Skip to content

OpenSourceOM Core

CI CodeQL License Release GHCR

Self-hosted, graph-native cloud security — prioritize what attackers can actually reach.

OpenSourceOM console — demo graph

The screenshot is the web console after docker compose up and om scan demo — internet-exposed web-1 on a path to prod-db, plus public S3 and an over-privileged admin role.

OpenSourceOM Core is the platform behind opensourceom.org: collectors that ingest cloud inventory and security signals, a graph engine that models attack paths, and APIs/UI to explore risk in context.

Traditional scanners flood you with CVEs and misconfigurations. OpenSourceOM connects the dots — showing which findings sit on paths from the internet to your sensitive data and privileged identities.

Status: Early development (Phase 3). CSPM rules, identity blast radius, Kubernetes ingest, exports, a collector plugin SDK, and a Helm chart are available. CVE findings follow package and image inventory. Datastores can carry a sensitivity mark from a tag or label. Current work is graph accuracy: attack-path findings, rule packs, and cloud audit ingest. See the roadmap.

Why this exists

CNAPP platforms demonstrated that context beats volume: a critical CVE on an isolated dev box is not the same as a high-severity issue on an internet-exposed path to production.

OpenSourceOM brings that graph-first model to teams that want:

  • Transparency — inspect scoring, rules, and enrichment in code
  • Control — run entirely in your VPC
  • Community — extend collectors and policies without vendor lock-in

What Core does

Capability Description
Security graph Model workloads, identities, network paths, data stores, and findings as nodes and edges
Attack path analysis Query reachable paths — e.g. internet → CVE → prod database
Risk prioritization Rank findings by exposure, blast radius, and path length — not CVSS alone
CSPM Graph-context policy rules with prioritized findings
Multi-cloud AWS, Azure, GCP, and Kubernetes collectors

Architecture

Cloud APIs → Collectors → Normalizer → Graph Store → API / UI
                              ↘ Rules Engine → Findings (with path context)

Graph schema (v0): nodes like Workload, Identity, Datastore, Finding; edges like REACHABLE, ASSUMES, AFFECTS.

Full design: docs/ARCHITECTURE.md

Repository layout

cmd/om/              `om` CLI (migrate, serve, scan, enrich, rules, identity, export)
sdk/collector/       Public SDK for external collector plugins
examples/collector/  Sample plugin (`om scan plugin`)
internal/collectors/ AWS, Azure, GCP, Kubernetes, demo graph
packs/               Embedded YAML CSPM rule packs
internal/rules/      CSPM rules engine with graph-context scoring
internal/graph/      Graph schema, Postgres store, path + blast-radius queries
internal/enrichment/ CVE lookup (NVD) and severity normalization
internal/export/     Slack, SIEM, Jira exporters
internal/api/        REST API + embedded web console
migrations/          Postgres schema migrations
docs/                Architecture, roadmap, ADRs
docker-compose.yml   Local dev stack (Postgres + API)
deploy/helm/         Production Kubernetes chart

Quick start

Phase 2 stack — Postgres, multi-cloud + Kubernetes collectors, CSPM rules, CVE enrichment, blast-radius analysis, exports, and a web console.

git clone https://github.com/OpenSourceOM/core.git
cd core
cp .env.example .env

# Start Postgres + API (http://localhost:8080)
docker compose up -d

# Build the CLI
go build -o om ./cmd/om

# Apply graph schema migrations
./om migrate

# Load the sample graph (no cloud credentials)
./om scan demo

# Or scan cloud / cluster inventory
export AWS_REGION=us-east-1
./om scan aws
./om scan k8s      # requires kubeconfig

# Or ingest a custom collector (stdout is a graph batch)
go build -o example-collector ./examples/collector
./om scan plugin -- ./example-collector

# Run CSPM rules (builtin graph-context + embedded packs)
./om rules list
./om rules run

# Identity blast radius
./om identity blast-radius --name AdminRole

# Enrich with CVE data that matches workload inventory.
# The demo graph lists log4j 2.14.1 on web-1 and 2.17.1 on worker-1.
# NVD matches the CPE. This catalog is the offline equivalent.
./om enrich cve --catalog examples/cve-catalog.json

# Export findings
./om export findings run --format siem --out findings.jsonl

# Open the web console (click identities for blast radius)
open http://localhost:8080

Compose sets OM_API_SECRET. The console sends that value as X-API-Key from localStorage.om_api_key on every /v1 call except health. Leave the secret empty to keep local API calls open.

API endpoints: GET /v1/health, POST /v1/ingest, GET /v1/findings, GET /v1/graph/snapshot, POST /v1/rules/run, GET /v1/identity/blast-radius

Multi-cloud scan:

./om scan demo     # sample environment, no credentials
./om scan aws
./om scan azure    # requires AZURE_SUBSCRIPTION_ID + az login
./om scan gcp      # requires GCP_PROJECT_ID + ADC
./om scan k8s      # requires kubeconfig or in-cluster credentials
./om scan plugin -- ./my-collector

For local CLI-only use without Docker API, run docker compose up -d postgres and set POSTGRES_HOST=localhost.

Kubernetes:

docker build -t ghcr.io/opensourceom/core:0.2.1 .
helm install om deploy/helm/opensourceom \
  --set api.secret='change-me' \
  --set postgres.password='change-me' \
  --set image.tag=0.2.1

Collectors stay off until you enable one and supply credentials, an existing Secret, or serviceAccountAuth. The CronJob runs om scan against the same Postgres the API reads. om scan demo stays a one-shot command. See scan in deploy/helm/opensourceom/values.yaml.

Full documentation: opensourceom.org (docs at opensourceom.org/docs)

Roadmap snapshot

Phase Focus
0 Graph schema v0, AWS collector, ingest API, om CLI
1 Attack path queries, CVE enrichment, web UI, Azure/GCP collectors
2 CSPM rules, blast radius, K8s connector, exports
3 (now) Graph accuracy, crown-jewel datastores, attack-path findings, rule packs, cloud audit ingest

Details: docs/ROADMAP.md

Contributing

We welcome issues, discussions, and PRs.

  1. Read the roadmap and architecture
  2. Comment on an open issue, or open a discussion with the roadmap label before a large change that is not tracked yet
  3. Keep collectors read-only toward cloud accounts by default
  4. See CONTRIBUTING.md — PRs get an automatic CodeRabbit review once the GitHub App is installed on this repo

Related repositories

Repo Purpose
website Marketing site and user docs
core This repository

Security

Report vulnerabilities to security@opensourceom.org. Do not open public issues for security bugs. See SECURITY.md.

License

Apache-2.0 — see LICENSE.

About

Open-source cloud security platform — collectors, graph engine, API

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages