diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index d1058d8b95..59c9bb2394 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -12,6 +12,8 @@ All notable changes to the **Prowler SDK** are documented in this file. - Oracle Cloud `kms_key_rotation_enabled` now checks current key version age to avoid false positives on vaults without auto-rotation support [(#10450)](https://github.com/prowler-cloud/prowler/pull/10450) - Oracle Cloud patch for filestorage, blockstorage, kms, and compute services in OCI to allow for region scanning outside home [(#10455)](https://github.com/prowler-cloud/prowler/pull/10472) - Oracle cloud provider now supports multi-region filtering [(#10435)](https://github.com/prowler-cloud/prowler/pull/10473) +- `prowler image --registry` failing with `ImageNoImagesProvidedError` due to registry arguments not being forwarded to `ImageProvider` in `init_global_provider` [(#10457)](https://github.com/prowler-cloud/prowler/issues/10457) +- Oracle Cloud multi-region support for identity client configuration in blockstorage, identity, and filestorage services [(#10519)](https://github.com/prowler-cloud/prowler/pull/10520) --- diff --git a/prowler/providers/oraclecloud/services/blockstorage/blockstorage_service.py b/prowler/providers/oraclecloud/services/blockstorage/blockstorage_service.py index 8c0e4e1b66..5b43f8d64b 100644 --- a/prowler/providers/oraclecloud/services/blockstorage/blockstorage_service.py +++ b/prowler/providers/oraclecloud/services/blockstorage/blockstorage_service.py @@ -111,7 +111,8 @@ class BlockStorage(OCIService): try: # Get availability domains for this compartment identity_client = self._create_oci_client( - oci.identity.IdentityClient + oci.identity.IdentityClient, + config_overrides={"region": regional_client.region}, ) availability_domains = identity_client.list_availability_domains( compartment_id=compartment.id diff --git a/prowler/providers/oraclecloud/services/filestorage/filestorage_service.py b/prowler/providers/oraclecloud/services/filestorage/filestorage_service.py index 9d9c2b3e82..edbfabf395 100644 --- a/prowler/providers/oraclecloud/services/filestorage/filestorage_service.py +++ b/prowler/providers/oraclecloud/services/filestorage/filestorage_service.py @@ -39,7 +39,8 @@ class Filestorage(OCIService): try: # Get availability domains for this compartment identity_client = self._create_oci_client( - oci.identity.IdentityClient + oci.identity.IdentityClient, + config_overrides={"region": regional_client.region}, ) availability_domains = identity_client.list_availability_domains( compartment_id=compartment.id diff --git a/prowler/providers/oraclecloud/services/identity/identity_service.py b/prowler/providers/oraclecloud/services/identity/identity_service.py index 12b3c7e7e9..a0932bd54f 100644 --- a/prowler/providers/oraclecloud/services/identity/identity_service.py +++ b/prowler/providers/oraclecloud/services/identity/identity_service.py @@ -35,7 +35,7 @@ class Identity(OCIService): self.__threading_call__(self.__list_dynamic_groups__) self.__threading_call__(self.__list_domains__) self.__threading_call__(self.__list_domain_password_policies__) - self.__get_password_policy__() + self.__threading_call__(self.__get_password_policy__) self.__threading_call__(self.__search_root_compartment_resources__) self.__threading_call__(self.__search_active_non_root_compartments__) @@ -49,10 +49,9 @@ class Identity(OCIService): Returns: Identity client instance """ - client_region = self.regional_clients.get(region) - if client_region: - return self._create_oci_client(oci.identity.IdentityClient) - return None + return self._create_oci_client( + oci.identity.IdentityClient, config_overrides={"region": region} + ) def __list_users__(self, regional_client): """ @@ -66,7 +65,7 @@ class Identity(OCIService): if regional_client.region not in self.provider.identity.region: return - identity_client = self._create_oci_client(oci.identity.IdentityClient) + identity_client = self.__get_client__(regional_client.region) logger.info("Identity - Listing Users...") @@ -316,7 +315,7 @@ class Identity(OCIService): if regional_client.region not in self.provider.identity.region: return - identity_client = self._create_oci_client(oci.identity.IdentityClient) + identity_client = self.__get_client__(regional_client.region) logger.info("Identity - Listing Groups...") @@ -359,7 +358,7 @@ class Identity(OCIService): if regional_client.region not in self.provider.identity.region: return - identity_client = self._create_oci_client(oci.identity.IdentityClient) + identity_client = self.__get_client__(regional_client.region) logger.info("Identity - Listing Policies...") @@ -404,7 +403,7 @@ class Identity(OCIService): if regional_client.region not in self.provider.identity.region: return - identity_client = self._create_oci_client(oci.identity.IdentityClient) + identity_client = self.__get_client__(regional_client.region) logger.info("Identity - Listing Dynamic Groups...") @@ -452,7 +451,7 @@ class Identity(OCIService): if regional_client.region not in self.provider.identity.region: return - identity_client = self._create_oci_client(oci.identity.IdentityClient) + identity_client = self.__get_client__(regional_client.region) logger.info("Identity - Listing Identity Domains...") @@ -549,10 +548,13 @@ class Identity(OCIService): f"{regional_client.region} -- {error.__class__.__name__}[{error.__traceback__.tb_lineno}]: {error}" ) - def __get_password_policy__(self): + def __get_password_policy__(self, regional_client): """Get the password policy for the tenancy.""" try: - identity_client = self._create_oci_client(oci.identity.IdentityClient) + if regional_client.region not in self.provider.identity.region: + return + + identity_client = self.__get_client__(regional_client.region) logger.info("Identity - Getting Password Policy...") @@ -584,7 +586,8 @@ class Identity(OCIService): # Create search client using the helper method for proper authentication search_client = self._create_oci_client( - oci.resource_search.ResourceSearchClient + oci.resource_search.ResourceSearchClient, + config_overrides={"region": regional_client.region}, ) # Query to search for resources in root compartment @@ -631,7 +634,8 @@ class Identity(OCIService): # Create search client using the helper method for proper authentication search_client = self._create_oci_client( - oci.resource_search.ResourceSearchClient + oci.resource_search.ResourceSearchClient, + config_overrides={"region": regional_client.region}, ) # Query to search for active compartments in the tenancy (excluding root)