Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
cli — AWS, Azure, GCP, K8s 및 tencent를 위한 범용 GraphQL API 및 CSPM 도구 | Kitploit
도구/GitHubGitHub/cloudgraphdev/cli
Cloud Infrastructure SecurityVulnerability ScannersConfiguration AuditingCloud SecurityDevSecOpsAPI Security
GitHubcloudgraphdev/cli

cli

AWS, Azure, GCP, K8s 및 tencent를 위한 범용 GraphQL API 및 CSPM 도구

저장소 보기
888423년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트

CloudGraph



CloudGraph는 AWS, Azure, GCP, K8s를 위한 무료 오픈소스 유니버설 GraphQL API 및 클라우드 보안 구성 관리(CSPM) 도구입니다. CloudGraph를 사용하면 다음과 같은 기능을 얻을 수 있습니다:

  • 무료이며 간편한 규정 준수 검사 (예: Azure CIS 1.3.1, GCP CIS 1.2, AWS CIS 1.2, AWS CIS 1.3, AWS CIS 1.4, AWS PCI 3.2.1, AWS NIST 800-53 Rev. 4)
  • 모든 클라우드 환경의 모든 리소스에 대한 타입 안전 자산 인벤토리
  • 자동 생성된 문서 및 쿼리 검증 - 쿼리를 보내기 전에 유효한지 확인할 수 있습니다!
  • 리소스 간의 _관계_를 포함한 전체 리소스 데이터로 맥락을 이해할 수 있습니다
  • 시간 경과에 따른 데이터의 과거 스냅샷
  • 모든 클라우드 데이터를 한 번에 조회할 수 있는 단일 엔드포인트 (예: 동일한 쿼리에서 AWS + GCP 데이터 가져오기, AWS 스테이지와 AWS 프로덕션 비교)
  • 개선된 청구 데이터 (AWS 전용)
  • 개선된 CloudWatch 데이터 (AWS EC2 전용)

Cloud Graph를 사용하면 5분 안에 클라우드를 알 수 있습니다. AutoCloud 팀이 사랑을 담아 만들고 유지 관리합니다 ❤️ AutoCloud ❤️


🌐 웹사이트

💻 문서

💰 CloudGraph 제공업체 구축에 대한 보상 받기


oclif Version node-current Downloads/week License GitHub commit activity GitHub contributors GitHub issues


커뮤니티 참여하기

Slack Tweet Twitter Follow

  • CloudGraph를 사용하는 놀라운 기업들**
  • 왜 CloudGraph인가
  • 작동 방식
  • 인증 및 권한
  • 설치
  • 빠른 시작
  • 이전 버전 로드
  • 지원되는 서비스
  • 예제 쿼리
  • 쿼리 도구
  • 커뮤니티
  • 기여 지침
  • 배포 옵션
  • 호스팅 버전
  • 디버깅
  • 일반적인 오류
  • 명령어

CloudGraph를 사용하는 놀라운 기업들**

  • AWS
  • Microsoft
  • Oracle
  • IBM
  • NASA
  • Grafana
  • Pinterest
  • Zendesk
  • McKinsey
  • Pulumi
  • Siemens
  • MasterCard

** 사용이 보증을 의미하지는 않습니다

왜 CloudGraph인가

AWS, Azure, GPC는 점점 더 상호 연결된 세상을 위한 시스템을 구축할 수 있도록 엔지니어 같은 우리를 위한 솔루션을 훌륭하게 구축해 왔습니다. 지난 15년 동안 EC2, S3, RDS, Lambda와 같은 제품들은 컴퓨팅, 스토리지, 데이터베이스에 대한 우리의 생각을 근본적으로 바꾸어 놓았습니다.


지난 5년 정도 동안 Kubernetes 및 Serverless의 확산으로 클라우드 서비스는 물리적 서버 랙 위에서 점점 더 추상화되었습니다. 최종 사용자에게 클라우드의 모든 것은 단지 API일 뿐이므로 애플리케이션 구축에 사용하기 위해 Lambda 함수나 EKS가 내부적으로 어떻게 작동하는지 반드시 알 필요는 없습니다. 약간의 문서, API 또는 콘솔 액세스, 튜토리얼만 있으면 누구든지 필요한 거의 모든 것을 만들 수 있습니다.


이러한 추상화는 CSP 서비스 제공의 전반적인 편의성과 범위에서 엄청난 개선을 가져왔습니다. 한때 새 서버, 데이터베이스 또는 파일 시스템을 프로비저닝하는 것이 고통스럽고 시간이 많이 걸리며 오류가 발생하기 쉬운 과정이었지만, 이제는 버튼 클릭 한 번이나 IAC 배포만으로 몇 초 만에 수행할 수 있습니다. 모든 것이 단지 API 추상화이기 때문에 CSP가 새로운 "제품"을 도입할 준비가 되면 새 API를 노출하기만 하면 됩니다. 물론 약간 단순화한 것입니다 :)


CSP에 익숙한 사람이라면 서비스 API가 거의 항상 수십 개, 경우에 따라 수백 개의 개별 API 메서드를 포함하는 모듈식 네임스페이스로 분할된다는 것을 알고 있습니다. 예를 들어 AWS EC2 서비스에는 500개가 넘는 API 메서드가 있으며, 때때로 새로운 메서드가 추가됩니다. CSP에서 상당한 규모의 시스템을 구축하는 모든 회사는 아마도 매우 다양한 서비스를 사용하고 있을 것입니다.


데이터센터 아키텍처의 걸작이지만, 수백 가지 서비스와 구성 옵션의 선택은 이러한 서비스를 올바르게 사용하는 방법에 대한 지식의 부담을 우리 엔지니어에게 고스란히 안겨주었습니다. 그 결과, 우리는 모든 서비스 제공이나 새로운 변경 사항을 지속적으로 업데이트하고 배워야 하는 상황에 처하게 됩니다. 이는 상당한 시간과 정신적 에너지를 필요로 합니다. 개발자로서 AWS CLI를 사용하여 예를 들어 AWS ECS 클러스터, 그 서비스, 작업 정의, 작업, 컨테이너 정의 등을 설명하기 위해 5개의 다른 API 호출을 해야 하는 것은 어렵고 시간이 많이 걸리며 좌절스러울 수 있습니다. 우리는 종종 문서에서 길을 잃고 "이 VPC에서 정확히 무엇이 실행되고 있나요?"와 같은 질문에 대한 답을 얻기 위해 수많은 API를 사용해야 합니다.


이는 AWS, Azure, GCP가 숙련된 클라우드 아키텍트에게조차 빠르게 압도적으로 느껴질 수 있음을 의미합니다. CSP는 우리 비즈니스를 구동하는 실제 서비스를 구축하는 데는 환상적이지만, 수백 가지 서비스를 합리적인 방식으로 쿼리하는 일상적인 UX를 단순화하는 데는 많은 진전이 없었습니다.


AWS의 Cloud Control API와 같은 새로운 솔루션은 다양한 유형의 AWS 리소스를 쿼리하기 위한 표준화된 인터페이스를 만들려고 시도했습니다. 불행히도 Cloud Control API의 사용은 심각하게 제한되어 있으며, 사용자는 여전히 데이터를 올바르게 쿼리하는 방법을 알아야 합니다. 즉, 문서를 읽고 서비스가 어떻게 작동하고 서로 관련되어 있는지 이해하는 데 더 많은 시간을 소비해야 합니다.


CSP API의 모듈성은 훌륭한 논리적 구성 시스템이며 타당하지만, 인지적 부담과 학습 곡선 측면에서 최종 사용자에게 부담이 됩니다. 끊임없이 변화하는 수백 가지 서비스가 어떻게 작동하고 연결되어 있는지 기억해야 하는 것은 카페인 중독과 탐정 놀이에 시간 낭비로 이어집니다.


DevOps/클라우드 엔지니어로서 AWS, Azure, GCP 등에서 데이터를 더 간단하게 가져올 수 있는 방법이 있다면 좋지 않을까요? 계정에 관계없이 모든 서비스에 대한 모든 데이터를 쉽게 쿼리할 수 있는, 문서나 스택 오버플로에서 몇 시간을 소비하지 않아도 되는 방법이 있다면요?


이러한 이유로 우리는 모든 클라우드를 위한 GraphQL API인 CloudGraph를 구축했습니다. CloudGraph는 클라우드 데이터를 추출하고, 정규화하고, 처리하고, 보강하여 여러 제공업체에 걸쳐 깊은 통찰력에 쉽게 액세스할 수 있도록 합니다. 자세한 내용은 블로그 게시물 The GraphQL API for everything을 확인하세요.

example queries


작동 방식

CloudGraph는 실행하기 위해 읽기 전용 권한이 필요하며, 따라서 실제 클라우드 인프라를 절대 변경할 수 없습니다. 또한 사용자의 클라우드 환경 정보가 CloudGraph, AutoCloud 또는 다른 제3자에게 전송되거나 공유되지 않습니다.


내부적으로 CloudGraph는 클라우드 제공업체에 연결하여 모든 구성 데이터를 수집하고, 처리한 후, 이 데이터의 복사본을 Dgraph에 저장합니다. 그런 다음 http://localhost:8997에서 엔드포인트를 노출하여 저장된 데이터에 대해 GraphQL 쿼리를 작성할 수 있습니다. 이러한 쿼리를 통해 AWS SDK/CLI 등으로 할 수 있는 모든 것을 수행할 수 있을 뿐만 아니라 훨씬 더 강력한 쿼리도 실행할 수 있습니다. CloudGraph는 GraphQL Playground 및 Altair를 포함한 사전 패키지된 GraphQL 쿼리 도구와 함께 제공되지만, 자신만의 도구를 자유롭게 사용할 수도 있습니다. 또한 엔티티 간의 관계를 이해할 수 있도록 Voyager라는 스키마 시각화 도구도 포함되어 있습니다.


인증 및 권한

CloudGraph는 현재 AWS, Azure, GCP, K8s, Tencent를 지원합니다 (곧 몇 가지 더 추가 예정). CloudGraph는 데이터를 수집하기 위해 읽기 권한이 필요합니다. 쉽게 하기 위해 AutoCloud을 구동할 때 CloudGraph를 실행하는 데 내부적으로 사용하는 것과 동일한 권한을 사용할 수 있습니다. 각 제공업체에 대한 인증 가이드 및 자격 증명 생성 방법은 다음과 같습니다 (AutoCloud 관련 구성은 생략해도 됩니다):


  • AWS 문서
  • Azure 문서
  • GCP 문서
  • K8s 문서
  • Tencent 문서

설치

시스템 요구 사항

  • Docker

CloudGraph CLI를 설치하는 방법은 2가지가 있습니다.

Homebrew (권장)

다음 명령어로 Homebrew를 사용하여 CloudGraph를 설치할 수 있습니다: brew install cloudgraphdev/tap/cg

NPM

  • Node 16+ 필요

이 명령어를 사용하여 CloudGraph를 최신 버전으로 설치하고 업데이트하세요.```bash npm i -g @cloudgraph/cli

root@kitploit:~
<p align="center">
  <a href="https://github.com/cloudgraphdev/cli/raw/main/docs/images/install.gif">
    <img alt="install" src="https://raw.githubusercontent.com/cloudgraphdev/cli/main/docs/images/install.gif" width="95%" style="display: block; margin: auto"/>
  </a>
</p>

<br/>

그런 다음 원하는 공급자를 추가할 수 있습니다 (공급자 저장소 링크: [AWS](https://github.com/cloudgraphdev/cloudgraph-provider-aws), [Azure](https://github.com/cloudgraphdev/cloudgraph-provider-azure), [GCP](https://github.com/cloudgraphdev/cloudgraph-provider-gcp), [K8s](https://github.com/cloudgraphdev/cloudgraph-provider-k8s), [Tencent Docs](https://github.com/cloudgraphdev/cloudgraph-provider-tencent)):```bash
cg init aws
cg init azure
cg init gcp
cg init k8s
cg init tencent

또한 원하는 만큼 한 번에 추가할 수 있습니다.```bash cg init aws azure gcp k8s tencent

root@kitploit:~
그리고 규정 준수 정책 팩을 추가하여 데이터를 즉각적인 보안 인사이트로 보강하세요:```bash
cg policy add gcp-cis-1.2.0
cg policy add azure-cis-1.3.1
cg policy add aws-cis-1.2.0
cg policy add aws-cis-1.3.0
cg policy add aws-cis-1.2.0
cg policy add aws-pci-dss-3.2.1
cg policy add aws-nist-800-53-rev4

현재 지원되는 정책 팩 목록은 Policy Packs 리포지토리에서 확인할 수 있습니다.


빠른 시작

세 가지 간단한 명령어로 바로 시작할 수 있습니다:


```bash

cg init

root@kitploit:~
이 명령은 CloudGraph의 구성을 초기화합니다. 이 명령은 사용 중인 공급자와 CloudGraph를 어떻게 구성할지에 대한 일련의 질문을 할 것입니다.

<p align="center">
  <a href="https://github.com/cloudgraphdev/cli/raw/main/docs/images/init.gif">
    <img alt="init" src="https://raw.githubusercontent.com/cloudgraphdev/cli/main/docs/images/init.gif" width="95%" style="display: block; margin: auto"/>
  </a>
</p>

<br/>

---

<br/>```bash
cg launch

  1. 이 명령은 CloudGraph가 데이터를 저장하기 위해 내부적으로 사용하는 그래프 데이터베이스인 Dgraph 인스턴스를 실행합니다. 인스턴스를 실행하는 방법은 두 가지가 있습니다. 두 방법 모두 Docker가 설치되어 실행 중이어야 합니다. 권장되는 방법은 cg launch 편의 명령을 사용하는 것입니다.

launch

이 명령을 사용하지 않으려는 경우, 예를 들어 Dgraph 컨테이너를 대화형 모드로 실행하려면 아래의 docker 명령을 사용할 수 있습니다.```bash docker run -it -p 8995:5080 -p 8996:6080 -p 8997:8080 -p 8998:9080 -p 8999:8000 --label cloudgraph-cli-dgraph-standalone -v ~/dgraph:/dgraph --name dgraph dgraph/standalone:v21.03.1

root@kitploit:~
---

<br/>```bash
cg scan

  1. 구성된 모든 공급자에 대해 클라우드 인프라를 스캔합니다. 이 명령은 클라우드 인프라의 모든 메타데이터를 읽어옵니다. cg scan 명령이 실행되는 동안 경고 및 오류가 표시되는 것은 완전히 정상입니다. 이는 일반적으로 권한 문제로 인해 발생합니다. 하지만 CloudGraph 실행 시 문제가 되는 오류가 발생하면 명령 앞에 CG_DEBUG=5를 추가하여 CG_DEBUG=5 cg scan과 같이 실행할 수 있습니다. 이렇게 하면 자세한 로그가 출력되고 cg-debug.log 파일에 저장됩니다. 로그가 있으면 GitHub 이슈를 열거나 Slack Workspace를 통해 공유해 주세요.

scan

이제 쿼리를 시작할 준비가 끝났습니다! cg init 명령 중 선택한 쿼리 도구가 기본 브라우저에서 열려 모든 클라우드 인프라에 대한 쿼리, 뮤테이션 및 시각화를 실행할 수 있습니다! 또한 AWS CIS 1.2와 같은 정책 팩을 설치한 경우 정책 팩 인사이트 데이터가 자동으로 클라우드 데이터에 추가됩니다!


원하는 경우 모든 GraphQL 쿼리 도구를 http://localhost:8997/graphql에 연결하여 사용할 수도 있습니다.


Dgraph 인스턴스 중지


Dgraph 인스턴스(dgraph 컨테이너)를 중지하려면 다음을 실행하십시오:


```bash cg teardown

root@kitploit:~
<br />

추가로, 컨테이너를 중지한 후 제거하려면 다음을 실행하세요:

<br />```bash
cg teardown --delete-image

이전 버전 로드


CloudGraph는 cg init 명령어에서 설정한 만큼 데이터의 이전 버전을 저장합니다. 이전 버전의 데이터를 로드하고 쿼리하려면 cg load 명령어를 실행하고 검사하려는 데이터 버전을 선택하기만 하면 됩니다:


load


지원되는 서비스


각 제공업체별로 현재 지원되는 서비스 목록은 다음 제공업체 저장소에서 확인할 수 있습니다:

AWS Provider Repo

Azure Provider Repo

GCP Provider Repo

K8s Provider Repo


예제 쿼리

전체 문서 링크: https://docs.cloudgraph.dev/overview.

CloudGraph를 사용하려면 GraphQL에 익숙해야 합니다. 이 섹션에는 시작하는 데 도움이 되는 몇 가지 예제 쿼리가 포함되어 있지만, 결코 완벽하지는 않습니다. 상상할 수 있는 모든 것을 쿼리할 수 있습니다! 문서에서 수백 개의 추가 예제 쿼리를 찾을 수 있습니다.


기본 쿼리 구문 예제:

참고: 이 섹션은 AWS에 초점을 맞추지만, 동일한 아이디어가 Azure 및 GCP와 같은 다른 제공업체에도 적용됩니다.

CloudGraph의 작동 방식을 설명하기 위해 단일 EC2 인스턴스의 ID와 ARN을 가져오기 위해 실행할 수 있는 다음 쿼리를 고려해 보겠습니다. 이 예제의 목적을 위해 간결성을 위해 AWS 리소스의 IDs와 ARNs만 요청할 것이지만, 원하는 모든 속성을 쿼리할 수 있습니다:


```graphql query { getawsEc2( arn: "arn:aws:ec2:us-east-1:123445678997:instance/i-12345567889012234" ) { id arn } }

root@kitploit:~
<br />

이 쿼리는 다음과 같은 `JSON` 페이로드를 반환합니다. 다음 예시들도 모두 이와 같습니다:

<br />```json
{
  "data": {
    "getawsEc2": {
      "id": "i-12345567889012234",
      "arn": "arn:aws:ec2:us-east-1:123445678997:instance/i-12345567889012234"
    }
  },
  "extensions": {
    "touched_uids": 4
  }
}

스캔한 모든 AWS 계정에서 각 EC2의 ID와 ARN을 가져옵니다:```graphql query { queryawsEc2 { id arn } }

root@kitploit:~
<br />

계정 ID를 필터링하여 AWS 계정 **하나**에 있는 모든 `EC2` 인스턴스의 `ID` 및 `ARN`을 가져옵니다:```graphql
query {
  queryawsEc2(filter: { accountId: { eq: "123456" } }) {
    id
    arn
  }
}

"us-east-1"에 있는 각 EC2의 ID와 ARN을 정규식을 사용하여 ARN을 검색해 가져옵니다:```graphql query { queryawsEc2(filter: { arn: { regexp: "/.us-east-1./" } }) { id arn } }

root@kitploit:~
<br />

같은 작업을 수행하되, regex를 사용하는 대신 `region`이 `"us-east-1"`과 같은지 확인합니다.```graphql
query {
  queryawsEc2(filter: { region: { eq: "us-east-1" } }) {
    id
    arn
  }
}

동일한 작업을 수행하되, eq를 사용하는 대신 region이 이름에 "us-east-1"을 포함하는지 확인합니다:```graphql query { queryawsEc2(filter: { region: { in: "us-east-1" } }) { id arn } }

root@kitploit:~
<br />

`"us-east-1"`에서 각 `M5` 시리즈 `EC2 instance`의 `ID` 및 `ARN`을 가져옵니다.```graphql
query {
  queryawsEc2(
    filter: { region: { eq: "us-east-1" }, instanceType: { regexp: "/^m5a*/" } }
  ) {
    id
    arn
  }
}

동일한 작업을 수행하되, 첫 번째로 찾은 결과를 건너뛰고(즉, offset: 1) 그 후 처음 두 개의 결과만 반환하며(즉, first: 2), 해당 결과를 AZ 기준 오름차순으로 정렬하여(order: { asc: availabilityZone }) "us-east-1a"에 있는 인스턴스(들)가 목록의 맨 위에 반환되도록 합니다.```graphql query { queryawsEc2( filter: { region: { eq: "us-east-1" }, instanceType: { regexp: "/^m5a*/" } } order: { asc: availabilityZone } first: 2 offset: 1 ) { id arn } }

root@kitploit:~
<br />

동일한 작업을 수행하되, 각 `EC2 instance`의 부트 디스크인 `EBS Volume`도 포함하십시오:```graphql
query {
  queryawsEc2(
    filter: { region: { eq: "us-east-1" }, instanceType: { regexp: "/^m5a*/" } }
    order: { asc: availabilityZone }
    first: 2
    offset: 1
  ) {
    id
    arn
    ebs(filter: { isBootDisk: true }, first: 1) {
      id
      arn
      isBootDisk
    }
  }
}

동일한 작업을 수행하되, 각 EC2에 대한 SGs 및 ALBs도 포함하십시오. ALBs의 경우, 연결된 EC2s를 찾고, 발견된 각 EC2 instance의 ID 및 ARN을 함께 가져오십시오 (즉, 순환 쿼리).```graphql query { queryawsEc2( filter: { region: { eq: "us-east-1" }, instanceType: { regexp: "/^m5a*/" } } order: { asc: availabilityZone } first: 2 offset: 1 ) { id arn ebs(filter: { isBootDisk: true }, first: 1) { id arn isBootDisk } securityGroups { id arn } alb { id arn ec2Instance { id arn } } } }

root@kitploit:~
<br />

각 `VPC`, 해당 `VPC` 내의 `ALB` 및 `Lambda`, 그리고 그 외 중첩된 하위 데이터도 함께 가져옵니다. 또한 `us-east-1`의 각 `S3 버킷`도 가져옵니다. `ARN`이 `arn:aws:sqs:us-east-1:8499274828484:autocloud.fifo`인 `SQS` 대기열도 가져오고 `approximateNumberOfMessages`를 확인합니다. 감이 오시죠? CloudGraph는 **매우** 강력합니다.```graphql
query {
  queryawsVpc {
    id
    arn
    alb {
      id
      arn
      ec2Instance {
        id
        arn
        ebs(filter: { isBootDisk: true }) {
          id
          arn
        }
      }
    }
    lambda {
      id
      arn
      kms {
        id
        arn
      }
    }
  }
  queryawsS3(filter: { region: { eq: "us-east-1" } }) {
    id
    arn
  }
  getawsSqs(arn: "arn:aws:sqs:us-east-1:8499274828484:autocloud.fifo") {
    approximateNumberOfMessages
  }
}

AWS 보안, 규정 준수 및 거버넌스 예시:

CloudGraph Policy Pack은 특정 클라우드 제공업체의 기존 인프라에 걸친 규정 준수를 보장합니다. Pack은 Center for Internet Security와 같은 보안 기관에서 제공하는 규칙/벤치마크 세트를 기반으로 하며, 인프라를 업계 보안 표준에 맞춰 최신 상태로 유지하는 것을 목표로 합니다. cg policy add 명령어(예: cg policy add aws-cis-1.2.0)를 사용하여 정책 팩을 추가한 후, 스캔을 실행할 때마다 CloudGraph는 구성된 정책을 자동으로 실행합니다. 해당 결과는 Dgraph에 저장되고 기존 리소스에 연결되어, 리소스와 함께 규정 준수 결과를 쉽게 쿼리할 수 있습니다.

현재 사용 가능한 정책 팩에 대한 자세한 내용은 Policy Packs 저장소를 방문해 주세요.


CloudGraph Policy Pack for AWS CIS 1.2를 사용하여 모든 AWS 계정의 모든 CIS 결과를 쿼리하세요:```graphql query { queryawsCISFindings { id resourceId result rule { id description severity } } }

root@kitploit:~
<br />

특정 공급자(예: AWS)에 대한 여러 가지 규정 준수 결과를 한 번에 조회하려면 다음과 같이 요청할 수 있습니다:```graphql
query {
  queryawsFindings {
    CISFindings {
      id
      resourceId
      result
      rule {
        id
        description
        severity
      }
    }
    AutoCloudFindings {
      id
      resourceId
      result
      rule {
        id
        description
        severity
      }
    }
  }
}

각 CIS 규칙에 대해, 규칙과 연관된 리소스를 가져옵니다. 이 경우 IAM 사용자의 데이터를 쿼리하여 통과 및 실패를 확인합니다:```graphql query { queryawsCISFindings { id resourceId result rule { id description severity } iamUser { id arn name } } }

root@kitploit:~
<br />

만약 특정 IAM User에 적용되는 CIS rules를 이해하고 싶다면 다음 쿼리를 사용할 수 있습니다:```graphql
query {
  getawsIamUser(id: "123456789") {
    name
    CISFindings {
      id
      resourceId
      result
      rule {
        id
        description
        severity
      }
    }
  }
}

정책 팩이 설치되어 있지 않더라도, 다음과 같은 강력한 보안 쿼리를 작성하여 암호화되지 않은 모든 EBS Volumes를 찾을 수 있습니다:```graphql query { queryawsEbs(filter: { encrypted: false }) { id arn availabilityZone encrypted } }

root@kitploit:~
<br />

모든 공개 `S3 Buckets`를 찾습니다:```graphql
query {
  queryawsS3(filter: { access: { eq: "Public" } }) {
    id
    arn
    access
  }
}

자체적으로 공개되어 있거나 내부에 공개된 객체를 가질 수 있는 모든 S3 Buckets를 찾으세요:```graphql query { queryawsS3(filter: { not: { access: { eq: "Private" } } }) { id arn access } }

root@kitploit:~
<br />

모든 `KMS` 키를 `"us-east-1"`에서 찾으십시오:```graphql
query {
  queryawsKms(filter: { arn: { regexp: "/.*us-east-1.*/" } }) {
    id
    arn
    description
    keyRotationEnabled
    tags {
      key
      value
    }
  }
}

모든 버스터블 T 시리즈 인스턴스 찾기:```graphql query { queryawsEc2(filter: { instanceType: { regexp: "/^t.*/" } }) { id arn availabilityZone instanceType } }

root@kitploit:~
<br />

기본 `VPCs` 찾기:```graphql
query {
  queryawsVpc(filter: { defaultVpc: true }) {
    id
    arn
    defaultVpc
    state
  }
}

공용 ALBs를 찾으세요:```graphql query { queryawsAlb(filter: { scheme: { eq: "internet-facing" } }) { id arn dnsName createdAt tags { key value } } }

root@kitploit:~
<br />

`EC2s`, `Lambdas`, `VPCs` 중에서 `Tag` 값이 `"Production"`인 모든 것을 찾으십시오:```graphql
query {
  queryawsTag(filter: { value: { eq: "Production" } }) {
    key
    value
    ec2Instance {
      id
      arn
    }
    lambda {
      id
      arn
    }
    vpc {
      id
      arn
    }
  }
}

같은 작업을 수행하되, key와 value를 모두 찾으세요:```graphql query { queryawsTag( filter: { key: { eq: "Environment" }, value: { eq: "Production" } } ) { key value ec2Instance { id arn } lambda { id arn } vpc { id arn } } }

root@kitploit:~
<br />

`queryawsTag` 대신 `getawsTag`를 사용하여 동일한 작업을 수행하십시오. `getawsTag`를 사용하여 태그를 검색할 때는 `key`와 `value`를 **모두** `id`로 지정해야 합니다. 아래와 같이 `"Environment:Production"`으로 지정하면 됩니다:```graphql
query {
  getawsTag(id: "Environment:Production") {
    key
    value
    ec2Instance {
      id
      arn
    }
    lambda {
      id
      arn
    }
    vpc {
      id
      arn
    }
  }
}

AWS FinOps 예시:


청구 데이터는 현재 AWS에서만 사용할 수 있습니다. FinOps 관련 데이터를 성공적으로 수집하려면 AWS 계정에서 Cost Explorer API가 활성화되어 있어야 합니다. 방법은 여기에서 확인할 수 있습니다


지난 30일간 AWS 계정의 총 비용, 이번 달 누적 AWS 계정의 총 비용, 지난 30일간 각 서비스별 비용 분석, 이번 달 누적 각 서비스별 비용 분석, 그리고 월별 및 이번 달 누적 평균 비용을 확인하세요:```graphql query { queryawsBilling { totalCostLast30Days { cost currency formattedCost } totalCostMonthToDate { cost currency formattedCost } monthToDate { name cost currency formattedCost } last30Days { name cost currency formattedCost } monthToDateDailyAverage { name cost currency formattedCost } last30DaysDailyAverage { name cost currency formattedCost } } }

root@kitploit:~
<br />

이 쿼리는 다음과 같은 `JSON` 페이로드를 반환합니다:```json
{
  "data": {
    "queryawsBilling": [
      {
        "totalCostLast30Days": {
          "cost": 7088.87,
          "currency": "USD",
          "formattedCost": "$7088.87"
        },
        "totalCostMonthToDate": {
          "cost": 7089.28,
          "currency": "USD",
          "formattedCost": "$7089.28"

        },
        "monthToDate": [
          {
            "name": "Amazon Relational Database Service",
            "cost": 548.68,
            "currency": "USD",
            "formattedCost": "$548.68"
          },
          {
            "name": "Amazon Managed Streaming for Apache Kafka",
            "cost": 67.49,
            "currency": "USD",
            "formattedCost": "$67.49"
          },
          {
            "name": "Amazon OpenSearch Service",
            "cost": 1155.04,
            "currency": "USD",
            "formattedCost": "$1155.04"
          }
          ...More Services
        ],
        "last30Days": [
          {
            "name": "AWS Step Functions",
            "cost": 330.20,
            "currency": "USD",
            "formattedCost": "$330.20"
          },
          {
            "name": "Amazon Elastic Container Service for Kubernetes",
            "cost": 194.40,
            "currency": "USD",
            "formattedCost": "$194.40"
          },
          {
            "name": "AmazonCloudWatch",
            "cost": 310.54,
            "currency": "USD",
            "formattedCost": "$310.54"
          }
          ...More Services
        ],
        "monthToDateDailyAverage": [
          {
            "name": "Amazon Relational Database Service",
            "cost": 54.86,
            "currency": "USD",
            "formattedCost": "$54.86"
          },
          {
            "name": "Amazon Managed Streaming for Apache Kafka",
            "cost": 6.74,
            "currency": "USD",
            "formattedCost": "$6.74"
          },
          {
            "name": "Amazon OpenSearch Service",
            "cost": 115.50,
            "currency": "USD",
            "formattedCost": "$115.50"
          }
          ...More Services
        ],
        "last30DaysDailyAverage": [
          {
            "name": "AWS Step Functions",
            "cost": 33.01,
            "currency": "USD",
            "formattedCost": "$33.01"
          },
          {
            "name": "Amazon Elastic Container Service for Kubernetes",
            "cost": 19.44,
            "currency": "USD",
            "formattedCost": "$19.44"
          },
          {
            "name": "AmazonCloudWatch",
            "cost": 31.05,
            "currency": "USD",
            "formattedCost": "$31.05"
          }
          ...More Services
        ],
      }
    ]
  },
  "extensions": {
    "touched_uids": 212
  }
}

AWS 계정의 각 EC2 인스턴스와 해당 일일 비용을 가져옵니다:```graphql query { queryawsEc2 { arn dailyCost { cost currency formattedCost } } }

root@kitploit:~
<br />

이 쿼리는 다음과 같은 `JSON` 페이로드를 반환합니다. 다음 예제들도 동일한 방식을 따릅니다:```json
{
{
  "data": {
    "queryawsEc2": [
      {
        "arn": "arn:aws:ec2:us-east-1:12345678910:instance/i-0c8b3vhfgf8df923f",
        "dailyCost": {
          "cost": 2.06,
          "currency": "USD",
          "formattedCost": "$2.06"
        }
      },
      {
        "arn": "arn:aws:ec2:us-east-1:12345678910:instance/i-060b3dsfds7sdf62e3",
        "dailyCost": {
          "cost": 2.06,
          "currency": "USD",
          "formattedCost": "$2.06"
        }
      },
     ...More EC2 Instances
    ]
  },
  "extensions": {
    "touched_uids": 28
  }
}

각 AWS 계정의 NAT Gateway와 그 일일 비용을 가져옵니다:```graphql query { queryawsNatGateway { arn dailyCost { cost currency formattedCost } } }

root@kitploit:~
<br />

## AWS CloudWatch 예시:

CloudGraph는 CloudWatch 메트릭 데이터를 수집하여 선택된 AWS 서비스와 함께 저장합니다. 이 기능은 현재 베타 버전이며 EC2에서만 작동합니다:```graphql
query {
  queryawsEc2 {
    arn
    cloudWatchMetricData {
      lastWeek {
        cpuUtilizationAverage
        networkInAverage
        networkOutAverage
        networkPacketsInAverage
        networkPacketsOutAverage
        statusCheckFailedSum
        statusCheckFailedInstanceSum
        statusCheckFailedSystemSum
        diskReadOpsAverage
        diskWriteOpsAverage
        diskReadBytesAverage
        diskWriteBytesAverage
      }

      lastMonth {
        cpuUtilizationAverage
        networkInAverage
        networkOutAverage
        networkPacketsInAverage
        networkPacketsOutAverage
        statusCheckFailedSum
        statusCheckFailedInstanceSum
        statusCheckFailedSystemSum
        diskReadOpsAverage
        diskWriteOpsAverage
        diskReadBytesAverage
        diskWriteBytesAverage
      }
      last6Hours {
        cpuUtilizationAverage
        networkInAverage
        networkOutAverage
        networkPacketsInAverage
        networkPacketsOutAverage
        statusCheckFailedSum
        statusCheckFailedInstanceSum
        statusCheckFailedSystemSum
        diskReadOpsAverage
        diskWriteOpsAverage
        diskReadBytesAverage
        diskWriteBytesAverage
      }
      last24Hours {
        cpuUtilizationAverage
        networkInAverage
        networkOutAverage
        networkPacketsInAverage
        networkPacketsOutAverage
        statusCheckFailedSum
        statusCheckFailedInstanceSum
        statusCheckFailedSystemSum
        diskReadOpsAverage
        diskWriteOpsAverage
        diskReadBytesAverage
        diskWriteBytesAverage
      }
    }
  }
}

그래프의 관점에서 생각하기:


당신이 "그래프의 관점에서" 생각할 때, CloudGraph로 거의 모든 것을 할 수 있습니다. 예를 들어, 어떤 Lamba 함수가 VPC에 속하지 않는지(즉, VPC 네트워킹을 활용하지 않는지) 알고 싶다고 가정해 보십시오. CloudGraph는 VPC 부모와 Lambda 자식과 같은 관계를 가진 모든 리소스를 연결하기 때문에 이 질문에 쉽게 답할 수 있습니다. 간단히 VPC가 "연결된" lambda 함수를 확인하고, 모든 lambda 함수 목록과 다음과 같이 비교하기만 하면 됩니다:```graphql query { queryawsVpc { id arn lambda { id arn } } queryawsLambda { id arn } }

root@kitploit:~
<br />

## 한계

<br />

현재 CloudGraph와 쿼리 기능의 가장 큰 한계는 자식 속성 기반의 중첩 필터링을 지원하지 않는다는 점입니다. 예를 들어, 다음과 같은 작업을 수행하는 것이 얼마나 멋질지는 알지만, 아직은 불가능합니다:

<br />```graphql
query {
  # This won't work just yet...
  queryawsEc2(filter: { ebs: { isBootDisk: true } }) {
    id
    arn
    ebs {
      id
      arn
    }
  }
  # So you have to do this instead :(
  queryawsEc2 {
    id
    arn
    ebs(filter: { isBootDisk: true }) {
      id
      arn
    }
  }
}

이것은 실제로 CloudGraph의 제한 사항이 아니라, Dgraph에서 아직 구현되지 않은 기능입니다. 여기에서 토론 스레드를 보고 의견을 남길 수 있습니다


쿼리 도구

CloudGraph는 2개의 훌륭한 쿼리 도구와 GraphQL 스키마 탐색기를 제공합니다. 다른 옵션을 선호한다면 어떤 GraphQL 쿼리 도구든 사용할 수 있으며, 노출된 /graphql 엔드포인트에 연결하기만 하면 됩니다!


GraphQL Playground

GraphQL Playground는 GraphQL 스키마를 빠르고 간단하게 쿼리하기에 좋은 유려하고 매력적인 UX를 제공합니다. 내장된 자동 생성 문서와 입력 중 자동 완성 기능이 있습니다. Playground에 접근하려면 init 명령에서 선호하는 쿼리 도구로 선택하거나 CG가 시작하는 서버의 /playground를 방문하세요.


gqlPlayground


Altair

Altair는 파워 유저를 위한 많은 기능을 제공하는 또 다른 훌륭한 GraphQL 쿼리 도구입니다. 쿼리 자동 완성, 동적 프래그먼트 추가, 쿼리 모음 내보내기/가져오기 등을 할 수 있습니다. Altair에 접근하려면 init 명령에서 선호하는 쿼리 도구로 선택하거나 CG가 시작하는 서버의 /altair를 방문하세요.


gqlAltair


Voyager

GraphQL Voyager는 CG 공급자의 스키마를 탐색하기에 훌륭한 방법입니다. 모든 타입과 쿼리를 포함한 멋진 양방향 차트를 제공합니다. 엔티티나 화살표를 클릭하여 연결을 발견하거나, 특정 항목을 검색하고, 스키마에 대한 더 깊은 이해를 얻을 수 있습니다. Voyager에 접근하려면 CG가 시작하는 서버의 /voyager를 방문하세요.


voyager


커뮤니티


의견, 질문 또는 피드백이 있으신가요? Slack 워크스페이스에 참여해 주세요. 여러분의 이야기를 듣고 싶습니다.


기여 가이드라인

CloudGraph에 기여하는 데 관심이 있으시다면 기여 가이드라인을 확인해 주세요.


배포 옵션

CloudGraph를 로컬에서 실행하거나 선택한 클라우드 공급자에 배포할 수 있습니다. 클라우드 배포를 위한 Terraform 모듈과 가이드가 곧 제공됩니다!


호스팅 버전

내장된 3D 시각화 기능, 자동 스캔 및 수백 개의 추가 규정 준수 검사를 갖춘 완전 관리형 SaaS/자체 호스팅 버전의 CloudGraph에 관심이 있으신가요? 자세한 내용은 AutoCloud를 확인하세요.


autocloud

디버깅

CloudGraph 실행 중 오류가 발생하면 명령어 앞에 CG_DEBUG=5를 추가하세요(예: CG_DEBUG=5 cg scan). 그러면 자세한 정보가 포함된 상세 로그가 출력되며, 이를 사용하여 GitHub에 이슈를 열거나 Slack 워크스페이스로 알려주실 수 있습니다.


일반적인 오류

CloudGraph 실행 시 일반적으로 권한 또는 연결 문제와 관련된 몇 가지 일반적인 오류가 발생할 수 있습니다.

  • ⚠️ 일부 연결을 만들 수 없음 - 이 경고는 CG가 두 리소스 간 연결을 시도했지만 실패할 때 스캔 보고서에 나타납니다. CG의 공식 지원 공급자 중 하나를 사용할 때 이 문제가 발생하면 새 이슈를 생성하여 해결할 수 있도록 해주세요. 이 오류의 가장 일반적인 원인은 기반 공급자의 리소스 연결 로직의 버그입니다.

  • 🚫 Dgraph에 데이터를 저장할 수 없음 - 이 오류는 CG가 클라우드 공급자 데이터를 그래프 DB에 삽입하려고 시도했지만 실패할 때 스캔 보고서에 나타납니다. 이 오류가 발생한 서비스는 GraphQL 쿼리 도구에서 쿼리할 수 없습니다. 이는 일반적으로 공급자 SDK 호출 시 오류(주로 권한 부족)로 인해 CG가 리소스에 필요한 데이터(예: ARN)를 가져올 수 없을 때 발생합니다.

  • Provider {name}@${version} requires cli version {version} but cli version is ${version} - 이 경고는 CG와 사용하려는 공급자의 버전이 호환되지 않음을 의미합니다. CG를 npm install -g @cloudgraphdev/cli로 업데이트하고 공급자 모듈을 cg provider update로 업데이트하여 둘 다 최신 버전으로 만드세요. 공급자의 pacakge.json을 확인하여 지원하는 CG 버전을 확인할 수도 있습니다.

  • Manager failed to install plugin for {provider} - 이 오류는 CG의 플러그인 관리자가 사용하려는 공급자 모듈을 찾을 수 없을 때 발생합니다. 관리자는 공개 NPM 레지스트리에서 공급자 모듈을 검색합니다. 공식 지원 공급자의 경우 공급자 이름만 전달하면 됩니다(CG init aws). 커뮤니티 지원 공급자의 경우 네임스페이스도 함께 전달해야 합니다(CG init @{providerNamespace}/{provider}).


명령어

  • cg help [COMMAND]
  • cg init [PROVIDER]
  • cg launch [PROVIDER]
  • cg load [PROVIDER]
  • cg policy [PROVIDER]
  • cg policy add [PROVIDER]
  • cg policy install [PROVIDER]
  • cg policy list [PROVIDER]
  • cg policy remove [PROVIDER]
  • cg policy update [PROVIDER]
  • cg provider [PROVIDER]

cg help [COMMAND]

cg에 대한 도움말을 표시합니다.``` USAGE $ cg help [COMMAND] [-n]

ARGUMENTS COMMAND Command to show help for.

FLAGS -n, --nested-commands Include all nested commands in the output.

DESCRIPTION Display help for cg.

root@kitploit:~
_코드 보기: [@oclif/plugin-help](https://github.com/oclif/plugin-help/blob/v5.1.12/src/commands/help.ts)_

## `cg init [PROVIDER]`

제공자의 초기 구성을 설정합니다```
USAGE
  $ cg init [PROVIDER] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p <value>]
    [-q playground|altair] [-l <value>] [--use-roles] [-P <value>] [-r]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -r, --resources
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Set initial configuration for providers

EXAMPLES
  $ cg init

  $ cg init aws [Initialize AWS provider]

  $ cg init aws -r [Specify resources to crawl]

See code: src/commands/init.ts

cg launch [PROVIDER]

데이터 저장을 위한 Dgraph 인스턴스를 실행합니다``` USAGE $ cg launch [PROVIDER] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Launch an instance of Dgraph to store data

EXAMPLES $ cg launch

root@kitploit:~
_See code: [src/commands/launch.ts](https://github.com/cloudgraphdev/cli/blob/v0.25.1/src/commands/launch.ts)_

## `cg load [PROVIDER]`

CloudGraph 데이터의 특정 버전을 로드합니다.```
USAGE
  $ cg load [PROVIDER] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p <value>]
    [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Load a specific version of your CloudGraph data

EXAMPLES
  $ cg load [Load data for all providers configured]

  $ cg load aws [Load data for AWS]

코드 보기: src/commands/load.ts

cg policy [PROVIDER]

정책 팩 모듈을 관리하는 명령어입니다. 더 많은 정보를 보려면 $ cg policy를 실행하세요.``` USAGE $ cg policy [PROVIDER] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Commands to manage policy pack modules, run $ cg policy for more info.

root@kitploit:~
_코드 보기: [src/commands/policy/index.ts](https://github.com/cloudgraphdev/cli/blob/v0.25.1/src/commands/policy/index.ts)_

## `cg policy add [PROVIDER]`

새 정책 팩 추가```
USAGE
  $ cg policy add [PROVIDER] [--no-save] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p
    <value>] [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-save                    Set to not alter lock file, just delete plugin
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Add new policy packs

ALIASES
  $ cg add policy

EXAMPLES
  $ cg policy add aws-cis-1.2.0

  $ cg policy add [email protected]

cg policy install [PROVIDER]

잠금 파일을 기반으로 정책 팩 설치``` USAGE $ cg policy install [PROVIDER] [--no-save] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-save Set to not alter lock file, just delete plugin --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Install policy packs based on the lock file

ALIASES $ cg install policy

EXAMPLES $ cg policy install

root@kitploit:~
## `cg policy list [PROVIDER]`

현재 설치된 정책 팩과 버전을 나열합니다.```
USAGE
  $ cg policy list [PROVIDER] [--no-save] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p
    <value>] [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-save                    Set to not alter lock file, just delete plugin
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  List currently installed policy packs and versions

ALIASES
  $ cg ls policy
  $ cg list policy

EXAMPLES
  $ cg policy list

  $ cg policy list aws

cg policy remove [PROVIDER]

현재 설치된 정책 팩을 제거합니다.``` USAGE $ cg policy remove [PROVIDER] [--no-save] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-save Set to not alter lock file, just delete plugin --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Remove currently installed policy pack

ALIASES $ cg remove policy $ cg policy remove $ cg policy rm $ cg del policy $ cg rm policy

EXAMPLES $ cg policy remove

$ cg policy remove aws-cis-1.2.0

$ cg policy remove aws-cis-1.2.0 --no-save

root@kitploit:~
## `cg policy update [PROVIDER]`

현재 설치된 정책 팩 업데이트```
USAGE
  $ cg policy update [PROVIDER] [--no-save] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p
    <value>] [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-save                    Set to not alter lock file, just delete plugin
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Update currently installed policy packs

EXAMPLES
  $ cg policy update

  $ cg policy update aws-cis-1.2.0

  $ cg policy update [email protected]

cg provider [PROVIDER]

공급자 모듈을 관리하는 명령어입니다. 자세한 정보를 보려면 $ cg provider를 실행하세요.``` USAGE $ cg provider [PROVIDER] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Commands to manage provider modules, run $ cg provider for more info.

root@kitploit:~
_코드 참조: [src/commands/provider/index.ts](https://github.com/cloudgraphdev/cli/blob/v0.25.1/src/commands/provider/index.ts)_

## `cg provider add [PROVIDER]`

새로운 공급자 추가```
USAGE
  $ cg provider add [PROVIDER] [--no-save] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p
    <value>] [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-save                    Set to not alter lock file, just delete plugin
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Add new providers

ALIASES
  $ cg add provider

EXAMPLES
  $ cg provider add aws

  $ cg provider add [email protected]

cg provider install [PROVIDER]

잠금 파일을 기반으로 프로바이더를 설치합니다.``` USAGE $ cg provider install [PROVIDER] [--no-save] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-save Set to not alter lock file, just delete plugin --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Install providers based on the lock file

ALIASES $ cg install provider

EXAMPLES $ cg provider install

root@kitploit:~
## `cg provider list [PROVIDER]`

현재 설치된 공급자와 버전을 나열합니다.```
USAGE
  $ cg provider list [PROVIDER] [--no-save] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p
    <value>] [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-save                    Set to not alter lock file, just delete plugin
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  List currently installed providers and versions

ALIASES
  $ cg ls provider
  $ cg list provider

EXAMPLES
  $ cg provider list

  $ cg provider list aws

cg provider remove [PROVIDER]

현재 설치된 제공자를 제거합니다.``` USAGE $ cg provider remove [PROVIDER] [--no-save] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-save Set to not alter lock file, just delete plugin --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Remove currently installed provider

ALIASES $ cg remove provider $ cg provider remove $ cg provider rm $ cg del provider $ cg rm provider

EXAMPLES $ cg provider remove

$ cg provider remove aws

$ cg provider remove aws --no-save

root@kitploit:~
## `cg provider update [PROVIDER]`

현재 설치된 제공자를 업데이트합니다.```
USAGE
  $ cg provider update [PROVIDER] [--no-save] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p
    <value>] [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-save                    Set to not alter lock file, just delete plugin
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Update currently installed providers

EXAMPLES
  $ cg provider update

  $ cg provider update aws

  $ cg provider update [email protected]

cg scan [PROVIDER]

하나 이상의 제공업체 데이터를 스캔하여 Dgraph를 통해 쿼리할 수 있도록 합니다.``` USAGE $ cg scan [PROVIDER] [--dev] [-d ] [-s dgraph] [--directory ] [--no-serve] [-p ] [-q playground|altair] [-l ] [--use-roles] [-P ]

FLAGS -P, --policies= Policy Packs to execute during scan -d, --dgraph= Set where dgraph is running (default localhost:8997) -l, --version-limit= Limit the amount of version folders stored on the filesystem (default 10) -p, --port= Set port to serve query engine -q, --query-engine= Query engine to launch <options: playground|altair> -s, --storage= Select a storage engine to use. Currently only supports Dgraph <options: dgraph> --dev Turn on developer mode --directory= Set the folder where CloudGraph will store data. (default cg) --no-serve Set to not serve a query engine --use-roles Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION Scan one or multiple providers data to be queried through Dgraph

EXAMPLES $ cg scan

$ cg scan aws

$ cg scan aws --dgraph http://localhost:1000 [Save data in dgraph running on port 1000]

$ cg scan aws --no-serve [Do not start the query engine]

root@kitploit:~
_코드 보기: [src/commands/scan.ts](https://github.com/cloudgraphdev/cli/blob/v0.25.1/src/commands/scan.ts)_

## `cg serve [PROVIDER]`

CloudGraph 데이터를 쿼리하기 위한 GraphQL 쿼리 도구를 제공합니다.```
USAGE
  $ cg serve [PROVIDER] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p <value>]
    [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Serve a GraphQL query tool to query your CloudGraph data.

EXAMPLES
  $ cg serve

코드 보기: src/commands/serve.ts

cg teardown [PROVIDER]

Dgraph Docker 컨테이너를 중지합니다.``` USAGE $ cg teardown [PROVIDER] [--delete-image]

FLAGS --delete-image Remove dgraph docker image after stopping it

DESCRIPTION Stops the Dgraph Docker container.

EXAMPLES $ cg teardown

$ cg teardown --delete-image

root@kitploit:~
_코드 보기: [src/commands/teardown.ts](https://github.com/cloudgraphdev/cli/blob/v0.25.1/src/commands/teardown.ts)_

## `cg update [PROVIDER]`

현재 설치된 플러그인을 업그레이드합니다.```
USAGE
  $ cg update [PROVIDER] [--no-save] [--dev] [-d <value>] [-s dgraph] [--directory <value>] [--no-serve] [-p
    <value>] [-q playground|altair] [-l <value>] [--use-roles] [-P <value>]

FLAGS
  -P, --policies=<value>       Policy Packs to execute during scan
  -d, --dgraph=<value>         Set where dgraph is running (default localhost:8997)
  -l, --version-limit=<value>  Limit the amount of version folders stored on the filesystem (default 10)
  -p, --port=<value>           Set port to serve query engine
  -q, --query-engine=<option>  Query engine to launch
                               <options: playground|altair>
  -s, --storage=<option>       Select a storage engine to use. Currently only supports Dgraph
                               <options: dgraph>
  --dev                        Turn on developer mode
  --directory=<value>          Set the folder where CloudGraph will store data. (default cg)
  --no-save                    Set to not alter lock file, just delete plugin
  --no-serve                   Set to not serve a query engine
  --use-roles                  Set to true to use roleARNs instead of profiles for AWS credentials

DESCRIPTION
  Upgrade currently installed plugins.

ALIASES
  $ cg update

EXAMPLES
  $ cg update

코드 보기: src/commands/update.ts

도구 다운로드
  • cg provider add [PROVIDER]
  • cg provider install [PROVIDER]
  • cg provider list [PROVIDER]
  • cg provider remove [PROVIDER]
  • cg provider update [PROVIDER]
  • cg scan [PROVIDER]
  • cg serve [PROVIDER]
  • cg teardown [PROVIDER]
  • cg update [PROVIDER]