named by roleName instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"uid":{"name":"uid","type":"\u0007","is_mandatory":true,"title":"ID of the RAM user or role holding the grant","provider":"go.mondoo.com/mql/providers/alicloud"},"user":{"name":"user","type":"\u001balicloud.ram.user","title":"RAM user holding the grant","desc":"Null when the grant is held by a RAM role.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Service cluster access grant","desc":"A single cluster access grant held by a RAM user or role, keyed by the principal together with the scope and role it confers. Exposes what the grant covers (one cluster, one namespace of a cluster, or every cluster in the account), which preset role it confers, and whether it is the cluster creator's implicit administrator right. This is the answer to who can reach a cluster's API server and with what rights, which cluster settings alone do not show.","min_provider_version":"13.5.1","defaults":"principalName roleType resourceType resourceId","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.cs.nodePool":{"id":"alicloud.cs.nodePool","name":"alicloud.cs.nodePool","fields":{"autoRepair":{"name":"autoRepair","type":"\u0004","is_mandatory":true,"title":"Whether managed nodes are automatically repaired","provider":"go.mondoo.com/mql/providers/alicloud"},"autoScalingEnabled":{"name":"autoScalingEnabled","type":"\u0004","is_mandatory":true,"title":"Whether autoscaling is enabled for the node pool","provider":"go.mondoo.com/mql/providers/alicloud"},"autoScalingType":{"name":"autoScalingType","type":"\u0007","is_mandatory":true,"title":"Autoscaling type, for example cpu, gpu, or spot","provider":"go.mondoo.com/mql/providers/alicloud"},"autoUpgrade":{"name":"autoUpgrade","type":"\u0004","is_mandatory":true,"title":"Whether managed nodes are automatically upgraded","provider":"go.mondoo.com/mql/providers/alicloud"},"autoVulFix":{"name":"autoVulFix","type":"\u0004","is_mandatory":true,"title":"Whether managed nodes automatically receive CVE fixes","provider":"go.mondoo.com/mql/providers/alicloud"},"cisEnabled":{"name":"cisEnabled","type":"\u0004","is_mandatory":true,"title":"Whether CIS benchmark hardening is enabled for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"cluster":{"name":"cluster","type":"\u001balicloud.cs.cluster","title":"Cluster the node pool belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterId":{"name":"clusterId","type":"\u0007","is_mandatory":true,"title":"ID of the cluster the node pool belongs to","desc":"A node pool ID is unique only within its cluster, so both are needed to identify a node pool.","provider":"go.mondoo.com/mql/providers/alicloud"},"cmsEnabled":{"name":"cmsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the CloudMonitor agent is installed on nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"cpuPolicy":{"name":"cpuPolicy","type":"\u0007","is_mandatory":true,"title":"CPU management policy, either none or static","provider":"go.mondoo.com/mql/providers/alicloud"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Time the node pool was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dataDisks":{"name":"dataDisks","type":"\u0019\n","is_mandatory":true,"title":"Data disks attached to nodes","desc":"Each entry lists the category, size, encrypted, kmsKeyId, performanceLevel, and autoSnapshotPolicyId of a data disk.","provider":"go.mondoo.com/mql/providers/alicloud"},"desiredSize":{"name":"desiredSize","type":"\u0005","is_mandatory":true,"title":"Desired number of nodes in the pool","provider":"go.mondoo.com/mql/providers/alicloud"},"failedNodes":{"name":"failedNodes","type":"\u0005","is_mandatory":true,"title":"Number of failed nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"healthyNodes":{"name":"healthyNodes","type":"\u0005","is_mandatory":true,"title":"Number of healthy nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Image the node pool launches nodes from","desc":"Null on a node pool that names no image, and on one whose image is not visible to the account, for example a public image that has been retired.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"ID of the image used for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"imageType":{"name":"imageType","type":"\u0007","is_mandatory":true,"title":"Image type used for nodes, for example AliyunLinux or ContainerOS","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Node billing method","desc":"Either PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceTypes":{"name":"instanceTypes","type":"\u0019\u0007","is_mandatory":true,"title":"ECS instance types used for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthOut":{"name":"internetMaxBandwidthOut","type":"\u0005","is_mandatory":true,"title":"Maximum outbound internet bandwidth in Mbps assigned to nodes, 0 when nodes have no public bandwidth","provider":"go.mondoo.com/mql/providers/alicloud"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether this is the cluster's default node pool","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPair":{"name":"keyPair","type":"\u0007","is_mandatory":true,"title":"Key pair name used for node SSH access, empty when password or managed login is used","provider":"go.mondoo.com/mql/providers/alicloud"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Kubernetes labels applied to nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"managed":{"name":"managed","type":"\u0004","is_mandatory":true,"title":"Whether the node pool is managed (control-plane operated)","provider":"go.mondoo.com/mql/providers/alicloud"},"maxInstances":{"name":"maxInstances","type":"\u0005","is_mandatory":true,"title":"Maximum number of nodes when autoscaling is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"minInstances":{"name":"minInstances","type":"\u0005","is_mandatory":true,"title":"Minimum number of nodes when autoscaling is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"multiAzPolicy":{"name":"multiAzPolicy","type":"\u0007","is_mandatory":true,"title":"Multi-zone scaling policy, for example PRIORITY, COST_OPTIMIZED, or BALANCE","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Node pool name","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePoolId":{"name":"nodePoolId","type":"\u0007","is_mandatory":true,"title":"Node pool ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"nodePoolState":{"name":"nodePoolState","type":"\u0007","is_mandatory":true,"title":"Node pool state, for example active or scaling","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u001balicloud.ram.role","title":"RAM role assigned to the nodes, null when the node pool has no RAM role","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the node pool resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the node pool","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the node pool belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"runtime":{"name":"runtime","type":"\u0007","is_mandatory":true,"title":"Container runtime, for example containerd or docker","provider":"go.mondoo.com/mql/providers/alicloud"},"runtimeVersion":{"name":"runtimeVersion","type":"\u0007","is_mandatory":true,"title":"Container runtime version","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to the nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"securityHardeningOs":{"name":"securityHardeningOs","type":"\u0004","is_mandatory":true,"title":"Whether OS security hardening is applied to nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"servingNodes":{"name":"servingNodes","type":"\u0005","is_mandatory":true,"title":"Number of nodes serving workloads","provider":"go.mondoo.com/mql/providers/alicloud"},"socEnabled":{"name":"socEnabled","type":"\u0004","is_mandatory":true,"title":"Whether MLPS (Multi-Level Protection Scheme) compliance hardening is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"spotStrategy":{"name":"spotStrategy","type":"\u0007","is_mandatory":true,"title":"Spot instance strategy","desc":"One of NoSpot, SpotWithPriceLimit, or SpotAsPriceGo.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskCategory":{"name":"systemDiskCategory","type":"\u0007","is_mandatory":true,"title":"System disk category, for example cloud_essd","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskEncryptAlgorithm":{"name":"systemDiskEncryptAlgorithm","type":"\u0007","is_mandatory":true,"title":"System disk encryption algorithm, for example aes-256 or sm4","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskEncrypted":{"name":"systemDiskEncrypted","type":"\u0004","is_mandatory":true,"title":"Whether the system disk is encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskKmsKey":{"name":"systemDiskKmsKey","type":"\u001balicloud.kms.key","title":"KMS key used to encrypt the system disk, null when the system disk is not encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskSize":{"name":"systemDiskSize","type":"\u0005","is_mandatory":true,"title":"System disk size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"taints":{"name":"taints","type":"\u0019\n","is_mandatory":true,"title":"Kubernetes taints applied to nodes","desc":"Each entry lists the key, value, and effect (NoSchedule, PreferNoSchedule, or NoExecute) of a node taint.","provider":"go.mondoo.com/mql/providers/alicloud"},"teeEnabled":{"name":"teeEnabled","type":"\u0004","is_mandatory":true,"title":"Whether trusted (confidential) computing is enabled for nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"totalNodes":{"name":"totalNodes","type":"\u0005","is_mandatory":true,"title":"Total number of nodes in the pool","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Node pool type, for example ess or edge","provider":"go.mondoo.com/mql/providers/alicloud"},"unschedulable":{"name":"unschedulable","type":"\u0004","is_mandatory":true,"title":"Whether nodes are marked unschedulable","provider":"go.mondoo.com/mql/providers/alicloud"},"updated":{"name":"updated","type":"\t","is_mandatory":true,"title":"Time the node pool was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the nodes attach to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Container Service for Kubernetes node pool","desc":"A single node pool within an ACK cluster, keyed by nodePoolId. Exposes the node instance configuration, scaling and management policy, OS hardening flags, disk encryption, and the typed references to the security groups, vSwitches, RAM role, and KMS key the nodes use. Use it to audit node disk encryption, OS hardening, and automatic CVE patching.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs":{"id":"alicloud.ecs","name":"alicloud.ecs","fields":{"disk":{"name":"disk","type":"\u001balicloud.ecs.disk","title":"Elastic Compute Service disk","desc":"A single block-storage disk (cloud disk or local disk), keyed by the composite region and diskId. Exposes the disk category and size, its attachment to an instance, encryption state and KMS key, snapshot behavior, and the performance level.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"disks":{"name":"disks","type":"\u0019\u001balicloud.ecs.disk","title":"Block-storage disks across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Elastic Compute Service image","desc":"A single machine image visible to the account, keyed by the composite region and imageId. Exposes the operating system and architecture, the image size and version, its ownership and sharing state, and whether it is public or supports cloud-init.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"images":{"name":"images","type":"\u0019\u001balicloud.ecs.image","title":"Machine images visible to the account across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"instance":{"name":"instance","type":"\u001balicloud.ecs.instance","title":"Elastic Compute Service instance","desc":"A single ECS virtual machine, keyed by the composite region and instanceId. Exposes the lifecycle status, the instance type and zone, hardware sizing (vCPUs, memory, GPUs), billing and charge configuration, the private, public, and elastic IP addresses, the VPC and vSwitch it is attached to, and the security groups controlling its traffic.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.ecs.instance","title":"ECS instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairs":{"name":"keyPairs","type":"\u0019\u001balicloud.ecs.keypair","title":"SSH key pairs across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"keypair":{"name":"keypair","type":"\u001balicloud.ecs.keypair","title":"Elastic Compute Service SSH key pair","desc":"A single SSH key pair, keyed by the composite region and keyPairName. Exposes the public-key fingerprint, the creation time, and the resource group the key pair belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"launchTemplate":{"name":"launchTemplate","type":"\u001balicloud.ecs.launchTemplate","title":"Elastic Compute Service launch template","desc":"A named instance launch template, keyed by launchTemplateId within its region. A template holds one or more versions, each fixing the image, security groups, RAM role, key pair, metadata-service settings and user data of the instances launched from it. Exposes the version list and which version is the default. Use it to audit the shape of instances that do not exist yet, which an instance-by-instance check cannot reach.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"launchTemplates":{"name":"launchTemplates","type":"\u0019\u001balicloud.ecs.launchTemplate","title":"Instance launch templates across all enabled regions","desc":"A launch template fixes the image, security groups, RAM role, key pair and user data of every instance launched from it, so a weakness in a template is reproduced on each new instance rather than existing on one.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"prefixList":{"name":"prefixList","type":"\u001balicloud.ecs.prefixList","title":"Prefix list","desc":"A named set of CIDR blocks that security group rules reference in place of a literal address range, keyed by prefixListId. A rule scoped to a prefix list carries no source or destination CIDR of its own, so the blocks it actually admits live here and nowhere else. associationCount reports how many rules and route tables point at the list, which is how far a change to it reaches.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"prefixLists":{"name":"prefixLists","type":"\u0019\u001balicloud.ecs.prefixList","title":"Prefix lists across all enabled regions","desc":"A prefix list names a set of CIDR blocks that security group rules point at instead of writing the blocks out, so a rule scoped to a list shows no CIDR of its own until the list is read.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"securitygroup":{"name":"securitygroup","type":"\u001balicloud.ecs.securitygroup","title":"Elastic Compute Service security group","desc":"A single security group, keyed by the composite region and securityGroupId. Exposes the group name and type, the VPC it belongs to, its inbound and outbound rules, and the instances it is applied to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"snapshot":{"name":"snapshot","type":"\u001balicloud.ecs.snapshot","title":"Elastic Compute Service disk snapshot","desc":"A point-in-time copy of a disk's contents, keyed by snapshotId within its region. Exposes the source disk, the encryption state and key, the retention setting, and the snapshot lifecycle. Use it to find an unencrypted snapshot of an encrypted disk, which puts the disk's contents outside the protection the disk itself has.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"snapshots":{"name":"snapshots","type":"\u0019\u001balicloud.ecs.snapshot","title":"Disk snapshots across all enabled regions","desc":"A snapshot holds a copy of a disk's contents and is encrypted (or not) independently of the disk it came from, so an unencrypted snapshot of an encrypted disk defeats the disk's own encryption.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service (ECS)","desc":"Compute resources in a region, including virtual machine instances, their attached block-storage disks, machine images, SSH key pairs, and the security groups that filter instance traffic. Fans out over every region enabled on the account.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.disk":{"id":"alicloud.ecs.disk","name":"alicloud.ecs.disk","fields":{"attachedTime":{"name":"attachedTime","type":"\t","is_mandatory":true,"title":"Time when the disk was last attached","provider":"go.mondoo.com/mql/providers/alicloud"},"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Disk category","desc":"One of cloud, cloud_efficiency, cloud_ssd, cloud_essd, cloud_auto, cloud_essd_entry, ephemeral_ssd, or local disk categories.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the disk was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteAutoSnapshot":{"name":"deleteAutoSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether automatic snapshots are deleted together with the disk","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteWithInstance":{"name":"deleteWithInstance","type":"\u0004","is_mandatory":true,"title":"Whether the disk is released together with its instance","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Disk description","provider":"go.mondoo.com/mql/providers/alicloud"},"detachedTime":{"name":"detachedTime","type":"\t","is_mandatory":true,"title":"Time when the disk was last detached","provider":"go.mondoo.com/mql/providers/alicloud"},"device":{"name":"device","type":"\u0007","is_mandatory":true,"title":"Device name the disk is mounted as, for example /dev/xvda","provider":"go.mondoo.com/mql/providers/alicloud"},"diskChargeType":{"name":"diskChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the disk","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"diskId":{"name":"diskId","type":"\u0007","is_mandatory":true,"title":"Disk ID, for example d-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"diskName":{"name":"diskName","type":"\u0007","is_mandatory":true,"title":"Disk name","provider":"go.mondoo.com/mql/providers/alicloud"},"enableAutoSnapshot":{"name":"enableAutoSnapshot","type":"\u0004","is_mandatory":true,"title":"Whether the automatic snapshot policy is enabled for the disk","provider":"go.mondoo.com/mql/providers/alicloud"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the disk is encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"instance":{"name":"instance","type":"\u001balicloud.ecs.instance","title":"Instance the disk is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"KMS key used to encrypt the disk, null when the disk is not encrypted","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"performanceLevel":{"name":"performanceLevel","type":"\u0007","is_mandatory":true,"title":"Performance level of an ESSD disk","desc":"One of PL0, PL1, PL2, or PL3.","provider":"go.mondoo.com/mql/providers/alicloud"},"portable":{"name":"portable","type":"\u0004","is_mandatory":true,"title":"Whether the disk can be detached","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the disk","provider":"go.mondoo.com/mql/providers/alicloud"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Disk size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"snapshots":{"name":"snapshots","type":"\u0019\u001balicloud.ecs.snapshot","title":"Snapshots taken from the disk","desc":"A snapshot is encrypted independently of the disk it came from, so an encrypted disk with an unencrypted snapshot has its contents readable outside the protection the disk itself has.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Disk status","desc":"One of In_use, Available, Attaching, Detaching, Creating, or ReIniting.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the disk, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Disk role","desc":"One of system or data.","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID of the disk","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service disk","desc":"A single block-storage disk (cloud disk or local disk), keyed by the composite region and diskId. Exposes the disk category and size, its attachment to an instance, encryption state and KMS key, snapshot behavior, and the performance level.","min_provider_version":"13.0.0","defaults":"diskId diskName category size status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.image":{"id":"alicloud.ecs.image","name":"alicloud.ecs.image","fields":{"architecture":{"name":"architecture","type":"\u0007","is_mandatory":true,"title":"CPU architecture of the image","desc":"One of i386 or x86_64.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the image was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Image description","provider":"go.mondoo.com/mql/providers/alicloud"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"Image ID, for example m-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"imageName":{"name":"imageName","type":"\u0007","is_mandatory":true,"title":"Image name","provider":"go.mondoo.com/mql/providers/alicloud"},"imageOwnerAlias":{"name":"imageOwnerAlias","type":"\u0007","is_mandatory":true,"title":"Alias of the image owner","desc":"One of system, self, others, or marketplace.","provider":"go.mondoo.com/mql/providers/alicloud"},"imageVersion":{"name":"imageVersion","type":"\u0007","is_mandatory":true,"title":"Image version","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","is_mandatory":true,"title":"Whether the image is public","provider":"go.mondoo.com/mql/providers/alicloud"},"isSelfShared":{"name":"isSelfShared","type":"\u0007","is_mandatory":true,"title":"Whether the image is shared to other accounts by the owner","provider":"go.mondoo.com/mql/providers/alicloud"},"isShared":{"name":"isShared","type":"\u0004","title":"Whether the image is shared outside the owning account","desc":"True when the image is shared with at least one account or share group. False when nothing is shared, and when the share permissions could not be read, so this must not stand alone as evidence that an image is private.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"isSupportCloudinit":{"name":"isSupportCloudinit","type":"\u0004","is_mandatory":true,"title":"Whether the image supports cloud-init","provider":"go.mondoo.com/mql/providers/alicloud"},"osName":{"name":"osName","type":"\u0007","is_mandatory":true,"title":"Name of the operating system in the image","provider":"go.mondoo.com/mql/providers/alicloud"},"osType":{"name":"osType","type":"\u0007","is_mandatory":true,"title":"Operating system family","desc":"One of windows or linux.","provider":"go.mondoo.com/mql/providers/alicloud"},"platform":{"name":"platform","type":"\u0007","is_mandatory":true,"title":"Platform of the operating system, for example CentOS or Ubuntu","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the image","provider":"go.mondoo.com/mql/providers/alicloud"},"shareGroups":{"name":"shareGroups","type":"\u0019\u0007","title":"Share groups the image is shared with","desc":"Each entry names a group of accounts, for example ALL, that may use the image.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"sharedAccounts":{"name":"sharedAccounts","type":"\u0019\u0007","title":"Accounts the image is shared with","desc":"Each entry is the Alibaba Cloud account the owner granted use of the image to. isPublic covers exposure through the marketplace; this covers a share to a named account, which that check does not see.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Image size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Image status","desc":"One of UnAvailable, Available, Creating, or CreateFailed.","provider":"go.mondoo.com/mql/providers/alicloud"},"usage":{"name":"usage","type":"\u0007","is_mandatory":true,"title":"How the image is used","desc":"One of instance, none, or reserved.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service image","desc":"A single machine image visible to the account, keyed by the composite region and imageId. Exposes the operating system and architecture, the image size and version, its ownership and sharing state, and whether it is public or supports cloud-init.","min_provider_version":"13.0.0","defaults":"imageId imageName osName status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.instance":{"id":"alicloud.ecs.instance","name":"alicloud.ecs.instance","fields":{"autoReleaseTime":{"name":"autoReleaseTime","type":"\t","is_mandatory":true,"title":"Automatic release time of a pay-as-you-go instance","provider":"go.mondoo.com/mql/providers/alicloud"},"cpu":{"name":"cpu","type":"\u0005","is_mandatory":true,"title":"Number of vCPUs","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"creditSpecification":{"name":"creditSpecification","type":"\u0007","is_mandatory":true,"title":"Performance mode of a burstable instance","desc":"One of Standard or Unlimited.","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether release protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"deploymentSetId":{"name":"deploymentSetId","type":"\u0007","is_mandatory":true,"title":"Deployment set ID the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Instance description","provider":"go.mondoo.com/mql/providers/alicloud"},"deviceAvailable":{"name":"deviceAvailable","type":"\u0004","is_mandatory":true,"title":"Whether data disks can be attached to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"eipAddress":{"name":"eipAddress","type":"\u0007","is_mandatory":true,"title":"Elastic IP address associated with the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"expiredTime":{"name":"expiredTime","type":"\t","is_mandatory":true,"title":"Expiration time of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"gpuAmount":{"name":"gpuAmount","type":"\u0005","is_mandatory":true,"title":"Number of GPUs attached to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"gpuSpec":{"name":"gpuSpec","type":"\u0007","is_mandatory":true,"title":"GPU model of the instance type, for example NVIDIA V100","provider":"go.mondoo.com/mql/providers/alicloud"},"hostName":{"name":"hostName","type":"\u0007","is_mandatory":true,"title":"Hostname of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Image the instance was created from","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the instance","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example i-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Instance type, for example ecs.g5.large","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceTypeFamily":{"name":"instanceTypeFamily","type":"\u0007","is_mandatory":true,"title":"Instance type family, for example ecs.g5","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method for network usage","desc":"One of PayByBandwidth or PayByTraffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetExposed":{"name":"internetExposed","type":"\u0004","title":"Whether the instance is reachable from the internet","desc":"True when the instance has a directly-assigned public IP address or an associated elastic IP address, indicating inbound reachability from the public internet before security-group rules are considered.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthIn":{"name":"internetMaxBandwidthIn","type":"\u0005","is_mandatory":true,"title":"Maximum inbound public bandwidth in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthOut":{"name":"internetMaxBandwidthOut","type":"\u0005","is_mandatory":true,"title":"Maximum outbound public bandwidth in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"ioOptimized":{"name":"ioOptimized","type":"\u0004","is_mandatory":true,"title":"Whether the instance is I/O optimized","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPair":{"name":"keyPair","type":"\u001balicloud.ecs.keypair","title":"SSH key pair used by the instance","desc":"Null on an instance launched without a key pair, and on one whose key pair has since been deleted.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairName":{"name":"keyPairName","type":"\u0007","is_mandatory":true,"title":"Name of the SSH key pair used by the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"localStorageAmount":{"name":"localStorageAmount","type":"\u0005","is_mandatory":true,"title":"Number of local disks attached to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"localStorageCapacity":{"name":"localStorageCapacity","type":"\u0005","is_mandatory":true,"title":"Capacity of local disks attached to the instance in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"memory":{"name":"memory","type":"\u0005","is_mandatory":true,"title":"Memory size in MiB","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataEndpointEnabled":{"name":"metadataEndpointEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the instance metadata service endpoint is reachable","desc":"False when the metadata endpoint is switched off entirely, which removes the instance RAM role credential path from the instance.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataHopLimit":{"name":"metadataHopLimit","type":"\u0005","is_mandatory":true,"title":"Maximum number of network hops a metadata response may travel","desc":"A limit of 1 keeps metadata responses on the instance itself, so a containerized workload on a bridged network cannot reach them.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataHttpTokens":{"name":"metadataHttpTokens","type":"\u0007","is_mandatory":true,"title":"Whether a session token is required to read instance metadata","desc":"Either optional, where a plain request to the metadata service returns credentials, or required, where the caller must obtain a token first. Requiring a token is what stops a server-side request forgery from reading the instance RAM role credentials.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type of the instance","desc":"One of classic or vpc.","provider":"go.mondoo.com/mql/providers/alicloud"},"osName":{"name":"osName","type":"\u0007","is_mandatory":true,"title":"Name of the operating system","provider":"go.mondoo.com/mql/providers/alicloud"},"osNameEn":{"name":"osNameEn","type":"\u0007","is_mandatory":true,"title":"English name of the operating system","provider":"go.mondoo.com/mql/providers/alicloud"},"osType":{"name":"osType","type":"\u0007","is_mandatory":true,"title":"Operating system family","desc":"One of windows or linux.","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIpAddresses":{"name":"privateIpAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Private IP addresses assigned to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"publicIpAddresses":{"name":"publicIpAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Public IP addresses assigned directly to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u001balicloud.ram.role","title":"Instance RAM role assumed by workloads on the instance","desc":"The role whose temporary credentials the instance metadata service hands to any process that can reach it. Traverse to attachedPolicies to see what a workload on this instance is authorized to do, and therefore what an attacker reaching the metadata service would inherit. Null when no instance RAM role is attached.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the instance, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups controlling the instance's traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"spotDuration":{"name":"spotDuration","type":"\u0005","is_mandatory":true,"title":"Protection period of a preemptible instance in hours","provider":"go.mondoo.com/mql/providers/alicloud"},"spotPriceLimit":{"name":"spotPriceLimit","type":"\u0006","is_mandatory":true,"title":"Maximum hourly price for a preemptible instance","provider":"go.mondoo.com/mql/providers/alicloud"},"spotStrategy":{"name":"spotStrategy","type":"\u0007","is_mandatory":true,"title":"Bidding policy for a pay-as-you-go instance","desc":"One of NoSpot, SpotWithPriceLimit, or SpotAsPriceGo.","provider":"go.mondoo.com/mql/providers/alicloud"},"startTime":{"name":"startTime","type":"\t","is_mandatory":true,"title":"Time when the instance was last started","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending, Running, Starting, Stopping, or Stopped.","provider":"go.mondoo.com/mql/providers/alicloud"},"stoppedMode":{"name":"stoppedMode","type":"\u0007","is_mandatory":true,"title":"Stopped-instance billing mode","desc":"One of KeepCharging, StopCharging, or Not-applicable.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the instance, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"userData":{"name":"userData","type":"\u0007","title":"Startup script and cloud-init data supplied to the instance","desc":"The user data as plain text, decoded from the base64 form the API returns. Anything readable here is also readable by any process on the instance that can reach the metadata service, so it is where hardcoded passwords, API keys, and private registry credentials end up. Empty when the instance was launched without user data.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the instance is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the instance is connected to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID of the instance, for example cn-hangzhou-g","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service instance","desc":"A single ECS virtual machine, keyed by the composite region and instanceId. Exposes the lifecycle status, the instance type and zone, hardware sizing (vCPUs, memory, GPUs), billing and charge configuration, the private, public, and elastic IP addresses, the VPC and vSwitch it is attached to, and the security groups controlling its traffic.","min_provider_version":"13.0.0","defaults":"instanceId instanceName status instanceType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.keypair":{"id":"alicloud.ecs.keypair","name":"alicloud.ecs.keypair","fields":{"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the key pair was created","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairFingerPrint":{"name":"keyPairFingerPrint","type":"\u0007","is_mandatory":true,"title":"Fingerprint of the public key","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairName":{"name":"keyPairName","type":"\u0007","is_mandatory":true,"title":"Key pair name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the key pair","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the key pair","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the key pair belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the key pair, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service SSH key pair","desc":"A single SSH key pair, keyed by the composite region and keyPairName. Exposes the public-key fingerprint, the creation time, and the resource group the key pair belongs to.","min_provider_version":"13.0.0","defaults":"keyPairName","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.launchTemplate":{"id":"alicloud.ecs.launchTemplate","name":"alicloud.ecs.launchTemplate","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the template was created","provider":"go.mondoo.com/mql/providers/alicloud"},"createdBy":{"name":"createdBy","type":"\u0007","is_mandatory":true,"title":"Account or service that created the template","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultVersion":{"name":"defaultVersion","type":"\u001balicloud.ecs.launchTemplate.version","title":"Version launched when a launch does not name one","desc":"Null when the default version could not be read. This is the version that actually shapes new instances, so it is the one an audit should read.","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultVersionNumber":{"name":"defaultVersionNumber","type":"\u0005","is_mandatory":true,"title":"Version number used when a launch does not name one","provider":"go.mondoo.com/mql/providers/alicloud"},"latestVersionNumber":{"name":"latestVersionNumber","type":"\u0005","is_mandatory":true,"title":"Highest version number the template has","desc":"A template whose default is behind its latest launches the older shape, so a fix applied in a new version does not reach new instances until the default moves.","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplateId":{"name":"launchTemplateId","type":"\u0007","is_mandatory":true,"title":"Launch template ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplateName":{"name":"launchTemplateName","type":"\u0007","is_mandatory":true,"title":"Name of the launch template","provider":"go.mondoo.com/mql/providers/alicloud"},"modifiedTime":{"name":"modifiedTime","type":"\t","is_mandatory":true,"title":"Time the template was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the template resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the template","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the template belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the template","provider":"go.mondoo.com/mql/providers/alicloud"},"version":{"name":"version","type":"\u001balicloud.ecs.launchTemplate.version","title":"Version of an Elastic Compute Service launch template","desc":"A single version of a launch template, keyed by the owning launchTemplateId and version number. Exposes the instance shape the version launches: the image, security groups, RAM role, key pair, metadata-service settings, disk encryption, and user data. Use it to find a template that grants a broad RAM role, leaves the metadata service on IMDSv1, or embeds a credential in user data.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"versions":{"name":"versions","type":"\u0019\u001balicloud.ecs.launchTemplate.version","title":"Versions of the template","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service launch template","desc":"A named instance launch template, keyed by launchTemplateId within its region. A template holds one or more versions, each fixing the image, security groups, RAM role, key pair, metadata-service settings and user data of the instances launched from it. Exposes the version list and which version is the default. Use it to audit the shape of instances that do not exist yet, which an instance-by-instance check cannot reach.","min_provider_version":"13.5.1","defaults":"launchTemplateName launchTemplateId latestVersionNumber","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.launchTemplate.version":{"id":"alicloud.ecs.launchTemplate.version","name":"alicloud.ecs.launchTemplate.version","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the version was created","provider":"go.mondoo.com/mql/providers/alicloud"},"createdBy":{"name":"createdBy","type":"\u0007","is_mandatory":true,"title":"Account or service that created the version","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether launched instances are protected from release","provider":"go.mondoo.com/mql/providers/alicloud"},"httpEndpoint":{"name":"httpEndpoint","type":"\u0007","is_mandatory":true,"title":"Whether the instance metadata service is reachable, either enabled or disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"httpPutResponseHopLimit":{"name":"httpPutResponseHopLimit","type":"\u0005","is_mandatory":true,"title":"Hop limit for metadata service responses","desc":"A limit above 1 lets a container on the instance reach the metadata service through the host's network namespace.","provider":"go.mondoo.com/mql/providers/alicloud"},"httpTokens":{"name":"httpTokens","type":"\u0007","is_mandatory":true,"title":"Whether the metadata service demands a session token","desc":"Either required, which is IMDSv2, or optional, which still answers the token-less IMDSv1 request that a server-side request forgery can reach.","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Image launched","desc":"Null when the image has since been deleted, which also means the template can no longer launch.","provider":"go.mondoo.com/mql/providers/alicloud"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"ID of the image launched","provider":"go.mondoo.com/mql/providers/alicloud"},"imageOwnerAlias":{"name":"imageOwnerAlias","type":"\u0007","is_mandatory":true,"title":"Where the image comes from, for example system, self, others, or marketplace","provider":"go.mondoo.com/mql/providers/alicloud"},"imdsV2Required":{"name":"imdsV2Required","type":"\u0004","is_mandatory":true,"title":"Whether the metadata service requires IMDSv2","desc":"False when httpTokens is optional, which leaves the instance role credentials reachable through a server-side request forgery against the workload.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Instance type launched, for example ecs.g6.large","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthIn":{"name":"internetMaxBandwidthIn","type":"\u0005","is_mandatory":true,"title":"Maximum inbound public bandwidth in Mbit/s, 0 when no public address is assigned","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthOut":{"name":"internetMaxBandwidthOut","type":"\u0005","is_mandatory":true,"title":"Maximum outbound public bandwidth in Mbit/s","desc":"A value above 0 assigns a public IP address to every instance the version launches.","provider":"go.mondoo.com/mql/providers/alicloud"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether this version launches when a launch does not name one","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPairName":{"name":"keyPairName","type":"\u0007","is_mandatory":true,"title":"Name of the SSH key pair installed on launch, empty when none is installed","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplateId":{"name":"launchTemplateId","type":"\u0007","is_mandatory":true,"title":"ID of the launch template the version belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordInherit":{"name":"passwordInherit","type":"\u0004","is_mandatory":true,"title":"Whether the instance inherits the password of the image","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u001balicloud.ram.role","title":"RAM role attached to launched instances","desc":"Null when the template attaches no role. An instance carrying a role can mint credentials for it from the metadata service, so a broad role here is granted to every instance the template launches.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the template resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"securityEnhancementStrategy":{"name":"securityEnhancementStrategy","type":"\u0007","is_mandatory":true,"title":"Security-hardening applied at launch, for example Active or Deactive","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupIds":{"name":"securityGroupIds","type":"\u0019\u0007","is_mandatory":true,"title":"IDs of the security groups applied at launch","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied at launch","desc":"A group that has since been deleted is left out, so this can be shorter than securityGroupIds.","provider":"go.mondoo.com/mql/providers/alicloud"},"spotStrategy":{"name":"spotStrategy","type":"\u0007","is_mandatory":true,"title":"Preemption strategy, for example NoSpot, SpotWithPriceLimit, or SpotAsPriceGo","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskCategory":{"name":"systemDiskCategory","type":"\u0007","is_mandatory":true,"title":"Storage category of the system disk, for example cloud_essd","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskDeleteWithInstance":{"name":"systemDiskDeleteWithInstance","type":"\u0004","is_mandatory":true,"title":"Whether the system disk is released with the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskEncrypted":{"name":"systemDiskEncrypted","type":"\u0004","is_mandatory":true,"title":"Whether the system disk is encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskKmsKeyId":{"name":"systemDiskKmsKeyId","type":"\u0007","is_mandatory":true,"title":"ID of the KMS key encrypting the system disk, empty when the service-managed key is used","provider":"go.mondoo.com/mql/providers/alicloud"},"userData":{"name":"userData","type":"\u0007","is_mandatory":true,"title":"Startup script and cloud-init data written into every launched instance","desc":"The user data as plain text, decoded from the base64 form the API returns. Every instance launched from this version receives it, and any process on those instances that can reach the metadata service can read it back, so a credential embedded here is exposed on every instance the template has ever launched. Empty when the version carries no user data.","provider":"go.mondoo.com/mql/providers/alicloud"},"versionDescription":{"name":"versionDescription","type":"\u0007","is_mandatory":true,"title":"Description of the version","provider":"go.mondoo.com/mql/providers/alicloud"},"versionNumber":{"name":"versionNumber","type":"\u0005","is_mandatory":true,"title":"Version number","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC launched instances join","desc":"Null when the template names no VPC, and when the VPC lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch launched instances join","desc":"Null when the template names no vSwitch, and when the vSwitch lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone the instance is launched into","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Version of an Elastic Compute Service launch template","desc":"A single version of a launch template, keyed by the owning launchTemplateId and version number. Exposes the instance shape the version launches: the image, security groups, RAM role, key pair, metadata-service settings, disk encryption, and user data. Use it to find a template that grants a broad RAM role, leaves the metadata service on IMDSv1, or embeds a credential in user data.","min_provider_version":"13.5.1","defaults":"versionNumber instanceType isDefault","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.prefixList":{"id":"alicloud.ecs.prefixList","name":"alicloud.ecs.prefixList","fields":{"addressFamily":{"name":"addressFamily","type":"\u0007","is_mandatory":true,"title":"Address family of the entries","desc":"Either IPv4 or IPv6.","provider":"go.mondoo.com/mql/providers/alicloud"},"associationCount":{"name":"associationCount","type":"\u0005","is_mandatory":true,"title":"Number of resources that reference the list","desc":"Counts the security group rules and route entries pointing at the list, so a change to its blocks reaches every one of them.","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlocks":{"name":"cidrBlocks","type":"\u0019\u0007","title":"CIDR blocks the list admits","desc":"These are the addresses a rule scoped to this list actually matches. An entry of 0.0.0.0/0 opens every rule that points at the list.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the prefix list was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Prefix list description","provider":"go.mondoo.com/mql/providers/alicloud"},"maxEntries":{"name":"maxEntries","type":"\u0005","is_mandatory":true,"title":"Maximum number of entries the list can hold","provider":"go.mondoo.com/mql/providers/alicloud"},"prefixListId":{"name":"prefixListId","type":"\u0007","is_mandatory":true,"title":"Prefix list ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"prefixListName":{"name":"prefixListName","type":"\u0007","is_mandatory":true,"title":"Prefix list name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the prefix list lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the prefix list belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the prefix list belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the prefix list","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Prefix list","desc":"A named set of CIDR blocks that security group rules reference in place of a literal address range, keyed by prefixListId. A rule scoped to a prefix list carries no source or destination CIDR of its own, so the blocks it actually admits live here and nowhere else. associationCount reports how many rules and route tables point at the list, which is how far a change to it reaches.","min_provider_version":"13.4.1","defaults":"prefixListName prefixListId addressFamily associationCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.securitygroup":{"id":"alicloud.ecs.securitygroup","name":"alicloud.ecs.securitygroup","fields":{"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the security group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Security group description","provider":"go.mondoo.com/mql/providers/alicloud"},"instances":{"name":"instances","type":"\u0019\u001balicloud.ecs.instance","title":"Instances the security group is applied to","provider":"go.mondoo.com/mql/providers/alicloud"},"permission":{"name":"permission","type":"\u001balicloud.ecs.securitygroup.permission","title":"Elastic Compute Service security group rule","desc":"A single inbound or outbound rule of a security group, keyed by the security group ID, direction, and position. Exposes the protocol and port range, the source and destination CIDR blocks, referenced security groups, prefix lists, and the accept or drop policy.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"permissions":{"name":"permissions","type":"\u0019\u001balicloud.ecs.securitygroup.permission","title":"Inbound and outbound rules of the security group","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the security group","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the security group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the security group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupId":{"name":"securityGroupId","type":"\u0007","is_mandatory":true,"title":"Security group ID, for example sg-bp1234567890abcdef","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupName":{"name":"securityGroupName","type":"\u0007","is_mandatory":true,"title":"Security group name","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupType":{"name":"securityGroupType","type":"\u0007","is_mandatory":true,"title":"Security group type","desc":"One of normal or enterprise.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the security group, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the security group belongs to","desc":"Null on a classic-network security group, which is not in a VPC.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcId":{"name":"vpcId","type":"\u0007","is_mandatory":true,"title":"VPC ID the security group belongs to","desc":"Deprecated in favor of vpc.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.ecs.securitygroup.vpc"}},"title":"Elastic Compute Service security group","desc":"A single security group, keyed by the composite region and securityGroupId. Exposes the group name and type, the VPC it belongs to, its inbound and outbound rules, and the instances it is applied to.","min_provider_version":"13.0.0","defaults":"securityGroupId securityGroupName securityGroupType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.securitygroup.permission":{"id":"alicloud.ecs.securitygroup.permission","name":"alicloud.ecs.securitygroup.permission","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/mql/providers/alicloud"},"destCidrIp":{"name":"destCidrIp","type":"\u0007","is_mandatory":true,"title":"Destination IPv4 CIDR block for an outbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"destPrefixList":{"name":"destPrefixList","type":"\u001balicloud.ecs.prefixList","title":"Destination prefix list for an outbound rule","desc":"Null unless the rule is scoped to a prefix list. When it is set, the rule has no destCidrIp of its own and the list's cidrBlocks are what the rule permits traffic to reach.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"destPrefixListId":{"name":"destPrefixListId","type":"\u0007","is_mandatory":true,"title":"Destination prefix list ID for an outbound rule","desc":"Deprecated in favor of destPrefixList.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.ecs.securitygroup.permission.destPrefixList"},"destSecurityGroup":{"name":"destSecurityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Destination security group for an outbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationCidrs":{"name":"destinationCidrs","type":"\u0019\u0007","title":"Effective IPv4 destination CIDR blocks of an outbound rule","desc":"Combines destCidrIp with the cidrBlocks of the prefix list the rule is scoped to, so one list holds every IPv4 address the rule permits traffic to reach. An entry of 0.0.0.0/0 means the rule permits traffic to the whole internet. Empty for an inbound rule, for a rule scoped to a security group, and for a rule whose only destination is IPv6. When the prefix list cannot be read, the list carries only the rule's own destCidrIp.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Rule direction","desc":"One of ingress or egress.","provider":"go.mondoo.com/mql/providers/alicloud"},"fromPort":{"name":"fromPort","type":"\u0005","is_mandatory":true,"title":"Lowest destination port the rule matches","desc":"A rule written as -1/-1 matches every port, and reports 1 here alongside 65535 in toPort. Null when portRange holds no range that resolves to a pair of ports, which leaves portRange as the only record of it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ipProtocol":{"name":"ipProtocol","type":"\u0007","is_mandatory":true,"title":"Transport protocol the rule matches","desc":"One of TCP, UDP, ICMP, ICMPv6, GRE, or ALL.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6DestCidrIp":{"name":"ipv6DestCidrIp","type":"\u0007","is_mandatory":true,"title":"Destination IPv6 CIDR block for an outbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6DestinationCidrs":{"name":"ipv6DestinationCidrs","type":"\u0019\u0007","title":"Effective IPv6 destination CIDR blocks of an outbound rule","desc":"Combines ipv6DestCidrIp with the cidrBlocks of the prefix list the rule is scoped to, when that list holds IPv6 entries. An entry of ::/0 means the rule permits traffic to the whole IPv6 internet. Empty for an inbound rule and for a rule whose only destination is IPv4. When the prefix list cannot be read, the list carries only the rule's own ipv6DestCidrIp.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6SourceCidrIp":{"name":"ipv6SourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Source IPv6 CIDR block for an inbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6SourceCidrs":{"name":"ipv6SourceCidrs","type":"\u0019\u0007","title":"Effective IPv6 source CIDR blocks of an inbound rule","desc":"Combines ipv6SourceCidrIp with the cidrBlocks of the prefix list the rule is scoped to, when that list holds IPv6 entries. An entry of ::/0 means the rule admits the whole IPv6 internet. Empty for an outbound rule and for a rule whose only source is IPv4. When the prefix list cannot be read, the list carries only the rule's own ipv6SourceCidrIp.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"nicType":{"name":"nicType","type":"\u0007","is_mandatory":true,"title":"Network interface type the rule applies to","desc":"One of internet or intranet.","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","is_mandatory":true,"title":"Access policy of the rule","desc":"One of Accept or Drop.","provider":"go.mondoo.com/mql/providers/alicloud"},"portRange":{"name":"portRange","type":"\u0007","is_mandatory":true,"title":"Destination port range matched by the rule, for example 22/22 or 1/65535","provider":"go.mondoo.com/mql/providers/alicloud"},"priority":{"name":"priority","type":"\u0007","is_mandatory":true,"title":"Priority of the rule, from 1 (highest) to 100 (lowest)","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroupRuleId":{"name":"securityGroupRuleId","type":"\u0007","is_mandatory":true,"title":"Rule ID","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCidrIp":{"name":"sourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Source IPv4 CIDR block for an inbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCidrs":{"name":"sourceCidrs","type":"\u0019\u0007","title":"Effective IPv4 source CIDR blocks of an inbound rule","desc":"Combines sourceCidrIp with the cidrBlocks of the prefix list the rule is scoped to, so one list holds every IPv4 address the rule admits. An entry of 0.0.0.0/0 means the rule admits the whole internet. Empty for an outbound rule, for a rule scoped to a security group, and for a rule whose only source is IPv6. When the prefix list cannot be read, the list carries only the rule's own sourceCidrIp.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"sourcePortRange":{"name":"sourcePortRange","type":"\u0007","is_mandatory":true,"title":"Source port range matched by the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"sourcePrefixList":{"name":"sourcePrefixList","type":"\u001balicloud.ecs.prefixList","title":"Source prefix list for an inbound rule","desc":"Null unless the rule is scoped to a prefix list. When it is set, the rule has no sourceCidrIp of its own and the list's cidrBlocks are what the rule admits.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"sourcePrefixListId":{"name":"sourcePrefixListId","type":"\u0007","is_mandatory":true,"title":"Source prefix list ID for an inbound rule","desc":"Deprecated in favor of sourcePrefixList.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.ecs.securitygroup.permission.sourcePrefixList"},"sourceSecurityGroup":{"name":"sourceSecurityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Source security group for an inbound rule","provider":"go.mondoo.com/mql/providers/alicloud"},"toPort":{"name":"toPort","type":"\u0005","is_mandatory":true,"title":"Highest destination port the rule matches","desc":"A rule written as -1/-1 matches every port, and reports 65535 here alongside 1 in fromPort. Null when portRange holds no range that resolves to a pair of ports.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service security group rule","desc":"A single inbound or outbound rule of a security group, keyed by the security group ID, direction, and position. Exposes the protocol and port range, the source and destination CIDR blocks, referenced security groups, prefix lists, and the accept or drop policy.","min_provider_version":"13.0.0","defaults":"direction ipProtocol portRange policy","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ecs.snapshot":{"id":"alicloud.ecs.snapshot","name":"alicloud.ecs.snapshot","fields":{"available":{"name":"available","type":"\u0004","is_mandatory":true,"title":"Whether the snapshot can be used to create a disk or image","provider":"go.mondoo.com/mql/providers/alicloud"},"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Storage category of the snapshot, for example standard or flash","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the snapshot was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the snapshot","provider":"go.mondoo.com/mql/providers/alicloud"},"disk":{"name":"disk","type":"\u001balicloud.ecs.disk","title":"Disk the snapshot was taken from","desc":"Null when the disk has since been deleted, and when it lies outside the scanned regions. Compare its encrypted field with this snapshot's to find a snapshot that is not protected to the same standard as its source.","provider":"go.mondoo.com/mql/providers/alicloud"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the snapshot contents are encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptedWithCustomerKey":{"name":"encryptedWithCustomerKey","type":"\u0004","is_mandatory":true,"title":"Whether a customer master key protects the snapshot","desc":"False both for an unencrypted snapshot and for one encrypted with the service-managed key, where key rotation and revocation are not under the account's control.","provider":"go.mondoo.com/mql/providers/alicloud"},"fullSnapshotSizeInBytes":{"name":"fullSnapshotSizeInBytes","type":"\u0005","is_mandatory":true,"title":"Size of the full snapshot in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"instantAccess":{"name":"instantAccess","type":"\u0004","is_mandatory":true,"title":"Whether instant access is enabled for the snapshot","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"KMS key that encrypts the snapshot","desc":"Null when the snapshot is unencrypted, and when it is encrypted with the service-managed key rather than a customer master key.","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKeyId":{"name":"kmsKeyId","type":"\u0007","is_mandatory":true,"title":"ID of the KMS key that encrypts the snapshot, empty when none is used","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifiedTime":{"name":"lastModifiedTime","type":"\t","is_mandatory":true,"title":"Time the snapshot was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"progress":{"name":"progress","type":"\u0007","is_mandatory":true,"title":"Percentage of the snapshot that has been taken, for example 100%","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the snapshot resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the snapshot","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the snapshot belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"retentionDays":{"name":"retentionDays","type":"\u0005","is_mandatory":true,"title":"Days the snapshot is retained before automatic deletion, 0 when it is retained indefinitely","provider":"go.mondoo.com/mql/providers/alicloud"},"snapshotId":{"name":"snapshotId","type":"\u0007","is_mandatory":true,"title":"Snapshot ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"snapshotName":{"name":"snapshotName","type":"\u0007","is_mandatory":true,"title":"Name of the snapshot","provider":"go.mondoo.com/mql/providers/alicloud"},"snapshotType":{"name":"snapshotType","type":"\u0007","is_mandatory":true,"title":"How the snapshot was created, either user or auto for an automatic snapshot policy","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceDiskId":{"name":"sourceDiskId","type":"\u0007","is_mandatory":true,"title":"ID of the disk the snapshot was taken from","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceDiskSize":{"name":"sourceDiskSize","type":"\u0007","is_mandatory":true,"title":"Size of the source disk in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceDiskType":{"name":"sourceDiskType","type":"\u0007","is_mandatory":true,"title":"Kind of the source disk, either system or data","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceRegionId":{"name":"sourceRegionId","type":"\u0007","is_mandatory":true,"title":"Region the snapshot was copied from, empty when it was not copied","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceSnapshotId":{"name":"sourceSnapshotId","type":"\u0007","is_mandatory":true,"title":"ID of the snapshot this one was copied from, empty when it was not copied","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the snapshot","desc":"One of progressing, accomplished, or failed. Only an accomplished snapshot can be restored.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the snapshot","provider":"go.mondoo.com/mql/providers/alicloud"},"usage":{"name":"usage","type":"\u0007","is_mandatory":true,"title":"What the snapshot is used by, for example image, disk, image_disk, or none","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic Compute Service disk snapshot","desc":"A point-in-time copy of a disk's contents, keyed by snapshotId within its region. Exposes the source disk, the encryption state and key, the retention setting, and the snapshot lifecycle. Use it to find an unencrypted snapshot of an encrypted disk, which puts the disk's contents outside the protection the disk itself has.","min_provider_version":"13.5.1","defaults":"snapshotName snapshotId status encrypted","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.es":{"id":"alicloud.es","name":"alicloud.es","fields":{"instance":{"name":"instance","type":"\u001balicloud.es.instance","title":"Elasticsearch cluster","desc":"A single Elasticsearch cluster, keyed by instanceId. Reports the engine version and node layout, whether the transport is plain HTTP, whether disks are encrypted, and, through its detail accessors, whether the cluster and its Kibana console answer on a public endpoint and which address lists gate them.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.es.instance","title":"Elasticsearch clusters in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Elasticsearch","desc":"Elasticsearch clusters in the account. A cluster holds indexed copies of whatever was shipped into it, which is often log and application data, and it can be published on a public endpoint of its own alongside a Kibana console. Reports what each cluster accepts connections on and which addresses are allowed to reach it.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.es.instance":{"id":"alicloud.es.instance","name":"alicloud.es.instance","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the cluster was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dedicatedMaster":{"name":"dedicatedMaster","type":"\u0004","is_mandatory":true,"title":"Whether the cluster runs dedicated master nodes","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Cluster description, which is the name shown in the console","provider":"go.mondoo.com/mql/providers/alicloud"},"diskEncrypted":{"name":"diskEncrypted","type":"\u0004","is_mandatory":true,"title":"Whether the data node disks are encrypted at rest","provider":"go.mondoo.com/mql/providers/alicloud"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Private domain the cluster answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"esVersion":{"name":"esVersion","type":"\u0007","is_mandatory":true,"title":"Elasticsearch version the cluster runs","desc":"An unsupported version stops receiving security fixes, so the version is part of the cluster's exposure and not only its capability.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceCategory":{"name":"instanceCategory","type":"\u0007","title":"Cluster edition","desc":"Values include x-pack for a standard commercial cluster and advanced for the enterprise edition.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"internetExposed":{"name":"internetExposed","type":"\u0004","title":"Whether the cluster is reachable from the internet","desc":"True when either the cluster endpoint or the Kibana console answers publicly. False means both are confined to the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"kibanaDomain":{"name":"kibanaDomain","type":"\u0007","title":"Public domain the Kibana console answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"kibanaIpWhitelist":{"name":"kibanaIpWhitelist","type":"\u0019\u0007","title":"Addresses allowed to reach the Kibana console","provider":"go.mondoo.com/mql/providers/alicloud"},"kibanaPublicNetworkEnabled":{"name":"kibanaPublicNetworkEnabled","type":"\u0004","title":"Whether the Kibana console answers on a public endpoint","desc":"Kibana reads everything the cluster holds, so a public console is a data exposure in its own right even when the cluster endpoint stays private.","provider":"go.mondoo.com/mql/providers/alicloud"},"nodeAmount":{"name":"nodeAmount","type":"\u0005","is_mandatory":true,"title":"Number of data nodes in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"paymentType":{"name":"paymentType","type":"\u0007","is_mandatory":true,"title":"Billing method","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the cluster answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIpWhitelist":{"name":"privateIpWhitelist","type":"\u0019\u0007","title":"Addresses allowed to reach the cluster from inside the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Protocol the cluster accepts connections on","desc":"HTTP or HTTPS. HTTP means credentials and query results cross the network in the clear, which matters most on a cluster that also answers publicly.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicDomain":{"name":"publicDomain","type":"\u0007","title":"Public domain the cluster answers on","desc":"Empty when no public endpoint is switched on.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicIpWhitelist":{"name":"publicIpWhitelist","type":"\u0019\u0007","title":"Addresses allowed to reach the public endpoint","desc":"An entry of 0.0.0.0/0 leaves the cluster open to the whole internet, which is the default the console offers when a public endpoint is switched on.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicNetworkEnabled":{"name":"publicNetworkEnabled","type":"\u0004","title":"Whether the cluster answers on a public endpoint","desc":"True means the cluster is reachable from outside its VPC, leaving publicIpWhitelist as the control over who may connect.","provider":"go.mondoo.com/mql/providers/alicloud"},"publicPort":{"name":"publicPort","type":"\u0005","title":"Port the public endpoint answers on","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the cluster lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Cluster status","desc":"One of active, activating, inactive, or invalid.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the cluster was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"whitelistAllowsAllAddresses":{"name":"whitelistAllowsAllAddresses","type":"\u0004","title":"Whether the public endpoint whitelist admits every address","desc":"True when an entry in publicIpWhitelist admits any source address: the 0.0.0.0/0 block, the bare 0.0.0.0 the console writes for it, any other block with a /0 prefix length, the % wildcard, an address range spanning the whole space, or ::/0. Only the public endpoint whitelist is read, not privateIpWhitelist or kibanaIpWhitelist. An empty whitelist reports false, and an entry that cannot be parsed is not counted as open.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneCount":{"name":"zoneCount","type":"\u0005","is_mandatory":true,"title":"Number of zones the cluster spans","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elasticsearch cluster","desc":"A single Elasticsearch cluster, keyed by instanceId. Reports the engine version and node layout, whether the transport is plain HTTP, whether disks are encrypted, and, through its detail accessors, whether the cluster and its Kibana console answer on a public endpoint and which address lists gate them.","min_provider_version":"13.4.1","defaults":"description instanceId esVersion status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ess":{"id":"alicloud.ess","name":"alicloud.ess","fields":{"scalingConfiguration":{"name":"scalingConfiguration","type":"\u001balicloud.ess.scalingConfiguration","title":"Auto Scaling scaling configuration","desc":"The instance template a scaling group launches from: the image and instance type, the user data written into every instance, the RAM role and security groups each instance receives, the metadata service hardening, and the system disk encryption. The scalingConfigurationId and regionId fields together select a single configuration, for example `alicloud.ess.scalingConfiguration(scalingConfigurationId: \"asc-bp1abc\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"scalingConfigurations":{"name":"scalingConfigurations","type":"\u0019\u001balicloud.ess.scalingConfiguration","title":"Scaling configurations across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingGroup":{"name":"scalingGroup","type":"\u001balicloud.ess.scalingGroup","title":"Auto Scaling scaling group","desc":"A scaling group and the sizing, placement, and health-check settings that govern it, along with the scaling configurations it can launch from and the one currently active. The scalingGroupId and regionId fields together select a single group, for example `alicloud.ess.scalingGroup(scalingGroupId: \"asg-bp1abc\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"scalingGroups":{"name":"scalingGroups","type":"\u0019\u001balicloud.ess.scalingGroup","title":"Scaling groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Auto Scaling","desc":"Scaling groups and the scaling configurations they launch instances from, across every enabled region on the account. Instances created by a scaling group are transient, so the scaling configuration is the durable record of how they are built: the user data written into them, the RAM role and security groups they receive, the image they boot, and the metadata service hardening they inherit.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ess.scalingConfiguration":{"id":"alicloud.ess.scalingConfiguration","name":"alicloud.ess.scalingConfiguration","fields":{"confidentialComputingMode":{"name":"confidentialComputingMode","type":"\u0007","is_mandatory":true,"title":"Confidential computing mode of launched instances","desc":"Either Enclave or TDX when the instance builds a confidential computing environment. Empty when confidential computing is not configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the scaling configuration was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether launched instances are protected from deletion","provider":"go.mondoo.com/mql/providers/alicloud"},"image":{"name":"image","type":"\u001balicloud.ecs.image","title":"Image launched instances boot from","desc":"Null when the image has been deleted or is not visible to the account, which leaves the configuration unable to launch.","provider":"go.mondoo.com/mql/providers/alicloud"},"imageOwnerAlias":{"name":"imageOwnerAlias","type":"\u0007","is_mandatory":true,"title":"Where the image comes from","desc":"One of system for an Alibaba Cloud public image, self for a private image in the account, others for an image shared from another account, or marketplace.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Instance type launched from this configuration, for example ecs.g6.large","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthIn":{"name":"internetMaxBandwidthIn","type":"\u0005","is_mandatory":true,"title":"Maximum inbound public bandwidth in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"internetMaxBandwidthOut":{"name":"internetMaxBandwidthOut","type":"\u0005","is_mandatory":true,"title":"Maximum outbound public bandwidth in Mbit/s","desc":"A value above zero means every instance the group launches is assigned a public IP address, making it reachable from the internet subject to its security groups. Zero means instances get no public address.","provider":"go.mondoo.com/mql/providers/alicloud"},"keyPair":{"name":"keyPair","type":"\u001balicloud.ecs.keypair","title":"Key pair installed on every instance the configuration launches","desc":"Null when the configuration installs no key pair, in which case logon depends on a password, and also when the named key pair has since been deleted.","provider":"go.mondoo.com/mql/providers/alicloud"},"lifecycleState":{"name":"lifecycleState","type":"\u0007","is_mandatory":true,"title":"Lifecycle state of the scaling configuration","desc":"Either Active, meaning the scaling group launches instances from this configuration, or Inactive.","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataEndpointEnabled":{"name":"metadataEndpointEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the instance metadata service endpoint is reachable","desc":"False when the metadata endpoint is switched off entirely, which removes the RAM role credential path from every instance the group launches.","provider":"go.mondoo.com/mql/providers/alicloud"},"metadataHttpTokens":{"name":"metadataHttpTokens","type":"\u0007","is_mandatory":true,"title":"Whether a session token is required to read instance metadata","desc":"Either optional, where a plain request to the metadata service returns credentials, or required, where the caller must obtain a token first. Requiring a token is what stops a server-side request forgery on a launched instance from reading the RAM role credentials.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Scaling configuration name","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordInherit":{"name":"passwordInherit","type":"\u0004","is_mandatory":true,"title":"Whether launched instances keep the password baked into the image","desc":"True when the configuration inherits the image password rather than setting one, which leaves every instance sharing whatever credential the image was built with.","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordSet":{"name":"passwordSet","type":"\u0004","is_mandatory":true,"title":"Whether a logon password is configured","desc":"True when the configuration sets a password for the instance, enabling password logon alongside or instead of key-pair logon. The password itself is never returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"ramRole":{"name":"ramRole","type":"\u001balicloud.ram.role","title":"RAM role granted to every instance the configuration launches","desc":"The role whose temporary credentials the metadata service hands to any process on a launched instance. Traverse to attachedPolicies to see what a workload on those instances is authorized to do. Null when no instance RAM role is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the scaling configuration resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingConfigurationId":{"name":"scalingConfigurationId","type":"\u0007","is_mandatory":true,"title":"Scaling configuration ID","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingGroup":{"name":"scalingGroup","type":"\u001balicloud.ess.scalingGroup","title":"Scaling group the configuration belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityEnhancementStrategy":{"name":"securityEnhancementStrategy","type":"\u0007","is_mandatory":true,"title":"Hardening applied to the operating system at launch","desc":"Either Active, which installs the Security Center agent on each instance, or Deactive.","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to every instance the configuration launches","desc":"Traverse to permissions to see the inbound rules that will apply to each new instance, which is where a group launching into an open security group shows up.","provider":"go.mondoo.com/mql/providers/alicloud"},"spotStrategy":{"name":"spotStrategy","type":"\u0007","is_mandatory":true,"title":"Purchasing option for launched instances","desc":"One of NoSpot for pay-as-you-go, SpotWithPriceLimit, or SpotAsPriceGo.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskCategory":{"name":"systemDiskCategory","type":"\u0007","is_mandatory":true,"title":"System disk category","desc":"One of cloud, cloud_efficiency, cloud_ssd, cloud_essd, cloud_auto, or ephemeral_ssd.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskEncrypted":{"name":"systemDiskEncrypted","type":"\u0004","is_mandatory":true,"title":"Whether the system disk is encrypted at rest","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskKmsKey":{"name":"systemDiskKmsKey","type":"\u001balicloud.kms.key","title":"KMS key encrypting the system disk","desc":"Null when the system disk is unencrypted, or when it is encrypted with the service-managed key rather than a customer master key.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemDiskSize":{"name":"systemDiskSize","type":"\u0005","is_mandatory":true,"title":"System disk size in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"tenancy":{"name":"tenancy","type":"\u0007","is_mandatory":true,"title":"Tenancy of the underlying host","desc":"Either default for shared hosts or host for a dedicated host.","provider":"go.mondoo.com/mql/providers/alicloud"},"userData":{"name":"userData","type":"\u0007","is_mandatory":true,"title":"Startup script and cloud-init data written into every instance","desc":"The user data as plain text, decoded from the base64 form the API returns. Every instance the group launches receives it, and any process on those instances that can reach the metadata service can read it back, so a credential embedded here is exposed on every instance the group has ever created. Empty when the configuration carries no user data.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Auto Scaling scaling configuration","desc":"The instance template a scaling group launches from: the image and instance type, the user data written into every instance, the RAM role and security groups each instance receives, the metadata service hardening, and the system disk encryption. The scalingConfigurationId and regionId fields together select a single configuration, for example `alicloud.ess.scalingConfiguration(scalingConfigurationId: \"asc-bp1abc\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.2.5","defaults":"name scalingConfigurationId instanceType lifecycleState","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ess.scalingGroup":{"id":"alicloud.ess.scalingGroup","name":"alicloud.ess.scalingGroup","fields":{"activeCapacity":{"name":"activeCapacity","type":"\u0005","is_mandatory":true,"title":"Number of instances in the group that are serving traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"activeScalingConfiguration":{"name":"activeScalingConfiguration","type":"\u001balicloud.ess.scalingConfiguration","title":"Scaling configuration the group currently launches from","desc":"Null when the group has no active configuration, which is the case for a group that launches from a launch template.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the scaling group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultCooldown":{"name":"defaultCooldown","type":"\u0005","is_mandatory":true,"title":"Seconds after a scaling activity before another may start","provider":"go.mondoo.com/mql/providers/alicloud"},"desiredCapacity":{"name":"desiredCapacity","type":"\u0005","is_mandatory":true,"title":"Expected number of instances the group tries to hold","provider":"go.mondoo.com/mql/providers/alicloud"},"groupDeletionProtection":{"name":"groupDeletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether the group is protected from deletion","provider":"go.mondoo.com/mql/providers/alicloud"},"groupType":{"name":"groupType","type":"\u0007","is_mandatory":true,"title":"Kind of instance the group manages","desc":"Either ECS for Elastic Compute Service instances or ECI for elastic container instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckType":{"name":"healthCheckType","type":"\u0007","is_mandatory":true,"title":"How the group decides an instance is unhealthy","desc":"One of ECS, where the group replaces instances the ECS service reports as unhealthy, LOAD_BALANCER, or NONE, which disables replacement entirely.","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplate":{"name":"launchTemplate","type":"\u001balicloud.ecs.launchTemplate","title":"Launch template the group creates instances from","desc":"Null when the group launches from a scaling configuration instead, and when the template has since been deleted. Traverse to its versions to see the image, security groups, RAM role and user data the group's instances get.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplateId":{"name":"launchTemplateId","type":"\u0007","is_mandatory":true,"title":"ID of the launch template the group creates instances from","desc":"Empty on a group that launches from a scaling configuration instead. When set, the instance shape lives in the launch template rather than in scalingConfigurations, so those settings are not visible here.","provider":"go.mondoo.com/mql/providers/alicloud"},"launchTemplateVersion":{"name":"launchTemplateVersion","type":"\u0007","is_mandatory":true,"title":"Version of the launch template the group uses","desc":"A version number, or Latest or Default. Empty when the group launches from a scaling configuration.","provider":"go.mondoo.com/mql/providers/alicloud"},"lifecycleState":{"name":"lifecycleState","type":"\u0007","is_mandatory":true,"title":"Lifecycle state of the scaling group","desc":"One of Active, Inactive, or Deleting. Only an Active group launches and releases instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxInstanceLifetime":{"name":"maxInstanceLifetime","type":"\u0005","is_mandatory":true,"title":"Maximum seconds an instance may stay in the group before replacement","desc":"Zero when instances are never replaced on age alone, which lets a long-lived instance drift from the image the group launches today.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxSize":{"name":"maxSize","type":"\u0005","is_mandatory":true,"title":"Maximum number of instances the group may create","provider":"go.mondoo.com/mql/providers/alicloud"},"minSize":{"name":"minSize","type":"\u0005","is_mandatory":true,"title":"Minimum number of instances the group maintains","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationTime":{"name":"modificationTime","type":"\t","is_mandatory":true,"title":"Time the scaling group was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"multiAZPolicy":{"name":"multiAZPolicy","type":"\u0007","is_mandatory":true,"title":"How instances are spread across zones","desc":"One of PRIORITY, BALANCE, or COST_OPTIMIZED.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Scaling group name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the scaling group resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the scaling group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the scaling group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingConfigurations":{"name":"scalingConfigurations","type":"\u0019\u001balicloud.ess.scalingConfiguration","title":"Scaling configurations defined on the group","desc":"Every configuration attached to the group, active or not. An inactive configuration still ships whatever user data and permissions it holds the moment someone makes it active.","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingGroupId":{"name":"scalingGroupId","type":"\u0007","is_mandatory":true,"title":"Scaling group ID","provider":"go.mondoo.com/mql/providers/alicloud"},"scalingPolicy":{"name":"scalingPolicy","type":"\u0007","is_mandatory":true,"title":"Reclaim mode applied when the group removes an instance","desc":"One of recycle, which stops the instance, release, which deletes it, or forcerelease.","provider":"go.mondoo.com/mql/providers/alicloud"},"suspendedProcesses":{"name":"suspendedProcesses","type":"\u0019\u0007","is_mandatory":true,"title":"Scaling processes the group has been told to stop running","desc":"Any of ScaleIn, ScaleOut, HealthCheck, AlarmNotification, or ScheduledAction. A suspended HealthCheck stops unhealthy instances being replaced, so a group can sit degraded without any activity recorded.","provider":"go.mondoo.com/mql/providers/alicloud"},"systemSuspended":{"name":"systemSuspended","type":"\u0004","is_mandatory":true,"title":"Whether Auto Scaling itself has suspended the group","provider":"go.mondoo.com/mql/providers/alicloud"},"totalCapacity":{"name":"totalCapacity","type":"\u0005","is_mandatory":true,"title":"Number of instances currently in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the scaling group launches instances into","desc":"Null on a classic-network group.","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the scaling group may place instances in","desc":"The subnets available to the group, which determine the zones it can spread across. Empty on a classic-network group.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Auto Scaling scaling group","desc":"A scaling group and the sizing, placement, and health-check settings that govern it, along with the scaling configurations it can launch from and the one currently active. The scalingGroupId and regionId fields together select a single group, for example `alicloud.ess.scalingGroup(scalingGroupId: \"asg-bp1abc\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.2.5","defaults":"name scalingGroupId lifecycleState totalCapacity","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.fc":{"id":"alicloud.fc","name":"alicloud.fc","fields":{"function":{"name":"function","type":"\u001balicloud.fc.function","title":"Function Compute function","desc":"A single FC 3.0 function, keyed by functionName within its region. Exposes the runtime and resource configuration, the execution RAM role, the VPC and log configuration, public network egress, environment variables, and the function's triggers. Use it to audit the function's privilege and network exposure. For example alicloud.fc.function(functionName: \"my-fn\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"functions":{"name":"functions","type":"\u0019\u001balicloud.fc.function","title":"Functions across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"trigger":{"name":"trigger","type":"\u001balicloud.fc.trigger","title":"Function Compute trigger","desc":"A single trigger on an FC function, keyed by the owning functionName and triggerName. Exposes the trigger type and event source, the public and intranet HTTP endpoints for HTTP triggers, and the RAM role the event source assumes to invoke the function. Use it to audit whether a function is invocable from the internet.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud Function Compute","desc":"Function Compute (FC 3.0) functions across an Alibaba Cloud account. Exposes the serverless functions in every enabled region, along with their triggers. Use it to audit function execution roles, network placement, public egress and invocation, and whether environment variables might carry secrets.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.fc.function":{"id":"alicloud.fc.function","name":"alicloud.fc.function","fields":{"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the function","provider":"go.mondoo.com/mql/providers/alicloud"},"codeChecksum":{"name":"codeChecksum","type":"\u0007","is_mandatory":true,"title":"CRC-64 checksum of the deployed code","provider":"go.mondoo.com/mql/providers/alicloud"},"codeSize":{"name":"codeSize","type":"\u0005","is_mandatory":true,"title":"Deployed code size in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"cpu":{"name":"cpu","type":"\u0006","is_mandatory":true,"title":"vCPU cores allocated to the function","provider":"go.mondoo.com/mql/providers/alicloud"},"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the function was created","provider":"go.mondoo.com/mql/providers/alicloud"},"customContainerImage":{"name":"customContainerImage","type":"\u0007","is_mandatory":true,"title":"Container image for a custom-container function, empty for other runtimes","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the function","provider":"go.mondoo.com/mql/providers/alicloud"},"diskSize":{"name":"diskSize","type":"\u0005","is_mandatory":true,"title":"Ephemeral disk size in MB, either 512 or 10240","provider":"go.mondoo.com/mql/providers/alicloud"},"environmentVariables":{"name":"environmentVariables","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Environment variables configured on the function","desc":"Audit these for plaintext secrets; values are returned as configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"executionRole":{"name":"executionRole","type":"\u001balicloud.ram.role","title":"RAM role the function assumes when it runs","desc":"Null when the function has no execution role. The role determines the permissions the function code runs with.","provider":"go.mondoo.com/mql/providers/alicloud"},"functionId":{"name":"functionId","type":"\u0007","is_mandatory":true,"title":"System-generated function ID","provider":"go.mondoo.com/mql/providers/alicloud"},"functionName":{"name":"functionName","type":"\u0007","is_mandatory":true,"title":"Function name, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"handler":{"name":"handler","type":"\u0007","is_mandatory":true,"title":"Request handler entry point, for example index.handler","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceConcurrency":{"name":"instanceConcurrency","type":"\u0005","is_mandatory":true,"title":"Maximum number of concurrent requests handled by one instance","provider":"go.mondoo.com/mql/providers/alicloud"},"internetAccess":{"name":"internetAccess","type":"\u0004","is_mandatory":true,"title":"Whether the function has public internet egress","desc":"True when the function may reach the public internet for outbound requests.","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifiedTime":{"name":"lastModifiedTime","type":"\t","is_mandatory":true,"title":"Time the function was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"logProject":{"name":"logProject","type":"\u001balicloud.log.project","title":"Log Service project that receives function logs, null when logging is not configured","provider":"go.mondoo.com/mql/providers/alicloud"},"logStore":{"name":"logStore","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service logstore that receives function logs","provider":"go.mondoo.com/mql/providers/alicloud"},"memorySize":{"name":"memorySize","type":"\u0005","is_mandatory":true,"title":"Memory allocated to the function in MB","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the function resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the function","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the function belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"runtime":{"name":"runtime","type":"\u0007","is_mandatory":true,"title":"Function runtime","desc":"For example nodejs18, python3.10, go1, java11, php7.2, custom, custom.debian10, or custom-container.","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroup":{"name":"securityGroup","type":"\u001balicloud.ecs.securitygroup","title":"Security group applied to the function's VPC elastic network interface","provider":"go.mondoo.com/mql/providers/alicloud"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Function state, for example Active or Pending","provider":"go.mondoo.com/mql/providers/alicloud"},"stateReason":{"name":"stateReason","type":"\u0007","is_mandatory":true,"title":"Reason for the current state, empty when healthy","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the function","provider":"go.mondoo.com/mql/providers/alicloud"},"timeout":{"name":"timeout","type":"\u0005","is_mandatory":true,"title":"Maximum execution time in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"triggers":{"name":"triggers","type":"\u0019\u001balicloud.fc.trigger","title":"Triggers configured on the function","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the function is attached to, null when the function has no VPC configuration","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the function's elastic network interfaces attach to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Function Compute function","desc":"A single FC 3.0 function, keyed by functionName within its region. Exposes the runtime and resource configuration, the execution RAM role, the VPC and log configuration, public network egress, environment variables, and the function's triggers. Use it to audit the function's privilege and network exposure. For example alicloud.fc.function(functionName: \"my-fn\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.fc.trigger":{"id":"alicloud.fc.trigger","name":"alicloud.fc.trigger","fields":{"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the trigger was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the trigger","provider":"go.mondoo.com/mql/providers/alicloud"},"function":{"name":"function","type":"\u001balicloud.fc.function","title":"Function the trigger belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"functionName":{"name":"functionName","type":"\u0007","is_mandatory":true,"title":"Name of the function the trigger belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"httpUrlInternet":{"name":"httpUrlInternet","type":"\u0007","is_mandatory":true,"title":"Public HTTP endpoint for an http trigger","desc":"Empty for non-http triggers or when the public URL is disabled. A non-empty value means the function can be invoked over the internet.","provider":"go.mondoo.com/mql/providers/alicloud"},"httpUrlIntranet":{"name":"httpUrlIntranet","type":"\u0007","is_mandatory":true,"title":"Intranet (VPC-only) HTTP endpoint for an http trigger","provider":"go.mondoo.com/mql/providers/alicloud"},"internetInvocable":{"name":"internetInvocable","type":"\u0004","title":"Whether the function is invocable from the public internet through this trigger","desc":"True when an http trigger exposes a public URL. Combine with the triggerConfig authType to determine whether anonymous invocation is allowed.","provider":"go.mondoo.com/mql/providers/alicloud"},"invocationRole":{"name":"invocationRole","type":"\u001balicloud.ram.role","title":"RAM role the event source assumes to invoke the function, null when none","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifiedTime":{"name":"lastModifiedTime","type":"\t","is_mandatory":true,"title":"Time the trigger was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"qualifier":{"name":"qualifier","type":"\u0007","is_mandatory":true,"title":"Version or alias the trigger invokes","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the trigger resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceArn":{"name":"sourceArn","type":"\u0007","is_mandatory":true,"title":"ARN of the event source that fires the trigger","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Trigger status, for example OK or Disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"targetArn":{"name":"targetArn","type":"\u0007","is_mandatory":true,"title":"ARN of the invocation target","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerConfig":{"name":"triggerConfig","type":"\n","is_mandatory":true,"title":"Type-specific trigger configuration","desc":"Parsed from the trigger's config document; the shape varies by type, for example authType and methods for an http trigger, or events for an oss trigger.","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerId":{"name":"triggerId","type":"\u0007","is_mandatory":true,"title":"System-generated trigger ID","provider":"go.mondoo.com/mql/providers/alicloud"},"triggerName":{"name":"triggerName","type":"\u0007","is_mandatory":true,"title":"Trigger name, used with the function name as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Trigger type","desc":"One of http, oss, timer, log, mns_topic, cdn_events, or eventbridge.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Function Compute trigger","desc":"A single trigger on an FC function, keyed by the owning functionName and triggerName. Exposes the trigger type and event source, the public and intranet HTTP endpoints for HTTP triggers, and the RAM role the event source assumes to invoke the function. Use it to audit whether a function is invocable from the internet.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.kms":{"id":"alicloud.kms","name":"alicloud.kms","fields":{"key":{"name":"key","type":"\u001balicloud.kms.key","title":"Key Management Service customer master key","desc":"A single customer master key (CMK), keyed by keyId within its region. Exposes the key lifecycle state, cryptographic spec and usage, material origin, protection level, and the automatic-rotation configuration, along with the aliases that point at the key. Use it to audit whether keys rotate, whether deletion protection is on, and whether the key material lives in an HSM. For example `alicloud.kms.key(keyId: \"0d24xxxx\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"keys":{"name":"keys","type":"\u0019\u001balicloud.kms.key","title":"Customer master keys across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"secret":{"name":"secret","type":"\u001balicloud.kms.secret","title":"Key Management Service secret","desc":"A single secret held in Secrets Manager, keyed by secretName within its region. Exposes the secret metadata, type, rotation configuration, and the customer master key that encrypts the secret value. The secret value itself is never exposed. Use it to audit which secrets rotate and which key protects each one.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"secrets":{"name":"secrets","type":"\u0019\u001balicloud.kms.secret","title":"Secrets held in Secrets Manager across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Key Management Service","desc":"Encryption keys and secrets managed for an Alibaba Cloud account. Exposes the customer master keys across all enabled regions, including their lifecycle state, cryptographic spec, rotation configuration, and protection level, and the secrets held in Secrets Manager along with the master key that protects each one. Use it to audit key rotation, deletion protection, and whether keys are backed by a hardware security module.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.kms.key":{"id":"alicloud.kms.key","name":"alicloud.kms.key","fields":{"aliases":{"name":"aliases","type":"\u0019\u0007","title":"Alias names that point at the key, for example alias/my-key","provider":"go.mondoo.com/mql/providers/alicloud"},"allowsExternalPrincipal":{"name":"allowsExternalPrincipal","type":"\u0004","title":"Whether the key policy grants use of the key outside its own account","desc":"True when an allowing statement names a principal in another account, or names the wildcard `*`. Note that a key with no readable policy reports false, because an unread policy must not be reported as a grant.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the key","provider":"go.mondoo.com/mql/providers/alicloud"},"automaticRotation":{"name":"automaticRotation","type":"\u0007","is_mandatory":true,"title":"Automatic key-rotation state","desc":"One of Enabled, Disabled, or Suspended. Suspended means rotation was enabled but KMS cannot rotate the key, for example after the key was disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationDate":{"name":"creationDate","type":"\t","is_mandatory":true,"title":"Time the key was created","provider":"go.mondoo.com/mql/providers/alicloud"},"creator":{"name":"creator","type":"\u0007","is_mandatory":true,"title":"Account (UID) or service that created the key","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteDate":{"name":"deleteDate","type":"\t","is_mandatory":true,"title":"Time the key is scheduled for deletion, null when no deletion is scheduled","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0007","is_mandatory":true,"title":"Deletion-protection state","desc":"Enabled when the key cannot be scheduled for deletion until protection is turned off.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the key","provider":"go.mondoo.com/mql/providers/alicloud"},"dkmsInstanceId":{"name":"dkmsInstanceId","type":"\u0007","is_mandatory":true,"title":"Dedicated KMS instance ID that holds the key, empty for the shared default KMS","provider":"go.mondoo.com/mql/providers/alicloud"},"externalPrincipalAccountIds":{"name":"externalPrincipalAccountIds","type":"\u0019\u0007","title":"Accounts outside the key's own account that the key policy grants use of the key","desc":"Sorted and deduplicated. A non-empty list means the key can be used to decrypt from another Alibaba Cloud account, so data encrypted with it is readable outside this account's control.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"hasWildcardPrincipal":{"name":"hasWildcardPrincipal","type":"\u0004","title":"Whether the key policy names the wildcard as a principal","desc":"True when an allowing statement grants use of the key to `*`, which admits any identity the key's resource-sharing configuration reaches.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"keyId":{"name":"keyId","type":"\u0007","is_mandatory":true,"title":"Key ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"keySpec":{"name":"keySpec","type":"\u0007","is_mandatory":true,"title":"Cryptographic specification of the key","desc":"For example Aliyun_AES_256, Aliyun_SM4, RSA_2048, EC_P256, or EC_SM2.","provider":"go.mondoo.com/mql/providers/alicloud"},"keyState":{"name":"keyState","type":"\u0007","is_mandatory":true,"title":"Key lifecycle state","desc":"One of Enabled, Disabled, PendingDeletion, or PendingImport.","provider":"go.mondoo.com/mql/providers/alicloud"},"keyUsage":{"name":"keyUsage","type":"\u0007","is_mandatory":true,"title":"Cryptographic operations the key may perform","desc":"Either ENCRYPT/DECRYPT for encryption keys or SIGN/VERIFY for signing keys.","provider":"go.mondoo.com/mql/providers/alicloud"},"lastRotationDate":{"name":"lastRotationDate","type":"\t","is_mandatory":true,"title":"Time the key material was last rotated, null when never rotated","provider":"go.mondoo.com/mql/providers/alicloud"},"materialExpireTime":{"name":"materialExpireTime","type":"\t","is_mandatory":true,"title":"Time imported key material expires, null when it does not expire","provider":"go.mondoo.com/mql/providers/alicloud"},"nextRotationDate":{"name":"nextRotationDate","type":"\t","is_mandatory":true,"title":"Time the key is next scheduled to rotate, null when rotation is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Source of the key material","desc":"Aliyun_KMS when the material was generated by KMS, or EXTERNAL when it was imported.","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","title":"Key policy document","desc":"The resource policy attached to the key, as a JSON string. It names the identities permitted to use the key for cryptographic operations, which is a grant that the RAM policies attached to those identities do not show on their own. Empty when the key carries no policy, and on a key policy the scan is not permitted to read.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"primaryKeyVersion":{"name":"primaryKeyVersion","type":"\u0007","is_mandatory":true,"title":"Identifier of the current primary key version","provider":"go.mondoo.com/mql/providers/alicloud"},"protectionLevel":{"name":"protectionLevel","type":"\u0007","is_mandatory":true,"title":"Protection level of the key material","desc":"SOFTWARE for software-protected keys, or HSM when the material is stored in a hardware security module.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the key resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"rotationInterval":{"name":"rotationInterval","type":"\u0005","is_mandatory":true,"title":"Interval between automatic rotations, in seconds","desc":"For example 31536000 for a key that rotates once a year. Null when the key reports no interval, which is the case while automatic rotation is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"statements":{"name":"statements","type":"\u0019\u001balicloud.ram.policy.statement","title":"Parsed statements of the key policy","desc":"The key policy decoded into statements, so the principals and the actions they are granted can be queried directly rather than by matching text.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Key Management Service customer master key","desc":"A single customer master key (CMK), keyed by keyId within its region. Exposes the key lifecycle state, cryptographic spec and usage, material origin, protection level, and the automatic-rotation configuration, along with the aliases that point at the key. Use it to audit whether keys rotate, whether deletion protection is on, and whether the key material lives in an HSM. For example `alicloud.kms.key(keyId: \"0d24xxxx\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.kms.secret":{"id":"alicloud.kms.secret","name":"alicloud.kms.secret","fields":{"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the secret","provider":"go.mondoo.com/mql/providers/alicloud"},"automaticRotation":{"name":"automaticRotation","type":"\u0007","is_mandatory":true,"title":"Automatic-rotation state","desc":"One of Enabled, Disabled, or Suspended.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the secret was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the secret","provider":"go.mondoo.com/mql/providers/alicloud"},"dkmsInstanceId":{"name":"dkmsInstanceId","type":"\u0007","is_mandatory":true,"title":"Dedicated KMS instance ID that holds the secret, empty for the shared default KMS","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionKey":{"name":"encryptionKey","type":"\u001balicloud.kms.key","title":"Customer master key that encrypts the secret value","provider":"go.mondoo.com/mql/providers/alicloud"},"extendedConfig":{"name":"extendedConfig","type":"\n","is_mandatory":true,"title":"Type-specific extended configuration","desc":"Parsed from the secret's extended-config document; the shape varies by secretType, for example the linked instance and account for an Rds secret. Null for Generic secrets.","provider":"go.mondoo.com/mql/providers/alicloud"},"lastRotationDate":{"name":"lastRotationDate","type":"\t","is_mandatory":true,"title":"Time the secret was last rotated, null when never rotated","provider":"go.mondoo.com/mql/providers/alicloud"},"nextRotationDate":{"name":"nextRotationDate","type":"\t","is_mandatory":true,"title":"Time the secret is next scheduled to rotate, null when rotation is disabled","provider":"go.mondoo.com/mql/providers/alicloud"},"owingService":{"name":"owingService","type":"\u0007","is_mandatory":true,"title":"Service that owns the secret, empty for user-managed secrets","provider":"go.mondoo.com/mql/providers/alicloud"},"plannedDeleteTime":{"name":"plannedDeleteTime","type":"\t","is_mandatory":true,"title":"Time the secret is scheduled for deletion, null when no deletion is scheduled","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the secret resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"rotationInterval":{"name":"rotationInterval","type":"\u0005","is_mandatory":true,"title":"Interval between automatic rotations, in seconds","desc":"For example 604800 for a secret that rotates once a week. Null when the secret reports no interval, which is the case while automatic rotation is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"secretName":{"name":"secretName","type":"\u0007","is_mandatory":true,"title":"Secret name, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"secretType":{"name":"secretType","type":"\u0007","is_mandatory":true,"title":"Secret type","desc":"One of Generic, Rds, RAMCredentials, or ECS. Managed types (Rds, ECS, RAMCredentials) are rotated by the owning service.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the secret","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the secret was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Key Management Service secret","desc":"A single secret held in Secrets Manager, keyed by secretName within its region. Exposes the secret metadata, type, rotation configuration, and the customer master key that encrypts the secret value. The secret value itself is never exposed. Use it to audit which secrets rotate and which key protects each one.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log":{"id":"alicloud.log","name":"alicloud.log","fields":{"alert":{"name":"alert","type":"\u001balicloud.log.alert","title":"Log Service alert rule","desc":"A single alert rule in a Log Service project, keyed by the project and the rule name. Exposes whether the rule is enabled, how often it is evaluated, and the queries it runs, each naming the store it reads and the search it performs. Both halves matter: a rule whose query matches nothing raises nothing, and so does a rule that is disabled or muted, however well written its query is.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"apiKey":{"name":"apiKey","type":"\u001balicloud.log.apiKey","title":"Log Service API key","desc":"A single standing API key of a Log Service project, keyed by the project name and the key name within a region. An API key is a long-lived credential for the logging plane, so its store scope and its state decide how much log data one leaked string reaches. Exposes the key state, the stores the key is limited to, whether that scope leaves it unrestricted, and the creation and last-update times. The key material is never read.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"logstore":{"name":"logstore","type":"\u001balicloud.log.logstore","title":"Log Service logstore","desc":"A single logstore within a Log Service project, keyed by the owning project name and logstore name. A logstore ingests, stores, and indexes a stream of logs. Exposes the retention period, shard layout, telemetry type, and the server-side encryption configuration. Use it to audit log retention and whether logs are encrypted with a customer master key.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Log Service project","desc":"A single Log Service project, keyed by name within its region. A project is the top-level container that groups logstores, dashboards, and alerts. Exposes the project metadata, endpoints, and the logstores it contains. For example `alicloud.log.project(name: \"my-project\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"projects":{"name":"projects","type":"\u0019\u001balicloud.log.project","title":"Log Service projects across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Log Service","desc":"Log Service (SLS) projects and their logstores across an Alibaba Cloud account. Exposes the projects in every enabled region and, within each, the logstores that ingest and store logs, including their retention period and server-side encryption configuration. Log Service is the delivery target for ActionTrail trails and VPC flow logs, so these resources anchor the account's logging posture.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log.alert":{"id":"alicloud.log.alert","name":"alicloud.log.alert","fields":{"annotations":{"name":"annotations","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Annotations attached to the rule as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name shown in the console","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is evaluated","desc":"A disabled rule is kept but never runs, so it raises nothing regardless of what its query would have matched.","provider":"go.mondoo.com/mql/providers/alicloud"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Labels attached to the rule as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifiedTime":{"name":"lastModifiedTime","type":"\t","is_mandatory":true,"title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"muteUntil":{"name":"muteUntil","type":"\t","is_mandatory":true,"title":"Time until which the rule is muted","desc":"Null when the rule is not muted. A muted rule is evaluated but raises no notification, so it can read as enabled while notifying nobody.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name, used with the project as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"noDataFire":{"name":"noDataFire","type":"\u0004","is_mandatory":true,"title":"Whether the rule fires when its query returns no data at all","desc":"A rule watching for the absence of an expected event needs this, otherwise a silent source is indistinguishable from a healthy one.","provider":"go.mondoo.com/mql/providers/alicloud"},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Log Service project the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the project the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"queries":{"name":"queries","type":"\u0019\u001balicloud.log.alert.query","title":"Queries the rule evaluates","desc":"A rule can read several stores. Each entry names the store and the search run against it, which is what decides whether the rule notices the events it was meant to.","provider":"go.mondoo.com/mql/providers/alicloud"},"query":{"name":"query","type":"\u001balicloud.log.alert.query","title":"Log Service alert rule query","desc":"A single query an alert rule evaluates. Exposes the store it reads, the search it runs, and the time range it covers, so the events a rule can actually notice are readable rather than implied by the rule's name.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region of the project the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduleCronExpression":{"name":"scheduleCronExpression","type":"\u0007","is_mandatory":true,"title":"Cron expression the rule is evaluated on","desc":"Empty when the rule runs at a fixed interval instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduleInterval":{"name":"scheduleInterval","type":"\u0007","is_mandatory":true,"title":"How often the rule is evaluated, for example 1m or 5m","desc":"Empty when the rule runs on a cron expression instead, given by scheduleCronExpression.","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduleRunImmediately":{"name":"scheduleRunImmediately","type":"\u0004","is_mandatory":true,"title":"Whether the schedule is currently running","desc":"False when the rule is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduleTimeZone":{"name":"scheduleTimeZone","type":"\u0007","is_mandatory":true,"title":"Time zone the schedule is interpreted in","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduleType":{"name":"scheduleType","type":"\u0007","is_mandatory":true,"title":"Kind of schedule the rule runs on, for example FixedRate or Cron","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status the API reports, either ENABLED or DISABLED","provider":"go.mondoo.com/mql/providers/alicloud"},"threshold":{"name":"threshold","type":"\u0005","is_mandatory":true,"title":"Consecutive matches required before the rule fires","desc":"A threshold above 1 means a single match does not raise anything.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Log Service alert rule","desc":"A single alert rule in a Log Service project, keyed by the project and the rule name. Exposes whether the rule is enabled, how often it is evaluated, and the queries it runs, each naming the store it reads and the search it performs. Both halves matter: a rule whose query matches nothing raises nothing, and so does a rule that is disabled or muted, however well written its query is.","min_provider_version":"13.5.1","defaults":"name enabled scheduleInterval","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log.alert.query":{"id":"alicloud.log.alert.query","name":"alicloud.log.alert.query","fields":{"end":{"name":"end","type":"\u0007","is_mandatory":true,"title":"End of the time range the query covers, relative to each evaluation","desc":"For example now.","provider":"go.mondoo.com/mql/providers/alicloud"},"logstore":{"name":"logstore","type":"\u001balicloud.log.logstore","title":"Logstore the query reads","desc":"Null when the query reads a store in another account or region, or a store that can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the project the query reads from","provider":"go.mondoo.com/mql/providers/alicloud"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Search the query runs","desc":"The Log Service query the rule evaluates, for example a filter over an ActionTrail logstore selecting a particular event name.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the queried store resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"roleArn":{"name":"roleArn","type":"\u0007","is_mandatory":true,"title":"RAM role assumed to read the store","desc":"Set when the query reads a store in another account. Empty when it reads a store in the account being scanned.","provider":"go.mondoo.com/mql/providers/alicloud"},"start":{"name":"start","type":"\u0007","is_mandatory":true,"title":"Start of the time range the query covers, relative to each evaluation","desc":"For example -5m.","provider":"go.mondoo.com/mql/providers/alicloud"},"store":{"name":"store","type":"\u0007","is_mandatory":true,"title":"Name of the logstore or metricstore the query reads","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Log Service alert rule query","desc":"A single query an alert rule evaluates. Exposes the store it reads, the search it runs, and the time range it covers, so the events a rule can actually notice are readable rather than implied by the rule's name.","min_provider_version":"13.5.1","defaults":"store query","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log.apiKey":{"id":"alicloud.log.apiKey","name":"alicloud.log.apiKey","fields":{"allowedLogstores":{"name":"allowedLogstores","type":"\u0019\u001balicloud.log.logstore","title":"Logstores named in the key scope","desc":"Empty when the key names no store, which means it is unrestricted, and empty when every name in the scope is a metricstore rather than a logstore. Read allowsAllStores before concluding a key is narrowly scoped.","provider":"go.mondoo.com/mql/providers/alicloud"},"allowedStores":{"name":"allowedStores","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the stores the key is limited to","desc":"The logstores and metricstores named in the key scope. An empty list is not \"reaches nothing\": it means the key carries no store restriction and reaches every store in the project, which allowsAllStores reports directly.","provider":"go.mondoo.com/mql/providers/alicloud"},"allowsAllStores":{"name":"allowsAllStores","type":"\u0004","is_mandatory":true,"title":"Whether the key reaches every store in the project","desc":"True when allowedStores is empty, which leaves the key unrestricted within the project.","provider":"go.mondoo.com/mql/providers/alicloud"},"apiKeyName":{"name":"apiKeyName","type":"\u0007","is_mandatory":true,"title":"Name of the API key, unique within the project","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"When the API key was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the API key, empty when none is set","provider":"go.mondoo.com/mql/providers/alicloud"},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Project the key is scoped to","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the project the key is scoped to","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the project the key belongs to, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"State of the API key","desc":"Enabled while the key authenticates requests, Disabled once it has been turned off. A disabled key still exists and can be turned back on.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"When the API key was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Log Service API key","desc":"A single standing API key of a Log Service project, keyed by the project name and the key name within a region. An API key is a long-lived credential for the logging plane, so its store scope and its state decide how much log data one leaked string reaches. Exposes the key state, the stores the key is limited to, whether that scope leaves it unrestricted, and the creation and last-update times. The key material is never read.","min_provider_version":"13.5.1","defaults":"apiKeyName status allowsAllStores","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log.logstore":{"id":"alicloud.log.logstore","name":"alicloud.log.logstore","fields":{"appendMeta":{"name":"appendMeta","type":"\u0004","title":"Whether the built-in reserved fields (for example __topic__) are recorded","provider":"go.mondoo.com/mql/providers/alicloud"},"autoSplit":{"name":"autoSplit","type":"\u0004","title":"Whether the logstore automatically splits shards under load","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","title":"Time the logstore was created","provider":"go.mondoo.com/mql/providers/alicloud"},"enableTracking":{"name":"enableTracking","type":"\u0004","title":"Whether WebTracking ingestion is enabled for the logstore","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionEnabled":{"name":"encryptionEnabled","type":"\u0004","title":"Whether server-side encryption is enabled for the logstore","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionKey":{"name":"encryptionKey","type":"\u001balicloud.kms.key","title":"Customer master key used for server-side encryption","desc":"Null when encryption is disabled or uses a service-managed key rather than a specific customer master key.","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptionType":{"name":"encryptionType","type":"\u0007","title":"Server-side encryption algorithm","desc":"For example default or sm4. Empty when encryption is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"hotTtl":{"name":"hotTtl","type":"\u0005","title":"Number of days logs are kept in hot storage before moving to cold storage","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifyTime":{"name":"lastModifyTime","type":"\t","title":"Time the logstore was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"maxSplitShard":{"name":"maxSplitShard","type":"\u0005","title":"Maximum number of shards the logstore may auto-split into","provider":"go.mondoo.com/mql/providers/alicloud"},"mode":{"name":"mode","type":"\u0007","title":"Logstore mode, for example standard or query","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Logstore name, used with the project name as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Project that contains the logstore","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the project that contains the logstore","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the logstore resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"shardCount":{"name":"shardCount","type":"\u0005","title":"Number of read/write shards the logstore is split into","provider":"go.mondoo.com/mql/providers/alicloud"},"telemetryType":{"name":"telemetryType","type":"\u0007","title":"Telemetry type stored, for example None for logs or Metrics","provider":"go.mondoo.com/mql/providers/alicloud"},"ttl":{"name":"ttl","type":"\u0005","title":"Number of days ingested logs are retained; 3650 means permanent retention","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Log Service logstore","desc":"A single logstore within a Log Service project, keyed by the owning project name and logstore name. A logstore ingests, stores, and indexes a stream of logs. Exposes the retention period, shard layout, telemetry type, and the server-side encryption configuration. Use it to audit log retention and whether logs are encrypted with a customer master key.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.log.project":{"id":"alicloud.log.project","name":"alicloud.log.project","fields":{"alerts":{"name":"alerts","type":"\u0019\u001balicloud.log.alert","title":"Alert rules defined in the project","desc":"The rules that watch the project's logs and raise a notification when a query matches. Logs being collected is only half of monitoring; without a rule reading them, nothing is noticed.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"apiKeys":{"name":"apiKeys","type":"\u0019\u001balicloud.log.apiKey","title":"API keys scoped to the project","desc":"The standing credentials that reach the project's stores directly, outside the RAM identities the rest of the account is audited through.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the project was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dataRedundancyType":{"name":"dataRedundancyType","type":"\u0007","is_mandatory":true,"title":"Data-redundancy type of the project storage, for example LRS or ZRS","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the project","provider":"go.mondoo.com/mql/providers/alicloud"},"internalEndpoint":{"name":"internalEndpoint","type":"\u0007","is_mandatory":true,"title":"Internal endpoint for access from within Alibaba Cloud","provider":"go.mondoo.com/mql/providers/alicloud"},"internetEndpoint":{"name":"internetEndpoint","type":"\u0007","is_mandatory":true,"title":"Public endpoint for access over the Internet","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","title":"Whether the resource policy grants access to any principal","desc":"True when a granting statement names a wildcard principal, which opens the project's log data to callers outside the account. False when no policy is attached or every grant is scoped to named principals.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"lastModifyTime":{"name":"lastModifyTime","type":"\t","is_mandatory":true,"title":"Time the project was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"logstores":{"name":"logstores","type":"\u0019\u001balicloud.log.logstore","title":"Logstores contained in the project","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Project name, globally unique and used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"owner":{"name":"owner","type":"\u0007","is_mandatory":true,"title":"Account (UID) that owns the project","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","title":"Resource policy attached to the project","desc":"The JSON policy document that grants principals outside the owning account access to the project and everything in it. Empty when no policy is attached, which leaves access governed by RAM alone. Audit logs delivered into a project are only as protected as this policy allows.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"recycleBinEnabled":{"name":"recycleBinEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the recycle bin is enabled for the project","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the project resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the project","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the project belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Project status, for example Normal","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Log Service project","desc":"A single Log Service project, keyed by name within its region. A project is the top-level container that groups logstores, dashboards, and alerts. Exposes the project metadata, endpoints, and the logstores it contains. For example `alicloud.log.project(name: \"my-project\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.mongodb":{"id":"alicloud.mongodb","name":"alicloud.mongodb","fields":{"instance":{"name":"instance","type":"\u001balicloud.mongodb.instance","title":"ApsaraDB for MongoDB instance","desc":"A single ApsaraDB for MongoDB instance, keyed by dbInstanceId, for example dds-bp199659b178cef4. Exposes the deployment architecture, engine version, storage and network placement, maintenance window, and the security posture including TLS, transparent data encryption, the IP whitelist, the bound ECS security groups, and audit log status.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.mongodb.instance","title":"MongoDB instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for MongoDB","desc":"Managed MongoDB service in an Alibaba Cloud account. Exposes the MongoDB instances across every enabled region through instances, spanning replica set, sharded cluster, and serverless deployments together with their security posture.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.mongodb.instance":{"id":"alicloud.mongodb.instance","name":"alicloud.mongodb.instance","fields":{"auditPolicyEnabled":{"name":"auditPolicyEnabled","type":"\u0004","title":"Whether the audit log feature is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"backupRetentionPolicy":{"name":"backupRetentionPolicy","type":"\u0005","is_mandatory":true,"title":"Backup retention policy applied when the instance is released","desc":"One of 0 (all backup sets deleted immediately on release), 1 (one backup set retained long-term on release), or 2 (all backup sets retained long-term on release).","provider":"go.mondoo.com/mql/providers/alicloud"},"capacityUnit":{"name":"capacityUnit","type":"\u0007","is_mandatory":true,"title":"I/O throughput consumed by a serverless instance","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"currentKernelVersion":{"name":"currentKernelVersion","type":"\u0007","title":"Current minor kernel version of the database, for example 5.0.5-20220721143518_0","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceClass":{"name":"dbInstanceClass","type":"\u0007","is_mandatory":true,"title":"Instance type (specification), for example dds.mongo.mid","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceDescription":{"name":"dbInstanceDescription","type":"\u0007","is_mandatory":true,"title":"Instance name set by the user","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceId":{"name":"dbInstanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example dds-bp199659b178cef4","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStatus":{"name":"dbInstanceStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"Common values include Creating, Running, Deleting, Rebooting, DBInstanceClassChanging, and TransingToOthers. See the ApsaraDB for MongoDB instance state reference for the full set.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStorage":{"name":"dbInstanceStorage","type":"\u0005","is_mandatory":true,"title":"Storage capacity in GB","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceType":{"name":"dbInstanceType","type":"\u0007","is_mandatory":true,"title":"Deployment architecture","desc":"One of replicate (replica set or standalone), sharding (sharded cluster), or serverless.","provider":"go.mondoo.com/mql/providers/alicloud"},"destroyTime":{"name":"destroyTime","type":"\t","is_mandatory":true,"title":"Time when the released instance data is destroyed","provider":"go.mondoo.com/mql/providers/alicloud"},"encrypted":{"name":"encrypted","type":"\u0004","title":"Whether disk encryption is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"engine":{"name":"engine","type":"\u0007","is_mandatory":true,"title":"Database engine, for example MongoDB","provider":"go.mondoo.com/mql/providers/alicloud"},"engineVersion":{"name":"engineVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version","desc":"One of 7.0, 6.0, 5.0, 4.4, 4.2, 4.0, or 3.4.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Time when a subscription instance expires","provider":"go.mondoo.com/mql/providers/alicloud"},"hiddenZoneId":{"name":"hiddenZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the hidden (third) zone in a multi-zone deployment","provider":"go.mondoo.com/mql/providers/alicloud"},"kindCode":{"name":"kindCode","type":"\u0007","is_mandatory":true,"title":"Hardware kind code","desc":"One of 0 (physical machine), 1 (ECS instance), 2 (Docker cluster), or 18 (Kubernetes cluster).","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"KMS key used for disk encryption, null when disk encryption is disabled","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"lastDowngradeTime":{"name":"lastDowngradeTime","type":"\u0007","is_mandatory":true,"title":"Date of the last downgrade operation, for example 2021-05-08","provider":"go.mondoo.com/mql/providers/alicloud"},"lockMode":{"name":"lockMode","type":"\u0007","is_mandatory":true,"title":"Lock status","desc":"One of Unlock, ManualLock, LockByExpiration, LockByRestoration, LockByDiskQuota, or Released.","provider":"go.mondoo.com/mql/providers/alicloud"},"maintainEndTime":{"name":"maintainEndTime","type":"\u0007","title":"End of the maintenance window in UTC, for example 03:00Z","provider":"go.mondoo.com/mql/providers/alicloud"},"maintainStartTime":{"name":"maintainStartTime","type":"\u0007","title":"Start of the maintenance window in UTC, for example 18:00Z","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"One of Classic (classic network) or VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"protocolType":{"name":"protocolType","type":"\u0007","title":"Access protocol type of a sharded cluster instance","desc":"One of mongodb or dynamodb. Returned only for sharded cluster instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"readonlyReplicas":{"name":"readonlyReplicas","type":"\u0007","title":"Number of read-only nodes in the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the instance, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"releaseProtection":{"name":"releaseProtection","type":"\u0004","title":"Whether release protection is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"releaseTime":{"name":"releaseTime","type":"\t","is_mandatory":true,"title":"Time when the instance was released","provider":"go.mondoo.com/mql/providers/alicloud"},"replicationFactor":{"name":"replicationFactor","type":"\u0007","is_mandatory":true,"title":"Number of nodes in a replica set instance","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"secondaryZoneId":{"name":"secondaryZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the secondary zone in a multi-zone deployment","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"ECS security groups bound to the instance","desc":"The groups whose rules govern which sources may reach the instance. Traverse to permissions to see the allowed source ranges and ports alongside securityIPList, which controls the instance whitelist separately.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"securityIPList":{"name":"securityIPList","type":"\u0019\u0007","title":"IP addresses and CIDR blocks in the instance whitelist","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether TLS/SSL is enabled for client connections","provider":"go.mondoo.com/mql/providers/alicloud"},"sslExpireTime":{"name":"sslExpireTime","type":"\t","title":"Time when the current SSL certificate expires","provider":"go.mondoo.com/mql/providers/alicloud"},"storageEngine":{"name":"storageEngine","type":"\u0007","title":"Storage engine, for example WiredTiger or RocksDB","provider":"go.mondoo.com/mql/providers/alicloud"},"storageType":{"name":"storageType","type":"\u0007","is_mandatory":true,"title":"Disk storage type","desc":"One of cloud_essd, cloud_essd1, cloud_essd2, cloud_essd3, local_ssd, or cloud_essd_dbfs_s.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the instance, keyed by tag key","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether transparent data encryption (TDE) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC hosting the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcAuthMode":{"name":"vpcAuthMode","type":"\u0007","is_mandatory":true,"title":"Password-free access over VPC","desc":"One of Open (password-free access within the VPC is enabled), Close (a password is required), or NotSupport.","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch hosting the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"whitelistAllowsAllAddresses":{"name":"whitelistAllowsAllAddresses","type":"\u0004","title":"Whether the IP whitelist admits every address","desc":"True when an entry in securityIPList admits any source address: the 0.0.0.0/0 block, the bare 0.0.0.0 the console writes for it, any other block with a /0 prefix length, the % wildcard, an address range spanning the whole space, or ::/0. An empty whitelist reports false, and an entry that cannot be parsed is not counted as open.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Primary zone ID of the instance, for example cn-hangzhou-g","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for MongoDB instance","desc":"A single ApsaraDB for MongoDB instance, keyed by dbInstanceId, for example dds-bp199659b178cef4. Exposes the deployment architecture, engine version, storage and network placement, maintenance window, and the security posture including TLS, transparent data encryption, the IP whitelist, the bound ECS security groups, and audit log status.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas":{"id":"alicloud.nas","name":"alicloud.nas","fields":{"accessGroup":{"name":"accessGroup","type":"\u001balicloud.nas.accessGroup","title":"NAS access group","desc":"A single NAS access group, keyed by accessGroupName within its region. An access group is a named set of access rules that govern which client IP ranges may mount the file systems bound to it. Exposes the group metadata and its access rules. Use it to audit the client ranges permitted to mount.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"accessGroups":{"name":"accessGroups","type":"\u0019\u001balicloud.nas.accessGroup","title":"NAS access groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"accessRule":{"name":"accessRule","type":"\u001balicloud.nas.accessRule","title":"NAS access rule","desc":"A single access rule within a NAS access group, keyed by accessRuleId. A rule permits a client IP range to mount with a given read/write and user-squash policy. Exposes the allowed CIDR, access mode, and squash setting. Use it to find rules that open a file system to broad client ranges or disable root squashing.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"fileSystem":{"name":"fileSystem","type":"\u001balicloud.nas.fileSystem","title":"NAS file system","desc":"A single NAS file system, keyed by fileSystemId within its region. Exposes the storage and protocol type, the encryption state and key, capacity and used size, and the mount targets that expose it to clients. Use it to audit encryption at rest and the network exposure of the mount targets. For example alicloud.nas.fileSystem(fileSystemId: \"1a2b3c\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"fileSystems":{"name":"fileSystems","type":"\u0019\u001balicloud.nas.fileSystem","title":"NAS file systems across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"mountTarget":{"name":"mountTarget","type":"\u001balicloud.nas.mountTarget","title":"NAS mount target","desc":"A single mount target of a NAS file system, keyed by mountTargetDomain. A mount target is the network endpoint clients mount, bound to a VPC and access group. Exposes the network placement and the access group that controls which clients may mount it. Use it to audit whether a file system is reachable from a classic (non-VPC) network.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Alibaba Cloud NAS file storage","desc":"Apsara File Storage NAS file systems and access controls across an Alibaba Cloud account. Exposes the file systems in every enabled region, their mount targets, and the access groups and rules that govern which clients may mount them. Use it to audit whether file systems are encrypted and whether their exports are open to overly broad client ranges.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.accessGroup":{"id":"alicloud.nas.accessGroup","name":"alicloud.nas.accessGroup","fields":{"accessGroupName":{"name":"accessGroupName","type":"\u0007","is_mandatory":true,"title":"Access group name, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"accessGroupType":{"name":"accessGroupType","type":"\u0007","is_mandatory":true,"title":"Access group network type, either Vpc or Classic","provider":"go.mondoo.com/mql/providers/alicloud"},"accessRules":{"name":"accessRules","type":"\u0019\u001balicloud.nas.accessRule","title":"Access rules that govern which clients may mount","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the access group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the access group","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemType":{"name":"fileSystemType","type":"\u0007","is_mandatory":true,"title":"File system type the access group applies to","provider":"go.mondoo.com/mql/providers/alicloud"},"mountTargetCount":{"name":"mountTargetCount","type":"\u0005","is_mandatory":true,"title":"Number of mount targets bound to the group","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the access group resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"ruleCount":{"name":"ruleCount","type":"\u0005","is_mandatory":true,"title":"Number of access rules in the group","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS access group","desc":"A single NAS access group, keyed by accessGroupName within its region. An access group is a named set of access rules that govern which client IP ranges may mount the file systems bound to it. Exposes the group metadata and its access rules. Use it to audit the client ranges permitted to mount.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.accessRule":{"id":"alicloud.nas.accessRule","name":"alicloud.nas.accessRule","fields":{"accessGroupName":{"name":"accessGroupName","type":"\u0007","is_mandatory":true,"title":"Name of the access group the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"accessRuleId":{"name":"accessRuleId","type":"\u0007","is_mandatory":true,"title":"Access rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6SourceCidrIp":{"name":"ipv6SourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Allowed IPv6 client CIDR, empty when no IPv6 rule is set","desc":"The IPv6 client range permitted to mount. ::/0 permits every IPv6 client.","provider":"go.mondoo.com/mql/providers/alicloud"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Rule priority, 1 (highest) to 100 (lowest)","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the access rule resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"rwAccess":{"name":"rwAccess","type":"\u0007","is_mandatory":true,"title":"Read/write access granted, either RDWR (read-write) or RDONLY (read-only)","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCidrIp":{"name":"sourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Allowed IPv4 client CIDR","desc":"The client address range permitted to mount. 0.0.0.0/0 permits every IPv4 client.","provider":"go.mondoo.com/mql/providers/alicloud"},"userAccess":{"name":"userAccess","type":"\u0007","is_mandatory":true,"title":"Root-squash policy","desc":"One of no_squash (root is not squashed), root_squash (root maps to an anonymous user), or all_squash (every user maps to anonymous). no_squash gives mounting clients full root access to the file system.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS access rule","desc":"A single access rule within a NAS access group, keyed by accessRuleId. A rule permits a client IP range to mount with a given read/write and user-squash policy. Exposes the allowed CIDR, access mode, and squash setting. Use it to find rules that open a file system to broad client ranges or disable root squashing.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.fileSystem":{"id":"alicloud.nas.fileSystem","name":"alicloud.nas.fileSystem","fields":{"capacity":{"name":"capacity","type":"\u0005","is_mandatory":true,"title":"Provisioned capacity in GiB","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method, either PayAsYouGo or Subscription","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the file system was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the file system","provider":"go.mondoo.com/mql/providers/alicloud"},"encryptType":{"name":"encryptType","type":"\u0005","is_mandatory":true,"title":"Server-side encryption type","desc":"One of 0 (no encryption), 1 (NAS-managed service key), or 2 (a customer master key from KMS).","provider":"go.mondoo.com/mql/providers/alicloud"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the file system is encrypted at rest","desc":"True when the encryption type is 1 or 2. When false, data is stored unencrypted.","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemId":{"name":"fileSystemId","type":"\u0007","is_mandatory":true,"title":"File system ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemType":{"name":"fileSystemType","type":"\u0007","is_mandatory":true,"title":"File system type, one of standard, extreme, cpfs, or cpfsse","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"Customer master key used for encryption","desc":"Null unless the encryption type is 2 (a specific KMS key). The NAS-managed service key (type 1) is not a queryable KMS key.","provider":"go.mondoo.com/mql/providers/alicloud"},"meteredSize":{"name":"meteredSize","type":"\u0005","is_mandatory":true,"title":"Used (metered) size in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"mountTargets":{"name":"mountTargets","type":"\u0019\u001balicloud.nas.mountTarget","title":"Mount targets that expose the file system to clients","provider":"go.mondoo.com/mql/providers/alicloud"},"protocolType":{"name":"protocolType","type":"\u0007","is_mandatory":true,"title":"Access protocol, one of NFS, SMB, or cpfs","provider":"go.mondoo.com/mql/providers/alicloud"},"redundancyType":{"name":"redundancyType","type":"\u0007","is_mandatory":true,"title":"Storage redundancy type, for example LRS","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the file system resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the file system","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the file system belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"File system status, for example Running, Pending, or Stopped","provider":"go.mondoo.com/mql/providers/alicloud"},"storageType":{"name":"storageType","type":"\u0007","is_mandatory":true,"title":"Storage class, for example Performance, Capacity, standard, or advance","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the file system","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the file system resides in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS file system","desc":"A single NAS file system, keyed by fileSystemId within its region. Exposes the storage and protocol type, the encryption state and key, capacity and used size, and the mount targets that expose it to clients. Use it to audit encryption at rest and the network exposure of the mount targets. For example alicloud.nas.fileSystem(fileSystemId: \"1a2b3c\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nas.mountTarget":{"id":"alicloud.nas.mountTarget","name":"alicloud.nas.mountTarget","fields":{"accessGroup":{"name":"accessGroup","type":"\u001balicloud.nas.accessGroup","title":"Access group that controls which clients may mount the target","provider":"go.mondoo.com/mql/providers/alicloud"},"accessGroupName":{"name":"accessGroupName","type":"\u0007","is_mandatory":true,"title":"Name of the access group that controls which clients may mount the target","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystem":{"name":"fileSystem","type":"\u001balicloud.nas.fileSystem","title":"File system the mount target belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"fileSystemId":{"name":"fileSystemId","type":"\u0007","is_mandatory":true,"title":"ID of the file system the mount target belongs to","desc":"Deprecated in favor of fileSystem.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.nas.mountTarget.fileSystem"},"mountTargetDomain":{"name":"mountTargetDomain","type":"\u0007","is_mandatory":true,"title":"Mount target domain (the mount address), used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"Either Vpc (isolated to a VPC) or Classic (the legacy shared network).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the mount target resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Mount target status, for example Active or Inactive","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the mount target is attached to, null for a classic-network mount target","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the mount target attaches to, null for a classic-network mount target","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NAS mount target","desc":"A single mount target of a NAS file system, keyed by mountTargetDomain. A mount target is the network endpoint clients mount, bound to a VPC and access group. Exposes the network placement and the access group that controls which clients may mount it. Use it to audit whether a file system is reachable from a classic (non-VPC) network.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb":{"id":"alicloud.nlb","name":"alicloud.nlb","fields":{"listener":{"name":"listener","type":"\u001balicloud.nlb.listener","title":"Network Load Balancer listener","desc":"A single listener on an NLB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy and certificates for TCPSSL listeners, and the server group it forwards to. Use it to audit whether a TCPSSL listener enforces a strong TLS policy.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.nlb.loadBalancer","title":"Network Load Balancer instance","desc":"A single NLB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC, vSwitches, and security groups it runs in, and its listeners. Unlike an ALB, an NLB can enforce security groups directly. For example alicloud.nlb.loadBalancer(loadBalancerId: \"nlb-xxx\", regionId: \"cn-hangzhou\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001balicloud.nlb.loadBalancer","title":"Network load balancers across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicies":{"name":"securityPolicies","type":"\u0019\u001balicloud.nlb.securityPolicy","title":"Custom TLS security policies across all enabled regions","desc":"A security policy fixes the TLS versions and cipher suites a TCPSSL listener accepts. Only custom policies are listed; a listener using one of the built-in policies names it by id and has no entry here.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicy":{"name":"securityPolicy","type":"\u001balicloud.nlb.securityPolicy","title":"Network Load Balancer TLS security policy","desc":"A custom TLS security policy, keyed by securityPolicyId within its region. Exposes the TLS versions and cipher suites the policy permits on a TCPSSL listener. Use it to find a listener that still accepts TLS 1.0 or 1.1.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverGroup":{"name":"serverGroup","type":"\u001balicloud.nlb.serverGroup","title":"Network Load Balancer server group","desc":"A single NLB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward traffic to. Exposes the backend protocol, scheduling algorithm, client-IP preservation, health-check configuration, and the VPC the group belongs to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverGroups":{"name":"serverGroups","type":"\u0019\u001balicloud.nlb.serverGroup","title":"NLB server groups across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Network Load Balancer","desc":"NLB (Layer-4) load balancers across an Alibaba Cloud account. Exposes the network load balancers in every enabled region, along with their listeners and server groups. Use it to audit which load balancers are internet-facing, whether security groups are applied, and whether TCPSSL listeners use a strong TLS policy.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.listener":{"id":"alicloud.nlb.listener","name":"alicloud.nlb.listener","fields":{"alpnEnabled":{"name":"alpnEnabled","type":"\u0004","is_mandatory":true,"title":"Whether ALPN is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alpnPolicy":{"name":"alpnPolicy","type":"\u0007","is_mandatory":true,"title":"ALPN policy applied when ALPN is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"caCertificateIds":{"name":"caCertificateIds","type":"\u0019\u0007","is_mandatory":true,"title":"CA certificate IDs used for mutual TLS on a TCPSSL listener","provider":"go.mondoo.com/mql/providers/alicloud"},"caEnabled":{"name":"caEnabled","type":"\u0004","is_mandatory":true,"title":"Whether mutual TLS (client certificate authentication) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"certificateIds":{"name":"certificateIds","type":"\u0019\u0007","is_mandatory":true,"title":"Server certificate IDs presented by a TCPSSL listener","provider":"go.mondoo.com/mql/providers/alicloud"},"cps":{"name":"cps","type":"\u0005","is_mandatory":true,"title":"Connections-per-second limit for the listener, 0 when unlimited","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"idleTimeout":{"name":"idleTimeout","type":"\u0005","is_mandatory":true,"title":"Idle connection timeout in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"listenerId":{"name":"listenerId","type":"\u0007","is_mandatory":true,"title":"Listener ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.nlb.loadBalancer","title":"Load balancer the listener belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the load balancer the listener belongs to","desc":"Deprecated in favor of loadBalancer.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.nlb.listener.loadBalancer"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the listener serves on","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Listener protocol, one of TCP, UDP, or TCPSSL","provider":"go.mondoo.com/mql/providers/alicloud"},"proxyProtocolEnabled":{"name":"proxyProtocolEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the Proxy Protocol is enabled to pass client information to backends","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the listener resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicy":{"name":"securityPolicy","type":"\u001balicloud.nlb.securityPolicy","title":"TLS security policy applied to the listener","desc":"Null for a non-TCPSSL listener and for a listener using one of the built-in policies, which are not enumerable; securityPolicyId names those.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyId":{"name":"securityPolicyId","type":"\u0007","is_mandatory":true,"title":"TLS security policy applied to the listener, meaningful for TCPSSL listeners","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroup":{"name":"serverGroup","type":"\u001balicloud.nlb.serverGroup","title":"Server group the listener forwards traffic to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Listener status, for example Running, Configuring, or Stopped","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the listener","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network Load Balancer listener","desc":"A single listener on an NLB load balancer, keyed by listenerId. Exposes the protocol and port it serves, the TLS security policy and certificates for TCPSSL listeners, and the server group it forwards to. Use it to audit whether a TCPSSL listener enforces a strong TLS policy.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.loadBalancer":{"id":"alicloud.nlb.loadBalancer","name":"alicloud.nlb.loadBalancer","fields":{"addressIpVersion":{"name":"addressIpVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the address, either Ipv4 or DualStack","provider":"go.mondoo.com/mql/providers/alicloud"},"addressType":{"name":"addressType","type":"\u0007","is_mandatory":true,"title":"Address type","desc":"Either Internet (internet-facing) or Intranet (internal only).","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageId":{"name":"bandwidthPackageId","type":"\u0007","is_mandatory":true,"title":"ID of the bandwidth package bound to the load balancer, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (billing) status, either Normal or Abnormal","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the load balancer was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossZoneEnabled":{"name":"crossZoneEnabled","type":"\u0004","is_mandatory":true,"title":"Whether cross-zone load balancing is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtectionEnabled":{"name":"deletionProtectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"dnsName":{"name":"dnsName","type":"\u0007","is_mandatory":true,"title":"DNS name assigned to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"internetFacing":{"name":"internetFacing","type":"\u0004","title":"Whether the load balancer serves traffic from the public internet","desc":"True when the address type is Internet. An internet-facing load balancer is reachable from outside the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6AddressType":{"name":"ipv6AddressType","type":"\u0007","is_mandatory":true,"title":"IPv6 address type, either Internet or Intranet","provider":"go.mondoo.com/mql/providers/alicloud"},"listeners":{"name":"listeners","type":"\u0019\u001balicloud.nlb.listener","title":"Listeners configured on the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"Load balancer ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionStatus":{"name":"modificationProtectionStatus","type":"\u0007","is_mandatory":true,"title":"Modification-protection status, either NonProtection or ConsoleProtection","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Load balancer name","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the load balancer resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the load balancer","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the load balancer belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"Security groups applied to the load balancer","desc":"NLB enforces these security groups on traffic to the load balancer. An empty result means no security-group filtering is applied at the load balancer.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Load balancer status","desc":"For example Active, Inactive, Provisioning, or Configuring.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the load balancer","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Load balancer type, always Network for NLB","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the load balancer runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches the load balancer attaches to across its zones","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network Load Balancer instance","desc":"A single NLB load balancer, keyed by loadBalancerId within its region. Exposes the address type and the derived internet-facing state, the VPC, vSwitches, and security groups it runs in, and its listeners. Unlike an ALB, an NLB can enforce security groups directly. For example alicloud.nlb.loadBalancer(loadBalancerId: \"nlb-xxx\", regionId: \"cn-hangzhou\").","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.securityPolicy":{"id":"alicloud.nlb.securityPolicy","name":"alicloud.nlb.securityPolicy","fields":{"allowsLegacyTls":{"name":"allowsLegacyTls","type":"\u0004","is_mandatory":true,"title":"Whether the policy still accepts TLS 1.0 or TLS 1.1","desc":"Both versions are deprecated and carry known weaknesses, so a listener bound to such a policy accepts connections that a current client would refuse to make.","provider":"go.mondoo.com/mql/providers/alicloud"},"ciphers":{"name":"ciphers","type":"\u0019\u0007","is_mandatory":true,"title":"Cipher suites the policy permits","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the policy resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the policy belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyId":{"name":"securityPolicyId","type":"\u0007","is_mandatory":true,"title":"Security policy ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPolicyName":{"name":"securityPolicyName","type":"\u0007","is_mandatory":true,"title":"Name of the security policy","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the policy, for example Available or Configuring","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsVersions":{"name":"tlsVersions","type":"\u0019\u0007","is_mandatory":true,"title":"TLS versions the policy accepts, for example TLSv1.2 and TLSv1.3","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network Load Balancer TLS security policy","desc":"A custom TLS security policy, keyed by securityPolicyId within its region. Exposes the TLS versions and cipher suites the policy permits on a TCPSSL listener. Use it to find a listener that still accepts TLS 1.0 or 1.1.","min_provider_version":"13.5.1","defaults":"securityPolicyName tlsVersions status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.serverGroup":{"id":"alicloud.nlb.serverGroup","name":"alicloud.nlb.serverGroup","fields":{"addressIpVersion":{"name":"addressIpVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the backends, either Ipv4 or DualStack","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionDrainEnabled":{"name":"connectionDrainEnabled","type":"\u0004","is_mandatory":true,"title":"Whether connection draining is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckConnectPort":{"name":"healthCheckConnectPort","type":"\u0005","is_mandatory":true,"title":"Health-check connection port","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckEnabled":{"name":"healthCheckEnabled","type":"\u0004","is_mandatory":true,"title":"Whether health checks are enabled for the group","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckType":{"name":"healthCheckType","type":"\u0007","is_mandatory":true,"title":"Health-check protocol, one of TCP, HTTP, or UDP","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Server group name","provider":"go.mondoo.com/mql/providers/alicloud"},"preserveClientIpEnabled":{"name":"preserveClientIpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether client source IP preservation is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Backend protocol, one of TCP, UDP, or TCPSSL","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the server group resides in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the server group","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduler":{"name":"scheduler","type":"\u0007","is_mandatory":true,"title":"Scheduling algorithm, for example Wrr, rr, sch, tch, or qch","provider":"go.mondoo.com/mql/providers/alicloud"},"server":{"name":"server","type":"\u001balicloud.nlb.serverGroup.server","title":"NLB backend server","desc":"One server an NLB server group forwards traffic to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"serverCount":{"name":"serverCount","type":"\u0005","is_mandatory":true,"title":"Number of backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"serverGroupId":{"name":"serverGroupId","type":"\u0007","is_mandatory":true,"title":"Server group ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"servers":{"name":"servers","type":"\u0019\u001balicloud.nlb.serverGroup.server","title":"Servers in the group","desc":"What the load balancer forwards to. An internet-facing NLB makes every one of these reachable from the public internet on the listener's port.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Server group status","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the server group","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Server group type, either Instance or Ip","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the server group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network Load Balancer server group","desc":"A single NLB server group, keyed by serverGroupId within its region. A server group is a set of backends that listeners forward traffic to. Exposes the backend protocol, scheduling algorithm, client-IP preservation, health-check configuration, and the VPC the group belongs to.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.nlb.serverGroup.server":{"id":"alicloud.nlb.serverGroup.server","name":"alicloud.nlb.serverGroup.server","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Backend server description","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the backend","desc":"Null unless serverType is Ecs, or when the instance can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"ID of the backend server","desc":"An ECS instance ID, an elastic network interface ID, or an IP address, depending on serverType.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverIp":{"name":"serverIp","type":"\u0007","is_mandatory":true,"title":"IP address the load balancer forwards to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverType":{"name":"serverType","type":"\u0007","is_mandatory":true,"title":"Kind of backend","desc":"One of Ecs, Eni, or Ip.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Backend server status","provider":"go.mondoo.com/mql/providers/alicloud"},"weight":{"name":"weight","type":"\u0005","is_mandatory":true,"title":"Share of traffic the server receives","desc":"A weight of 0 takes the server out of rotation without detaching it.","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone the backend server sits in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"NLB backend server","desc":"One server an NLB server group forwards traffic to. The serverType decides what serverId names, and the ECS case is the one that reaches an instance whose own security groups may say nothing about the load balancer's address.","min_provider_version":"13.4.1","defaults":"serverType serverId serverIp port weight","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss":{"id":"alicloud.oss","name":"alicloud.oss","fields":{"bucket":{"name":"bucket","type":"\u001balicloud.oss.bucket","title":"Object Storage Service bucket","desc":"A single OSS bucket, keyed by name (bucket names are globally unique). The summary fields (region, storageClass, creationDate, endpoints, resourceGroupId) come from the account bucket listing. The remaining accessors call the per-bucket configuration APIs to expose the access control policy, default server-side encryption, versioning state, access logging target, bucket policy document, tags, and the block-public-access posture used to audit exposure.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"buckets":{"name":"buckets","type":"\u0019\u001balicloud.oss.bucket","title":"Buckets owned by the account across all regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Object Storage Service","desc":"Entry point for the Object Storage Service (OSS) in an Alibaba Cloud account. Exposes every bucket the credential can list across all regions through buckets, from which per-bucket access control, encryption, versioning, logging, tagging, and public-access posture are reachable.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss.bucket":{"id":"alicloud.oss.bucket","name":"alicloud.oss.bucket","fields":{"acl":{"name":"acl","type":"\u0007","title":"Access control list grant","desc":"The canned ACL applied to the bucket. One of private, public-read, or public-read-write. public-read and public-read-write expose bucket contents to anonymous callers.","provider":"go.mondoo.com/mql/providers/alicloud"},"allowEmptyReferer":{"name":"allowEmptyReferer","type":"\u0004","title":"Whether requests carrying no Referer header are allowed","desc":"True by default. Combined with an otherwise restrictive referer list, this being true leaves the restriction trivially bypassed, since the client chooses whether to send the header.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"blockPublicAccess":{"name":"blockPublicAccess","type":"\u0004","title":"Whether block public access is enabled for the bucket","provider":"go.mondoo.com/mql/providers/alicloud"},"bucketInfo":{"name":"bucketInfo","type":"\n","title":"Full bucket information","desc":"The complete bucket detail record, including access monitoring, data redundancy type, cross-region replication, transfer acceleration, the server-side encryption rule, the log bucket policy, owner, comment, and the block-public-access flag.","provider":"go.mondoo.com/mql/providers/alicloud"},"corsRule":{"name":"corsRule","type":"\u001balicloud.oss.bucket.corsRule","title":"OSS bucket cross-origin resource sharing rule","desc":"One CORS rule, deciding which origins a browser may read the bucket from and with which methods and headers. An allowed origin of `*` lets a page on any site read whatever the requesting browser is allowed to read.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"corsRules":{"name":"corsRules","type":"\u0019\u001balicloud.oss.bucket.corsRule","title":"Cross-origin resource sharing rules","desc":"Which other origins a browser may read the bucket from. Empty when CORS is not configured, which refuses every cross-origin browser request.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"creationDate":{"name":"creationDate","type":"\t","is_mandatory":true,"title":"Time the bucket was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossRegionReplication":{"name":"crossRegionReplication","type":"\u0007","title":"Cross-region replication state","desc":"Whether cross-region replication is enabled for the bucket. One of Enabled or Disabled. Empty when the setting is not returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"dataRedundancyType":{"name":"dataRedundancyType","type":"\u0007","title":"Data redundancy type","desc":"The redundancy model for stored data. One of LRS (locally redundant) or ZRS (zone redundant). Empty when the setting is not returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"encryption":{"name":"encryption","type":"\n","title":"Default server-side encryption rule","desc":"The default encryption applied to new objects, with the SSEAlgorithm (KMS, AES256, or SM4), the KMSMasterKeyID when a specific key is used, and the KMSDataEncryption algorithm. Null when no default encryption rule is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"extranetEndpoint":{"name":"extranetEndpoint","type":"\u0007","is_mandatory":true,"title":"Public endpoint for access over the Internet","provider":"go.mondoo.com/mql/providers/alicloud"},"intranetEndpoint":{"name":"intranetEndpoint","type":"\u0007","is_mandatory":true,"title":"Internal endpoint for access from ECS instances in the same region","provider":"go.mondoo.com/mql/providers/alicloud"},"isPublic":{"name":"isPublic","type":"\u0004","title":"Whether the bucket is readable from the internet without credentials","desc":"True when the bucket reaches anonymous callers, either through a public-read or public-read-write canned acl or through a bucket policy that allows a `*` principal. False whenever blockPublicAccess is on, which overrides both. Use it to find buckets exposed to the internet regardless of which of the two mechanisms opened them.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"kmsKey":{"name":"kmsKey","type":"\u001balicloud.kms.key","title":"KMS key used for default server-side encryption","desc":"The customer master key named by the bucket's default encryption rule. Null when the bucket has no default encryption or uses the AES256/SM4 built-in keys rather than a specific KMS key.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"location":{"name":"location","type":"\u0007","is_mandatory":true,"title":"Data center that stores the bucket, for example oss-cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"logging":{"name":"logging","type":"\n","title":"Access logging configuration","desc":"The access-logging target when logging is enabled, with TargetBucket, TargetPrefix, and LoggingRole. Null when access logging is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Bucket name, globally unique across Alibaba Cloud","provider":"go.mondoo.com/mql/providers/alicloud"},"objectLockRetentionDays":{"name":"objectLockRetentionDays","type":"\u0005","title":"Days objects are retained under the retention policy","desc":"Zero when no retention policy is configured.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"objectLockState":{"name":"objectLockState","type":"\u0007","title":"State of the retention policy applied to the bucket","desc":"InProgress for a policy that can still be withdrawn, Locked for one that cannot. Empty when no retention policy is configured, meaning objects can be deleted or overwritten at any time. A locked policy is what makes stored objects survive an attacker holding valid credentials.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","title":"Bucket policy document","desc":"The raw JSON bucket policy that grants cross-account or anonymous permissions. Empty when no bucket policy is attached.","provider":"go.mondoo.com/mql/providers/alicloud"},"policyAllowsPublicAccess":{"name":"policyAllowsPublicAccess","type":"\u0004","title":"Whether the bucket policy allows public access","desc":"Object Storage Service's own verdict on the attached policy, independent of the ACL. False when no policy is attached.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"publicAccessBlock":{"name":"publicAccessBlock","type":"\n","title":"Block public access configuration","desc":"The block-public-access setting, with BlockPublicAccess indicating whether public access is blocked. Null when never configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"refererAllowList":{"name":"refererAllowList","type":"\u0019\u0007","title":"Referer values allowed to reach the bucket","desc":"Empty when no referer restriction is configured.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"refererDenyList":{"name":"refererDenyList","type":"\u0019\u0007","title":"Referer values refused by the bucket","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region ID the bucket resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"replicationRule":{"name":"replicationRule","type":"\u001balicloud.oss.bucket.replicationRule","title":"OSS bucket replication rule","desc":"One rule copying objects to another bucket, keyed by its rule ID. Reports where the copies land and what is copied, so a rule sending object data to another region or another account is visible as one.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"replicationRules":{"name":"replicationRules","type":"\u0019\u001balicloud.oss.bucket.replicationRule","title":"Rules that copy objects to another bucket","desc":"Replication moves object data out of this bucket, and the destination can be in another region or owned by another account.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the bucket","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the bucket belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"sseAlgorithm":{"name":"sseAlgorithm","type":"\u0007","title":"Default server-side encryption algorithm","desc":"The SSEAlgorithm from the default encryption rule (KMS, AES256, or SM4), flattened for auditing. Empty when no default encryption is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"storageClass":{"name":"storageClass","type":"\u0007","is_mandatory":true,"title":"Storage class","desc":"One of Standard, IA, Archive, ColdArchive, or DeepColdArchive.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","title":"Bucket tags as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsEnforced":{"name":"tlsEnforced","type":"\u0004","title":"Whether the bucket restricts which TLS versions clients may use","desc":"False means every TLS version the service accepts is allowed, including versions no longer considered safe.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsVersions":{"name":"tlsVersions","type":"\u0019\u0007","title":"TLS versions clients may use","desc":"For example TLSv1.2 and TLSv1.3. Empty when tlsEnforced is false, which does not mean TLS is off, only that the bucket sets no floor of its own.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"transferAcceleration":{"name":"transferAcceleration","type":"\u0007","title":"Transfer acceleration state","desc":"Whether transfer acceleration is enabled for the bucket. One of Enabled or Disabled. Empty when the setting is not returned.","provider":"go.mondoo.com/mql/providers/alicloud"},"versioning":{"name":"versioning","type":"\u0007","title":"Versioning state","desc":"One of Enabled or Suspended. Empty when versioning was never configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"websiteEnabled":{"name":"websiteEnabled","type":"\u0004","title":"Whether the bucket serves a static website","desc":"Static hosting is an intentional public surface, so a bucket with it enabled is meant to be read anonymously.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"websiteErrorDocument":{"name":"websiteErrorDocument","type":"\u0007","title":"Page served for errors on the static website","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"websiteIndexDocument":{"name":"websiteIndexDocument","type":"\u0007","title":"Default page served for the static website","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Object Storage Service bucket","desc":"A single OSS bucket, keyed by name (bucket names are globally unique). The summary fields (region, storageClass, creationDate, endpoints, resourceGroupId) come from the account bucket listing. The remaining accessors call the per-bucket configuration APIs to expose the access control policy, default server-side encryption, versioning state, access logging target, bucket policy document, tags, and the block-public-access posture used to audit exposure.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss.bucket.corsRule":{"id":"alicloud.oss.bucket.corsRule","name":"alicloud.oss.bucket.corsRule","fields":{"allowedHeaders":{"name":"allowedHeaders","type":"\u0019\u0007","is_mandatory":true,"title":"Request headers allowed in a cross-origin request","desc":"A value of `*` allows every header.","provider":"go.mondoo.com/mql/providers/alicloud"},"allowedMethods":{"name":"allowedMethods","type":"\u0019\u0007","is_mandatory":true,"title":"Methods allowed in a cross-origin request","provider":"go.mondoo.com/mql/providers/alicloud"},"allowedOrigins":{"name":"allowedOrigins","type":"\u0019\u0007","is_mandatory":true,"title":"Origins a browser may issue cross-origin requests from","desc":"A value of `*` allows every site.","provider":"go.mondoo.com/mql/providers/alicloud"},"exposeHeaders":{"name":"exposeHeaders","type":"\u0019\u0007","is_mandatory":true,"title":"Response headers exposed to the requesting page","provider":"go.mondoo.com/mql/providers/alicloud"},"maxAgeSeconds":{"name":"maxAgeSeconds","type":"\u0005","is_mandatory":true,"title":"Seconds a browser may cache the preflight response","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"OSS bucket cross-origin resource sharing rule","desc":"One CORS rule, deciding which origins a browser may read the bucket from and with which methods and headers. An allowed origin of `*` lets a page on any site read whatever the requesting browser is allowed to read.","min_provider_version":"13.4.1","defaults":"allowedOrigins allowedMethods maxAgeSeconds","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.oss.bucket.replicationRule":{"id":"alicloud.oss.bucket.replicationRule","name":"alicloud.oss.bucket.replicationRule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Operations copied to the destination","desc":"ALL covers writes, deletes and aborted uploads. PUT covers writes only, so an object deleted here survives at the destination.","provider":"go.mondoo.com/mql/providers/alicloud"},"historicalObjectReplication":{"name":"historicalObjectReplication","type":"\u0007","is_mandatory":true,"title":"Whether objects that predate the rule are copied","desc":"Either enabled or disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Replication rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"prefixes":{"name":"prefixes","type":"\u0019\u0007","is_mandatory":true,"title":"Object name prefixes the rule covers","desc":"Empty when the rule covers the whole bucket.","provider":"go.mondoo.com/mql/providers/alicloud"},"replicaKmsKeyId":{"name":"replicaKmsKeyId","type":"\u0007","is_mandatory":true,"title":"KMS key ID used to encrypt the replicated objects","desc":"Empty when the destination objects are not encrypted with a customer key.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Replication status","desc":"One of starting, doing, or closing.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncRole":{"name":"syncRole","type":"\u0007","is_mandatory":true,"title":"RAM role Object Storage Service assumes to perform the replication","provider":"go.mondoo.com/mql/providers/alicloud"},"targetBucket":{"name":"targetBucket","type":"\u0007","is_mandatory":true,"title":"Bucket objects are copied to","provider":"go.mondoo.com/mql/providers/alicloud"},"targetLocation":{"name":"targetLocation","type":"\u0007","is_mandatory":true,"title":"Region the destination bucket sits in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"OSS bucket replication rule","desc":"One rule copying objects to another bucket, keyed by its rule ID. Reports where the copies land and what is copied, so a rule sending object data to another region or another account is visible as one.","min_provider_version":"13.4.1","defaults":"id targetBucket targetLocation status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb":{"id":"alicloud.polardb","name":"alicloud.polardb","fields":{"application":{"name":"application","type":"\u001balicloud.polardb.application","title":"PolarDB application","desc":"A single application provisioned on a PolarDB cluster, such as a PolarFS store or a vector store an AI workload reads. An application carries its own network endpoints and its own TLS settings, separate from the cluster ones, so a cluster with TLS on can still front an application that accepts unencrypted client connections. Exposes those endpoints, whether TLS is enabled and rotates automatically, and the server certificate common name, source, fingerprint, and expiry.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"cluster":{"name":"cluster","type":"\u001balicloud.polardb.cluster","title":"PolarDB cluster","desc":"A single ApsaraDB for PolarDB cluster, keyed by dbClusterId. Exposes the cluster lifecycle status, database engine and version, node class and count, storage usage, network placement, billing, and the security-posture controls that govern it: SSL/TLS encryption in transit, Transparent Data Encryption (TDE) at rest, the IP access whitelist, deletion protection, and the connection endpoints. Select a cluster with alicloud.polardb.cluster(dbClusterId: \"pc-xxxxxxxx\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"clusters":{"name":"clusters","type":"\u0019\u001balicloud.polardb.cluster","title":"PolarDB clusters across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeBase":{"name":"knowledgeBase","type":"\u001balicloud.polardb.knowledgeBase","title":"PolarDB knowledge base","desc":"A single knowledge base within a knowledge space, keyed by knowledgeBaseId within its region. A knowledge base groups the documents a retrieval workload answers from. Exposes the sharing scope that decides who reads it, the document and byte counts, how many AI applications are bound to it, and the synchronization links that pull content into it from an external messaging platform on a timer.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"knowledgeBases":{"name":"knowledgeBases","type":"\u0019\u001balicloud.polardb.knowledgeBase","title":"PolarDB knowledge bases across all enabled regions","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeSpace":{"name":"knowledgeSpace","type":"\u001balicloud.polardb.knowledgeSpace","title":"PolarDB knowledge space","desc":"A single knowledge space, the vector store a PolarDB retrieval-augmented generation workload answers from, keyed by knowledgeSpaceId within its region. Exposes the access control mode that decides how much of the corpus a caller retrieves, the OSS bucket the source documents are drawn from, the PolarDB cluster and database that hold the vectors, and the embedding, generation, and reranking models in use. The knowledgeSpaceId field selects the space, for example alicloud.polardb.knowledgeSpace(knowledgeSpaceId: \"pks-xxxxxxxx\", regionId: \"cn-beijing\").","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"knowledgeSpaces":{"name":"knowledgeSpaces","type":"\u0019\u001balicloud.polardb.knowledgeSpace","title":"PolarDB knowledge spaces across all enabled regions","desc":"The spaces reached from the knowledge bases listed in each region, because Alibaba Cloud offers no listing of knowledge spaces on their own. A space that holds no knowledge base is absent here and has to be named directly, for example alicloud.polardb.knowledgeSpace(knowledgeSpaceId: \"pks-xxxxxxxx\", regionId: \"cn-beijing\").","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"PolarDB","desc":"Entry point for querying ApsaraDB for PolarDB, the cloud-native relational database service. Exposes the PolarDB clusters provisioned across every enabled region through clusters, and the retrieval-augmented generation corpora built on them through knowledgeBases and knowledgeSpaces.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb.application":{"id":"alicloud.polardb.application","name":"alicloud.polardb.application","fields":{"applicationId":{"name":"applicationId","type":"\u0007","is_mandatory":true,"title":"Application ID, for example pa-xxxxxxxx","provider":"go.mondoo.com/mql/providers/alicloud"},"applicationType":{"name":"applicationType","type":"\u0007","is_mandatory":true,"title":"Kind of application","desc":"For example PolarFS or VectorStore. Reported as returned by the API, so a kind added after this provider shipped still appears.","provider":"go.mondoo.com/mql/providers/alicloud"},"certCommonName":{"name":"certCommonName","type":"\u0007","title":"Common Name of the server certificate","desc":"Null when TLS is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"certExpireTime":{"name":"certExpireTime","type":"\t","title":"When the server certificate expires","desc":"Null when TLS is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"certFingerprintSha256":{"name":"certFingerprintSha256","type":"\u0007","title":"SHA-256 fingerprint of the server certificate, in lowercase hex","desc":"The DER fingerprint, matching openssl -fingerprint -sha256, for clients that pin the certificate. Null when TLS is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"certModifiedTime":{"name":"certModifiedTime","type":"\t","title":"When the server certificate was last installed","desc":"Null when TLS is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"certSource":{"name":"certSource","type":"\u0007","title":"Where the server certificate comes from","desc":"For example aliyun for an Alibaba Cloud issued certificate, or custom for one uploaded by the account. Null when TLS is off.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"When the application was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dbCluster":{"name":"dbCluster","type":"\u001balicloud.polardb.cluster","title":"Cluster the application is provisioned on","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Application description, empty when none is set","provider":"go.mondoo.com/mql/providers/alicloud"},"dnatMapping":{"name":"dnatMapping","type":"\u001balicloud.polardb.application.dnatMapping","title":"DNAT entry of a PolarDB application","desc":"A single destination NAT entry that publishes one port of a PolarDB application through a VPC NAT gateway, keyed by entryId. Exposes the address the entry answers on, the front and backend ports it maps, the application port it fronts, and the entry state. Use it to find application ports that are reachable through the gateway even though the application's own endpoints are all private.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"dnatMappings":{"name":"dnatMappings","type":"\u0019\u001balicloud.polardb.application.dnatMapping","title":"DNAT entries that publish the application through the NAT gateway","desc":"Empty when the application is not published through DNAT. Each entry maps a port on the NAT gateway to a port on the application, which is a reachable path that endpoints does not report: an application whose endpoints are all Private still answers on every address listed here.","provider":"go.mondoo.com/mql/providers/alicloud"},"endpoints":{"name":"endpoints","type":"\u0019\n","is_mandatory":true,"title":"Network addresses the application is reachable on","desc":"One entry per address with ip, netType (the network type, Public or Private), and port. A Public entry means the application answers from outside the VPC, so the TLS and whitelist settings are what stand between it and the internet.","provider":"go.mondoo.com/mql/providers/alicloud"},"engineVersion":{"name":"engineVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version the application runs","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"When a prepaid application expires, null for postpaid","provider":"go.mondoo.com/mql/providers/alicloud"},"expired":{"name":"expired","type":"\u0007","is_mandatory":true,"title":"Whether the application has passed its expiry, empty for postpaid","provider":"go.mondoo.com/mql/providers/alicloud"},"natMappingSnatIpAddress":{"name":"natMappingSnatIpAddress","type":"\u0007","title":"SNAT address bound to the vSwitch the application resides on","desc":"The address the control plane discovered for NAT mapping, null when the application has no NAT mapping. It is a customer-managed SNAT entry and is unrelated to an Internet NAT gateway SNAT entry.","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method","desc":"One of Prepaid (subscription) or Postpaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"polarFsInstanceId":{"name":"polarFsInstanceId","type":"\u0007","is_mandatory":true,"title":"PolarFS instance backing the application, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the application resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"sslAutoRotate":{"name":"sslAutoRotate","type":"\u0004","title":"Whether the server certificate rotates automatically before it expires","desc":"Null when TLS is off. With it false, the certificate has to be rotated by hand and connections break when certExpireTime passes.","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether the application requires TLS on client connections","desc":"False when TLS is off, and when the setting could not be read, so a \"TLS is on\" check fails rather than passing on an application nobody could read. With it off, client traffic to the endpoints travels in the clear.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle state of the application, for example Running or Creating","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the application","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcNatGateway":{"name":"vpcNatGateway","type":"\u001balicloud.vpc.natGateway","title":"NAT gateway that publishes the application into the VPC","desc":"Null when no NAT mapping is configured. When set, the application is reached through the gateway's DNAT entries as well as through endpoints, so an application whose endpoints are all Private can still answer callers that reach the gateway.","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the application resides in, for example cn-hangzhou-i","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"PolarDB application","desc":"A single application provisioned on a PolarDB cluster, such as a PolarFS store or a vector store an AI workload reads. An application carries its own network endpoints and its own TLS settings, separate from the cluster ones, so a cluster with TLS on can still front an application that accepts unencrypted client connections. Exposes those endpoints, whether TLS is enabled and rotates automatically, and the server certificate common name, source, fingerprint, and expiry.","min_provider_version":"13.5.1","defaults":"applicationId applicationType status sslEnabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb.application.dnatMapping":{"id":"alicloud.polardb.application.dnatMapping","name":"alicloud.polardb.application.dnatMapping","fields":{"accessAddress":{"name":"accessAddress","type":"\u0007","is_mandatory":true,"title":"Address the entry answers on","desc":"In NatIp:FrontPort form, for example 10.64.0.10:10001.","provider":"go.mondoo.com/mql/providers/alicloud"},"backendPort":{"name":"backendPort","type":"\u0005","is_mandatory":true,"title":"Port on the application that the entry forwards traffic to","provider":"go.mondoo.com/mql/providers/alicloud"},"entryId":{"name":"entryId","type":"\u0007","is_mandatory":true,"title":"DNAT entry ID, for example fwd-xxxxxxxx","provider":"go.mondoo.com/mql/providers/alicloud"},"frontPort":{"name":"frontPort","type":"\u0005","is_mandatory":true,"title":"Port on the NAT gateway that the entry accepts traffic on","provider":"go.mondoo.com/mql/providers/alicloud"},"portName":{"name":"portName","type":"\u0007","is_mandatory":true,"title":"Application port the entry fronts","desc":"For example webui, hermesagent, dashboard, or ssh. Reported as returned by the API, so a port name added after this provider shipped still appears.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Entry state, for example Available","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"DNAT entry of a PolarDB application","desc":"A single destination NAT entry that publishes one port of a PolarDB application through a VPC NAT gateway, keyed by entryId. Exposes the address the entry answers on, the front and backend ports it maps, the application port it fronts, and the entry state. Use it to find application ports that are reachable through the gateway even though the application's own endpoints are all private.","min_provider_version":"13.5.1","defaults":"portName accessAddress status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb.cluster":{"id":"alicloud.polardb.cluster","name":"alicloud.polardb.cluster","fields":{"accessWhitelist":{"name":"accessWhitelist","type":"\u0019\u0007","title":"IP access whitelist entries","desc":"The flattened set of CIDR entries permitted to connect to the cluster, gathered across every whitelist group. An entry of 0.0.0.0/0 means the cluster accepts connections from any source.","provider":"go.mondoo.com/mql/providers/alicloud"},"aiType":{"name":"aiType","type":"\u0007","is_mandatory":true,"title":"AI feature type of the cluster","desc":"One of SearchNode, DLNode, or an empty string when no AI node is attached.","provider":"go.mondoo.com/mql/providers/alicloud"},"applications":{"name":"applications","type":"\u0019\u001balicloud.polardb.application","title":"Applications provisioned on the cluster","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"auditLogCollectorStatus":{"name":"auditLogCollectorStatus","type":"\u0007","title":"Raw state of the SQL audit collector","desc":"One of Enable, Enabling, Disable, or Disabling. Only Enable means statements are being recorded now.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"auditLogEnabled":{"name":"auditLogEnabled","type":"\u0004","title":"Whether SQL audit collection is running on the cluster","desc":"False when the collector is off, and when the setting could not be read, so an \"auditing is on\" check fails rather than passing on a cluster nobody could read. With it off there is no record of the statements run against the cluster.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Product edition","desc":"One of Normal (Cluster Edition), Basic (Single Node Edition), ArchiveNormal (X-Engine), or SENormal (Standard Edition).","provider":"go.mondoo.com/mql/providers/alicloud"},"cpuCores":{"name":"cpuCores","type":"\u0007","is_mandatory":true,"title":"Number of CPU cores per node","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Creation time","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterDescription":{"name":"dbClusterDescription","type":"\u0007","is_mandatory":true,"title":"User-defined cluster description","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterId":{"name":"dbClusterId","type":"\u0007","is_mandatory":true,"title":"Cluster ID, for example pc-bp1234567890abc","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterNetworkType":{"name":"dbClusterNetworkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"One of VPC or Classic.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbClusterStatus":{"name":"dbClusterStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"For example Creating, Running, Deleting, Rebooting, DBNodeCreating, DBNodeDeleting, ClassChanging, NetAddressCreating, NetAddressDeleting, or NetAddressModifying.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbNodeClass":{"name":"dbNodeClass","type":"\u0007","is_mandatory":true,"title":"Node specification class, for example polar.mysql.x4.medium","provider":"go.mondoo.com/mql/providers/alicloud"},"dbNodeNumber":{"name":"dbNodeNumber","type":"\u0005","is_mandatory":true,"title":"Number of nodes in the cluster","provider":"go.mondoo.com/mql/providers/alicloud"},"dbNodes":{"name":"dbNodes","type":"\u0019\n","is_mandatory":true,"title":"Database nodes in the cluster","desc":"One entry per node with dbNodeId, dbNodeClass, dbNodeRole (Writer or Reader), zoneId, regionId, imciSwitch (columnar index state), hotReplicaMode, and serverless.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbType":{"name":"dbType","type":"\u0007","is_mandatory":true,"title":"Database engine family","desc":"One of MySQL, PostgreSQL, or Oracle.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbVersion":{"name":"dbVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version, for example 8.0, 5.7, 5.6, 11, or 14","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionLock":{"name":"deletionLock","type":"\u0005","is_mandatory":true,"title":"Deletion protection flag","desc":"1 when release/deletion protection is enabled, 0 when it is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"endpoints":{"name":"endpoints","type":"\u0019\n","title":"Connection endpoints of the cluster","desc":"One entry per network address with endpointType (Cluster, Primary, or Custom), dbEndpointId, addressType (the network type, Public or Private), connectionString, port, readWriteMode, and nodes.","provider":"go.mondoo.com/mql/providers/alicloud"},"engine":{"name":"engine","type":"\u0007","is_mandatory":true,"title":"Storage engine of the cluster","desc":"One of POLARDB (compute-storage separated) or MySQL.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Expiration time (null for pay-as-you-go clusters)","provider":"go.mondoo.com/mql/providers/alicloud"},"expired":{"name":"expired","type":"\u0007","is_mandatory":true,"title":"Whether the subscription cluster has expired, as a string","desc":"One of true or false. Empty for pay-as-you-go clusters.","provider":"go.mondoo.com/mql/providers/alicloud"},"hotStandbyCluster":{"name":"hotStandbyCluster","type":"\u0007","is_mandatory":true,"title":"Whether the cluster is a hot-standby (multi-zone) cluster","desc":"One of ON or OFF.","provider":"go.mondoo.com/mql/providers/alicloud"},"lockMode":{"name":"lockMode","type":"\u0007","is_mandatory":true,"title":"Lock state of the cluster","desc":"One of Unlock, ManualLock, LockByExpiration, or LockByDiskQuota.","provider":"go.mondoo.com/mql/providers/alicloud"},"memorySize":{"name":"memorySize","type":"\u0007","is_mandatory":true,"title":"Memory size per node, in MB","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method","desc":"One of Prepaid (subscription) or Postpaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the cluster resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the cluster","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the cluster belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"serverlessType":{"name":"serverlessType","type":"\u0007","is_mandatory":true,"title":"Serverless cluster type, for example AgileServerless or SteadyServerless (empty for non-serverless clusters)","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether SSL/TLS encryption in transit is enabled on any endpoint","desc":"True when at least one endpoint reports SSLEnabled as Enabled. False when SSL is disabled on all endpoints.","provider":"go.mondoo.com/mql/providers/alicloud"},"storageMax":{"name":"storageMax","type":"\u0005","title":"Maximum storage capacity, in bytes","desc":"For PSL5/PSL4 (compute-storage separated) clusters this is the auto-scaling ceiling. Resolved from the cluster attribute detail.","provider":"go.mondoo.com/mql/providers/alicloud"},"storagePayType":{"name":"storagePayType","type":"\u0007","is_mandatory":true,"title":"Storage billing method","desc":"One of Prepaid (subscription) or Postpaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"storageSpace":{"name":"storageSpace","type":"\u0005","is_mandatory":true,"title":"Provisioned storage space, in GB (0 when storage auto-scales)","provider":"go.mondoo.com/mql/providers/alicloud"},"storageType":{"name":"storageType","type":"\u0007","is_mandatory":true,"title":"Storage type","desc":"For example HighPerformance, PSL5, PSL4, or ESSDAUTOPL.","provider":"go.mondoo.com/mql/providers/alicloud"},"storageUsed":{"name":"storageUsed","type":"\u0005","is_mandatory":true,"title":"Used storage, in bytes","provider":"go.mondoo.com/mql/providers/alicloud"},"strictConsistency":{"name":"strictConsistency","type":"\u0007","is_mandatory":true,"title":"Whether multi-node strict consistency is enabled","desc":"One of ON or OFF.","provider":"go.mondoo.com/mql/providers/alicloud"},"subCategory":{"name":"subCategory","type":"\u0007","is_mandatory":true,"title":"Product sub-edition, for example Exclusive or General","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the cluster, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether Transparent Data Encryption (TDE) at rest is enabled","desc":"True when the cluster TDE status is Enabled. False when TDE is disabled.","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the cluster is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"whitelistAllowsAllAddresses":{"name":"whitelistAllowsAllAddresses","type":"\u0004","title":"Whether the IP whitelist admits every address","desc":"True when an entry in accessWhitelist admits any source address: the 0.0.0.0/0 block, the bare 0.0.0.0 the console writes for it, any other block with a /0 prefix length, the % wildcard, an address range spanning the whole space, or ::/0. An empty whitelist reports false, and an entry that cannot be parsed is not counted as open.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the primary node resides in, for example cn-hangzhou-i","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"PolarDB cluster","desc":"A single ApsaraDB for PolarDB cluster, keyed by dbClusterId. Exposes the cluster lifecycle status, database engine and version, node class and count, storage usage, network placement, billing, and the security-posture controls that govern it: SSL/TLS encryption in transit, Transparent Data Encryption (TDE) at rest, the IP access whitelist, deletion protection, and the connection endpoints. Select a cluster with alicloud.polardb.cluster(dbClusterId: \"pc-xxxxxxxx\").","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb.knowledgeBase":{"id":"alicloud.polardb.knowledgeBase","name":"alicloud.polardb.knowledgeBase","fields":{"bindingAppCount":{"name":"bindingAppCount","type":"\u0005","is_mandatory":true,"title":"Number of AI applications bound to the knowledge base","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"When the knowledge base was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the knowledge base, empty when none is set","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeBaseId":{"name":"knowledgeBaseId","type":"\u0007","is_mandatory":true,"title":"Knowledge base ID, for example pkb-xxxxxxxx","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeBaseType":{"name":"knowledgeBaseType","type":"\u0007","is_mandatory":true,"title":"Sharing scope of the knowledge base","desc":"One of PUBLIC, readable by everyone with access to the knowledge space, or PERSONAL, readable only by the account that created it.","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeSpace":{"name":"knowledgeSpace","type":"\u001balicloud.polardb.knowledgeSpace","title":"Knowledge space that contains the knowledge base","desc":"Null when the knowledge base names no space, and when the space could not be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the knowledge base","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the knowledge base resides in, for example cn-beijing","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle state of the knowledge base, for example Activation","provider":"go.mondoo.com/mql/providers/alicloud"},"syncLink":{"name":"syncLink","type":"\u001balicloud.polardb.knowledgeBase.syncLink","title":"Synchronization link of a PolarDB knowledge base","desc":"A single link that pulls documents into a knowledge base from a directory on an external messaging platform, keyed by linkId. Exposes the platform and the client identity the link authenticates as, the source directory it reads, how often it runs, and whether it is running. A running link is an unattended path for outside content to enter the corpus a retrieval workload answers from.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"syncLinks":{"name":"syncLinks","type":"\u0019\u001balicloud.polardb.knowledgeBase.syncLink","title":"Synchronization links that feed content into the knowledge base","desc":"Empty when nothing is synchronized in. Each link pulls a directory from an external messaging platform on a timer, so documents reach the corpus with nobody reviewing them at the moment they land.","provider":"go.mondoo.com/mql/providers/alicloud"},"totalDocs":{"name":"totalDocs","type":"\u0005","is_mandatory":true,"title":"Total number of documents in the knowledge base","provider":"go.mondoo.com/mql/providers/alicloud"},"totalSizeBytes":{"name":"totalSizeBytes","type":"\u0005","is_mandatory":true,"title":"Total size of the documents in the knowledge base, in bytes","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"PolarDB knowledge base","desc":"A single knowledge base within a knowledge space, keyed by knowledgeBaseId within its region. A knowledge base groups the documents a retrieval workload answers from. Exposes the sharing scope that decides who reads it, the document and byte counts, how many AI applications are bound to it, and the synchronization links that pull content into it from an external messaging platform on a timer.","min_provider_version":"13.5.1","defaults":"name knowledgeBaseId knowledgeBaseType status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb.knowledgeBase.syncLink":{"id":"alicloud.polardb.knowledgeBase.syncLink","name":"alicloud.polardb.knowledgeBase.syncLink","fields":{"clientId":{"name":"clientId","type":"\u0007","is_mandatory":true,"title":"Client identity the link authenticates to the platform as, for example cli_xxxxxxbe8","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"When the synchronization link was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the synchronization link, empty when none is set","provider":"go.mondoo.com/mql/providers/alicloud"},"imPlatform":{"name":"imPlatform","type":"\u0007","is_mandatory":true,"title":"Messaging platform the link pulls content from","desc":"FEISHU is the documented source channel. Reported as returned by the API, so a platform added after this provider shipped still appears.","provider":"go.mondoo.com/mql/providers/alicloud"},"linkId":{"name":"linkId","type":"\u0007","is_mandatory":true,"title":"Synchronization link ID, for example pkbl-xxxxxxxx","provider":"go.mondoo.com/mql/providers/alicloud"},"linkName":{"name":"linkName","type":"\u0007","is_mandatory":true,"title":"Name of the synchronization link","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceDir":{"name":"sourceDir","type":"\u0007","is_mandatory":true,"title":"Source directory the link reads","desc":"For example https://example.feishu.cn/wiki/space/xxxxxx.","provider":"go.mondoo.com/mql/providers/alicloud"},"syncIntervalMinutes":{"name":"syncIntervalMinutes","type":"\u0005","is_mandatory":true,"title":"Minutes between synchronization runs","provider":"go.mondoo.com/mql/providers/alicloud"},"syncStatus":{"name":"syncStatus","type":"\u0007","is_mandatory":true,"title":"Synchronization state","desc":"One of CREATING, RUNNING, PAUSED, or DELETING. Only RUNNING pulls content in now.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Synchronization link of a PolarDB knowledge base","desc":"A single link that pulls documents into a knowledge base from a directory on an external messaging platform, keyed by linkId. Exposes the platform and the client identity the link authenticates as, the source directory it reads, how often it runs, and whether it is running. A running link is an unattended path for outside content to enter the corpus a retrieval workload answers from.","min_provider_version":"13.5.1","defaults":"linkName imPlatform sourceDir syncStatus","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.polardb.knowledgeSpace":{"id":"alicloud.polardb.knowledgeSpace","name":"alicloud.polardb.knowledgeSpace","fields":{"aclMode":{"name":"aclMode","type":"\u0007","is_mandatory":true,"title":"Access control applied when retrieving from the corpus","desc":"One of DISABLED or ENFORCED. With it DISABLED, no per-document access control is applied, so every caller that can query the space retrieves from the whole corpus.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"When the knowledge space was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dbCluster":{"name":"dbCluster","type":"\u001balicloud.polardb.cluster","title":"PolarDB cluster that stores the vectors","desc":"Null when the space names no cluster, and when the cluster lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbName":{"name":"dbName","type":"\u0007","is_mandatory":true,"title":"Name of the database that holds the vectors, for example polar_rag_meta","provider":"go.mondoo.com/mql/providers/alicloud"},"dbType":{"name":"dbType","type":"\u0007","is_mandatory":true,"title":"Database engine that holds the vectors","desc":"One of MySQL or PostgreSQL.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the knowledge space, empty when none is set","provider":"go.mondoo.com/mql/providers/alicloud"},"embeddingDimension":{"name":"embeddingDimension","type":"\u0005","is_mandatory":true,"title":"Number of dimensions in the stored vectors, for example 1536","provider":"go.mondoo.com/mql/providers/alicloud"},"embeddingModel":{"name":"embeddingModel","type":"\u0007","is_mandatory":true,"title":"Model that turns documents into vectors, for example text-embedding-v4","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeBaseCount":{"name":"knowledgeBaseCount","type":"\u0005","is_mandatory":true,"title":"Number of knowledge bases in the space","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeBases":{"name":"knowledgeBases","type":"\u0019\u001balicloud.polardb.knowledgeBase","title":"Knowledge bases contained in the space","provider":"go.mondoo.com/mql/providers/alicloud"},"knowledgeSpaceId":{"name":"knowledgeSpaceId","type":"\u0007","is_mandatory":true,"title":"Knowledge space ID, used with the region as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"llmModel":{"name":"llmModel","type":"\u0007","is_mandatory":true,"title":"Model that composes answers from the retrieved documents, for example qwen3.6-plus","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the knowledge space","provider":"go.mondoo.com/mql/providers/alicloud"},"ossBucket":{"name":"ossBucket","type":"\u001balicloud.oss.bucket","title":"OSS bucket the source documents are drawn from","desc":"Null when the space names no bucket. The bucket's own access controls decide who reaches the raw documents behind the corpus, which the access control on the space itself does not govern.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the knowledge space resides in, for example cn-beijing","provider":"go.mondoo.com/mql/providers/alicloud"},"rerankModel":{"name":"rerankModel","type":"\u0007","is_mandatory":true,"title":"Model that reorders retrieval results, for example qwen3-rerank","provider":"go.mondoo.com/mql/providers/alicloud"},"shardSize":{"name":"shardSize","type":"\u0005","is_mandatory":true,"title":"Chunk size in tokens","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle state of the knowledge space, for example Activation","provider":"go.mondoo.com/mql/providers/alicloud"},"strategy":{"name":"strategy","type":"\u0007","is_mandatory":true,"title":"Chunking strategy applied to documents, for example hybrid","provider":"go.mondoo.com/mql/providers/alicloud"},"totalDocs":{"name":"totalDocs","type":"\u0005","is_mandatory":true,"title":"Total number of documents across the space","provider":"go.mondoo.com/mql/providers/alicloud"},"totalSizeBytes":{"name":"totalSizeBytes","type":"\u0005","is_mandatory":true,"title":"Total size of the documents across the space, in bytes","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"PolarDB knowledge space","desc":"A single knowledge space, the vector store a PolarDB retrieval-augmented generation workload answers from, keyed by knowledgeSpaceId within its region. Exposes the access control mode that decides how much of the corpus a caller retrieves, the OSS bucket the source documents are drawn from, the PolarDB cluster and database that hold the vectors, and the embedding, generation, and reranking models in use. The knowledgeSpaceId field selects the space, for example alicloud.polardb.knowledgeSpace(knowledgeSpaceId: \"pks-xxxxxxxx\", regionId: \"cn-beijing\").","min_provider_version":"13.5.1","defaults":"name knowledgeSpaceId aclMode status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram":{"id":"alicloud.ram","name":"alicloud.ram","fields":{"accessKey":{"name":"accessKey","type":"\u001balicloud.ram.accessKey","title":"Resource Access Management access key","desc":"An access key credential belonging to a RAM user, keyed by the owning userName and accessKeyId. Exposes the key status and creation time. The secret access key is never exposed.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"allowUserToChangePassword":{"name":"allowUserToChangePassword","type":"\u0004","title":"Whether RAM users may change their own console password","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"allowUserToManageAccessKeys":{"name":"allowUserToManageAccessKeys","type":"\u0004","title":"Whether RAM users may create and rotate their own access keys","desc":"A user who can mint their own long-lived keys can move credentials out of any console-based control, including the MFA requirement on console sign-in.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"allowUserToManageMfaDevices":{"name":"allowUserToManageMfaDevices","type":"\u0004","title":"Whether RAM users may bind and unbind their own MFA devices","desc":"A user who can unbind their own device can remove the second factor an MFA requirement was meant to enforce.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"allowUserToManagePublicKeys":{"name":"allowUserToManagePublicKeys","type":"\u0004","title":"Whether RAM users may manage their own public keys","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"group":{"name":"group","type":"\u001balicloud.ram.group","title":"Resource Access Management user group","desc":"A collection of RAM users, keyed by groupName. Exposes the group metadata and lifecycle timestamps, plus the member users and the policies attached to the group.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"groups":{"name":"groups","type":"\u0019\u001balicloud.ram.group","title":"RAM user groups in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"loginNetworkMasks":{"name":"loginNetworkMasks","type":"\u0019\u0007","title":"Network masks console sign-in is restricted to","desc":"Console sign-in is refused from outside these CIDRs. An empty list means sign-in is accepted from anywhere on the internet.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"loginSessionDuration":{"name":"loginSessionDuration","type":"\u0005","title":"Console session duration in hours before re-authentication is required","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordPolicy":{"name":"passwordPolicy","type":"\u001balicloud.ram.passwordPolicy","title":"Account-wide password policy for RAM users","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\u001balicloud.ram.policy","title":"Permission policies in the account, both system and custom","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u001balicloud.ram.policy","title":"Resource Access Management permission policy","desc":"A permission policy. Exposes the policy metadata, attachment count, and default version, along with the policy document of the default version. System policies are managed by Alibaba Cloud; custom policies are defined in the account. The policyName and policyType fields together select a single policy, for example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"role":{"name":"role","type":"\u001balicloud.ram.role","title":"Resource Access Management role","desc":"A RAM role that trusted identities can assume, keyed by roleName. Exposes the role identifiers, description, session limits, and tags, along with the trust policy that governs who may assume it and the permission policies attached to it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"roles":{"name":"roles","type":"\u0019\u001balicloud.ram.role","title":"RAM roles in the account","provider":"go.mondoo.com/mql/providers/alicloud"},"saveMfaTicketEnabled":{"name":"saveMfaTicketEnabled","type":"\u0004","title":"Whether the console remembers an MFA verification for the session","desc":"When on, a browser that has passed MFA once is not challenged again for the remembered period, so a stolen session skips the second factor.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"securityPreference":{"name":"securityPreference","type":"\n","title":"Console and credential security preferences for the account","desc":"Deprecated in favor of allowUserToManageAccessKeys, allowUserToManageMfaDevices, allowUserToManagePublicKeys, allowUserToChangePassword, saveMfaTicketEnabled, loginNetworkMasks, and loginSessionDuration. Every value here is null on an account whose preferences cannot be read, and a null compares as true in an MQL `\u0026\u0026` assertion, so a check written against this dict passes on the accounts it was meant to catch.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"user":{"name":"user","type":"\u001balicloud.ram.user","title":"Resource Access Management user","desc":"A single RAM identity, keyed by userName. Exposes the user profile (display name, email, mobile phone, comments) and lifecycle timestamps, plus the user's access keys, group memberships, attached policies, MFA device binding, and console login profile.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"users":{"name":"users","type":"\u0019\u001balicloud.ram.user","title":"RAM users in the account","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Resource Access Management","desc":"Identity and access configuration for an Alibaba Cloud account. Exposes the RAM users, user groups, roles, and permission policies defined in the account, along with the account-wide password policy and the console and credential security preferences.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.accessKey":{"id":"alicloud.ram.accessKey","name":"alicloud.ram.accessKey","fields":{"accessKeyId":{"name":"accessKeyId","type":"\u0007","is_mandatory":true,"title":"Access key ID","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the access key was created","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Key status","desc":"Either Active or Inactive.","provider":"go.mondoo.com/mql/providers/alicloud"},"user":{"name":"user","type":"\u001balicloud.ram.user","title":"RAM user that owns the access key","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"User name that owns the access key","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management access key","desc":"An access key credential belonging to a RAM user, keyed by the owning userName and accessKeyId. Exposes the key status and creation time. The secret access key is never exposed.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.group":{"id":"alicloud.ram.group","name":"alicloud.ram.group","fields":{"attachedPolicies":{"name":"attachedPolicies","type":"\u0019\u001balicloud.ram.policy","title":"Policies attached to the group","desc":"The permission policies every member of the group inherits. Traverse to policyDocument to inspect the permission statements granted through group membership.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"comments":{"name":"comments","type":"\u0007","is_mandatory":true,"title":"Comments describing the group","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"groupId":{"name":"groupId","type":"\u0007","is_mandatory":true,"title":"Group ID","provider":"go.mondoo.com/mql/providers/alicloud"},"groupName":{"name":"groupName","type":"\u0007","is_mandatory":true,"title":"Group name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\n","title":"Policy attachment records for policies attached to the group","desc":"Each entry lists the policyName, policyType (System or Custom), defaultVersion, description, and attachDate of a policy attached to the group. Use attachedPolicies to reach the policy itself, including its permission statements.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the group was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"users":{"name":"users","type":"\u0019\u001balicloud.ram.user","title":"Users that belong to the group","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management user group","desc":"A collection of RAM users, keyed by groupName. Exposes the group metadata and lifecycle timestamps, plus the member users and the policies attached to the group.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.passwordPolicy":{"id":"alicloud.ram.passwordPolicy","name":"alicloud.ram.passwordPolicy","fields":{"hardExpiry":{"name":"hardExpiry","type":"\u0004","is_mandatory":true,"title":"Whether an expired password blocks console sign-in until an administrator resets it","desc":"When true, a user whose password has expired cannot sign in and an administrator must reset the password. When false, the user may change the expired password at sign-in.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxLoginAttempts":{"name":"maxLoginAttempts","type":"\u0005","is_mandatory":true,"title":"Number of consecutive failed sign-in attempts before the user is locked out","provider":"go.mondoo.com/mql/providers/alicloud"},"maxPasswordAge":{"name":"maxPasswordAge","type":"\u0005","is_mandatory":true,"title":"Maximum password age in days before it must be changed, or 0 when passwords never expire","provider":"go.mondoo.com/mql/providers/alicloud"},"minimumPasswordLength":{"name":"minimumPasswordLength","type":"\u0005","is_mandatory":true,"title":"Minimum number of characters required in a password","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordReusePrevention":{"name":"passwordReusePrevention","type":"\u0005","is_mandatory":true,"title":"Number of previous passwords that cannot be reused","provider":"go.mondoo.com/mql/providers/alicloud"},"requireLowercaseCharacters":{"name":"requireLowercaseCharacters","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain a lowercase letter","provider":"go.mondoo.com/mql/providers/alicloud"},"requireNumbers":{"name":"requireNumbers","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain a number","provider":"go.mondoo.com/mql/providers/alicloud"},"requireSymbols":{"name":"requireSymbols","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain a symbol","provider":"go.mondoo.com/mql/providers/alicloud"},"requireUppercaseCharacters":{"name":"requireUppercaseCharacters","type":"\u0004","is_mandatory":true,"title":"Whether passwords must contain an uppercase letter","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management password policy","desc":"Account-wide password requirements for RAM users. Exposes the minimum length, character-class requirements, expiration and reuse rules, and the failed-login lockout threshold.","private":true,"min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.policy":{"id":"alicloud.ram.policy","name":"alicloud.ram.policy","fields":{"allowsAdminAccess":{"name":"allowsAdminAccess","type":"\u0004","title":"Whether the policy grants every action on every resource","desc":"True when a statement allows action `*` on resource `*`, or on the fully wildcarded `acs:*:*:*:*`, with no NotAction or NotResource exception carved out of it. A condition on the statement does not clear the flag, because the grant is still unrestricted wherever that condition holds.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"attachmentCount":{"name":"attachmentCount","type":"\u0005","is_mandatory":true,"title":"Number of entities the policy is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the policy was created","provider":"go.mondoo.com/mql/providers/alicloud"},"defaultVersion":{"name":"defaultVersion","type":"\u0007","is_mandatory":true,"title":"Version ID of the default policy version, for example v1","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"hasUnscopedResource":{"name":"hasUnscopedResource","type":"\u0004","title":"Whether a granting statement applies to a whole service","desc":"True when any Allow statement names `*`, or an ACS resource name whose relative ID is `*`, such as `acs:oss:*:*:*`. Only the relative ID counts: the region and account fields are wildcarded in most real policies, so `acs:oss:*:*:mybucket/*` names one bucket and does not set the flag. Deny statements are ignored.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"hasWildcardAction":{"name":"hasWildcardAction","type":"\u0004","title":"Whether a granting statement names an action by wildcard","desc":"True when any Allow statement names an action containing `*`, covering both the full `*` and prefix forms such as `ecs:Describe*`. A prefix wildcard is worth surfacing because it also grants actions the service has not shipped yet. Deny statements are ignored.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"policyDocument":{"name":"policyDocument","type":"\u0007","title":"Policy document of the default version","desc":"The permission statements of the default version as a JSON string.","provider":"go.mondoo.com/mql/providers/alicloud"},"policyName":{"name":"policyName","type":"\u0007","is_mandatory":true,"title":"Policy name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"policyType":{"name":"policyType","type":"\u0007","is_mandatory":true,"title":"Policy type","desc":"Either System for an Alibaba Cloud managed policy or Custom for an account-defined policy.","provider":"go.mondoo.com/mql/providers/alicloud"},"statement":{"name":"statement","type":"\u001balicloud.ram.policy.statement","title":"Statement of a Resource Access Management permission policy","desc":"A single permission statement out of a policy's default version. Exposes the effect, the actions and resources the statement names or excludes, and the condition constraining the grant. For example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\").statements`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"statements":{"name":"statements","type":"\u0019\u001balicloud.ram.policy.statement","title":"Permission statements of the default policy version","desc":"The statements of policyDocument broken out one by one, each carrying the effect, the actions and resources it names, and any condition placed on the grant. Query into them to audit what a policy actually permits, for example `alicloud.ram.policies.where(policyType == \"Custom\") { policyName statements { effect action resource } }`.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the policy was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management permission policy","desc":"A permission policy. Exposes the policy metadata, attachment count, and default version, along with the policy document of the default version. System policies are managed by Alibaba Cloud; custom policies are defined in the account. The policyName and policyType fields together select a single policy, for example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\")`.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.policy.statement":{"id":"alicloud.ram.policy.statement","name":"alicloud.ram.policy.statement","fields":{"action":{"name":"action","type":"\u0019\u0007","is_mandatory":true,"title":"Actions the statement applies to","desc":"Each entry is either `service:Action`, a prefix wildcard such as `ecs:Describe*`, or the full wildcard `*`. Empty when the statement uses notAction instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"condition":{"name":"condition","type":"\n","is_mandatory":true,"title":"Condition constraining the grant","desc":"The condition block keyed by operator, for example `{\"StringEquals\": {\"acs:SourceVpc\": [\"vpc-1\"]}}` or `{\"IpAddress\": {\"acs:SourceIp\": [\"10.0.0.0/8\"]}}`. Null when the statement grants unconditionally.","provider":"go.mondoo.com/mql/providers/alicloud"},"effect":{"name":"effect","type":"\u0007","is_mandatory":true,"title":"Effect of the statement","desc":"Either Allow or Deny.","provider":"go.mondoo.com/mql/providers/alicloud"},"notAction":{"name":"notAction","type":"\u0019\u0007","is_mandatory":true,"title":"Actions excluded from the statement","desc":"The statement applies to every action except these. Empty on the usual statement, which names its actions through action.","provider":"go.mondoo.com/mql/providers/alicloud"},"notResource":{"name":"notResource","type":"\u0019\u0007","is_mandatory":true,"title":"Resources excluded from the statement","desc":"The statement applies to every resource except these. Empty on the usual statement, which names its resources through resource.","provider":"go.mondoo.com/mql/providers/alicloud"},"principal":{"name":"principal","type":"\n","is_mandatory":true,"title":"Identities the statement applies to","desc":"Keyed by principal kind, for example `{\"RAM\": [\"acs:ram::123456789:root\"], \"Service\": [\"ecs.aliyuncs.com\"]}`. Null on a permission policy statement, which names actions and resources rather than principals; set on a role trust statement and on a bucket policy statement.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"resource":{"name":"resource","type":"\u0019\u0007","is_mandatory":true,"title":"Resources the statement applies to","desc":"Each entry is either the full wildcard `*` or an ACS resource name of the form `acs:\u003cservice\u003e:\u003cregion\u003e:\u003caccount\u003e:\u003crelative-id\u003e`. Empty when the statement uses notResource instead, and on statements that name no resource at all, such as a role trust statement.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Statement of a Resource Access Management permission policy","desc":"A single permission statement out of a policy's default version. Exposes the effect, the actions and resources the statement names or excludes, and the condition constraining the grant. For example `alicloud.ram.policy(policyName: \"AdministratorAccess\", policyType: \"System\").statements`.","min_provider_version":"13.2.5","defaults":"effect action resource","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.role":{"id":"alicloud.ram.role","name":"alicloud.ram.role","fields":{"arn":{"name":"arn","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud Resource Name of the role","provider":"go.mondoo.com/mql/providers/alicloud"},"assumeRolePolicyDocument":{"name":"assumeRolePolicyDocument","type":"\u0007","title":"Trust policy document controlling which identities may assume the role","desc":"The assume-role policy as a JSON string, naming the principals permitted to assume this role and the conditions on that trust.","provider":"go.mondoo.com/mql/providers/alicloud"},"attachedPolicies":{"name":"attachedPolicies","type":"\u0019\u001balicloud.ram.policy","title":"Policies attached to the role","desc":"The permission policies a session that assumes this role receives. Traverse to policyDocument alongside assumeRolePolicyDocument to see both who may assume the role and what the assumed session is allowed to do.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the role was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the role","provider":"go.mondoo.com/mql/providers/alicloud"},"hasWildcardPrincipal":{"name":"hasWildcardPrincipal","type":"\u0004","title":"Whether any identity may assume the role","desc":"True when an allowing trust statement names the wildcard `*` as a principal, which lets any Alibaba Cloud identity anywhere assume the role.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"maxSessionDuration":{"name":"maxSessionDuration","type":"\u0005","is_mandatory":true,"title":"Maximum session duration in seconds allowed when assuming the role","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\n","title":"Policy attachment records for policies attached to the role","desc":"Each entry lists the policyName, policyType (System or Custom), defaultVersion, description, and attachDate of a policy attached to the role. Use attachedPolicies to reach the policy itself, including its permission statements.","provider":"go.mondoo.com/mql/providers/alicloud"},"roleId":{"name":"roleId","type":"\u0007","is_mandatory":true,"title":"Role ID","provider":"go.mondoo.com/mql/providers/alicloud"},"roleName":{"name":"roleName","type":"\u0007","is_mandatory":true,"title":"Role name, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the role","provider":"go.mondoo.com/mql/providers/alicloud"},"trustStatements":{"name":"trustStatements","type":"\u0019\u001balicloud.ram.policy.statement","title":"Parsed statements of the trust policy","desc":"The assume-role policy decoded into statements, so the principals and the conditions on the trust can be queried directly instead of by matching text against assumeRolePolicyDocument.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"trustedAccountIds":{"name":"trustedAccountIds","type":"\u0019\u0007","title":"Accounts permitted to assume the role","desc":"The account IDs parsed out of the RAM principals in the trust policy, sorted and deduplicated. Compare against the account under audit to find a role a foreign account can assume, which is a cross-account takeover path into whatever the role's attached policies grant.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"trustedPrincipals":{"name":"trustedPrincipals","type":"\u0019\u0007","title":"Principals permitted to assume the role","desc":"Every principal named by an allowing trust statement, across all principal kinds, sorted and deduplicated. For example `acs:ram::123456789:root`, `acs:ram::123456789:user/deploy`, `ecs.aliyuncs.com`, or the wildcard `*`.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"trustedServices":{"name":"trustedServices","type":"\u0019\u0007","title":"Alibaba Cloud services permitted to assume the role","desc":"The Service principals in the trust policy, for example ecs.aliyuncs.com or fc.aliyuncs.com. A service-linked role is expected to have these; a role meant for humans is not.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the role was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management role","desc":"A RAM role that trusted identities can assume, keyed by roleName. Exposes the role identifiers, description, session limits, and tags, along with the trust policy that governs who may assume it and the permission policies attached to it.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.ram.user":{"id":"alicloud.ram.user","name":"alicloud.ram.user","fields":{"accessKeys":{"name":"accessKeys","type":"\u0019\u001balicloud.ram.accessKey","title":"Access keys belonging to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"attachedPolicies":{"name":"attachedPolicies","type":"\u0019\u001balicloud.ram.policy","title":"Policies attached directly to the user","desc":"The permission policies granted to the user by direct attachment, not counting policies the user inherits through group membership. Traverse to policyDocument to inspect the permission statements a user holds, for example to find users granted the AdministratorAccess system policy.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"comments":{"name":"comments","type":"\u0007","is_mandatory":true,"title":"Comments describing the user","provider":"go.mondoo.com/mql/providers/alicloud"},"consoleLoginEnabled":{"name":"consoleLoginEnabled","type":"\u0004","title":"Whether the user can sign in to the Alibaba Cloud console","desc":"False for a user that holds only programmatic credentials. Console access is what the password policy, the MFA requirement, and the login network masks apply to, so it decides which account-wide controls reach this user at all.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the user was created","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name","provider":"go.mondoo.com/mql/providers/alicloud"},"effectivePolicies":{"name":"effectivePolicies","type":"\u0019\u001balicloud.ram.policy","title":"Every policy the user holds, directly or through a group","desc":"The union of attachedPolicies and the policies attached to each group the user belongs to, with a policy held by both routes listed once. This is the set that decides what a user can actually do, which attachedPolicies alone understates whenever permissions are granted through groups. For example `alicloud.ram.users.where(effectivePolicies.any(allowsAdminAccess))` finds every administrator in the account.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email address bound to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"groups":{"name":"groups","type":"\u0019\u001balicloud.ram.group","title":"Groups the user belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"lastLoginDate":{"name":"lastLoginDate","type":"\t","title":"Time the user last signed in to the console","provider":"go.mondoo.com/mql/providers/alicloud"},"loginProfile":{"name":"loginProfile","type":"\n","title":"Console login profile for the user","desc":"Deprecated in favor of consoleLoginEnabled, mfaBindRequired, passwordResetRequired, and loginProfileCreateDate. This dict is null for a user with no console access, and a null compares as true in an MQL `\u0026\u0026` assertion.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"loginProfileCreateDate":{"name":"loginProfileCreateDate","type":"\t","title":"Time the console login profile was created, null when the user has no console access","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaBindRequired":{"name":"mfaBindRequired","type":"\u0004","title":"Whether the user must bind an MFA device at the next console sign-in","desc":"This is the enforcement flag, not the state: a user with it set may still have no device bound today. Read mfaEnabled for whether a second factor is in place now.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaDevice":{"name":"mfaDevice","type":"\n","title":"Multi-factor authentication device bound to the user","desc":"Deprecated in favor of mfaEnabled, mfaDeviceType, and mfaDeviceSerialNumber. This dict is null for a user with no device bound, and a null compares as true in an MQL `\u0026\u0026` assertion, so a check written against it passes on exactly the users it was meant to catch.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated"},"mfaDeviceSerialNumber":{"name":"mfaDeviceSerialNumber","type":"\u0007","title":"Serial number identifying the bound MFA device, empty when none is bound","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaDeviceType":{"name":"mfaDeviceType","type":"\u0007","title":"Type of the bound MFA device, for example VMFA, empty when none is bound","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"mfaEnabled":{"name":"mfaEnabled","type":"\u0004","title":"Whether a multi-factor authentication device is bound to the user","desc":"False for a user with console access and no second factor, which is the case a console-sign-in audit is looking for. Also false for a user with no console access at all, where the question does not arise.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"mobilePhone":{"name":"mobilePhone","type":"\u0007","is_mandatory":true,"title":"Mobile phone number bound to the user","provider":"go.mondoo.com/mql/providers/alicloud"},"passwordResetRequired":{"name":"passwordResetRequired","type":"\u0004","title":"Whether the user must change their password at the next console sign-in","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"policies":{"name":"policies","type":"\u0019\n","title":"Policy attachment records for policies attached directly to the user","desc":"Each entry lists the policyName, policyType (System or Custom), defaultVersion, description, and attachDate of a policy attached to the user. Use attachedPolicies to reach the policy itself, including its permission statements.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the user was last updated","provider":"go.mondoo.com/mql/providers/alicloud"},"userId":{"name":"userId","type":"\u0007","is_mandatory":true,"title":"User ID","provider":"go.mondoo.com/mql/providers/alicloud"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"User name, used as the console sign-in name and the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Access Management user","desc":"A single RAM identity, keyed by userName. Exposes the user profile (display name, email, mobile phone, comments) and lifecycle timestamps, plus the user's access keys, group memberships, attached policies, MFA device binding, and console login profile.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.rds":{"id":"alicloud.rds","name":"alicloud.rds","fields":{"instance":{"name":"instance","type":"\u001balicloud.rds.instance","title":"ApsaraDB RDS instance","desc":"A single ApsaraDB relational database instance, keyed by dbInstanceId (for example rm-uf6wjk5xxxxxxx). Exposes the database engine and version, the instance class and storage, the network placement and connection endpoint, the billing and lock state, and the security posture: whether SSL/TLS and TDE encryption are enabled, the IP address whitelist, and the attached ECS security groups.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.rds.instance","title":"RDS instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB RDS","desc":"ApsaraDB relational database instances in an Alibaba Cloud account. Exposes the RDS instances discovered across every enabled region through instances, from which the database engine and version, the network placement, and the security posture (SSL/TLS, TDE encryption, public accessibility, and IP address whitelist) can be audited.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.rds.instance":{"id":"alicloud.rds.instance","name":"alicloud.rds.instance","fields":{"blueGreenDeploymentName":{"name":"blueGreenDeploymentName","type":"\u0007","title":"Name of the blue-green deployment the instance takes part in","desc":"Empty when the instance is not part of one. A blue-green deployment runs a second instance holding the same data as the one serving traffic, so both halves have to be hardened alike: the standby is a live copy of production data that a whitelist or encryption setting applied only to the original does not cover.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"blueInstanceName":{"name":"blueInstanceName","type":"\u0007","title":"Name of the blue instance in the deployment, empty when not part of one","desc":"The blue instance is the one currently serving traffic.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"RDS edition of the instance","desc":"One of Basic, HighAvailability, cluster, Finance, or serverless_basic.","provider":"go.mondoo.com/mql/providers/alicloud"},"computeBurstEnabled":{"name":"computeBurstEnabled","type":"\u0004","title":"Whether compute burst is enabled for the instance","desc":"A burst-enabled instance may exceed its purchased compute for short periods, so its effective capacity is not the class alone.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionMode":{"name":"connectionMode","type":"\u0007","is_mandatory":true,"title":"Connection mode of the instance","desc":"One of Standard (standard mode) or Safe (database proxy mode).","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionString":{"name":"connectionString","type":"\u0007","is_mandatory":true,"title":"Endpoint used to connect to the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceClass":{"name":"dbInstanceClass","type":"\u0007","is_mandatory":true,"title":"Instance type (class), for example rds.mys2.small","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceDescription":{"name":"dbInstanceDescription","type":"\u0007","is_mandatory":true,"title":"Description of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceId":{"name":"dbInstanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example rm-uf6wjk5xxxxxxx","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceNetType":{"name":"dbInstanceNetType","type":"\u0007","is_mandatory":true,"title":"Network connection type of the instance","desc":"One of Internet (public) or Intranet (internal).","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStatus":{"name":"dbInstanceStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the instance, for example Running or Creating","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStorage":{"name":"dbInstanceStorage","type":"\u0005","title":"Storage capacity of the instance in GB","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceStorageType":{"name":"dbInstanceStorageType","type":"\u0007","is_mandatory":true,"title":"Storage type of the instance","desc":"One of local_ssd, cloud_ssd, cloud_essd, cloud_essd2, or cloud_essd3.","provider":"go.mondoo.com/mql/providers/alicloud"},"dbInstanceType":{"name":"dbInstanceType","type":"\u0007","is_mandatory":true,"title":"Role of the instance","desc":"One of Primary (primary instance), Readonly (read-only instance), Guard (disaster recovery instance), or Temp (temporary instance).","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether release (deletion) protection is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"engine":{"name":"engine","type":"\u0007","is_mandatory":true,"title":"Database engine","desc":"One of MySQL, SQLServer, PostgreSQL, or MariaDB.","provider":"go.mondoo.com/mql/providers/alicloud"},"engineVersion":{"name":"engineVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version, for example 5.7","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","is_mandatory":true,"title":"Time when the instance expires (subscription instances only)","provider":"go.mondoo.com/mql/providers/alicloud"},"greenInstanceName":{"name":"greenInstanceName","type":"\u0007","title":"Name of the green instance in the deployment, empty when not part of one","desc":"The green instance is the standby the deployment will switch to.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceNetworkType":{"name":"instanceNetworkType","type":"\u0007","is_mandatory":true,"title":"Network type of the instance","desc":"One of VPC or Classic.","provider":"go.mondoo.com/mql/providers/alicloud"},"lockMode":{"name":"lockMode","type":"\u0007","is_mandatory":true,"title":"Lock state of the instance","desc":"One of Unlock, ManualLock, LockByExpiration, LockByRestoration, or LockByDiskQuota.","provider":"go.mondoo.com/mql/providers/alicloud"},"lockReason":{"name":"lockReason","type":"\u0007","is_mandatory":true,"title":"Reason the instance is locked","provider":"go.mondoo.com/mql/providers/alicloud"},"masterInstance":{"name":"masterInstance","type":"\u001balicloud.rds.instance","title":"Primary instance, set for read-only and disaster recovery instances","provider":"go.mondoo.com/mql/providers/alicloud"},"parameters":{"name":"parameters","type":"\u001a\u0007\u0007","title":"Running parameter values of the instance, keyed by parameter name","desc":"The values in effect on the running instance, so a check reads parameters[\"log_connections\"] without a nested traversal. Parameters changed but not yet applied are not reflected here. For a PostgreSQL instance this carries the log_connections, log_disconnections, and log_duration settings that decide what the database records about the sessions that connect to it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method of the instance","desc":"One of Postpaid (pay-as-you-go) or Prepaid (subscription).","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","title":"Port on which the instance listens for connections","provider":"go.mondoo.com/mql/providers/alicloud"},"readOnlyStatus":{"name":"readOnlyStatus","type":"\u0007","title":"Read-only state of the instance, empty when it reports none","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID where the instance is deployed, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"ECS security groups attached to the instance","desc":"The groups whose rules govern which sources may reach the instance. Traverse to permissions to see the allowed source ranges and ports alongside securityIPList, which controls the database whitelist separately.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"securityIPList":{"name":"securityIPList","type":"\u0019\u0007","title":"IP address whitelist","desc":"The IP addresses and CIDR blocks allowed to connect to the instance. A whitelist entry of 0.0.0.0/0 exposes the instance to the entire internet.","provider":"go.mondoo.com/mql/providers/alicloud"},"sqlAuditEnabled":{"name":"sqlAuditEnabled","type":"\u0004","title":"Whether SQL Explorer collects the statements executed against the instance","desc":"SQL Explorer (also called SQL audit) records each statement the instance executes, which is what makes after-the-fact review of database activity possible. False when the feature was never switched on, when it has been switched off, or when the engine does not offer it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"sqlAuditRetentionDays":{"name":"sqlAuditRetentionDays","type":"\u0005","title":"Days that SQL Explorer retains the statements it collects","desc":"Zero when SQL Explorer is switched off or the instance reports no retention setting. Configurable values are 30, 180, and 365 days.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether SSL/TLS encryption is enabled for client connections","provider":"go.mondoo.com/mql/providers/alicloud"},"sslExpireTime":{"name":"sslExpireTime","type":"\t","title":"Expiration time of the server certificate used for SSL/TLS","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","title":"Tags attached to the instance as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether Transparent Data Encryption (TDE) is enabled for the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEncryptionKey":{"name":"tdeEncryptionKey","type":"\u001balicloud.kms.key","title":"Key Management Service key that protects the instance under TDE","desc":"Null when TDE is disabled, when the instance is encrypted with a key Alibaba Cloud generated and holds, or when the key can no longer be read. Traverse to the key to see its rotation state, deletion protection, and who is allowed to use it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeMode":{"name":"tdeMode","type":"\u0007","title":"Key generation method used for Transparent Data Encryption","desc":"One of Aliyun_Generate_Key (the key is generated and held by Alibaba Cloud), Customer_Provided_Key (the key is one you supply through Key Management Service), or Unknown. Empty when TDE is disabled or the engine does not report a mode.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vectorSupportStatus":{"name":"vectorSupportStatus","type":"\u0007","title":"Whether the instance supports vector storage and search","desc":"Reports the state of the vector extension, which turns the instance into a store for embeddings and therefore a data surface an AI application reads from. Empty when the engine does not report it.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC that the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch that the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"whitelistAllowsAllAddresses":{"name":"whitelistAllowsAllAddresses","type":"\u0004","title":"Whether the IP whitelist admits every address","desc":"True when an entry in securityIPList admits any source address: the 0.0.0.0/0 block, the bare 0.0.0.0 the console writes for it, any other block with a /0 prefix length, the % wildcard, an address range spanning the whole space, or ::/0. An empty whitelist reports false, and an entry that cannot be parsed is not counted as open.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID where the instance is deployed, for example cn-hangzhou-a","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB RDS instance","desc":"A single ApsaraDB relational database instance, keyed by dbInstanceId (for example rm-uf6wjk5xxxxxxx). Exposes the database engine and version, the instance class and storage, the network placement and connection endpoint, the billing and lock state, and the security posture: whether SSL/TLS and TDE encryption are enabled, the IP address whitelist, and the attached ECS security groups.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.redis":{"id":"alicloud.redis","name":"alicloud.redis","fields":{"instance":{"name":"instance","type":"\u001balicloud.redis.instance","title":"ApsaraDB for Redis instance","desc":"A single ApsaraDB for Redis or Tair instance, keyed by instanceId (for example r-bp1zxszhcgatnx). Exposes the instance class and architecture, the engine version, the network placement, and the security posture (TLS encryption, transparent data encryption, the IP whitelist, attached ECS security groups, and whether password authentication is enforced).","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.redis.instance","title":"ApsaraDB for Redis (Tair) instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for Redis","desc":"Entry point for the ApsaraDB for Redis (Tair) instances in an Alibaba Cloud account. Enumerates every Redis and Tair instance across the enabled regions through instances, each of which exposes its configuration and security posture.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.redis.instance":{"id":"alicloud.redis.instance","name":"alicloud.redis.instance","fields":{"architectureType":{"name":"architectureType","type":"\u0007","is_mandatory":true,"title":"Deployment architecture","desc":"One of cluster (cluster architecture), standard (standard architecture), or rwsplit (read/write splitting architecture).","provider":"go.mondoo.com/mql/providers/alicloud"},"auditLogEnabled":{"name":"auditLogEnabled","type":"\u0004","title":"Whether the audit log records the commands run against the instance","desc":"False when audit logging is off, and when the setting could not be read, so an \"auditing is on\" check fails rather than passing on an instance nobody could read. With it off there is no record of what was read or written, which is the gap a fleet-wide database-activity check is looking for.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"auditLogRetentionDays":{"name":"auditLogRetentionDays","type":"\u0005","title":"Days the audit log is retained","desc":"Zero when audit logging is off. Entries older than this are dropped, which bounds how far back an investigation can reach.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"authEnabled":{"name":"authEnabled","type":"\u0004","title":"Whether password authentication is enforced","desc":"True when password authentication is required. False when password-free access is enabled, allowing connections from within the VPC without a password.","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Maximum internal bandwidth of the instance, in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"capacity":{"name":"capacity","type":"\u0005","is_mandatory":true,"title":"Storage capacity of the instance, in MB","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"connectionDomain":{"name":"connectionDomain","type":"\u0007","is_mandatory":true,"title":"Internal endpoint (connection domain) of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"connections":{"name":"connections","type":"\u0005","is_mandatory":true,"title":"Maximum number of concurrent connections the instance supports","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"editionType":{"name":"editionType","type":"\u0007","is_mandatory":true,"title":"Edition","desc":"One of Community (Redis Open-Source Edition) or Enterprise (Tair Enterprise Edition).","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"Time the subscription instance expires","provider":"go.mondoo.com/mql/providers/alicloud"},"engineVersion":{"name":"engineVersion","type":"\u0007","is_mandatory":true,"title":"Database engine version, for example 4.0, 5.0, 6.0, or 7.0","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceClass":{"name":"instanceClass","type":"\u0007","is_mandatory":true,"title":"Instance type, for example redis.master.small.default","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"Instance ID, for example r-bp1zxszhcgatnx","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceStatus":{"name":"instanceStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Normal, Creating, Changing, Inactive, Flushing, Released, Transforming, Unavailable, Error, Migrating, BackupRecovering, MinorVersionUpgrading, NetworkModifying, SSLModifying, or MajorVersionUpgrading.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Database engine","desc":"One of Redis (Redis Open-Source Edition), Tair (Tair Enterprise Edition), or Memcache.","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type","desc":"One of CLASSIC (classic network) or VPC (virtual private cloud).","provider":"go.mondoo.com/mql/providers/alicloud"},"nodeType":{"name":"nodeType","type":"\u0007","is_mandatory":true,"title":"Node type","desc":"One of double (master-replica) or single (standalone).","provider":"go.mondoo.com/mql/providers/alicloud"},"packageType":{"name":"packageType","type":"\u0007","is_mandatory":true,"title":"Package type","desc":"One of standard (standard package) or customized (custom package).","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Service port the instance listens on, for example 6379","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIp":{"name":"privateIp","type":"\u0007","is_mandatory":true,"title":"Private IP address of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"qps":{"name":"qps","type":"\u0005","is_mandatory":true,"title":"Maximum number of queries per second the instance can serve","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the instance is deployed in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the instance","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"secondaryZoneId":{"name":"secondaryZoneId","type":"\u0007","is_mandatory":true,"title":"Secondary zone ID for a zone-redundant instance","provider":"go.mondoo.com/mql/providers/alicloud"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001balicloud.ecs.securitygroup","title":"ECS security groups associated with the instance","desc":"The groups whose rules govern which sources may reach the instance. Traverse to permissions to see the allowed source ranges and ports alongside securityIPList, which controls the instance whitelist separately.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"securityIPList":{"name":"securityIPList","type":"\u0019\u0007","title":"IP addresses and CIDR blocks allowed by the instance whitelists","provider":"go.mondoo.com/mql/providers/alicloud"},"sslEnabled":{"name":"sslEnabled","type":"\u0004","title":"Whether TLS (SSL) encryption is enabled for in-transit traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the instance, as key/value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"tdeEnabled":{"name":"tdeEnabled","type":"\u0004","title":"Whether transparent data encryption (TDE) is enabled for data at rest","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the instance is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"whitelistAllowsAllAddresses":{"name":"whitelistAllowsAllAddresses","type":"\u0004","title":"Whether the IP whitelist admits every address","desc":"True when an entry in securityIPList admits any source address: the 0.0.0.0/0 block, the bare 0.0.0.0 the console writes for it, any other block with a /0 prefix length, the % wildcard, an address range spanning the whole space, or ::/0. An empty whitelist reports false, and an entry that cannot be parsed is not counted as open.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the instance is deployed in, for example cn-hangzhou-b","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"ApsaraDB for Redis instance","desc":"A single ApsaraDB for Redis or Tair instance, keyed by instanceId (for example r-bp1zxszhcgatnx). Exposes the instance class and architecture, the engine version, the network placement, and the security posture (TLS encryption, transparent data encryption, the IP whitelist, attached ECS security groups, and whether password authentication is enforced).","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager":{"id":"alicloud.resourceManager","name":"alicloud.resourceManager","fields":{"account":{"name":"account","type":"\u001balicloud.resourceManager.account","title":"Resource Directory account","desc":"A single member or management account in the resource directory, keyed by accountId. Exposes the account profile, its position in the folder hierarchy, how it joined the directory, and its lifecycle timestamps.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"accounts":{"name":"accounts","type":"\u0019\u001balicloud.resourceManager.account","title":"Member and management accounts in the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPolicies":{"name":"controlPolicies","type":"\u0019\u001balicloud.resourceManager.controlPolicy","title":"Control policies in the resource directory, both system and custom","provider":"go.mondoo.com/mql/providers/alicloud"},"controlPolicy":{"name":"controlPolicy","type":"\u001balicloud.resourceManager.controlPolicy","title":"Resource Directory control policy","desc":"A single control policy in the resource directory, keyed by policyId. A control policy sets the maximum permissions available to the accounts and folders it is attached to. Exposes the policy metadata and how many entities it is attached to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"controlPolicyStatus":{"name":"controlPolicyStatus","type":"\u0007","title":"Control-policy enablement state","desc":"Enabled when control policies may be attached to restrict member-account permissions.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","title":"Time the resource directory was created","provider":"go.mondoo.com/mql/providers/alicloud"},"folder":{"name":"folder","type":"\u001balicloud.resourceManager.folder","title":"Resource Directory folder","desc":"A single folder in the resource directory hierarchy, keyed by folderId. A folder groups member accounts and can nest other folders. Exposes the folder name, its parent, and creation time.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"folders":{"name":"folders","type":"\u0019\u001balicloud.resourceManager.folder","title":"Folders in the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"},"masterAccountId":{"name":"masterAccountId","type":"\u0007","title":"Management (master) account ID","provider":"go.mondoo.com/mql/providers/alicloud"},"masterAccountName":{"name":"masterAccountName","type":"\u0007","title":"Management (master) account name","provider":"go.mondoo.com/mql/providers/alicloud"},"memberDeletionStatus":{"name":"memberDeletionStatus","type":"\u0007","title":"Member-account deletion state","desc":"Enabled when member accounts may be deleted from the directory.","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceDirectoryId":{"name":"resourceDirectoryId","type":"\u0007","title":"Resource directory (organization) ID","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group","desc":"A single resource group in an Alibaba Cloud account, keyed by resourceGroupId, for example `alicloud.resourceManager.resourceGroups.where(name == \"production\")`. A resource group is the ownership and billing boundary that most Alibaba Cloud resources are placed into, and RAM policies are commonly scoped to one. Exposes the group identifier, its display name, lifecycle status, owning account, and tags. Resources across the provider reach their group through a resourceGroup field, so an audit can select or exclude an environment by group rather than by an opaque identifier.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"resourceGroups":{"name":"resourceGroups","type":"\u0019\u001balicloud.resourceManager.resourceGroup","title":"Resource groups in the account","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"rootFolderId":{"name":"rootFolderId","type":"\u0007","title":"Root folder ID of the resource directory","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Resource Directory","desc":"Multi-account governance structure for an Alibaba Cloud account. Exposes the resource directory (the organization), the management and member accounts it contains, the folder hierarchy that groups them, and the control policies available to restrict member-account permissions. Use it to audit organization membership and whether control policies are enabled.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.account":{"id":"alicloud.resourceManager.account","name":"alicloud.resourceManager.account","fields":{"accountId":{"name":"accountId","type":"\u0007","is_mandatory":true,"title":"Account (UID)","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name of the account","provider":"go.mondoo.com/mql/providers/alicloud"},"folder":{"name":"folder","type":"\u001balicloud.resourceManager.folder","title":"Folder that contains the account","provider":"go.mondoo.com/mql/providers/alicloud"},"folderId":{"name":"folderId","type":"\u0007","is_mandatory":true,"title":"ID of the folder that contains the account","provider":"go.mondoo.com/mql/providers/alicloud"},"joinMethod":{"name":"joinMethod","type":"\u0007","is_mandatory":true,"title":"How the account joined the directory","desc":"Either created or invited.","provider":"go.mondoo.com/mql/providers/alicloud"},"joinTime":{"name":"joinTime","type":"\t","is_mandatory":true,"title":"Time the account joined the directory","provider":"go.mondoo.com/mql/providers/alicloud"},"modifyTime":{"name":"modifyTime","type":"\t","is_mandatory":true,"title":"Time the account was last modified","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceDirectoryId":{"name":"resourceDirectoryId","type":"\u0007","is_mandatory":true,"title":"Resource directory (organization) ID","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Account status, for example CreateSuccess or InviteSuccess","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Account type","desc":"ResourceAccount for an account created in the directory, or CloudAccount for an existing account invited into it.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Directory account","desc":"A single member or management account in the resource directory, keyed by accountId. Exposes the account profile, its position in the folder hierarchy, how it joined the directory, and its lifecycle timestamps.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.controlPolicy":{"id":"alicloud.resourceManager.controlPolicy","name":"alicloud.resourceManager.controlPolicy","fields":{"attachmentCount":{"name":"attachmentCount","type":"\u0005","is_mandatory":true,"title":"Number of accounts and folders the policy is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the policy was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the policy","provider":"go.mondoo.com/mql/providers/alicloud"},"effectScope":{"name":"effectScope","type":"\u0007","is_mandatory":true,"title":"Identity types the policy governs, for example RAM","provider":"go.mondoo.com/mql/providers/alicloud"},"policyId":{"name":"policyId","type":"\u0007","is_mandatory":true,"title":"Policy ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"policyName":{"name":"policyName","type":"\u0007","is_mandatory":true,"title":"Policy name","provider":"go.mondoo.com/mql/providers/alicloud"},"policyType":{"name":"policyType","type":"\u0007","is_mandatory":true,"title":"Policy type","desc":"Either System for an Alibaba Cloud-managed policy or Custom for a user-defined one.","provider":"go.mondoo.com/mql/providers/alicloud"},"updateDate":{"name":"updateDate","type":"\t","is_mandatory":true,"title":"Time the policy was last updated","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource Directory control policy","desc":"A single control policy in the resource directory, keyed by policyId. A control policy sets the maximum permissions available to the accounts and folders it is attached to. Exposes the policy metadata and how many entities it is attached to.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.folder":{"id":"alicloud.resourceManager.folder","name":"alicloud.resourceManager.folder","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the folder was created","provider":"go.mondoo.com/mql/providers/alicloud"},"folderId":{"name":"folderId","type":"\u0007","is_mandatory":true,"title":"Folder ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"folderName":{"name":"folderName","type":"\u0007","is_mandatory":true,"title":"Folder name","provider":"go.mondoo.com/mql/providers/alicloud"},"parentFolder":{"name":"parentFolder","type":"\u001balicloud.resourceManager.folder","title":"Parent folder in the resource directory hierarchy","desc":"Null on the root folder, which has no parent.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"parentFolderId":{"name":"parentFolderId","type":"\u0007","is_mandatory":true,"title":"ID of the parent folder, empty for the root folder","desc":"Deprecated in favor of parentFolder.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.resourceManager.folder.parentFolder"}},"title":"Resource Directory folder","desc":"A single folder in the resource directory hierarchy, keyed by folderId. A folder groups member accounts and can nest other folders. Exposes the folder name, its parent, and creation time.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.resourceManager.resourceGroup":{"id":"alicloud.resourceManager.resourceGroup","name":"alicloud.resourceManager.resourceGroup","fields":{"accountId":{"name":"accountId","type":"\u0007","is_mandatory":true,"title":"ID of the account that owns the resource group","provider":"go.mondoo.com/mql/providers/alicloud"},"createDate":{"name":"createDate","type":"\t","is_mandatory":true,"title":"Time the resource group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name of the resource group","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the resource group within the account","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Creating, OK, PendingDelete, or Deleting.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the resource group","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Resource group","desc":"A single resource group in an Alibaba Cloud account, keyed by resourceGroupId, for example `alicloud.resourceManager.resourceGroups.where(name == \"production\")`. A resource group is the ownership and billing boundary that most Alibaba Cloud resources are placed into, and RAM policies are commonly scoped to one. Exposes the group identifier, its display name, lifecycle status, owning account, and tags. Resources across the provider reach their group through a resourceGroup field, so an audit can select or exclude an environment by group rather than by an opaque identifier.","min_provider_version":"13.3.2","defaults":"resourceGroupId name displayName status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas":{"id":"alicloud.sas","name":"alicloud.sas","fields":{"alarmEvent":{"name":"alarmEvent","type":"\u001balicloud.sas.alarmEvent","title":"Alert raised by Security Center threat detection","desc":"A single alert, keyed by its event ID. Exposes what was detected, where, and whether it has been handled, along with the container and Kubernetes context when the alert came from a containerized workload.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"alarmEvents":{"name":"alarmEvents","type":"\u0019\u001balicloud.sas.alarmEvent","title":"Alerts raised by threat detection","provider":"go.mondoo.com/mql/providers/alicloud"},"assetLevel":{"name":"assetLevel","type":"\u0005","title":"Number of assets the subscription covers","desc":"Protection stops applying to assets beyond this quota, so a machine count above it means part of the fleet is unprotected.","provider":"go.mondoo.com/mql/providers/alicloud"},"baselineCheck":{"name":"baselineCheck","type":"\u001balicloud.sas.baselineCheck","title":"Baseline check failure found by Security Center","desc":"A configuration baseline check that machines are failing, keyed by riskId. Exposes how many machines fail the check and the severity split of those failures, so a check with a high warningMachineCount is a systemic misconfiguration rather than a one-off.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"baselineChecks":{"name":"baselineChecks","type":"\u0019\u001balicloud.sas.baselineCheck","title":"Baseline check failures found across the protected machines, grouped by check","provider":"go.mondoo.com/mql/providers/alicloud"},"config":{"name":"config","type":"\u001balicloud.sas.config","title":"Account-level Security Center settings","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","title":"Whether Security Center is active for the account","desc":"False when the service has never been subscribed. The free tier still reports true, so pair this with version to tell the tiers apart.","provider":"go.mondoo.com/mql/providers/alicloud"},"expireTime":{"name":"expireTime","type":"\t","title":"Time the subscription expires","provider":"go.mondoo.com/mql/providers/alicloud"},"logDeliveries":{"name":"logDeliveries","type":"\u0019\u001balicloud.sas.logDelivery","title":"Log analysis delivery configured for each Security Center log type","desc":"Security Center delivers its host, network and security logs to Log Service under separate switches, so read every entry rather than assuming one setting covers all three.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logDelivery":{"name":"logDelivery","type":"\u001balicloud.sas.logDelivery","title":"Security Center log analysis delivery","desc":"The log analysis configuration for a single Security Center log type, keyed by topic (for example aegis-log-login). Exposes the category the log type belongs to, whether delivery to Log Service is switched on, the destination project and logstore, and how long the delivered logs are kept. A category left switched off means Security Center detects against those events but keeps no searchable record of them.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"machine":{"name":"machine","type":"\u001balicloud.sas.machine","title":"Machine protected by Security Center","desc":"A single asset in the Security Center inventory, keyed by uuid. Exposes the agent state, the vulnerability and risk counts attributed to the machine, and its network addresses. The clientStatus field is the coverage audit: an offline or unbound agent means the machine is in the inventory but not actually being protected.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"machines":{"name":"machines","type":"\u0019\u001balicloud.sas.machine","title":"Machines Security Center is protecting","provider":"go.mondoo.com/mql/providers/alicloud"},"noticeConfig":{"name":"noticeConfig","type":"\u001balicloud.sas.noticeConfig","title":"Security Center notification setting","desc":"The notification routing for one kind of Security Center event, keyed by project (the event type, for example sas_suspicious or health). Exposes which channels the notification goes to and during which hours, so an event type routed nowhere is visible as an empty channels list.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"openTime":{"name":"openTime","type":"\t","title":"Time the subscription was activated","provider":"go.mondoo.com/mql/providers/alicloud"},"postPay":{"name":"postPay","type":"\u0004","title":"Whether the subscription is billed pay-as-you-go","provider":"go.mondoo.com/mql/providers/alicloud"},"propertySchedule":{"name":"propertySchedule","type":"\u001balicloud.sas.propertySchedule","title":"Security Center asset fingerprint schedule","desc":"The collection schedule for one kind of asset fingerprint, keyed by type. Exposes how often the fingerprint is collected and when the next collection is due, so a fingerprint kind that is never collected is visible rather than simply reporting no data.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"trialVersion":{"name":"trialVersion","type":"\u0004","title":"Whether the current subscription is a trial","provider":"go.mondoo.com/mql/providers/alicloud"},"version":{"name":"version","type":"\u0005","title":"Subscription edition code","desc":"Higher codes carry more detection capability, with 1 for the free basic edition. Zero when the service has never been subscribed.","provider":"go.mondoo.com/mql/providers/alicloud"},"vulnerabilities":{"name":"vulnerabilities","type":"\u0019\u001balicloud.sas.vulnerability","title":"Vulnerabilities found across the protected machines, grouped by vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"vulnerability":{"name":"vulnerability","type":"\u001balicloud.sas.vulnerability","title":"Vulnerability found by Security Center","desc":"A vulnerability seen across the protected machines, keyed by its type and name. The counts break the affected machines down by remediation urgency, so asapCount is the number that Security Center judges must be fixed immediately.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vulnerabilityConfig":{"name":"vulnerabilityConfig","type":"\u001balicloud.sas.vulnerabilityConfig","title":"Security Center vulnerability scan setting","desc":"The scan setting for one vulnerability type, keyed by type. Exposes whether scanning for that type is switched on and the type-specific value behind it, so a type left off is visible even though the others are scanned.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"webPath":{"name":"webPath","type":"\u001balicloud.sas.webPath","title":"Webshell detection path","desc":"A single directory webshell detection covers, keyed by the path. Exposes the path, how it was configured, and the machines or groups it applies to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Security Center","desc":"Threat detection and posture management for the account. Exposes the subscription edition and quota, the protected machines and whether their agents are reporting, the vulnerabilities and baseline check failures found across them, and the alerts raised by threat detection.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.alarmEvent":{"id":"alicloud.sas.alarmEvent","name":"alicloud.sas.alarmEvent","fields":{"alarmEventName":{"name":"alarmEventName","type":"\u0007","is_mandatory":true,"title":"Alert name","provider":"go.mondoo.com/mql/providers/alicloud"},"alarmEventType":{"name":"alarmEventType","type":"\u0007","is_mandatory":true,"title":"Alert type","provider":"go.mondoo.com/mql/providers/alicloud"},"autoBreaking":{"name":"autoBreaking","type":"\u0004","is_mandatory":true,"title":"Whether the alert triggered automatic containment","provider":"go.mondoo.com/mql/providers/alicloud"},"canBeDealOnLine":{"name":"canBeDealOnLine","type":"\u0004","is_mandatory":true,"title":"Whether the alert can be handled from the console","provider":"go.mondoo.com/mql/providers/alicloud"},"containerId":{"name":"containerId","type":"\u0007","is_mandatory":true,"title":"ID of the affected container","provider":"go.mondoo.com/mql/providers/alicloud"},"containerImageName":{"name":"containerImageName","type":"\u0007","is_mandatory":true,"title":"Image the affected container was started from","provider":"go.mondoo.com/mql/providers/alicloud"},"dataSource":{"name":"dataSource","type":"\u0007","is_mandatory":true,"title":"Detection engine that raised the alert","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of what was detected","provider":"go.mondoo.com/mql/providers/alicloud"},"eventStatus":{"name":"eventStatus","type":"\u0005","is_mandatory":true,"title":"Handling state of the alert","desc":"A non-zero value marks the alert as still outstanding.","provider":"go.mondoo.com/mql/providers/alicloud"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Event ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the affected instance","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Name of the affected instance","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address of the affected machine","provider":"go.mondoo.com/mql/providers/alicloud"},"intranetIp":{"name":"intranetIp","type":"\u0007","is_mandatory":true,"title":"Private IP address of the affected machine","provider":"go.mondoo.com/mql/providers/alicloud"},"k8sClusterId":{"name":"k8sClusterId","type":"\u0007","is_mandatory":true,"title":"ID of the Kubernetes cluster the alert came from","provider":"go.mondoo.com/mql/providers/alicloud"},"k8sNamespace":{"name":"k8sNamespace","type":"\u0007","is_mandatory":true,"title":"Kubernetes namespace the alert came from","provider":"go.mondoo.com/mql/providers/alicloud"},"k8sPodName":{"name":"k8sPodName","type":"\u0007","is_mandatory":true,"title":"Kubernetes pod the alert came from","provider":"go.mondoo.com/mql/providers/alicloud"},"lastTime":{"name":"lastTime","type":"\t","is_mandatory":true,"title":"Time the activity behind the alert was last seen","provider":"go.mondoo.com/mql/providers/alicloud"},"level":{"name":"level","type":"\u0007","is_mandatory":true,"title":"Alert severity","desc":"One of serious, suspicious, or remind.","provider":"go.mondoo.com/mql/providers/alicloud"},"machine":{"name":"machine","type":"\u001balicloud.sas.machine","title":"Machine the alert was raised against","desc":"Null when the alert carries no asset UUID, which is the case for alerts raised against the account rather than a specific machine.","provider":"go.mondoo.com/mql/providers/alicloud"},"occurrenceTime":{"name":"occurrenceTime","type":"\t","is_mandatory":true,"title":"Time the activity behind the alert first occurred","provider":"go.mondoo.com/mql/providers/alicloud"},"stages":{"name":"stages","type":"\u0007","is_mandatory":true,"title":"Attack stages the alert maps to","provider":"go.mondoo.com/mql/providers/alicloud"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Security Center asset UUID of the affected machine","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alert raised by Security Center threat detection","desc":"A single alert, keyed by its event ID. Exposes what was detected, where, and whether it has been handled, along with the container and Kubernetes context when the alert came from a containerized workload.","min_provider_version":"13.2.5","defaults":"alarmEventName level eventStatus instanceName","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.baselineCheck":{"id":"alicloud.sas.baselineCheck","name":"alicloud.sas.baselineCheck","fields":{"checkCount":{"name":"checkCount","type":"\u0005","is_mandatory":true,"title":"Number of times the check has been run","provider":"go.mondoo.com/mql/providers/alicloud"},"checkExploit":{"name":"checkExploit","type":"\u0004","is_mandatory":true,"title":"Whether a known exploit exists for the condition the check detects","provider":"go.mondoo.com/mql/providers/alicloud"},"containerRisk":{"name":"containerRisk","type":"\u0004","is_mandatory":true,"title":"Whether the check applies to container workloads","provider":"go.mondoo.com/mql/providers/alicloud"},"databaseRisk":{"name":"databaseRisk","type":"\u0004","is_mandatory":true,"title":"Whether the check applies to databases","provider":"go.mondoo.com/mql/providers/alicloud"},"highWarningCount":{"name":"highWarningCount","type":"\u0005","is_mandatory":true,"title":"Number of high-severity failures of the check","provider":"go.mondoo.com/mql/providers/alicloud"},"lastFoundTime":{"name":"lastFoundTime","type":"\t","is_mandatory":true,"title":"Time the failure was last observed","provider":"go.mondoo.com/mql/providers/alicloud"},"level":{"name":"level","type":"\u0007","is_mandatory":true,"title":"Severity of the check","desc":"One of high, medium, or low.","provider":"go.mondoo.com/mql/providers/alicloud"},"lowWarningCount":{"name":"lowWarningCount","type":"\u0005","is_mandatory":true,"title":"Number of low-severity failures of the check","provider":"go.mondoo.com/mql/providers/alicloud"},"mediumWarningCount":{"name":"mediumWarningCount","type":"\u0005","is_mandatory":true,"title":"Number of medium-severity failures of the check","provider":"go.mondoo.com/mql/providers/alicloud"},"riskId":{"name":"riskId","type":"\u0005","is_mandatory":true,"title":"Baseline check ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"riskName":{"name":"riskName","type":"\u0007","is_mandatory":true,"title":"Name of the baseline check","provider":"go.mondoo.com/mql/providers/alicloud"},"subTypeAlias":{"name":"subTypeAlias","type":"\u0007","is_mandatory":true,"title":"Subcategory of the baseline check","provider":"go.mondoo.com/mql/providers/alicloud"},"typeAlias":{"name":"typeAlias","type":"\u0007","is_mandatory":true,"title":"Category of the baseline check","provider":"go.mondoo.com/mql/providers/alicloud"},"warningMachineCount":{"name":"warningMachineCount","type":"\u0005","is_mandatory":true,"title":"Number of machines currently failing the check","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Baseline check failure found by Security Center","desc":"A configuration baseline check that machines are failing, keyed by riskId. Exposes how many machines fail the check and the severity split of those failures, so a check with a high warningMachineCount is a systemic misconfiguration rather than a one-off.","min_provider_version":"13.2.5","defaults":"riskName level warningMachineCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.config":{"id":"alicloud.sas.config","name":"alicloud.sas.config","fields":{"configAssessmentAutoAddEnabled":{"name":"configAssessmentAutoAddEnabled","type":"\u0004","is_mandatory":true,"title":"Whether newly added assets are automatically brought into configuration assessment","desc":"False when a machine added after the schedule was set is assessed only once somebody adds it, so fleet growth quietly reduces coverage.","provider":"go.mondoo.com/mql/providers/alicloud"},"configAssessmentCycleDays":{"name":"configAssessmentCycleDays","type":"\u0019\u0005","is_mandatory":true,"title":"Days of the week the automatic configuration assessment runs","desc":"Empty when no automatic assessment is scheduled.","provider":"go.mondoo.com/mql/providers/alicloud"},"configAssessmentEnabled":{"name":"configAssessmentEnabled","type":"\u0004","is_mandatory":true,"title":"Whether configuration assessment runs automatically on a schedule","desc":"False when assessment only runs when somebody starts it by hand, which means the reported baseline results can be arbitrarily stale.","provider":"go.mondoo.com/mql/providers/alicloud"},"configAssessmentStandards":{"name":"configAssessmentStandards","type":"\u0019\u0007","is_mandatory":true,"title":"Baseline standards the configuration assessment applies","desc":"Empty when no standard is selected, in which case the assessment has nothing to check against.","provider":"go.mondoo.com/mql/providers/alicloud"},"noticeConfigs":{"name":"noticeConfigs","type":"\u0019\u001balicloud.sas.noticeConfig","title":"Where Security Center sends each kind of notification","provider":"go.mondoo.com/mql/providers/alicloud"},"propertySchedules":{"name":"propertySchedules","type":"\u0019\u001balicloud.sas.propertySchedule","title":"Asset fingerprint collection schedules, one entry per fingerprint kind","provider":"go.mondoo.com/mql/providers/alicloud"},"virusScanEnabled":{"name":"virusScanEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the scheduled antivirus scan is switched on","desc":"This is the scheduled scan, not real-time protection. Reports false when the account has never configured one.","provider":"go.mondoo.com/mql/providers/alicloud"},"virusScanInterval":{"name":"virusScanInterval","type":"\u0005","is_mandatory":true,"title":"How often the scheduled antivirus scan runs","desc":"Read together with virusScanPeriodUnit, which gives the unit. Zero when no scan is scheduled.","provider":"go.mondoo.com/mql/providers/alicloud"},"virusScanPaths":{"name":"virusScanPaths","type":"\u0019\u0007","is_mandatory":true,"title":"Directories the scheduled antivirus scan covers","desc":"Empty when the scan covers the default scope rather than named paths.","provider":"go.mondoo.com/mql/providers/alicloud"},"virusScanPeriodUnit":{"name":"virusScanPeriodUnit","type":"\u0007","is_mandatory":true,"title":"Unit of the antivirus scan interval, for example day","desc":"Empty when no scan is scheduled.","provider":"go.mondoo.com/mql/providers/alicloud"},"virusScanType":{"name":"virusScanType","type":"\u0007","is_mandatory":true,"title":"Scope of the scheduled antivirus scan","desc":"Empty when no scan is scheduled.","provider":"go.mondoo.com/mql/providers/alicloud"},"vulnerabilityConfigs":{"name":"vulnerabilityConfigs","type":"\u0019\u001balicloud.sas.vulnerabilityConfig","title":"Vulnerability scan settings, one entry per vulnerability type","provider":"go.mondoo.com/mql/providers/alicloud"},"webPaths":{"name":"webPaths","type":"\u0019\u001balicloud.sas.webPath","title":"Directories webshell detection covers","desc":"Webshell detection only inspects the directories listed here, so a web server whose document root is absent is not being checked at all.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Security Center settings","desc":"The account-level Security Center configuration behind the detections: the antivirus scan schedule, the configuration assessment schedule, the directories webshell detection covers, where alerts are routed, the vulnerability scan settings per vulnerability type, and how often asset fingerprints are collected. A machine can sit in the inventory reporting no findings because a scan it needed was never scheduled, which the machine inventory alone does not show.","private":true,"min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.logDelivery":{"id":"alicloud.sas.logDelivery","name":"alicloud.sas.logDelivery","fields":{"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Category of log the entry covers","desc":"One of host (host logs), network (network logs), or security (security logs).","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Name of the log type, for example Login","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether delivery of this log type to Log Service is switched on","provider":"go.mondoo.com/mql/providers/alicloud"},"logProject":{"name":"logProject","type":"\u001balicloud.log.project","title":"Log Service project the logs are delivered to","desc":"Null when the account has no dedicated project or it can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"logstoreName":{"name":"logstoreName","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service logstore in the account the logs are delivered to","desc":"Empty when the account has no dedicated logstore for this log type.","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service project in the account the logs are delivered to","desc":"Empty when the account has no dedicated project for Security Center logs.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the logs are delivered to","provider":"go.mondoo.com/mql/providers/alicloud"},"topic":{"name":"topic","type":"\u0007","is_mandatory":true,"title":"Log topic, used as the lookup key, for example aegis-log-login","provider":"go.mondoo.com/mql/providers/alicloud"},"ttlDays":{"name":"ttlDays","type":"\u0005","is_mandatory":true,"title":"Days the delivered logs are retained","desc":"Zero when the entry reports no retention window.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Security Center log analysis delivery","desc":"The log analysis configuration for a single Security Center log type, keyed by topic (for example aegis-log-login). Exposes the category the log type belongs to, whether delivery to Log Service is switched on, the destination project and logstore, and how long the delivered logs are kept. A category left switched off means Security Center detects against those events but keeps no searchable record of them.","min_provider_version":"13.5.1","defaults":"topic category enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.machine":{"id":"alicloud.sas.machine","name":"alicloud.sas.machine","fields":{"alarmStatus":{"name":"alarmStatus","type":"\u0007","is_mandatory":true,"title":"Whether the machine has outstanding alerts","provider":"go.mondoo.com/mql/providers/alicloud"},"assetTypeName":{"name":"assetTypeName","type":"\u0007","is_mandatory":true,"title":"Asset type, for example ECS or a non-Alibaba Cloud server","provider":"go.mondoo.com/mql/providers/alicloud"},"authVersionName":{"name":"authVersionName","type":"\u0007","is_mandatory":true,"title":"Protection edition applied to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"bind":{"name":"bind","type":"\u0004","is_mandatory":true,"title":"Whether the machine is bound to the Security Center subscription","desc":"False when the machine falls outside the purchased asset quota, so its findings are reported but protection is not applied.","provider":"go.mondoo.com/mql/providers/alicloud"},"clientStatus":{"name":"clientStatus","type":"\u0007","is_mandatory":true,"title":"Security Center agent state","desc":"Online when the agent is reporting, Offline when it has stopped, and Uninstalled when no agent is present. Anything other than Online means the machine is in the inventory without being protected.","provider":"go.mondoo.com/mql/providers/alicloud"},"clusterId":{"name":"clusterId","type":"\u0007","is_mandatory":true,"title":"ID of the Kubernetes cluster the machine belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the machine was added to the inventory","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the machine","desc":"Null when the machine is not an Alibaba Cloud ECS instance, which is the case for servers onboarded from another cloud or from on-premises.","provider":"go.mondoo.com/mql/providers/alicloud"},"exposedStatus":{"name":"exposedStatus","type":"\u0005","is_mandatory":true,"title":"Whether the machine is exposed to the internet","desc":"Non-zero when Security Center's exposure analysis found an internet-facing path to the machine.","provider":"go.mondoo.com/mql/providers/alicloud"},"groupTrace":{"name":"groupTrace","type":"\u0007","is_mandatory":true,"title":"Group the machine is filed under in the Security Center console","provider":"go.mondoo.com/mql/providers/alicloud"},"healthCheckCount":{"name":"healthCheckCount","type":"\u0005","is_mandatory":true,"title":"Number of baseline check failures on the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"importance":{"name":"importance","type":"\u0005","is_mandatory":true,"title":"Asset importance, where higher values mark more critical assets","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the underlying instance","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceName":{"name":"instanceName","type":"\u0007","is_mandatory":true,"title":"Name of the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address of the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"intranetIp":{"name":"intranetIp","type":"\u0007","is_mandatory":true,"title":"Private IP address of the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"lastLoginTime":{"name":"lastLoginTime","type":"\t","is_mandatory":true,"title":"Time of the last recorded sign-in to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"os":{"name":"os","type":"\u0007","is_mandatory":true,"title":"Operating system family, for example linux or windows","provider":"go.mondoo.com/mql/providers/alicloud"},"osName":{"name":"osName","type":"\u0007","is_mandatory":true,"title":"Operating system name and version","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the machine runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"riskCount":{"name":"riskCount","type":"\u0007","is_mandatory":true,"title":"Number of outstanding risks attributed to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"riskStatus":{"name":"riskStatus","type":"\u0007","is_mandatory":true,"title":"Whether the machine has outstanding risks","provider":"go.mondoo.com/mql/providers/alicloud"},"safeEventCount":{"name":"safeEventCount","type":"\u0005","is_mandatory":true,"title":"Number of security events recorded against the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Security Center asset UUID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vendorName":{"name":"vendorName","type":"\u0007","is_mandatory":true,"title":"Cloud vendor hosting the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"vulCount":{"name":"vulCount","type":"\u0005","is_mandatory":true,"title":"Number of unfixed vulnerabilities attributed to the machine","provider":"go.mondoo.com/mql/providers/alicloud"},"vulStatus":{"name":"vulStatus","type":"\u0007","is_mandatory":true,"title":"Whether the machine has outstanding vulnerabilities","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Machine protected by Security Center","desc":"A single asset in the Security Center inventory, keyed by uuid. Exposes the agent state, the vulnerability and risk counts attributed to the machine, and its network addresses. The clientStatus field is the coverage audit: an offline or unbound agent means the machine is in the inventory but not actually being protected.","min_provider_version":"13.2.5","defaults":"instanceName clientStatus vulCount riskCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.noticeConfig":{"id":"alicloud.sas.noticeConfig","name":"alicloud.sas.noticeConfig","fields":{"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Severity or grouping the event type belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"channels":{"name":"channels","type":"\u0019\u0007","is_mandatory":true,"title":"Channels the notification is sent through","desc":"Any of sms, email, and internal. An empty list means the event type raises no notification at all.","provider":"go.mondoo.com/mql/providers/alicloud"},"project":{"name":"project","type":"\u0007","is_mandatory":true,"title":"Event type the setting covers, used as the lookup key","desc":"For example sas_suspicious (suspicious events), remotelogin (remote logons), or health (security checks).","provider":"go.mondoo.com/mql/providers/alicloud"},"route":{"name":"route","type":"\u0005","is_mandatory":true,"title":"Raw channel code the API reports","desc":"A bit field where 1 is text message, 2 is email, and 4 is internal message, so 7 is all three. Zero means no channel.","provider":"go.mondoo.com/mql/providers/alicloud"},"timeLimit":{"name":"timeLimit","type":"\u0005","is_mandatory":true,"title":"Hours during which notifications are sent","desc":"0 for any time, or 1 for 08:00 to 22:00 only, in which case an event raised overnight is not notified until the morning.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Security Center notification setting","desc":"The notification routing for one kind of Security Center event, keyed by project (the event type, for example sas_suspicious or health). Exposes which channels the notification goes to and during which hours, so an event type routed nowhere is visible as an empty channels list.","min_provider_version":"13.5.1","defaults":"project channels","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.propertySchedule":{"id":"alicloud.sas.propertySchedule","name":"alicloud.sas.propertySchedule","fields":{"nextScheduleTime":{"name":"nextScheduleTime","type":"\t","is_mandatory":true,"title":"Time the next collection is due","desc":"Null when no schedule is configured for the kind.","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduleHours":{"name":"scheduleHours","type":"\u0005","is_mandatory":true,"title":"Hours between collections","desc":"For example 12 for twice a day, 24 for daily, or 168 for weekly. Zero when no schedule is configured for the kind.","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Fingerprint kind the schedule covers, used as the lookup key","desc":"One of scheduler_software_period (software), scheduler_cron_period (scheduled tasks), scheduler_sca_period (middleware), scheduler_autorun_period (startup items), scheduler_lkm_period (kernel modules), or scheduler_sca_proxy_period (websites).","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Security Center asset fingerprint schedule","desc":"The collection schedule for one kind of asset fingerprint, keyed by type. Exposes how often the fingerprint is collected and when the next collection is due, so a fingerprint kind that is never collected is visible rather than simply reporting no data.","min_provider_version":"13.5.1","defaults":"type scheduleHours","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.vulnerability":{"id":"alicloud.sas.vulnerability","name":"alicloud.sas.vulnerability","fields":{"aliasName":{"name":"aliasName","type":"\u0007","is_mandatory":true,"title":"Human-readable vulnerability title","provider":"go.mondoo.com/mql/providers/alicloud"},"asapCount":{"name":"asapCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines Security Center rates fix-immediately","provider":"go.mondoo.com/mql/providers/alicloud"},"handledCount":{"name":"handledCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines where the vulnerability has been handled","provider":"go.mondoo.com/mql/providers/alicloud"},"lastFoundTime":{"name":"lastFoundTime","type":"\t","is_mandatory":true,"title":"Time the vulnerability was last seen","provider":"go.mondoo.com/mql/providers/alicloud"},"laterCount":{"name":"laterCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines Security Center rates fix-later","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Vulnerability identifier, for example a CVE or advisory ID","provider":"go.mondoo.com/mql/providers/alicloud"},"nntfCount":{"name":"nntfCount","type":"\u0005","is_mandatory":true,"title":"Number of affected machines Security Center rates no-fix-required","provider":"go.mondoo.com/mql/providers/alicloud"},"raspDefend":{"name":"raspDefend","type":"\u0005","is_mandatory":true,"title":"Whether application self-protection can defend the vulnerability at runtime","desc":"Non-zero when runtime defense covers the vulnerability, which mitigates it without a patch.","provider":"go.mondoo.com/mql/providers/alicloud"},"related":{"name":"related","type":"\u0007","is_mandatory":true,"title":"Related vulnerability identifiers","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u0007","is_mandatory":true,"title":"Tags describing the vulnerability, for example whether an exploit exists","provider":"go.mondoo.com/mql/providers/alicloud"},"totalFixCount":{"name":"totalFixCount","type":"\u0005","is_mandatory":true,"title":"Total number of successful fixes recorded for the vulnerability","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Vulnerability category","desc":"One of cve for Linux software vulnerabilities, sys for Windows system vulnerabilities, cms for web content management vulnerabilities, app for application vulnerabilities, emg for urgent vulnerabilities, or sca for software component analysis findings.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Vulnerability found by Security Center","desc":"A vulnerability seen across the protected machines, keyed by its type and name. The counts break the affected machines down by remediation urgency, so asapCount is the number that Security Center judges must be fixed immediately.","min_provider_version":"13.2.5","defaults":"name aliasName type asapCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.vulnerabilityConfig":{"id":"alicloud.sas.vulnerabilityConfig","name":"alicloud.sas.vulnerabilityConfig","fields":{"config":{"name":"config","type":"\u0007","is_mandatory":true,"title":"Type-specific setting value","desc":"The meaning depends on type: a scan scope for the scan types, or a retention period in days when type is imageVulClean.","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether scanning for the type is switched on","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Vulnerability type the setting covers, used as the lookup key","desc":"One of cve (system vulnerabilities), sca (application vulnerabilities found by version fingerprint), app (web scanner findings), emg (emergency vulnerabilities), scanMode (whether only real-risk vulnerabilities are shown), imageVulClean (the retention period for image vulnerabilities), or yum (whether Alibaba Cloud sources are preferred when fixing).","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Security Center vulnerability scan setting","desc":"The scan setting for one vulnerability type, keyed by type. Exposes whether scanning for that type is switched on and the type-specific value behind it, so a type left off is visible even though the others are scanned.","min_provider_version":"13.5.1","defaults":"type enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.sas.webPath":{"id":"alicloud.sas.webPath","name":"alicloud.sas.webPath","fields":{"targets":{"name":"targets","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Machines and groups the path applies to, keyed by target","desc":"The value gives the kind of target, for example a single machine or a machine group.","provider":"go.mondoo.com/mql/providers/alicloud"},"webPath":{"name":"webPath","type":"\u0007","is_mandatory":true,"title":"Directory webshell detection covers, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"webPathType":{"name":"webPathType","type":"\u0007","is_mandatory":true,"title":"How the path was configured, for example a manually added or a detected path","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Webshell detection path","desc":"A single directory webshell detection covers, keyed by the path. Exposes the path, how it was configured, and the machines or groups it applies to.","min_provider_version":"13.5.1","defaults":"webPath webPathType","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb":{"id":"alicloud.slb","name":"alicloud.slb","fields":{"acl":{"name":"acl","type":"\u001balicloud.slb.acl","title":"Server Load Balancer access control list","desc":"A named list of addresses a CLB listener allows or denies, keyed by aclId within its region. Exposes the address entries and the listeners bound to the list. Use it to find an allowlist that admits every address, which leaves a listener open despite access control reading as enabled.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"acls":{"name":"acls","type":"\u0019\u001balicloud.slb.acl","title":"Access control lists across all enabled regions","desc":"An access control list holds the addresses a CLB listener allows or denies. A listener naming an allowlist that turns out to hold 0.0.0.0/0 is indistinguishable from an unrestricted listener, which the listener's own fields cannot show.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"backendServer":{"name":"backendServer","type":"\u001balicloud.slb.backendServer","title":"CLB backend server","desc":"One server a CLB forwards traffic to, whether attached directly to the load balancer or through a vServer group. An internet-facing CLB makes its backends reachable from the public internet on the listener's port, regardless of what the backend's own security groups say about its address, which is why the load balancer and not the instance is where that exposure becomes visible.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"listener":{"name":"listener","type":"\u001balicloud.slb.listener","title":"Server Load Balancer (CLB) listener","desc":"A single listener configured on a CLB instance, keyed by the composite of loadBalancerId, protocol, and listenerPort. Exposes the protocol and port mapping, the scheduling algorithm, the access-control (ACL) settings, and, for HTTPS listeners, the TLS cipher policy and the server and CA certificates. Protocol-specific health-check and forwarding settings are available through config.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.slb.loadBalancer","title":"Server Load Balancer (CLB) instance","desc":"A single Classic Load Balancer instance, keyed by loadBalancerId (for example lb-bp1b6c719dfa08ex). Exposes the instance addressing and network placement, the internet or intranet exposure signalled by addressType, the billing and specification settings, the deletion and modification protection flags, and the configured listeners and backend servers.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001balicloud.slb.loadBalancer","title":"CLB instances across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroup":{"name":"vServerGroup","type":"\u001balicloud.slb.vServerGroup","title":"CLB vServer group","desc":"A named set of backend servers that a CLB listener or forwarding rule sends traffic to, keyed by vServerGroupId. A group lets one load balancer serve several backend sets, so the servers behind a listener are found here rather than on the load balancer itself.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true}},"title":"Server Load Balancer","desc":"Classic Load Balancer (CLB) resources in an Alibaba Cloud account. Exposes the CLB instances discovered across every enabled region through loadBalancers, from which listeners, backend servers, addressing, and protection settings can be audited.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.acl":{"id":"alicloud.slb.acl","name":"alicloud.slb.acl","fields":{"aclId":{"name":"aclId","type":"\u0007","is_mandatory":true,"title":"Access control list ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"aclName":{"name":"aclName","type":"\u0007","is_mandatory":true,"title":"Name of the access control list","provider":"go.mondoo.com/mql/providers/alicloud"},"addressIPVersion":{"name":"addressIPVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the entries, either ipv4 or ipv6","provider":"go.mondoo.com/mql/providers/alicloud"},"allowsAllAddresses":{"name":"allowsAllAddresses","type":"\u0004","title":"Whether the list covers every address","desc":"True when an entry is 0.0.0.0/0 or ::/0. On a listener whose aclType is white this makes the allowlist a no-op, so access control reads as enabled while admitting the whole internet.","provider":"go.mondoo.com/mql/providers/alicloud"},"entries":{"name":"entries","type":"\u0019\u0007","title":"Address entries in the list, as CIDR blocks","provider":"go.mondoo.com/mql/providers/alicloud"},"entryCount":{"name":"entryCount","type":"\u0005","title":"Number of address entries in the list","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the list resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the list","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the list belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the list","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Server Load Balancer access control list","desc":"A named list of addresses a CLB listener allows or denies, keyed by aclId within its region. Exposes the address entries and the listeners bound to the list. Use it to find an allowlist that admits every address, which leaves a listener open despite access control reading as enabled.","min_provider_version":"13.5.1","defaults":"aclName aclId addressIPVersion entryCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.backendServer":{"id":"alicloud.slb.backendServer","name":"alicloud.slb.backendServer","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Backend server description","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsInstance":{"name":"ecsInstance","type":"\u001balicloud.ecs.instance","title":"ECS instance behind the backend","desc":"Null when the backend is an elastic network interface or the instance can no longer be read.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the load balancer forwards to","desc":"Zero for a backend attached directly to the load balancer, where the port comes from the listener instead.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"ID of the backend server","desc":"An ECS instance ID or an elastic network interface ID, depending on type.","provider":"go.mondoo.com/mql/providers/alicloud"},"serverIp":{"name":"serverIp","type":"\u0007","is_mandatory":true,"title":"IP address the load balancer forwards to","desc":"Set when the backend is an elastic network interface or is addressed by IP.","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Kind of backend","desc":"Either ecs for an instance or eni for an elastic network interface.","provider":"go.mondoo.com/mql/providers/alicloud"},"weight":{"name":"weight","type":"\u0005","is_mandatory":true,"title":"Share of traffic the server receives","desc":"A weight of 0 takes the server out of rotation without detaching it.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CLB backend server","desc":"One server a CLB forwards traffic to, whether attached directly to the load balancer or through a vServer group. An internet-facing CLB makes its backends reachable from the public internet on the listener's port, regardless of what the backend's own security groups say about its address, which is why the load balancer and not the instance is where that exposure becomes visible.","min_provider_version":"13.4.1","defaults":"type serverId serverIp port weight","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.listener":{"id":"alicloud.slb.listener","name":"alicloud.slb.listener","fields":{"aclId":{"name":"aclId","type":"\u0007","is_mandatory":true,"title":"ID of the access control list bound to the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"aclIds":{"name":"aclIds","type":"\u0019\u0007","is_mandatory":true,"title":"IDs of the access control lists bound to the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"aclStatus":{"name":"aclStatus","type":"\u0007","is_mandatory":true,"title":"Whether access control is enabled for the listener","desc":"One of on or off.","provider":"go.mondoo.com/mql/providers/alicloud"},"aclType":{"name":"aclType","type":"\u0007","is_mandatory":true,"title":"Type of access control applied when aclStatus is on","desc":"One of white (only requests from allowlisted addresses are forwarded) or black (requests from blocklisted addresses are denied).","provider":"go.mondoo.com/mql/providers/alicloud"},"acls":{"name":"acls","type":"\u0019\u001balicloud.slb.acl","title":"Access control lists bound to the listener","desc":"Empty when the listener names no list, and when the named lists could not be read. Traverse to allowsAllAddresses to tell an allowlist that restricts anything from one that admits every address.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"backendServerPort":{"name":"backendServerPort","type":"\u0005","is_mandatory":true,"title":"Backend server port that the listener forwards requests to","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Maximum bandwidth of the listener, in Mbit/s (-1 indicates unlimited)","provider":"go.mondoo.com/mql/providers/alicloud"},"caCertificateId":{"name":"caCertificateId","type":"\u0007","is_mandatory":true,"title":"ID of the CA certificate used for mutual TLS on an HTTPS listener","provider":"go.mondoo.com/mql/providers/alicloud"},"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Protocol-specific listener configuration","desc":"The health-check, session-persistence, connection-drain, and request-header settings for the listener. The available keys vary by protocol (HTTP, HTTPS, TCP, or UDP).","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the listener","provider":"go.mondoo.com/mql/providers/alicloud"},"enableHttp2":{"name":"enableHttp2","type":"\u0007","is_mandatory":true,"title":"Whether HTTP/2 is enabled on an HTTPS listener","desc":"One of on or off. Null for non-HTTPS listeners.","provider":"go.mondoo.com/mql/providers/alicloud"},"listenerPort":{"name":"listenerPort","type":"\u0005","is_mandatory":true,"title":"Frontend port on which the listener accepts requests","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancer":{"name":"loadBalancer","type":"\u001balicloud.slb.loadBalancer","title":"CLB instance that the listener belongs to","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the CLB instance that the listener belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Protocol used by the listener","desc":"One of http, https, tcp, or udp.","provider":"go.mondoo.com/mql/providers/alicloud"},"scheduler":{"name":"scheduler","type":"\u0007","is_mandatory":true,"title":"Scheduling algorithm used to distribute requests","desc":"One of wrr (weighted round-robin), rr (round-robin), sch (source-IP consistent hashing), tch (four-tuple consistent hashing), or qch (QUIC-ID consistent hashing).","provider":"go.mondoo.com/mql/providers/alicloud"},"serverCertificateId":{"name":"serverCertificateId","type":"\u0007","is_mandatory":true,"title":"ID of the server certificate bound to an HTTPS listener","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the listener","desc":"One of running or stopped.","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsCipherPolicy":{"name":"tlsCipherPolicy","type":"\u0007","is_mandatory":true,"title":"TLS security policy applied to an HTTPS listener","desc":"One of tls_cipher_policy_1_0, tls_cipher_policy_1_1, tls_cipher_policy_1_2, tls_cipher_policy_1_2_strict, or tls_cipher_policy_1_2_strict_with_1_3, each enabling a different set of TLS versions and cipher suites. Null for non-HTTPS listeners.","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroup":{"name":"vServerGroup","type":"\u001balicloud.slb.vServerGroup","title":"vServer group the listener forwards to","desc":"Null when the listener forwards to the load balancer's default backend servers rather than a group.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroupId":{"name":"vServerGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the vServer group associated with the listener","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Server Load Balancer (CLB) listener","desc":"A single listener configured on a CLB instance, keyed by the composite of loadBalancerId, protocol, and listenerPort. Exposes the protocol and port mapping, the scheduling algorithm, the access-control (ACL) settings, and, for HTTPS listeners, the TLS cipher policy and the server and CA certificates. Protocol-specific health-check and forwarding settings are available through config.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.loadBalancer":{"id":"alicloud.slb.loadBalancer","name":"alicloud.slb.loadBalancer","fields":{"address":{"name":"address","type":"\u0007","is_mandatory":true,"title":"Service IP address that the CLB instance uses to provide services","provider":"go.mondoo.com/mql/providers/alicloud"},"addressIPVersion":{"name":"addressIPVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the service address","desc":"One of ipv4 or ipv6.","provider":"go.mondoo.com/mql/providers/alicloud"},"addressType":{"name":"addressType","type":"\u0007","is_mandatory":true,"title":"Network exposure of the CLB instance","desc":"One of internet (a public IP address is assigned and requests are forwarded over the internet) or intranet (a private IP address is assigned and requests are forwarded only over internal networks).","provider":"go.mondoo.com/mql/providers/alicloud"},"backendServers":{"name":"backendServers","type":"\u0019\n","title":"Backend server summaries","desc":"Deprecated in favor of backends. Each entry carries the serverId, serverIp, weight, type (ecs or eni), and an optional description.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.slb.loadBalancer.backends"},"backends":{"name":"backends","type":"\u0019\u001balicloud.slb.backendServer","title":"Backend servers attached directly to the CLB instance","desc":"What the load balancer forwards to. An internet-facing CLB makes every one of these reachable from the public internet on the listener's port, whatever the backend's own security groups say about its address.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Maximum bandwidth of a pay-by-bandwidth internet-facing instance, in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time when the CLB instance was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deleteProtection":{"name":"deleteProtection","type":"\u0007","is_mandatory":true,"title":"Whether deletion protection is enabled","desc":"One of on or off.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method of the CLB instance","desc":"One of PayBySpec or PayByCLCU. Takes effect only for pay-as-you-go instances.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method of internet data transfer","desc":"One of paybybandwidth (pay-by-bandwidth) or paybytraffic (pay-by-data-transfer).","provider":"go.mondoo.com/mql/providers/alicloud"},"internetFacing":{"name":"internetFacing","type":"\u0004","title":"Whether the load balancer is reachable from the internet","desc":"True when addressType is internet, meaning the CLB has a public IP address and forwards requests from the public internet to its backend servers.","provider":"go.mondoo.com/mql/providers/alicloud"},"listeners":{"name":"listeners","type":"\u0019\u001balicloud.slb.listener","title":"Listeners configured on the CLB instance","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"CLB instance ID, for example lb-bp1b6c719dfa08ex","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerName":{"name":"loadBalancerName","type":"\u0007","is_mandatory":true,"title":"Name of the CLB instance","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerSpec":{"name":"loadBalancerSpec","type":"\u0007","is_mandatory":true,"title":"Specification of the CLB instance, for example slb.s1.small","desc":"Pay-as-you-go instances are not subject to specifications and report slb.lcu.elastic by default.","provider":"go.mondoo.com/mql/providers/alicloud"},"masterZoneId":{"name":"masterZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the primary zone, for example cn-hangzhou-b","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionReason":{"name":"modificationProtectionReason","type":"\u0007","is_mandatory":true,"title":"Reason recorded when the configuration read-only mode is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"modificationProtectionStatus":{"name":"modificationProtectionStatus","type":"\u0007","is_mandatory":true,"title":"Whether the configuration read-only (modification protection) mode is enabled","desc":"One of NonProtection (disabled) or ConsoleProtection (enabled, instance configuration cannot be changed in the console).","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type of an internal-facing CLB instance","desc":"One of vpc or classic.","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method of the CLB instance","desc":"One of PayOnDemand (pay-as-you-go) or PrePay (subscription).","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID where the CLB instance is deployed, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the load balancer","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group that the CLB instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"slaveZoneId":{"name":"slaveZoneId","type":"\u0007","is_mandatory":true,"title":"ID of the secondary zone, for example cn-hangzhou-d","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the CLB instance","desc":"One of active (running as expected), inactive (disabled, does not forward traffic), or locked (locked, for example after expiration or non-payment).","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the CLB instance, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroups":{"name":"vServerGroups","type":"\u0019\u001balicloud.slb.vServerGroup","title":"vServer groups defined on the CLB instance","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC that the CLB instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch that the CLB instance belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Server Load Balancer (CLB) instance","desc":"A single Classic Load Balancer instance, keyed by loadBalancerId (for example lb-bp1b6c719dfa08ex). Exposes the instance addressing and network placement, the internet or intranet exposure signalled by addressType, the billing and specification settings, the deletion and modification protection flags, and the configured listeners and backend servers.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.slb.vServerGroup":{"id":"alicloud.slb.vServerGroup","name":"alicloud.slb.vServerGroup","fields":{"backends":{"name":"backends","type":"\u0019\u001balicloud.slb.backendServer","title":"Backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the group was created","provider":"go.mondoo.com/mql/providers/alicloud"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the CLB instance the group belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region the group lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"serverCount":{"name":"serverCount","type":"\u0005","is_mandatory":true,"title":"Number of backend servers in the group","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the group","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroupId":{"name":"vServerGroupId","type":"\u0007","is_mandatory":true,"title":"vServer group ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vServerGroupName":{"name":"vServerGroupName","type":"\u0007","is_mandatory":true,"title":"vServer group name","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"CLB vServer group","desc":"A named set of backend servers that a CLB listener or forwarding rule sends traffic to, keyed by vServerGroupId. A group lets one load balancer serve several backend sets, so the servers behind a listener are found here rather than on the load balancer itself.","min_provider_version":"13.4.1","defaults":"vServerGroupName vServerGroupId serverCount","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc":{"id":"alicloud.vpc","name":"alicloud.vpc","fields":{"customerGateway":{"name":"customerGateway","type":"\u001balicloud.vpc.customerGateway","title":"VPN customer gateway","desc":"The remote end of a site-to-site VPN tunnel, keyed by customerGatewayId. Exposes the public address of the on-premises or third-party device and its BGP autonomous system number. The BGP authentication key is never exposed; authKeyConfigured reports only whether one is set.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"customerGateways":{"name":"customerGateways","type":"\u0019\u001balicloud.vpc.customerGateway","title":"Customer gateways across all enabled regions","desc":"A customer gateway represents the remote end of a site-to-site VPN tunnel: the public address of the on-premises or third-party device the VPC will establish a tunnel with.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"eipAddress":{"name":"eipAddress","type":"\u001balicloud.vpc.eipAddress","title":"Elastic IP address (EIP)","desc":"A single elastic IP address, keyed by allocationId, for example eip-2zeerraiwb7uabc. Exposes the public IP address, the bandwidth and billing configuration, the ISP line, the lifecycle status, and the instance the EIP is bound to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"eipAddresses":{"name":"eipAddresses","type":"\u0019\u001balicloud.vpc.eipAddress","title":"Elastic IP addresses across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLog":{"name":"flowLog","type":"\u001balicloud.vpc.flowLog","title":"VPC flow log","desc":"A single flow log that captures traffic metadata for a VPC, vSwitch, or elastic network interface, keyed by flowLogId within its region. Exposes the monitored resource, the traffic direction and path captured, and the Log Service project and logstore that receive the records. Use it to audit whether flow logging is enabled for a network and where the records are delivered. For example `alicloud.vpc.flowLog(flowLogId: \"fl-xxx\", regionId: \"cn-hangzhou\")`.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"flowLogs":{"name":"flowLogs","type":"\u0019\u001balicloud.vpc.flowLog","title":"Flow logs across all enabled regions","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"natGateway":{"name":"natGateway","type":"\u001balicloud.vpc.natGateway","title":"VPC NAT gateway","desc":"A single NAT gateway, keyed by natGatewayId, for example ngw-bp1uewa15k4abc. Exposes the specification, the NAT type and network type, the lifecycle and billing status, the SNAT and DNAT table IDs, and the private-network placement.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"natGateways":{"name":"natGateways","type":"\u0019\u001balicloud.vpc.natGateway","title":"NAT gateways across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"network":{"name":"network","type":"\u001balicloud.vpc.network","title":"Virtual Private Cloud network","desc":"A single VPC, keyed by vpcId, for example vpc-bp1qpo0kug3a20qqe0abc. Exposes the primary and secondary CIDR blocks, the IPv6 configuration, the lifecycle status, the default-VPC flag, the vRouter, and the vSwitches, route tables, and NAT gateways associated with the network.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"networkAcl":{"name":"networkAcl","type":"\u001balicloud.vpc.networkAcl","title":"VPC network ACL","desc":"A single network ACL, keyed by networkAclId, for example nacl-a2do9e413e0spzasx. Exposes the lifecycle status, the ingress and egress rule entries, and the vSwitches the ACL is bound to.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"networkAcls":{"name":"networkAcls","type":"\u0019\u001balicloud.vpc.networkAcl","title":"Network ACLs across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"networks":{"name":"networks","type":"\u0019\u001balicloud.vpc.network","title":"VPC networks across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"physicalConnection":{"name":"physicalConnection","type":"\u001balicloud.vpc.physicalConnection","title":"Express Connect physical connection","desc":"A leased-line circuit into Alibaba Cloud, keyed by physicalConnectionId. Exposes the circuit status, capacity, access point and carrier, along with the virtual border routers that hand its traffic to the Alibaba Cloud side. Traffic over the circuit never touches the internet, so no internet-facing control sees it.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"physicalConnections":{"name":"physicalConnections","type":"\u0019\u001balicloud.vpc.physicalConnection","title":"Express Connect physical connections across all enabled regions","desc":"A leased-line circuit into Alibaba Cloud. Traffic over it bypasses the internet entirely, so no internet-facing control sees it, and the routes it carries reach the VPC through its virtual border routers.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTable":{"name":"routeTable","type":"\u001balicloud.vpc.routeTable","title":"VPC route table","desc":"A single route table, keyed by routeTableId, for example vtb-bp1e123abc. Exposes the route table type, the bound vSwitches and gateways, the lifecycle status, and the individual route entries through routeEntries.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"routeTables":{"name":"routeTables","type":"\u0019\u001balicloud.vpc.routeTable","title":"Route tables across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnClientCert":{"name":"sslVpnClientCert","type":"\u001balicloud.vpc.sslVpnClientCert","title":"SSL VPN client certificate","desc":"A client certificate issued for an SSL VPN server, keyed by sslVpnClientCertId. Exposes the certificate lifecycle and expiry. The private key is never exposed. Use it to find certificates that have expired without being revoked, or that are close to expiry.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"sslVpnServer":{"name":"sslVpnServer","type":"\u001balicloud.vpc.sslVpnServer","title":"SSL VPN server","desc":"An SSL VPN server on a VPN gateway, keyed by sslVpnServerId. Exposes the client address pool, the subnets it publishes to clients, the transport and cipher, the connection limit, and whether a second authentication factor is demanded. Use it to find a remote-access path into a VPC that clients reach with a certificate alone.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"sslVpnServers":{"name":"sslVpnServers","type":"\u0019\u001balicloud.vpc.sslVpnServer","title":"SSL VPN servers across all enabled regions","desc":"An SSL VPN server admits individual client machines into the VPC over TLS, which is a different ingress path from the site-to-site IPsec tunnels that vpnConnections covers, and one that reaches the VPC from any address a client certificate is installed on.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"virtualBorderRouter":{"name":"virtualBorderRouter","type":"\u001balicloud.vpc.virtualBorderRouter","title":"Virtual border router","desc":"The routed hand-off between an Express Connect circuit and the Alibaba Cloud side, keyed by vbrId. Exposes both gateway addresses of the peering, the VLAN it runs on, the BFD settings, and which circuit it attaches to. Use it to find a router attached to a circuit owned by another account, which is a path into the network from outside this account's control.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"virtualBorderRouters":{"name":"virtualBorderRouters","type":"\u0019\u001balicloud.vpc.virtualBorderRouter","title":"Virtual border routers across all enabled regions","desc":"The routed hand-off between a physical connection and the Alibaba Cloud side. A router whose physical connection is owned by another account is a path into the VPC from outside this account's control.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnConnection":{"name":"vpnConnection","type":"\u001balicloud.vpc.vpnConnection","title":"VPN connection","desc":"A single IPsec tunnel terminating on a VPN gateway, keyed by vpnConnectionId. The local and remote subnets are the reachability this connection creates: traffic from the remote subnet reaches the local one without crossing an internet gateway. The negotiated algorithms and lifetimes are exposed so weak cipher suites can be found, but the pre-shared key is deliberately not.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpnConnections":{"name":"vpnConnections","type":"\u0019\u001balicloud.vpc.vpnConnection","title":"VPN connections across all enabled regions","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGateway":{"name":"vpnGateway","type":"\u001balicloud.vpc.vpnGateway","title":"VPN gateway","desc":"A VPN gateway attached to a VPC, keyed by vpnGatewayId. Exposes the IPsec and SSL capabilities, the public address traffic arrives on, and the connections terminating on it. A gateway is how traffic reaches the VPC from outside Alibaba Cloud, so its connections describe reachability that security groups alone do not explain.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vpnGateways":{"name":"vpnGateways","type":"\u0019\u001balicloud.vpc.vpnGateway","title":"VPN gateways across all enabled regions","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch (VPC subnet)","desc":"A single vSwitch, keyed by vSwitchId, for example vsw-25bcdxs7pv1abc. Exposes the CIDR blocks, the zone, the number of free IP addresses, the associated route table and network ACL, and the parent VPC.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches (subnets) across all enabled regions","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Virtual Private Cloud (VPC)","desc":"Entry point for the Alibaba Cloud VPC networking service. Exposes the VPCs, vSwitches, route tables, NAT gateways, elastic IP addresses, and network ACLs defined across every enabled region on the account.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.customerGateway":{"id":"alicloud.vpc.customerGateway","name":"alicloud.vpc.customerGateway","fields":{"asn":{"name":"asn","type":"\u0005","is_mandatory":true,"title":"BGP autonomous system number of the remote device, 0 when BGP is not used","provider":"go.mondoo.com/mql/providers/alicloud"},"authKeyConfigured":{"name":"authKeyConfigured","type":"\u0004","is_mandatory":true,"title":"Whether a BGP authentication key is configured","desc":"The key itself is a shared secret and is never exposed. False means BGP sessions with this peer are unauthenticated, so a peer that can reach the address can inject routes.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the gateway was registered","provider":"go.mondoo.com/mql/providers/alicloud"},"customerGatewayId":{"name":"customerGatewayId","type":"\u0007","is_mandatory":true,"title":"Customer gateway ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"ipAddress":{"name":"ipAddress","type":"\u0007","is_mandatory":true,"title":"Public IP address of the remote device","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the gateway is registered in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the gateway","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPN customer gateway","desc":"The remote end of a site-to-site VPN tunnel, keyed by customerGatewayId. Exposes the public address of the on-premises or third-party device and its BGP autonomous system number. The BGP authentication key is never exposed; authKeyConfigured reports only whether one is set.","min_provider_version":"13.5.1","defaults":"name customerGatewayId ipAddress","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.eipAddress":{"id":"alicloud.vpc.eipAddress","name":"alicloud.vpc.eipAddress","fields":{"allocationId":{"name":"allocationId","type":"\u0007","is_mandatory":true,"title":"Allocation ID of the EIP, for example eip-2zeerraiwb7uabc","provider":"go.mondoo.com/mql/providers/alicloud"},"allocationTime":{"name":"allocationTime","type":"\t","is_mandatory":true,"title":"Time when the EIP was allocated","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0007","is_mandatory":true,"title":"Peak bandwidth of the EIP in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageBandwidth":{"name":"bandwidthPackageBandwidth","type":"\u0007","is_mandatory":true,"title":"Maximum bandwidth of the bandwidth plan in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageId":{"name":"bandwidthPackageId","type":"\u0007","is_mandatory":true,"title":"ID of the bandwidth plan (shared bandwidth) the EIP joined","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidthPackageType":{"name":"bandwidthPackageType","type":"\u0007","is_mandatory":true,"title":"Type of the bandwidth plan the EIP joined","provider":"go.mondoo.com/mql/providers/alicloud"},"bizType":{"name":"bizType","type":"\u0007","is_mandatory":true,"title":"Business type of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (payment) status of the EIP","desc":"One of Normal or FinancialLocked.","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the EIP","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"eipBandwidth":{"name":"eipBandwidth","type":"\u0007","is_mandatory":true,"title":"Maximum bandwidth of the EIP in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"expiredTime":{"name":"expiredTime","type":"\t","is_mandatory":true,"title":"Time when the EIP expires","provider":"go.mondoo.com/mql/providers/alicloud"},"hasReservationData":{"name":"hasReservationData","type":"\u0007","is_mandatory":true,"title":"Whether the EIP has renewal (reservation) data","provider":"go.mondoo.com/mql/providers/alicloud"},"hdMonitorStatus":{"name":"hdMonitorStatus","type":"\u0007","is_mandatory":true,"title":"High-definition monitoring status of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the instance the EIP is bound to","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceRegionId":{"name":"instanceRegionId","type":"\u0007","is_mandatory":true,"title":"Region ID of the instance the EIP is bound to","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceType":{"name":"instanceType","type":"\u0007","is_mandatory":true,"title":"Type of the instance the EIP is bound to","desc":"One of EcsInstance, SlbInstance, Nat, HaVip, NetworkInterface, or IpAddress.","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method for internet data transfer","desc":"One of PayByBandwidth or PayByTraffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipAddress":{"name":"ipAddress","type":"\u0007","is_mandatory":true,"title":"Public IP address of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"isp":{"name":"isp","type":"\u0007","is_mandatory":true,"title":"ISP line of the EIP","desc":"One of BGP, BGP_PRO, ChinaTelecom, ChinaUnicom, or ChinaMobile.","provider":"go.mondoo.com/mql/providers/alicloud"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Association mode of the EIP","desc":"One of NAT, MULTI_BINDED, or BINDED.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"netmode":{"name":"netmode","type":"\u0007","is_mandatory":true,"title":"Network mode of the EIP","desc":"One of public or a private network mode.","provider":"go.mondoo.com/mql/providers/alicloud"},"privateIpAddress":{"name":"privateIpAddress","type":"\u0007","is_mandatory":true,"title":"Private IP address of the instance the EIP is bound to","provider":"go.mondoo.com/mql/providers/alicloud"},"publicIpAddressPoolId":{"name":"publicIpAddressPoolId","type":"\u0007","is_mandatory":true,"title":"ID of the IP address pool the EIP was drawn from","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the elastic IP address","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"secondLimited":{"name":"secondLimited","type":"\u0004","is_mandatory":true,"title":"Whether second-level (fine-grained) monitoring is limited","provider":"go.mondoo.com/mql/providers/alicloud"},"securityProtectionTypes":{"name":"securityProtectionTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Firewall (security protection) types enabled on the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"segmentInstanceId":{"name":"segmentInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the contiguous EIP group the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"serviceManaged":{"name":"serviceManaged","type":"\u0005","is_mandatory":true,"title":"Whether the EIP is managed by an Alibaba Cloud service","desc":"0 indicates the EIP is user-managed, 1 indicates it is managed by a service.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Associating, Unassociating, InUse, or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the EIP","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the EIP is associated with","provider":"go.mondoo.com/mql/providers/alicloud"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Zone the EIP belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Elastic IP address (EIP)","desc":"A single elastic IP address, keyed by allocationId, for example eip-2zeerraiwb7uabc. Exposes the public IP address, the bandwidth and billing configuration, the ISP line, the lifecycle status, and the instance the EIP is bound to.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.flowLog":{"id":"alicloud.vpc.flowLog","name":"alicloud.vpc.flowLog","fields":{"aggregationInterval":{"name":"aggregationInterval","type":"\u0005","is_mandatory":true,"title":"Interval in seconds over which records are aggregated, for example 600","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (billing) state of the flow log","desc":"For example Normal, or FinancialLocked when the flow log is locked for overdue payment.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the flow log was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deliverErrorMessage":{"name":"deliverErrorMessage","type":"\u0007","is_mandatory":true,"title":"Most recent delivery error, empty when delivery is healthy","provider":"go.mondoo.com/mql/providers/alicloud"},"deliverStatus":{"name":"deliverStatus","type":"\u0007","is_mandatory":true,"title":"Delivery state of the records to Log Service","desc":"For example FlowLogDeliverStarted when records are being delivered, or a failure state when delivery is not succeeding.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the flow log","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLogId":{"name":"flowLogId","type":"\u0007","is_mandatory":true,"title":"Flow log ID, used as the lookup key within its region","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLogName":{"name":"flowLogName","type":"\u0007","is_mandatory":true,"title":"Flow log name","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version captured","desc":"One of IPv4, IPv6, or all.","provider":"go.mondoo.com/mql/providers/alicloud"},"logStoreName":{"name":"logStoreName","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service logstore that receives the records","provider":"go.mondoo.com/mql/providers/alicloud"},"logstore":{"name":"logstore","type":"\u001balicloud.log.logstore","title":"Log Service logstore that receives the records","provider":"go.mondoo.com/mql/providers/alicloud"},"network":{"name":"network","type":"\u001balicloud.vpc.network","title":"VPC network monitored by the flow log","desc":"Null when the monitored resource is a vSwitch or an elastic network interface rather than a VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"project":{"name":"project","type":"\u001balicloud.log.project","title":"Log Service project that receives the records","desc":"Null when the flow log names no project, and when the project lives in another account that the scan cannot read.","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"projectName":{"name":"projectName","type":"\u0007","is_mandatory":true,"title":"Name of the Log Service project that receives the records","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the flow log resides in, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the flow log","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the flow log belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceId":{"name":"resourceId","type":"\u0007","is_mandatory":true,"title":"ID of the monitored resource (a VPC, vSwitch, or elastic network interface)","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceType":{"name":"resourceType","type":"\u0007","is_mandatory":true,"title":"Type of the monitored resource","desc":"One of VPC, VSwitch, or NetworkInterface.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Flow log state","desc":"One of Active or Inactive. A flow log only captures traffic while Active.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the flow log","provider":"go.mondoo.com/mql/providers/alicloud"},"trafficPath":{"name":"trafficPath","type":"\u0019\u0007","is_mandatory":true,"title":"Traffic path captured","desc":"The network paths the flow log records, for example full for all paths or a subset such as internetGateway. Empty when no path filter is applied.","provider":"go.mondoo.com/mql/providers/alicloud"},"trafficType":{"name":"trafficType","type":"\u0007","is_mandatory":true,"title":"Traffic direction captured","desc":"One of All, Allow (accepted traffic), or Drop (rejected traffic).","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch monitored by the flow log","desc":"Null when the monitored resource is a VPC or an elastic network interface rather than a vSwitch.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC flow log","desc":"A single flow log that captures traffic metadata for a VPC, vSwitch, or elastic network interface, keyed by flowLogId within its region. Exposes the monitored resource, the traffic direction and path captured, and the Log Service project and logstore that receive the records. Use it to audit whether flow logging is enabled for a network and where the records are delivered. For example `alicloud.vpc.flowLog(flowLogId: \"fl-xxx\", regionId: \"cn-hangzhou\")`.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.natGateway":{"id":"alicloud.vpc.natGateway","name":"alicloud.vpc.natGateway","fields":{"accessMode":{"name":"accessMode","type":"\n","is_mandatory":true,"title":"Access mode of the NAT gateway","desc":"Carries modeValue and tunnelType.","provider":"go.mondoo.com/mql/providers/alicloud"},"autoPay":{"name":"autoPay","type":"\u0004","is_mandatory":true,"title":"Whether the order is automatically paid for a subscription NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Business (payment) status of the NAT gateway","desc":"One of Normal or FinancialLocked.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the NAT gateway was created","provider":"go.mondoo.com/mql/providers/alicloud"},"deletionProtection":{"name":"deletionProtection","type":"\u0004","is_mandatory":true,"title":"Whether deletion protection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"ecsMetricEnabled":{"name":"ecsMetricEnabled","type":"\u0004","is_mandatory":true,"title":"Whether flow monitoring (ECS metrics) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"eipBindMode":{"name":"eipBindMode","type":"\u0007","is_mandatory":true,"title":"EIP binding mode of the NAT gateway","desc":"One of MULTI_BINDED or NAT.","provider":"go.mondoo.com/mql/providers/alicloud"},"enableSessionLog":{"name":"enableSessionLog","type":"\u0007","is_mandatory":true,"title":"Whether NAT session logging is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"expiredTime":{"name":"expiredTime","type":"\t","is_mandatory":true,"title":"Time when the NAT gateway expires","provider":"go.mondoo.com/mql/providers/alicloud"},"forwardEntries":{"name":"forwardEntries","type":"\u0019\u001balicloud.vpc.natGateway.forwardEntry","title":"DNAT rules forwarding inbound traffic to private addresses","desc":"Each rule publishes a private address and port on a public IP. This is an inbound path from the internet that no security group audit sees, because the security group is evaluated against the private address the traffic arrives at.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"forwardEntry":{"name":"forwardEntry","type":"\u001balicloud.vpc.natGateway.forwardEntry","title":"DNAT rule of a NAT gateway","desc":"A single destination-NAT (port forwarding) rule, keyed by forwardEntryId. A rule publishes a private address and port on a public IP, which is an inbound path from the internet. Exposes both ends of the mapping, the protocol, and whether the rule forwards every port. Use it to find private workloads reachable from the internet without a public address of their own.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"forwardTableIds":{"name":"forwardTableIds","type":"\u0019\u0007","is_mandatory":true,"title":"DNAT (forward) table IDs of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"fullNatTableIds":{"name":"fullNatTableIds","type":"\u0019\u0007","is_mandatory":true,"title":"FULLNAT table IDs of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"icmpReplyEnabled":{"name":"icmpReplyEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the NAT gateway replies to ICMP (ping) requests","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceChargeType":{"name":"instanceChargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the NAT gateway","desc":"One of PrePaid (subscription) or PostPaid (pay-as-you-go).","provider":"go.mondoo.com/mql/providers/alicloud"},"internetChargeType":{"name":"internetChargeType","type":"\u0007","is_mandatory":true,"title":"Metering method for internet data transfer","desc":"One of PayByLcu or PayBySpec.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipLists":{"name":"ipLists","type":"\u0019\n","is_mandatory":true,"title":"Elastic IP addresses associated with the NAT gateway","desc":"Each entry carries allocationId, ipAddress, privateIpAddress, snatEntryEnabled, and usingStatus.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"NAT gateway name","provider":"go.mondoo.com/mql/providers/alicloud"},"natGatewayId":{"name":"natGatewayId","type":"\u0007","is_mandatory":true,"title":"NAT gateway ID, for example ngw-bp1uewa15k4abc","provider":"go.mondoo.com/mql/providers/alicloud"},"natGatewayPrivateInfo":{"name":"natGatewayPrivateInfo","type":"\n","is_mandatory":true,"title":"Private-network placement of an enhanced NAT gateway","desc":"Carries vswitchId, privateIpAddress, eniInstanceId, eniType, izNo, maxBandwidth, maxSessionEstablishRate, and maxSessionQuota.","provider":"go.mondoo.com/mql/providers/alicloud"},"natType":{"name":"natType","type":"\u0007","is_mandatory":true,"title":"NAT gateway type","desc":"One of Normal or Enhanced.","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Network type of the NAT gateway","desc":"One of internet for a public gateway or intranet for a private gateway.","provider":"go.mondoo.com/mql/providers/alicloud"},"privateLinkEnabled":{"name":"privateLinkEnabled","type":"\u0004","is_mandatory":true,"title":"Whether PrivateLink is enabled for the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"privateLinkMode":{"name":"privateLinkMode","type":"\u0007","is_mandatory":true,"title":"PrivateLink mode of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the NAT gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the NAT gateway","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the NAT gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"securityProtectionEnabled":{"name":"securityProtectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether firewall (security protection) is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"snatEntries":{"name":"snatEntries","type":"\u0019\u001balicloud.vpc.natGateway.snatEntry","title":"SNAT rules giving private addresses outbound internet access","desc":"Each rule maps a source range or vSwitch onto one or more public addresses. An instance with no public address of its own still reaches the internet whenever a SNAT rule covers it, which a check on the instance's own addressing does not show.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"snatEntry":{"name":"snatEntry","type":"\u001balicloud.vpc.natGateway.snatEntry","title":"SNAT rule of a NAT gateway","desc":"A single source-NAT rule, keyed by snatEntryId. A rule gives a source range, a vSwitch, or one network interface outbound internet access through a public address. Exposes the source it covers, the public addresses it uses, and the rule status. Use it to find which private workloads can reach the internet.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"snatTableIds":{"name":"snatTableIds","type":"\u0019\u0007","is_mandatory":true,"title":"SNAT table IDs of the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"spec":{"name":"spec","type":"\u0007","is_mandatory":true,"title":"Specification of the NAT gateway","desc":"One of Small, Middle, Large, or XLarge.1 for a standard NAT gateway.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Creating, Available, Modifying, Deleting, or Converting.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the NAT gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the NAT gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC NAT gateway","desc":"A single NAT gateway, keyed by natGatewayId, for example ngw-bp1uewa15k4abc. Exposes the specification, the NAT type and network type, the lifecycle and billing status, the SNAT and DNAT table IDs, and the private-network placement.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.natGateway.forwardEntry":{"id":"alicloud.vpc.natGateway.forwardEntry","name":"alicloud.vpc.natGateway.forwardEntry","fields":{"externalIp":{"name":"externalIp","type":"\u0007","is_mandatory":true,"title":"Public address traffic arrives at","provider":"go.mondoo.com/mql/providers/alicloud"},"externalPort":{"name":"externalPort","type":"\u0007","is_mandatory":true,"title":"Public port traffic arrives at, or any when every port is forwarded","provider":"go.mondoo.com/mql/providers/alicloud"},"forwardEntryId":{"name":"forwardEntryId","type":"\u0007","is_mandatory":true,"title":"DNAT rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"forwardEntryName":{"name":"forwardEntryName","type":"\u0007","is_mandatory":true,"title":"Name of the DNAT rule","provider":"go.mondoo.com/mql/providers/alicloud"},"forwardTableId":{"name":"forwardTableId","type":"\u0007","is_mandatory":true,"title":"ID of the DNAT table holding the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"forwardsAllPorts":{"name":"forwardsAllPorts","type":"\u0004","is_mandatory":true,"title":"Whether the rule forwards every port","desc":"True when the rule maps the whole port range rather than one port, which publishes every listening service on the private address rather than the one that was meant to be exposed.","provider":"go.mondoo.com/mql/providers/alicloud"},"internalIp":{"name":"internalIp","type":"\u0007","is_mandatory":true,"title":"Private address traffic is forwarded to","provider":"go.mondoo.com/mql/providers/alicloud"},"internalPort":{"name":"internalPort","type":"\u0007","is_mandatory":true,"title":"Private port traffic is forwarded to, or any when every port is forwarded","provider":"go.mondoo.com/mql/providers/alicloud"},"ipProtocol":{"name":"ipProtocol","type":"\u0007","is_mandatory":true,"title":"Protocol the rule forwards, one of TCP, UDP, or Any","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the rule","desc":"One of Pending, Available, or Deleting. Only an Available rule forwards traffic.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"DNAT rule of a NAT gateway","desc":"A single destination-NAT (port forwarding) rule, keyed by forwardEntryId. A rule publishes a private address and port on a public IP, which is an inbound path from the internet. Exposes both ends of the mapping, the protocol, and whether the rule forwards every port. Use it to find private workloads reachable from the internet without a public address of their own.","min_provider_version":"13.5.1","defaults":"forwardEntryName externalIp externalPort internalIp status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.natGateway.snatEntry":{"id":"alicloud.vpc.natGateway.snatEntry","name":"alicloud.vpc.natGateway.snatEntry","fields":{"eipAffinity":{"name":"eipAffinity","type":"\u0007","is_mandatory":true,"title":"Whether the rule pins a connection to one public address","desc":"Enabled when consecutive connections from the same source keep the same public address.","provider":"go.mondoo.com/mql/providers/alicloud"},"networkInterfaceId":{"name":"networkInterfaceId","type":"\u0007","is_mandatory":true,"title":"ID of the network interface the rule applies to, empty when it is not interface-scoped","provider":"go.mondoo.com/mql/providers/alicloud"},"snatEntryId":{"name":"snatEntryId","type":"\u0007","is_mandatory":true,"title":"SNAT rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"snatEntryName":{"name":"snatEntryName","type":"\u0007","is_mandatory":true,"title":"Name of the SNAT rule","provider":"go.mondoo.com/mql/providers/alicloud"},"snatIp":{"name":"snatIp","type":"\u0007","is_mandatory":true,"title":"Public addresses the rule translates to, comma-separated when several","provider":"go.mondoo.com/mql/providers/alicloud"},"snatTableId":{"name":"snatTableId","type":"\u0007","is_mandatory":true,"title":"ID of the SNAT table holding the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCIDR":{"name":"sourceCIDR","type":"\u0007","is_mandatory":true,"title":"Source CIDR the rule applies to, empty when the rule is scoped by vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceVSwitchId":{"name":"sourceVSwitchId","type":"\u0007","is_mandatory":true,"title":"ID of the vSwitch the rule applies to, empty when the rule is scoped by CIDR","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceVswitch":{"name":"sourceVswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the rule applies to","desc":"Null when the rule is scoped by CIDR or network interface rather than by vSwitch, and when the vSwitch lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the rule","desc":"One of Pending, Available, or Deleting. Only an Available rule forwards traffic.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"SNAT rule of a NAT gateway","desc":"A single source-NAT rule, keyed by snatEntryId. A rule gives a source range, a vSwitch, or one network interface outbound internet access through a public address. Exposes the source it covers, the public addresses it uses, and the rule status. Use it to find which private workloads can reach the internet.","min_provider_version":"13.5.1","defaults":"snatEntryName snatIp sourceCIDR status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.network":{"id":"alicloud.vpc.network","name":"alicloud.vpc.network","fields":{"cenStatus":{"name":"cenStatus","type":"\u0007","is_mandatory":true,"title":"Cloud Enterprise Network (CEN) attachment status","desc":"Returned as Attached only when the VPC is attached to a CEN instance.","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlock":{"name":"cidrBlock","type":"\u0007","is_mandatory":true,"title":"Primary IPv4 CIDR block of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlocks":{"name":"cidrBlocks","type":"\u0019\u0007","is_mandatory":true,"title":"Secondary IPv4 CIDR blocks of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the VPC was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"dhcpOptionsSetId":{"name":"dhcpOptionsSetId","type":"\u0007","is_mandatory":true,"title":"DHCP options set ID bound to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"dhcpOptionsSetStatus":{"name":"dhcpOptionsSetStatus","type":"\u0007","is_mandatory":true,"title":"DHCP options set status","desc":"One of Available, InUse, Deleted, or Pending.","provider":"go.mondoo.com/mql/providers/alicloud"},"dnsHostnameStatus":{"name":"dnsHostnameStatus","type":"\u0007","is_mandatory":true,"title":"DNS hostname feature status","desc":"Indicates whether the DNS hostname feature is enabled, for example ENABLED or DISABLED.","provider":"go.mondoo.com/mql/providers/alicloud"},"enabledIpv6":{"name":"enabledIpv6","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 is enabled for the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"flowLogs":{"name":"flowLogs","type":"\u0019\u001balicloud.vpc.flowLog","title":"Flow logs monitoring this VPC","desc":"Flow logs whose monitored resource is the VPC itself. A flow log only captures traffic while its status is Active. Flow logs scoped to a vSwitch or an elastic network interface inside the VPC are not included.","min_provider_version":"13.2.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6CidrBlock":{"name":"ipv6CidrBlock","type":"\u0007","is_mandatory":true,"title":"IPv6 CIDR block of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6CidrBlocks":{"name":"ipv6CidrBlocks","type":"\u0019\n","is_mandatory":true,"title":"IPv6 CIDR blocks with their ISP line type","desc":"Each entry carries the ipv6CidrBlock and its ipv6Isp line type (for example BGP, ChinaMobile, ChinaUnicom, or ChinaTelecom).","provider":"go.mondoo.com/mql/providers/alicloud"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether this is the default VPC in the region","provider":"go.mondoo.com/mql/providers/alicloud"},"natGateways":{"name":"natGateways","type":"\u0019\u001balicloud.vpc.natGateway","title":"NAT gateways attached to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the VPC belongs to, for example cn-hangzhou","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the VPC","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the VPC belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTables":{"name":"routeTables","type":"\u0019\u001balicloud.vpc.routeTable","title":"Route tables associated with the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"userCidrs":{"name":"userCidrs","type":"\u0019\u0007","is_mandatory":true,"title":"User CIDR blocks associated with the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"vRouterId":{"name":"vRouterId","type":"\u0007","is_mandatory":true,"title":"vRouter ID of the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcId":{"name":"vpcId","type":"\u0007","is_mandatory":true,"title":"VPC ID, for example vpc-bp1qpo0kug3a20qqe0abc","provider":"go.mondoo.com/mql/providers/alicloud"},"vpcName":{"name":"vpcName","type":"\u0007","is_mandatory":true,"title":"VPC name","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGateways":{"name":"vpnGateways","type":"\u0019\u001balicloud.vpc.vpnGateway","title":"VPN gateways attached to the VPC","desc":"Each gateway terminates connections that reach the VPC from outside Alibaba Cloud, so this is reachability that security-group rules alone do not explain.","min_provider_version":"13.2.5","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches in the VPC","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Virtual Private Cloud network","desc":"A single VPC, keyed by vpcId, for example vpc-bp1qpo0kug3a20qqe0abc. Exposes the primary and secondary CIDR blocks, the IPv6 configuration, the lifecycle status, the default-VPC flag, the vRouter, and the vSwitches, route tables, and NAT gateways associated with the network.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.networkAcl":{"id":"alicloud.vpc.networkAcl","name":"alicloud.vpc.networkAcl","fields":{"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the network ACL was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the network ACL","provider":"go.mondoo.com/mql/providers/alicloud"},"egressAclEntries":{"name":"egressAclEntries","type":"\u0019\n","is_mandatory":true,"title":"Outbound rule summaries","desc":"Deprecated in favor of egressEntries. Each entry carries protocol, port, destinationCidrIp, policy, description, entryType, ipVersion, networkAclEntryId, and networkAclEntryName.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.vpc.networkAcl.egressEntries"},"egressEntries":{"name":"egressEntries","type":"\u0019\u001balicloud.vpc.networkAcl.entry","is_mandatory":true,"title":"Outbound rules of the network ACL","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"entry":{"name":"entry","type":"\u001balicloud.vpc.networkAcl.entry","title":"Network ACL rule","desc":"A single inbound or outbound rule, keyed by entryId. Network ACLs are evaluated before security groups, so an accept rule here decides what reaches the security groups at all and a drop rule overrides whatever they allow. Ports arrive as a range string such as 22/22 or -1/-1 for every port.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"ingressAclEntries":{"name":"ingressAclEntries","type":"\u0019\n","is_mandatory":true,"title":"Inbound rule summaries","desc":"Deprecated in favor of ingressEntries. Each entry carries protocol, port, sourceCidrIp, policy, description, entryType, ipVersion, networkAclEntryId, and networkAclEntryName.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.vpc.networkAcl.ingressEntries"},"ingressEntries":{"name":"ingressEntries","type":"\u0019\u001balicloud.vpc.networkAcl.entry","is_mandatory":true,"title":"Inbound rules of the network ACL","desc":"Evaluated before security groups on traffic entering the attached vSwitches, so a rule here can admit traffic no security group was ever asked about.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"networkAclId":{"name":"networkAclId","type":"\u0007","is_mandatory":true,"title":"Network ACL ID, for example nacl-a2do9e413e0spzasx","provider":"go.mondoo.com/mql/providers/alicloud"},"networkAclName":{"name":"networkAclName","type":"\u0007","is_mandatory":true,"title":"Network ACL name","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the network ACL","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the network ACL belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resources":{"name":"resources","type":"\u0019\n","is_mandatory":true,"title":"Resources the network ACL is bound to","desc":"Each entry carries resourceId, resourceType, and status.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Available or Modifying.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the network ACL","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the network ACL belongs to","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC network ACL","desc":"A single network ACL, keyed by networkAclId, for example nacl-a2do9e413e0spzasx. Exposes the lifecycle status, the ingress and egress rule entries, and the vSwitches the ACL is bound to.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.networkAcl.entry":{"id":"alicloud.vpc.networkAcl.entry","name":"alicloud.vpc.networkAcl.entry","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationCidrIp":{"name":"destinationCidrIp","type":"\u0007","is_mandatory":true,"title":"Destination addresses an outbound rule matches","desc":"Empty on an ingress rule.","provider":"go.mondoo.com/mql/providers/alicloud"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Which way the rule applies","desc":"Either ingress or egress.","provider":"go.mondoo.com/mql/providers/alicloud"},"entryId":{"name":"entryId","type":"\u0007","is_mandatory":true,"title":"Rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"entryType":{"name":"entryType","type":"\u0007","is_mandatory":true,"title":"How the rule was created","desc":"custom for a rule added deliberately, system for one created with the ACL.","provider":"go.mondoo.com/mql/providers/alicloud"},"fromPort":{"name":"fromPort","type":"\u0005","is_mandatory":true,"title":"Lowest port the rule matches","desc":"A rule written as -1/-1 matches every port, and reports 1 here alongside 65535 in toPort. Null when port holds no range that resolves to a pair of ports, which leaves port as the only record of it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version the rule applies to","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"policy":{"name":"policy","type":"\u0007","is_mandatory":true,"title":"What the rule does with matching traffic","desc":"Either accept or drop.","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0007","is_mandatory":true,"title":"Port range the rule matches","desc":"Written as first/last, for example 22/22. A value of -1/-1 matches every port, which is the form a rule takes when the protocol is not tcp or udp.","provider":"go.mondoo.com/mql/providers/alicloud"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Protocol the rule matches","desc":"One of icmp, gre, tcp, udp, or all.","provider":"go.mondoo.com/mql/providers/alicloud"},"sourceCidrIp":{"name":"sourceCidrIp","type":"\u0007","is_mandatory":true,"title":"Source addresses an inbound rule matches","desc":"Empty on an egress rule. A value of 0.0.0.0/0 matches the whole internet.","provider":"go.mondoo.com/mql/providers/alicloud"},"toPort":{"name":"toPort","type":"\u0005","is_mandatory":true,"title":"Highest port the rule matches","desc":"A rule written as -1/-1 matches every port, and reports 65535 here alongside 1 in fromPort. Null when port holds no range that resolves to a pair of ports.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Network ACL rule","desc":"A single inbound or outbound rule, keyed by entryId. Network ACLs are evaluated before security groups, so an accept rule here decides what reaches the security groups at all and a drop rule overrides whatever they allow. Ports arrive as a range string such as 22/22 or -1/-1 for every port.","min_provider_version":"13.4.1","defaults":"direction policy protocol port","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.physicalConnection":{"id":"alicloud.vpc.physicalConnection","name":"alicloud.vpc.physicalConnection","fields":{"accessPointId":{"name":"accessPointId","type":"\u0007","is_mandatory":true,"title":"Access point the circuit lands at","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Capacity of the circuit in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Commercial status of the circuit, for example Normal or FinancialLocked","provider":"go.mondoo.com/mql/providers/alicloud"},"circuitCode":{"name":"circuitCode","type":"\u0007","is_mandatory":true,"title":"Circuit code assigned by the carrier","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the circuit was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the circuit","provider":"go.mondoo.com/mql/providers/alicloud"},"enabledTime":{"name":"enabledTime","type":"\t","is_mandatory":true,"title":"Time the circuit was enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"Time the circuit expires","provider":"go.mondoo.com/mql/providers/alicloud"},"lineOperator":{"name":"lineOperator","type":"\u0007","is_mandatory":true,"title":"Carrier providing the line, for example CT, CU, CM, or Other","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the circuit","provider":"go.mondoo.com/mql/providers/alicloud"},"parentPhysicalConnectionId":{"name":"parentPhysicalConnectionId","type":"\u0007","is_mandatory":true,"title":"ID of the parent circuit when this is a hosted connection, empty otherwise","provider":"go.mondoo.com/mql/providers/alicloud"},"peerLocation":{"name":"peerLocation","type":"\u0007","is_mandatory":true,"title":"Physical location of the remote end","provider":"go.mondoo.com/mql/providers/alicloud"},"physicalConnectionId":{"name":"physicalConnectionId","type":"\u0007","is_mandatory":true,"title":"Physical connection ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"portType":{"name":"portType","type":"\u0007","is_mandatory":true,"title":"Port type of the circuit, for example 10GBase-LR","provider":"go.mondoo.com/mql/providers/alicloud"},"redundantPhysicalConnectionId":{"name":"redundantPhysicalConnectionId","type":"\u0007","is_mandatory":true,"title":"ID of the redundant circuit paired with this one, empty when there is none","desc":"A circuit with no redundant pair is a single point of failure for everything routed over it.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the circuit terminates in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the circuit","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the circuit belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"spec":{"name":"spec","type":"\u0007","is_mandatory":true,"title":"Specification of the circuit, for example 10G","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the circuit","desc":"For example Initial, Approved, Allocating, Allocated, Confirmed, Enabled, or Terminated. Only an Enabled circuit carries traffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the circuit","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Kind of circuit, for example VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"virtualBorderRouters":{"name":"virtualBorderRouters","type":"\u0019\u001balicloud.vpc.virtualBorderRouter","title":"Virtual border routers handing the circuit's traffic to Alibaba Cloud","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Express Connect physical connection","desc":"A leased-line circuit into Alibaba Cloud, keyed by physicalConnectionId. Exposes the circuit status, capacity, access point and carrier, along with the virtual border routers that hand its traffic to the Alibaba Cloud side. Traffic over the circuit never touches the internet, so no internet-facing control sees it.","min_provider_version":"13.5.1","defaults":"name physicalConnectionId status bandwidth","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.routeTable":{"id":"alicloud.vpc.routeTable","name":"alicloud.vpc.routeTable","fields":{"associateType":{"name":"associateType","type":"\u0007","is_mandatory":true,"title":"Type of resource the route table is associated with","desc":"One of VSwitch or Gateway.","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the route table was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"gatewayIds":{"name":"gatewayIds","type":"\u0019\u0007","is_mandatory":true,"title":"Gateway IDs associated with the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the route table","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the route table belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"route":{"name":"route","type":"\u001balicloud.vpc.routeTable.route","title":"Route in a VPC route table","desc":"A single route, keyed by routeEntryId. Reports the destination it matches and the next hop traffic is handed to. A system route is created with the VPC and a custom route was added deliberately, which the type field distinguishes.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"routeEntries":{"name":"routeEntries","type":"\u0019\n","title":"Route entry summaries","desc":"Deprecated in favor of routes. Each entry carries destinationCidrBlock, nextHopType, nextHopId, status, type, routeEntryId, routeEntryName, description, ipVersion, and origin.","provider":"go.mondoo.com/mql/providers/alicloud","maturity":"deprecated","replaced_by":"alicloud.vpc.routeTable.routes"},"routePropagationEnable":{"name":"routePropagationEnable","type":"\u0004","is_mandatory":true,"title":"Whether route propagation is enabled for the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableId":{"name":"routeTableId","type":"\u0007","is_mandatory":true,"title":"Route table ID, for example vtb-bp1e123abc","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableName":{"name":"routeTableName","type":"\u0007","is_mandatory":true,"title":"Route table name","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableType":{"name":"routeTableType","type":"\u0007","is_mandatory":true,"title":"Route table type","desc":"One of System or Custom.","provider":"go.mondoo.com/mql/providers/alicloud"},"routerId":{"name":"routerId","type":"\u0007","is_mandatory":true,"title":"ID of the router the route table belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"routerType":{"name":"routerType","type":"\u0007","is_mandatory":true,"title":"Type of router the route table belongs to","desc":"One of VRouter or VBR.","provider":"go.mondoo.com/mql/providers/alicloud"},"routes":{"name":"routes","type":"\u0019\u001balicloud.vpc.routeTable.route","title":"Routes in the route table","desc":"Where traffic leaving the attached vSwitches is sent. A route for 0.0.0.0/0 is the one that decides whether a subnet reaches the internet at all, and which gateway it leaves through.","min_provider_version":"13.4.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the route table","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the route table belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitches":{"name":"vswitches","type":"\u0019\u001balicloud.vpc.vswitch","title":"vSwitches associated with the route table","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPC route table","desc":"A single route table, keyed by routeTableId, for example vtb-bp1e123abc. Exposes the route table type, the bound vSwitches and gateways, the lifecycle status, and the individual route entries through routeEntries.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.routeTable.route":{"id":"alicloud.vpc.routeTable.route","name":"alicloud.vpc.routeTable.route","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Route description","provider":"go.mondoo.com/mql/providers/alicloud"},"destinationCidrBlock":{"name":"destinationCidrBlock","type":"\u0007","is_mandatory":true,"title":"Destination the route matches","desc":"A CIDR block. 0.0.0.0/0 is the default route, which catches everything not matched by a more specific entry.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipVersion":{"name":"ipVersion","type":"\u0007","is_mandatory":true,"title":"IP version of the destination","provider":"go.mondoo.com/mql/providers/alicloud"},"nextHopId":{"name":"nextHopId","type":"\u0007","is_mandatory":true,"title":"ID of the next hop","provider":"go.mondoo.com/mql/providers/alicloud"},"nextHopType":{"name":"nextHopType","type":"\u0007","is_mandatory":true,"title":"Kind of next hop traffic is handed to","desc":"Values include Instance, NatGateway, VpnGateway, RouterInterface, NetworkInterface, IPv6Gateway, and Attachment. The kind decides whether the route leads out of the VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Origin of the route","provider":"go.mondoo.com/mql/providers/alicloud"},"routeEntryId":{"name":"routeEntryId","type":"\u0007","is_mandatory":true,"title":"Route entry ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"routeEntryName":{"name":"routeEntryName","type":"\u0007","is_mandatory":true,"title":"Route entry name","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Route status","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"How the route was created","desc":"System for a route created with the VPC, Custom for one added afterwards.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Route in a VPC route table","desc":"A single route, keyed by routeEntryId. Reports the destination it matches and the next hop traffic is handed to. A system route is created with the VPC and a custom route was added deliberately, which the type field distinguishes.","min_provider_version":"13.4.1","defaults":"destinationCidrBlock nextHopType nextHopId status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.sslVpnClientCert":{"id":"alicloud.vpc.sslVpnClientCert","name":"alicloud.vpc.sslVpnClientCert","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the certificate was issued","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"Time the certificate expires","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the certificate","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the certificate belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the certificate","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the certificate belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnClientCertId":{"name":"sslVpnClientCertId","type":"\u0007","is_mandatory":true,"title":"Client certificate ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnServerId":{"name":"sslVpnServerId","type":"\u0007","is_mandatory":true,"title":"ID of the SSL VPN server the certificate is issued for","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the certificate","desc":"One of expiring-soon, normal, or expired. A certificate reported here at all is still installed on the server, whatever its status.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"SSL VPN client certificate","desc":"A client certificate issued for an SSL VPN server, keyed by sslVpnClientCertId. Exposes the certificate lifecycle and expiry. The private key is never exposed. Use it to find certificates that have expired without being revoked, or that are close to expiry.","min_provider_version":"13.5.1","defaults":"name status endTime","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.sslVpnServer":{"id":"alicloud.vpc.sslVpnServer","name":"alicloud.vpc.sslVpnServer","fields":{"cipher":{"name":"cipher","type":"\u0007","is_mandatory":true,"title":"Encryption algorithm negotiated with clients, for example AES-128-CBC or none","provider":"go.mondoo.com/mql/providers/alicloud"},"clientCerts":{"name":"clientCerts","type":"\u0019\u001balicloud.vpc.sslVpnClientCert","title":"Client certificates issued for the server","provider":"go.mondoo.com/mql/providers/alicloud"},"clientIpPool":{"name":"clientIpPool","type":"\u0007","is_mandatory":true,"title":"Address pool clients are assigned from","provider":"go.mondoo.com/mql/providers/alicloud"},"compress":{"name":"compress","type":"\u0004","is_mandatory":true,"title":"Whether the tunnel compresses traffic","provider":"go.mondoo.com/mql/providers/alicloud"},"connections":{"name":"connections","type":"\u0005","is_mandatory":true,"title":"Number of clients connected now","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the server was created","provider":"go.mondoo.com/mql/providers/alicloud"},"dnsServers":{"name":"dnsServers","type":"\u0007","is_mandatory":true,"title":"DNS servers pushed to clients, comma-separated when several","provider":"go.mondoo.com/mql/providers/alicloud"},"idaasInstanceId":{"name":"idaasInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the IDaaS instance providing the second factor, empty when none is configured","provider":"go.mondoo.com/mql/providers/alicloud"},"idaasRegionId":{"name":"idaasRegionId","type":"\u0007","is_mandatory":true,"title":"Region of the IDaaS instance, empty when none is configured","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public address clients connect to","provider":"go.mondoo.com/mql/providers/alicloud"},"localSubnet":{"name":"localSubnet","type":"\u0007","is_mandatory":true,"title":"CIDR blocks on the Alibaba Cloud side published to clients","desc":"Everything a connected client can reach. A broad local subnet gives a single client certificate reach across the whole VPC.","provider":"go.mondoo.com/mql/providers/alicloud"},"maxConnections":{"name":"maxConnections","type":"\u0005","is_mandatory":true,"title":"Maximum number of simultaneous client connections","provider":"go.mondoo.com/mql/providers/alicloud"},"multiFactorAuthEnabled":{"name":"multiFactorAuthEnabled","type":"\u0004","is_mandatory":true,"title":"Whether clients must pass a second authentication factor","desc":"False means a client certificate alone admits a machine to the VPC, so a copied certificate file is enough to reach it.","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the server","provider":"go.mondoo.com/mql/providers/alicloud"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port the server listens on","provider":"go.mondoo.com/mql/providers/alicloud"},"proto":{"name":"proto","type":"\u0007","is_mandatory":true,"title":"Transport protocol, either UDP or TCP","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the server runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the server","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the server belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnServerId":{"name":"sslVpnServerId","type":"\u0007","is_mandatory":true,"title":"SSL VPN server ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGateway":{"name":"vpnGateway","type":"\u001balicloud.vpc.vpnGateway","title":"VPN gateway hosting the server","desc":"Null when the gateway lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGatewayId":{"name":"vpnGatewayId","type":"\u0007","is_mandatory":true,"title":"ID of the VPN gateway hosting the server","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"SSL VPN server","desc":"An SSL VPN server on a VPN gateway, keyed by sslVpnServerId. Exposes the client address pool, the subnets it publishes to clients, the transport and cipher, the connection limit, and whether a second authentication factor is demanded. Use it to find a remote-access path into a VPC that clients reach with a certificate alone.","min_provider_version":"13.5.1","defaults":"name sslVpnServerId clientIpPool connections","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.virtualBorderRouter":{"id":"alicloud.vpc.virtualBorderRouter","name":"alicloud.vpc.virtualBorderRouter","fields":{"activationTime":{"name":"activationTime","type":"\t","is_mandatory":true,"title":"Time the router was activated","provider":"go.mondoo.com/mql/providers/alicloud"},"bandwidth":{"name":"bandwidth","type":"\u0005","is_mandatory":true,"title":"Capacity of the router in Mbit/s","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time the router was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossAccountConnection":{"name":"crossAccountConnection","type":"\u0004","is_mandatory":true,"title":"Whether the attached circuit belongs to another account","desc":"True on a hosted connection, where the circuit and therefore the physical path is under a third party's control.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the router","provider":"go.mondoo.com/mql/providers/alicloud"},"detectMultiplier":{"name":"detectMultiplier","type":"\u0005","is_mandatory":true,"title":"Number of missed BFD packets before the peer is declared down, 0 when BFD is off","provider":"go.mondoo.com/mql/providers/alicloud"},"enableIpv6":{"name":"enableIpv6","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 is enabled on the peering","provider":"go.mondoo.com/mql/providers/alicloud"},"localGatewayIp":{"name":"localGatewayIp","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud side address of the peering","provider":"go.mondoo.com/mql/providers/alicloud"},"localIpv6GatewayIp":{"name":"localIpv6GatewayIp","type":"\u0007","is_mandatory":true,"title":"Alibaba Cloud side IPv6 address of the peering, empty when IPv6 is off","provider":"go.mondoo.com/mql/providers/alicloud"},"minRxInterval":{"name":"minRxInterval","type":"\u0005","is_mandatory":true,"title":"Minimum BFD receive interval in milliseconds, 0 when BFD is off","provider":"go.mondoo.com/mql/providers/alicloud"},"minTxInterval":{"name":"minTxInterval","type":"\u0005","is_mandatory":true,"title":"Minimum BFD transmit interval in milliseconds, 0 when BFD is off","provider":"go.mondoo.com/mql/providers/alicloud"},"mtu":{"name":"mtu","type":"\u0005","is_mandatory":true,"title":"Maximum transmission unit of the peering","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the router","provider":"go.mondoo.com/mql/providers/alicloud"},"peerGatewayIp":{"name":"peerGatewayIp","type":"\u0007","is_mandatory":true,"title":"Remote side address of the peering","provider":"go.mondoo.com/mql/providers/alicloud"},"peerIpv6GatewayIp":{"name":"peerIpv6GatewayIp","type":"\u0007","is_mandatory":true,"title":"Remote side IPv6 address of the peering, empty when IPv6 is off","provider":"go.mondoo.com/mql/providers/alicloud"},"peeringSubnetMask":{"name":"peeringSubnetMask","type":"\u0007","is_mandatory":true,"title":"Subnet mask of the peering addresses","provider":"go.mondoo.com/mql/providers/alicloud"},"physicalConnection":{"name":"physicalConnection","type":"\u001balicloud.vpc.physicalConnection","title":"Physical connection the router attaches to","desc":"Null when the circuit belongs to another account, which is the hosted Express Connect arrangement, and when it lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"physicalConnectionId":{"name":"physicalConnectionId","type":"\u0007","is_mandatory":true,"title":"ID of the physical connection the router attaches to","provider":"go.mondoo.com/mql/providers/alicloud"},"physicalConnectionOwnerUid":{"name":"physicalConnectionOwnerUid","type":"\u0007","is_mandatory":true,"title":"Account that owns the attached circuit","provider":"go.mondoo.com/mql/providers/alicloud"},"physicalConnectionStatus":{"name":"physicalConnectionStatus","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the attached circuit","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the router runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the router","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"ID of the resource group the router belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableId":{"name":"routeTableId","type":"\u0007","is_mandatory":true,"title":"ID of the route table the router uses","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status of the router","desc":"For example active, terminating, terminated, recovering, or unconfirmed. Only an active router carries traffic.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags applied to the router","provider":"go.mondoo.com/mql/providers/alicloud"},"terminationTime":{"name":"terminationTime","type":"\t","is_mandatory":true,"title":"Time the router was terminated, null when it has not been","provider":"go.mondoo.com/mql/providers/alicloud"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Kind of router, for example VBR","provider":"go.mondoo.com/mql/providers/alicloud"},"vbrId":{"name":"vbrId","type":"\u0007","is_mandatory":true,"title":"Virtual border router ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vlanId":{"name":"vlanId","type":"\u0005","is_mandatory":true,"title":"VLAN the peering runs on","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Virtual border router","desc":"The routed hand-off between an Express Connect circuit and the Alibaba Cloud side, keyed by vbrId. Exposes both gateway addresses of the peering, the VLAN it runs on, the BFD settings, and which circuit it attaches to. Use it to find a router attached to a circuit owned by another account, which is a path into the network from outside this account's control.","min_provider_version":"13.5.1","defaults":"name vbrId status vlanId","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.vpnConnection":{"id":"alicloud.vpc.vpnConnection","name":"alicloud.vpc.vpnConnection","fields":{"attachInstanceId":{"name":"attachInstanceId","type":"\u0007","is_mandatory":true,"title":"ID of the gateway or transit router the connection attaches to","provider":"go.mondoo.com/mql/providers/alicloud"},"attachType":{"name":"attachType","type":"\u0007","is_mandatory":true,"title":"Whether the connection attaches to a VPN gateway or a transit router","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the connection was created","provider":"go.mondoo.com/mql/providers/alicloud"},"crossAccountAuthorized":{"name":"crossAccountAuthorized","type":"\u0004","is_mandatory":true,"title":"Whether the connection is authorized across accounts","desc":"True when the tunnel joins networks owned by different accounts.","provider":"go.mondoo.com/mql/providers/alicloud"},"customerGateway":{"name":"customerGateway","type":"\u001balicloud.vpc.customerGateway","title":"Customer gateway representing the remote end","desc":"Null when the gateway has since been deleted, and when it lies outside the scanned regions.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"customerGatewayId":{"name":"customerGatewayId","type":"\u0007","is_mandatory":true,"title":"ID of the customer gateway representing the remote end","provider":"go.mondoo.com/mql/providers/alicloud"},"effectImmediately":{"name":"effectImmediately","type":"\u0004","is_mandatory":true,"title":"Whether configuration changes take effect immediately","provider":"go.mondoo.com/mql/providers/alicloud"},"enableDpd":{"name":"enableDpd","type":"\u0004","is_mandatory":true,"title":"Whether dead peer detection is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"enableNatTraversal":{"name":"enableNatTraversal","type":"\u0004","is_mandatory":true,"title":"Whether NAT traversal is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"enableTunnelsBgp":{"name":"enableTunnelsBgp","type":"\u0004","is_mandatory":true,"title":"Whether the tunnel exchanges routes over BGP","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeAuthenticationAlgorithm":{"name":"ikeAuthenticationAlgorithm","type":"\u0007","is_mandatory":true,"title":"Authentication algorithm negotiated for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeEncryptionAlgorithm":{"name":"ikeEncryptionAlgorithm","type":"\u0007","is_mandatory":true,"title":"Encryption algorithm negotiated for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeEncryptionAlgorithms":{"name":"ikeEncryptionAlgorithms","type":"\u0019\u0007","title":"IKE encryption algorithms in effect across the connection","desc":"Every distinct encryption algorithm negotiated for the key exchange, spanning the connection and all of its tunnels, deduplicated and sorted. A dual-tunnel connection is only as strong as its weaker tunnel, so the weakest entry is the one that matters for an audit. Empty when neither the connection nor any tunnel reports an algorithm.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeLifetime":{"name":"ikeLifetime","type":"\u0005","is_mandatory":true,"title":"Lifetime of the key-exchange security association in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeMode":{"name":"ikeMode","type":"\u0007","is_mandatory":true,"title":"IKE negotiation mode, either main or aggressive","desc":"Aggressive mode completes in fewer exchanges but sends identity information before the channel is encrypted.","provider":"go.mondoo.com/mql/providers/alicloud"},"ikePfs":{"name":"ikePfs","type":"\u0007","is_mandatory":true,"title":"Diffie-Hellman group used for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikePfsGroups":{"name":"ikePfsGroups","type":"\u0019\u0007","title":"Diffie-Hellman groups in effect for the key exchange","desc":"Every distinct group used for the key exchange, spanning the connection and all of its tunnels, deduplicated and sorted. A dual-tunnel connection is only as strong as its weaker tunnel, so the weakest entry is the one that matters for an audit. Empty when neither the connection nor any tunnel reports a group.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeVersion":{"name":"ikeVersion","type":"\u0007","is_mandatory":true,"title":"IKE protocol version, either ikev1 or ikev2","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address of the remote peer","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecAuthenticationAlgorithm":{"name":"ipsecAuthenticationAlgorithm","type":"\u0007","is_mandatory":true,"title":"Authentication algorithm protecting the tunnel payload","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecEncryptionAlgorithm":{"name":"ipsecEncryptionAlgorithm","type":"\u0007","is_mandatory":true,"title":"Encryption algorithm protecting the tunnel payload","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecEncryptionAlgorithms":{"name":"ipsecEncryptionAlgorithms","type":"\u0019\u0007","title":"IPsec encryption algorithms in effect across the connection","desc":"Every distinct encryption algorithm protecting the tunnel payload, spanning the connection and all of its tunnels, deduplicated and sorted. A dual-tunnel connection is only as strong as its weaker tunnel, so the weakest entry is the one that matters for an audit. Empty when neither the connection nor any tunnel reports an algorithm.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecLifetime":{"name":"ipsecLifetime","type":"\u0005","is_mandatory":true,"title":"Lifetime of the tunnel security association in seconds","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecPfs":{"name":"ipsecPfs","type":"\u0007","is_mandatory":true,"title":"Diffie-Hellman group used to rekey the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecPfsGroups":{"name":"ipsecPfsGroups","type":"\u0019\u0007","title":"Diffie-Hellman groups in effect for tunnel rekeying","desc":"Every distinct group used to rekey the tunnel, spanning the connection and all of its tunnels, deduplicated and sorted. A dual-tunnel connection is only as strong as its weaker tunnel, so the weakest entry is the one that matters for an audit. Empty when neither the connection nor any tunnel reports a group.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"localSubnet":{"name":"localSubnet","type":"\u0007","is_mandatory":true,"title":"CIDR blocks on the Alibaba Cloud side reachable through the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the connection","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the connection lives in","provider":"go.mondoo.com/mql/providers/alicloud"},"remoteSubnet":{"name":"remoteSubnet","type":"\u0007","is_mandatory":true,"title":"CIDR blocks on the remote side reachable through the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Negotiation state of the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Connection status, for example ike_sa_established or active","provider":"go.mondoo.com/mql/providers/alicloud"},"tunnel":{"name":"tunnel","type":"\u001balicloud.vpc.vpnConnection.tunnel","title":"VPN connection tunnel","desc":"A single tunnel of an IPsec-VPN connection, keyed by tunnelId. A dual-tunnel connection runs two tunnels that each negotiate their own IKE and IPsec parameters, so the algorithms and lifetimes here describe that one tunnel and the weaker of the pair is the one that matters. The pre-shared key is deliberately not exposed.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"tunnels":{"name":"tunnels","type":"\u0019\u001balicloud.vpc.vpnConnection.tunnel","is_mandatory":true,"title":"Tunnels the connection is built from","desc":"A dual-tunnel connection negotiates IKE and IPsec separately for each tunnel, so every entry carries its own algorithms and lifetimes and a check that only reads ikeEncryptionAlgorithm and ipsecEncryptionAlgorithm misses whatever the second tunnel agreed to. Empty on a connection the API reports without per-tunnel options.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnConnectionId":{"name":"vpnConnectionId","type":"\u0007","is_mandatory":true,"title":"VPN connection ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGateway":{"name":"vpnGateway","type":"\u001balicloud.vpc.vpnGateway","title":"VPN gateway the connection terminates on","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPN connection","desc":"A single IPsec tunnel terminating on a VPN gateway, keyed by vpnConnectionId. The local and remote subnets are the reachability this connection creates: traffic from the remote subnet reaches the local one without crossing an internet gateway. The negotiated algorithms and lifetimes are exposed so weak cipher suites can be found, but the pre-shared key is deliberately not.","min_provider_version":"13.2.5","defaults":"vpnConnectionId name status","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.vpnConnection.tunnel":{"id":"alicloud.vpc.vpnConnection.tunnel","name":"alicloud.vpc.vpnConnection.tunnel","fields":{"customerGateway":{"name":"customerGateway","type":"\u001balicloud.vpc.customerGateway","title":"Customer gateway representing the remote end of the tunnel","desc":"Each tunnel of a dual-tunnel connection may face a different remote gateway. Null when the gateway has since been deleted, and when it lies outside the scanned regions.","provider":"go.mondoo.com/mql/providers/alicloud"},"enableDpd":{"name":"enableDpd","type":"\u0004","is_mandatory":true,"title":"Whether dead peer detection is enabled on the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"enableNatTraversal":{"name":"enableNatTraversal","type":"\u0004","is_mandatory":true,"title":"Whether NAT traversal is enabled on the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeAuthenticationAlgorithm":{"name":"ikeAuthenticationAlgorithm","type":"\u0007","is_mandatory":true,"title":"Authentication algorithm negotiated for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeEncryptionAlgorithm":{"name":"ikeEncryptionAlgorithm","type":"\u0007","is_mandatory":true,"title":"Encryption algorithm negotiated for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeLifetime":{"name":"ikeLifetime","type":"\u0005","is_mandatory":true,"title":"Lifetime of the key-exchange security association in seconds","desc":"Null when the API reports no lifetime for the tunnel.","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeLocalId":{"name":"ikeLocalId","type":"\u0007","is_mandatory":true,"title":"Identifier the Alibaba Cloud side presents during IKE negotiation","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeMode":{"name":"ikeMode","type":"\u0007","is_mandatory":true,"title":"IKE negotiation mode, either main or aggressive","desc":"Aggressive mode completes in fewer exchanges but sends identity information before the channel is encrypted.","provider":"go.mondoo.com/mql/providers/alicloud"},"ikePfs":{"name":"ikePfs","type":"\u0007","is_mandatory":true,"title":"Diffie-Hellman group used for the key exchange","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeRemoteId":{"name":"ikeRemoteId","type":"\u0007","is_mandatory":true,"title":"Identifier the remote peer presents during IKE negotiation","provider":"go.mondoo.com/mql/providers/alicloud"},"ikeVersion":{"name":"ikeVersion","type":"\u0007","is_mandatory":true,"title":"IKE protocol version, either ikev1 or ikev2","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address the tunnel terminates on","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecAuthenticationAlgorithm":{"name":"ipsecAuthenticationAlgorithm","type":"\u0007","is_mandatory":true,"title":"Authentication algorithm protecting the tunnel payload","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecEncryptionAlgorithm":{"name":"ipsecEncryptionAlgorithm","type":"\u0007","is_mandatory":true,"title":"Encryption algorithm protecting the tunnel payload","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecLifetime":{"name":"ipsecLifetime","type":"\u0005","is_mandatory":true,"title":"Lifetime of the tunnel security association in seconds","desc":"Null when the API reports no lifetime for the tunnel.","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecPfs":{"name":"ipsecPfs","type":"\u0007","is_mandatory":true,"title":"Diffie-Hellman group used to rekey the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"role":{"name":"role","type":"\u0007","is_mandatory":true,"title":"Which side of the pair the tunnel serves","desc":"master for the tunnel carrying traffic, slave for the standby one.","provider":"go.mondoo.com/mql/providers/alicloud"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Negotiation state of the tunnel","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Tunnel status, for example active or updating","provider":"go.mondoo.com/mql/providers/alicloud"},"tunnelId":{"name":"tunnelId","type":"\u0007","is_mandatory":true,"title":"Tunnel ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"tunnelIndex":{"name":"tunnelIndex","type":"\u0005","is_mandatory":true,"title":"Position of the tunnel within the connection","desc":"1 for the first tunnel and 2 for the second on a dual-tunnel connection.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPN connection tunnel","desc":"A single tunnel of an IPsec-VPN connection, keyed by tunnelId. A dual-tunnel connection runs two tunnels that each negotiate their own IKE and IPsec parameters, so the algorithms and lifetimes here describe that one tunnel and the weaker of the pair is the one that matters. The pre-shared key is deliberately not exposed.","min_provider_version":"13.5.1","defaults":"tunnelId role status ikeEncryptionAlgorithm","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.vpnGateway":{"id":"alicloud.vpc.vpnGateway","name":"alicloud.vpc.vpnGateway","fields":{"autoPropagate":{"name":"autoPropagate","type":"\u0004","is_mandatory":true,"title":"Whether the gateway automatically propagates learned routes to the VPC","provider":"go.mondoo.com/mql/providers/alicloud"},"businessStatus":{"name":"businessStatus","type":"\u0007","is_mandatory":true,"title":"Billing status of the gateway, for example Normal or FinancialLocked","provider":"go.mondoo.com/mql/providers/alicloud"},"chargeType":{"name":"chargeType","type":"\u0007","is_mandatory":true,"title":"Billing method of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"connections":{"name":"connections","type":"\u0019\u001balicloud.vpc.vpnConnection","title":"Connections terminating on the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the gateway was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"enableBgp":{"name":"enableBgp","type":"\u0004","is_mandatory":true,"title":"Whether the gateway exchanges routes over BGP","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"Time the gateway subscription ends","provider":"go.mondoo.com/mql/providers/alicloud"},"internetIp":{"name":"internetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address the gateway terminates tunnels on","provider":"go.mondoo.com/mql/providers/alicloud"},"ipsecVpnEnabled":{"name":"ipsecVpnEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the gateway accepts IPsec connections","provider":"go.mondoo.com/mql/providers/alicloud"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the gateway","provider":"go.mondoo.com/mql/providers/alicloud"},"networkType":{"name":"networkType","type":"\u0007","is_mandatory":true,"title":"Whether the gateway is reachable over the internet or only privately","desc":"public for an internet-facing gateway, private for one reachable only from within Alibaba Cloud.","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Region ID the gateway runs in","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the VPN gateway","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the gateway belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"spec":{"name":"spec","type":"\u0007","is_mandatory":true,"title":"Gateway bandwidth specification","provider":"go.mondoo.com/mql/providers/alicloud"},"sslMaxConnections":{"name":"sslMaxConnections","type":"\u0005","is_mandatory":true,"title":"Maximum number of concurrent SSL clients the gateway accepts","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnEnabled":{"name":"sslVpnEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the gateway accepts SSL client connections","desc":"An SSL gateway lets individual clients dial into the VPC rather than joining a fixed network, so it widens reachability to anyone holding a client certificate.","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnInternetIp":{"name":"sslVpnInternetIp","type":"\u0007","is_mandatory":true,"title":"Public IP address SSL clients connect to","provider":"go.mondoo.com/mql/providers/alicloud"},"sslVpnServers":{"name":"sslVpnServers","type":"\u0019\u001balicloud.vpc.sslVpnServer","title":"SSL VPN servers hosted on the gateway","desc":"Empty on a gateway that terminates site-to-site tunnels only. An SSL VPN server is a remote-access path that individual client machines reach.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Gateway status, for example active or provisioning","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags on the gateway, as key-value pairs","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the gateway is attached to","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnGatewayId":{"name":"vpnGatewayId","type":"\u0007","is_mandatory":true,"title":"VPN gateway ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"vpnType":{"name":"vpnType","type":"\u0007","is_mandatory":true,"title":"Gateway type, for example Normal or National-Standard","provider":"go.mondoo.com/mql/providers/alicloud"},"vswitch":{"name":"vswitch","type":"\u001balicloud.vpc.vswitch","title":"vSwitch the gateway is placed in","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"VPN gateway","desc":"A VPN gateway attached to a VPC, keyed by vpnGatewayId. Exposes the IPsec and SSL capabilities, the public address traffic arrives on, and the connections terminating on it. A gateway is how traffic reaches the VPC from outside Alibaba Cloud, so its connections describe reachability that security groups alone do not explain.","min_provider_version":"13.2.5","defaults":"vpnGatewayId name status internetIp","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.vpc.vswitch":{"id":"alicloud.vpc.vswitch","name":"alicloud.vpc.vswitch","fields":{"availableIpAddressCount":{"name":"availableIpAddressCount","type":"\u0005","is_mandatory":true,"title":"Number of available IP addresses in the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"cidrBlock":{"name":"cidrBlock","type":"\u0007","is_mandatory":true,"title":"IPv4 CIDR block of the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Time when the vSwitch was created","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"enabledIpv6":{"name":"enabledIpv6","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 is enabled for the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"ipv6CidrBlock":{"name":"ipv6CidrBlock","type":"\u0007","is_mandatory":true,"title":"IPv6 CIDR block of the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether the vSwitch is the default vSwitch in its zone","provider":"go.mondoo.com/mql/providers/alicloud"},"networkAcl":{"name":"networkAcl","type":"\u001balicloud.vpc.networkAcl","title":"Network ACL bound to the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"ownerId":{"name":"ownerId","type":"\u0005","is_mandatory":true,"title":"ID of the Alibaba Cloud account that owns the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u001balicloud.resourceManager.resourceGroup","title":"Resource group that contains the vSwitch","min_provider_version":"13.3.2","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroupId":{"name":"resourceGroupId","type":"\u0007","is_mandatory":true,"title":"Resource group ID the vSwitch belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTable":{"name":"routeTable","type":"\u001balicloud.vpc.routeTable","title":"Route table associated with the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"routeTableType":{"name":"routeTableType","type":"\u0007","is_mandatory":true,"title":"Type of the associated route table, for example System or Custom","provider":"go.mondoo.com/mql/providers/alicloud"},"shareType":{"name":"shareType","type":"\u0007","is_mandatory":true,"title":"vSwitch sharing status","desc":"Empty for a regular vSwitch, Shared once the vSwitch is shared, or Sharing while sharing is in progress.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of Pending or Available.","provider":"go.mondoo.com/mql/providers/alicloud"},"tags":{"name":"tags","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Tags attached to the vSwitch","provider":"go.mondoo.com/mql/providers/alicloud"},"vSwitchId":{"name":"vSwitchId","type":"\u0007","is_mandatory":true,"title":"vSwitch ID, for example vsw-25bcdxs7pv1abc","provider":"go.mondoo.com/mql/providers/alicloud"},"vSwitchName":{"name":"vSwitchName","type":"\u0007","is_mandatory":true,"title":"vSwitch name","provider":"go.mondoo.com/mql/providers/alicloud"},"vpc":{"name":"vpc","type":"\u001balicloud.vpc.network","title":"VPC the vSwitch belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Zone ID the vSwitch belongs to, for example cn-hangzhou-d","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"vSwitch (VPC subnet)","desc":"A single vSwitch, keyed by vSwitchId, for example vsw-25bcdxs7pv1abc. Exposes the CIDR blocks, the zone, the number of free IP addresses, the associated route table and network ACL, and the parent VPC.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf":{"id":"alicloud.waf","name":"alicloud.waf","fields":{"defenseResource":{"name":"defenseResource","type":"\u001balicloud.waf.defenseResource","title":"Web Application Firewall protected resource","desc":"A single protected object of a WAF instance, keyed by the owning instanceId and resource name. A protected object is a CNAME domain or an attached cloud-native resource (ALB, CLB, MSE). Exposes the backing product, protection mode, and provisioning health. Use it to enumerate what WAF is protecting and whether protection is active.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"defenseRule":{"name":"defenseRule","type":"\u001balicloud.waf.defenseRule","title":"Web Application Firewall protection rule","desc":"A single rule inside a WAF 3.0 protection template, keyed by the owning instanceId and ruleId. Exposes the rule scene, the action taken on a match, the rule configuration, and whether the rule is enabled. Use it to confirm that a protection template blocks rather than merely observes, and to find rules left switched off.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"defenseTemplate":{"name":"defenseTemplate","type":"\u001balicloud.waf.defenseTemplate","title":"Web Application Firewall protection template","desc":"A single WAF 3.0 protection template, keyed by the owning instanceId and templateId. A template holds the rules for one protection scene and carries the switch that decides whether that scene inspects traffic at all. Exposes the scene, the template origin and type, whether it is enabled, and the rules it contains. Use it to find protected objects whose protection modules are bound but switched off.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"domain":{"name":"domain","type":"\u001balicloud.waf.domain","title":"Web Application Firewall protected domain","desc":"A single CNAME-access domain protected by a WAF instance, keyed by domain. Exposes the WAF-assigned CNAME, listen ports, and the TLS configuration (certificate, minimum TLS version) of the HTTPS listener. Use it to audit whether an HTTPS domain enforces a strong TLS version and presents a non-expired certificate.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instance":{"name":"instance","type":"\u001balicloud.waf.instance","title":"Web Application Firewall instance","desc":"A single WAF 3.0 instance, keyed by instanceId. WAF provisions one instance per account per center. Exposes the edition, subscription window, and status, and is the parent of the protected resources and domains. Use it to confirm WAF is provisioned and not expired.","provider":"go.mondoo.com/mql/providers/alicloud","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001balicloud.waf.instance","title":"WAF instances across the China and international centers","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Alibaba Cloud Web Application Firewall","desc":"WAF 3.0 instances and the resources they protect for an Alibaba Cloud account. WAF is a center service with one instance per account in each of the China and international centers. Exposes the instance edition and subscription state, the protected objects (domains and cloud-native resources), and the CNAME domains with their TLS configuration. Use it to audit which web assets are behind WAF and whether their listeners terminate TLS.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.defenseResource":{"id":"alicloud.waf.defenseResource","name":"alicloud.waf.defenseResource","fields":{"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the protected object was created","provider":"go.mondoo.com/mql/providers/alicloud"},"enabledDefenseScenes":{"name":"enabledDefenseScenes","type":"\u0019\u0007","title":"Protection scenes covered by an enabled template on this object","desc":"Each entry is a defenseScene value such as waf_group (basic protection), cc (HTTP flood protection), or custom_acl (custom rules). A scene whose template is bound but switched off is not listed, because a disabled template inspects no traffic.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the WAF instance protecting the resource","provider":"go.mondoo.com/mql/providers/alicloud"},"logDeliveryEnabled":{"name":"logDeliveryEnabled","type":"\u0004","title":"Whether the protected object's logs are delivered to Log Service","desc":"Log delivery is switched on per protected object as well as for the instance as a whole, so an instance whose logStatus reads normal still records nothing for an object left switched off.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"pattern":{"name":"pattern","type":"\u0007","is_mandatory":true,"title":"Protection mode of the object, for example domain","provider":"go.mondoo.com/mql/providers/alicloud"},"product":{"name":"product","type":"\u0007","is_mandatory":true,"title":"Cloud service backing the resource, for example alb, clb, or mse; empty for a CNAME domain","provider":"go.mondoo.com/mql/providers/alicloud"},"protectionEnabled":{"name":"protectionEnabled","type":"\u0004","title":"Whether at least one enabled protection template is applied to the object","desc":"False when the object is onboarded to WAF but every template bound to it is switched off, which is the case an onboarding check alone cannot see: traffic still flows through WAF, and nothing inspects it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the resource belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resource":{"name":"resource","type":"\u0007","is_mandatory":true,"title":"Protected object name, for example a domain or a cloud resource id","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceGroup":{"name":"resourceGroup","type":"\u0007","is_mandatory":true,"title":"WAF protection-group the resource belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resourceStatus":{"name":"resourceStatus","type":"\u0007","is_mandatory":true,"title":"Provisioning status","desc":"active when protection is running, or initializing / init_failed while it is being set up.","provider":"go.mondoo.com/mql/providers/alicloud"},"templates":{"name":"templates","type":"\u0019\u001balicloud.waf.defenseTemplate","title":"Protection templates applied to the protected object","desc":"Templates carry the rules WAF enforces for this object, one template per protection scene. An empty list means the object is onboarded to WAF but no protection module is bound to it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall protected resource","desc":"A single protected object of a WAF instance, keyed by the owning instanceId and resource name. A protected object is a CNAME domain or an attached cloud-native resource (ALB, CLB, MSE). Exposes the backing product, protection mode, and provisioning health. Use it to enumerate what WAF is protecting and whether protection is active.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.defenseRule":{"id":"alicloud.waf.defenseRule","name":"alicloud.waf.defenseRule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action taken when the rule matches","desc":"For example block, monitor, or js (JavaScript challenge). A rule set to monitor records the match and lets the request through.","provider":"go.mondoo.com/mql/providers/alicloud"},"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Rule configuration","desc":"The condition and action detail of the rule, as returned by the API. The shape varies by defenseScene: a custom_acl rule carries its match conditions, an ip_blacklist rule carries its address list. Null when the configuration is not valid JSON.","provider":"go.mondoo.com/mql/providers/alicloud"},"createTime":{"name":"createTime","type":"\t","is_mandatory":true,"title":"Time the rule was created","provider":"go.mondoo.com/mql/providers/alicloud"},"defenseOrigin":{"name":"defenseOrigin","type":"\u0007","is_mandatory":true,"title":"Origin of the rule, custom for user-created or system for generated","provider":"go.mondoo.com/mql/providers/alicloud"},"defenseScene":{"name":"defenseScene","type":"\u0007","is_mandatory":true,"title":"Protection scene the rule belongs to, for example custom_acl, cc, or ip_blacklist","provider":"go.mondoo.com/mql/providers/alicloud"},"defenseType":{"name":"defenseType","type":"\u0007","is_mandatory":true,"title":"Scope the rule was defined at","desc":"One of template (a rule inside a protection template), resource (a rule bound to one protected object), or global.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the rule","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the WAF instance the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the rule belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"resource":{"name":"resource","type":"\u0007","is_mandatory":true,"title":"Protected object the rule is bound to, empty for a template or global rule","provider":"go.mondoo.com/mql/providers/alicloud"},"ruleId":{"name":"ruleId","type":"\u0005","is_mandatory":true,"title":"Rule ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"ruleName":{"name":"ruleName","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/mql/providers/alicloud"},"ruleType":{"name":"ruleType","type":"\u0007","is_mandatory":true,"title":"Rule type","desc":"One of whitelist (a rule that skips inspection) or defense (a rule that inspects). A whitelist rule widens what reaches the origin, so it deserves the same scrutiny as an allow rule in a firewall.","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Raw rule status, 0 (disabled) or 1 (enabled)","provider":"go.mondoo.com/mql/providers/alicloud"},"templateId":{"name":"templateId","type":"\u0005","is_mandatory":true,"title":"ID of the template the rule belongs to, 0 for a global or per-object rule","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the rule was last modified","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall protection rule","desc":"A single rule inside a WAF 3.0 protection template, keyed by the owning instanceId and ruleId. Exposes the rule scene, the action taken on a match, the rule configuration, and whether the rule is enabled. Use it to confirm that a protection template blocks rather than merely observes, and to find rules left switched off.","min_provider_version":"13.5.1","defaults":"ruleName defenseScene action enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.defenseTemplate":{"id":"alicloud.waf.defenseTemplate","name":"alicloud.waf.defenseTemplate","fields":{"defenseScene":{"name":"defenseScene","type":"\u0007","is_mandatory":true,"title":"Protection scene the template covers","desc":"One of waf_group (basic protection), antiscan (scan protection), ip_blacklist, custom_acl (custom rules), whitelist, region_block (location blacklist), custom_response, cc (HTTP flood protection), tamperproof (web tamper proofing), dlp (data leak prevention), or bot_manager.","provider":"go.mondoo.com/mql/providers/alicloud"},"defenseSubScene":{"name":"defenseSubScene","type":"\u0007","is_mandatory":true,"title":"Sub-scene of the template","desc":"Set only for bot management templates, where it is one of web, app, basic, or bot_custom_acl. Empty for every other scene.","provider":"go.mondoo.com/mql/providers/alicloud"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the template","provider":"go.mondoo.com/mql/providers/alicloud"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the template is enabled","desc":"A disabled template is configured but inspects no traffic, so the scene it covers is unprotected on every object the template is bound to.","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the WAF instance the template belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the template belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"rules":{"name":"rules","type":"\u0019\u001balicloud.waf.defenseRule","title":"Protection rules contained in the template","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Raw template status, 0 (disabled) or 1 (enabled)","provider":"go.mondoo.com/mql/providers/alicloud"},"templateId":{"name":"templateId","type":"\u0005","is_mandatory":true,"title":"Template ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"templateName":{"name":"templateName","type":"\u0007","is_mandatory":true,"title":"Template name","provider":"go.mondoo.com/mql/providers/alicloud"},"templateOrigin":{"name":"templateOrigin","type":"\u0007","is_mandatory":true,"title":"Origin of the template, custom for a user-defined template","provider":"go.mondoo.com/mql/providers/alicloud"},"templateType":{"name":"templateType","type":"\u0007","is_mandatory":true,"title":"Template type","desc":"One of user_default (the account-wide default for the scene) or user_custom (a template bound to named protected objects).","provider":"go.mondoo.com/mql/providers/alicloud"},"updateTime":{"name":"updateTime","type":"\t","is_mandatory":true,"title":"Time the template was last modified","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall protection template","desc":"A single WAF 3.0 protection template, keyed by the owning instanceId and templateId. A template holds the rules for one protection scene and carries the switch that decides whether that scene inspects traffic at all. Exposes the scene, the template origin and type, whether it is enabled, and the rules it contains. Use it to find protected objects whose protection modules are bound but switched off.","min_provider_version":"13.5.1","defaults":"templateName defenseScene templateType enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.domain":{"id":"alicloud.waf.domain","name":"alicloud.waf.domain","fields":{"certExpireTime":{"name":"certExpireTime","type":"\t","title":"Expiry time of the bound certificate, null when no certificate is configured","provider":"go.mondoo.com/mql/providers/alicloud"},"certId":{"name":"certId","type":"\u0007","title":"ID of the certificate bound to the HTTPS listener, empty when none","provider":"go.mondoo.com/mql/providers/alicloud"},"cname":{"name":"cname","type":"\u0007","is_mandatory":true,"title":"WAF-assigned CNAME that traffic must resolve to","provider":"go.mondoo.com/mql/providers/alicloud"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Protected hostname, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"httpPorts":{"name":"httpPorts","type":"\u0019\u0005","is_mandatory":true,"title":"HTTP listener ports","provider":"go.mondoo.com/mql/providers/alicloud"},"httpsEnabled":{"name":"httpsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the domain serves HTTPS","desc":"True when at least one HTTPS listener port is configured.","provider":"go.mondoo.com/mql/providers/alicloud"},"httpsPorts":{"name":"httpsPorts","type":"\u0019\u0005","is_mandatory":true,"title":"HTTPS listener ports","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"ID of the WAF instance protecting the domain","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the domain belongs to","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Domain status","desc":"1 (normal), 2 (creating), 3 (modifying), 4 (releasing), or 5 (forwarding disabled).","provider":"go.mondoo.com/mql/providers/alicloud"},"tls13Enabled":{"name":"tls13Enabled","type":"\u0004","title":"Whether TLS 1.3 is enabled","provider":"go.mondoo.com/mql/providers/alicloud"},"tlsVersion":{"name":"tlsVersion","type":"\u0007","title":"Minimum TLS version accepted, for example tlsv1.2","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall protected domain","desc":"A single CNAME-access domain protected by a WAF instance, keyed by domain. Exposes the WAF-assigned CNAME, listen ports, and the TLS configuration (certificate, minimum TLS version) of the HTTPS listener. Use it to audit whether an HTTPS domain enforces a strong TLS version and presents a non-expired certificate.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"},"alicloud.waf.instance":{"id":"alicloud.waf.instance","name":"alicloud.waf.instance","fields":{"defenseResources":{"name":"defenseResources","type":"\u0019\u001balicloud.waf.defenseResource","title":"Protected objects (domains and cloud-native resources) behind the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"defenseTemplates":{"name":"defenseTemplates","type":"\u0019\u001balicloud.waf.defenseTemplate","title":"Protection templates configured on the instance","desc":"A template groups the rules for one protection scene (basic protection, HTTP flood protection, custom rules, and the rest) and carries its own enabled flag. An instance can have every template switched off while still reporting protected objects, so enumerate these to tell an onboarded asset from a defended one.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"domains":{"name":"domains","type":"\u0019\u001balicloud.waf.domain","title":"CNAME-access domains protected by the instance","provider":"go.mondoo.com/mql/providers/alicloud"},"edition":{"name":"edition","type":"\u0007","is_mandatory":true,"title":"Instance edition or plan","provider":"go.mondoo.com/mql/providers/alicloud"},"endTime":{"name":"endTime","type":"\t","is_mandatory":true,"title":"End of the subscription window","provider":"go.mondoo.com/mql/providers/alicloud"},"inDebt":{"name":"inDebt","type":"\u0007","is_mandatory":true,"title":"Whether the instance is in debt (overdue payment)","provider":"go.mondoo.com/mql/providers/alicloud"},"instanceId":{"name":"instanceId","type":"\u0007","is_mandatory":true,"title":"WAF instance ID, used as the lookup key","provider":"go.mondoo.com/mql/providers/alicloud"},"logDeliveryEnabled":{"name":"logDeliveryEnabled","type":"\u0004","title":"Whether the instance is delivering its logs to Log Service","desc":"True only while logStatus reports normal. A failed initialization and an in-progress release both leave the instance protecting traffic while recording nothing about it.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logRegionId":{"name":"logRegionId","type":"\u0007","title":"Region the instance delivers its logs to","desc":"Empty when log delivery has never been configured.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"logStatus":{"name":"logStatus","type":"\u0007","title":"State of Log Service log delivery for the instance","desc":"One of initializing, initialize_failed, normal, releasing, or release_failed. Empty when log delivery has never been configured.","min_provider_version":"13.5.1","provider":"go.mondoo.com/mql/providers/alicloud"},"payType":{"name":"payType","type":"\u0007","is_mandatory":true,"title":"Billing method, for example POSTPAY or SUBSCRIPTION","provider":"go.mondoo.com/mql/providers/alicloud"},"regionId":{"name":"regionId","type":"\u0007","is_mandatory":true,"title":"Center region the instance belongs to, either cn-hangzhou or ap-southeast-1","provider":"go.mondoo.com/mql/providers/alicloud"},"startTime":{"name":"startTime","type":"\t","is_mandatory":true,"title":"Start of the subscription window","provider":"go.mondoo.com/mql/providers/alicloud"},"status":{"name":"status","type":"\u0005","is_mandatory":true,"title":"Instance status","desc":"1 (Normal), 2 (Expired), or 3 (Released). Only a Normal instance is actively protecting traffic.","provider":"go.mondoo.com/mql/providers/alicloud"}},"title":"Web Application Firewall instance","desc":"A single WAF 3.0 instance, keyed by instanceId. WAF provisions one instance per account per center. Exposes the edition, subscription window, and status, and is the parent of the protected resources and domains. Use it to confirm WAF is provisioned and not expired.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/alicloud"}},"dependencies":{"core":{"id":"go.mondoo.com/mql/providers/core","name":"core"}},"provider_roots":{"go.mondoo.com/mql/providers/alicloud":"alicloud"}}