diff --git a/prowler/changelog.d/kubernetes-compliance-report-cluster-name.added.md b/prowler/changelog.d/kubernetes-compliance-report-cluster-name.added.md new file mode 100644 index 0000000000..f713013dff --- /dev/null +++ b/prowler/changelog.d/kubernetes-compliance-report-cluster-name.added.md @@ -0,0 +1 @@ +`Cluster` column in Kubernetes CIS, ISO27001, Prowler ThreatScore, and universal compliance outputs, populated with the resolved cluster name so multi-cluster scans can be told apart in the output diff --git a/prowler/lib/outputs/compliance/cis/cis_kubernetes.py b/prowler/lib/outputs/compliance/cis/cis_kubernetes.py index 23c482310e..d3349bcb49 100644 --- a/prowler/lib/outputs/compliance/cis/cis_kubernetes.py +++ b/prowler/lib/outputs/compliance/cis/cis_kubernetes.py @@ -55,6 +55,7 @@ class KubernetesCIS(ComplianceOutput): Provider=finding.provider, Description=compliance.Description, Context=finding.account_name, + Cluster=finding.account_uid, Namespace=finding.region, AssessmentDate=str(timestamp), Requirements_Id=requirement.Id, @@ -89,6 +90,7 @@ class KubernetesCIS(ComplianceOutput): Provider=compliance.Provider.lower(), Description=compliance.Description, Context="", + Cluster="", Namespace="", AssessmentDate=str(timestamp), Requirements_Id=requirement.Id, diff --git a/prowler/lib/outputs/compliance/cis/models.py b/prowler/lib/outputs/compliance/cis/models.py index 0f4b320fd0..999c8ca12c 100644 --- a/prowler/lib/outputs/compliance/cis/models.py +++ b/prowler/lib/outputs/compliance/cis/models.py @@ -148,6 +148,7 @@ class KubernetesCISModel(BaseModel): Provider: str Description: str Context: str + Cluster: str Namespace: str AssessmentDate: str Requirements_Id: str diff --git a/prowler/lib/outputs/compliance/iso27001/iso27001_kubernetes.py b/prowler/lib/outputs/compliance/iso27001/iso27001_kubernetes.py index 5ca81e82d5..a3515d0728 100644 --- a/prowler/lib/outputs/compliance/iso27001/iso27001_kubernetes.py +++ b/prowler/lib/outputs/compliance/iso27001/iso27001_kubernetes.py @@ -55,6 +55,7 @@ class KubernetesISO27001(ComplianceOutput): Provider=finding.provider, Description=compliance.Description, Context=finding.account_name, + Cluster=finding.account_uid, Namespace=finding.region, AssessmentDate=str(timestamp), Requirements_Id=requirement.Id, @@ -82,6 +83,7 @@ class KubernetesISO27001(ComplianceOutput): Provider=compliance.Provider.lower(), Description=compliance.Description, Context="", + Cluster="", Namespace="", AssessmentDate=str(timestamp), Requirements_Id=requirement.Id, diff --git a/prowler/lib/outputs/compliance/iso27001/models.py b/prowler/lib/outputs/compliance/iso27001/models.py index a10fa3c610..5eea733a7f 100644 --- a/prowler/lib/outputs/compliance/iso27001/models.py +++ b/prowler/lib/outputs/compliance/iso27001/models.py @@ -90,6 +90,7 @@ class KubernetesISO27001Model(BaseModel): Provider: str Description: str Context: str + Cluster: str Namespace: str AssessmentDate: str Requirements_Id: str diff --git a/prowler/lib/outputs/compliance/prowler_threatscore/models.py b/prowler/lib/outputs/compliance/prowler_threatscore/models.py index ab84bb6079..8dd0f97400 100644 --- a/prowler/lib/outputs/compliance/prowler_threatscore/models.py +++ b/prowler/lib/outputs/compliance/prowler_threatscore/models.py @@ -127,6 +127,7 @@ class ProwlerThreatScoreKubernetesModel(BaseModel): Provider: str Description: str Context: str + Cluster: str Namespace: str AssessmentDate: str Requirements_Id: str diff --git a/prowler/lib/outputs/compliance/prowler_threatscore/prowler_threatscore_kubernetes.py b/prowler/lib/outputs/compliance/prowler_threatscore/prowler_threatscore_kubernetes.py index 88bf41582a..d44a964773 100644 --- a/prowler/lib/outputs/compliance/prowler_threatscore/prowler_threatscore_kubernetes.py +++ b/prowler/lib/outputs/compliance/prowler_threatscore/prowler_threatscore_kubernetes.py @@ -58,6 +58,7 @@ class ProwlerThreatScoreKubernetes(ComplianceOutput): Provider=finding.provider, Description=compliance.Description, Context=finding.account_name, + Cluster=finding.account_uid, Namespace=finding.region, AssessmentDate=str(timestamp), Requirements_Id=requirement.Id, @@ -87,6 +88,7 @@ class ProwlerThreatScoreKubernetes(ComplianceOutput): Provider=compliance.Provider.lower(), Description=compliance.Description, Context="", + Cluster="", Namespace="", AssessmentDate=str(timestamp), Requirements_Id=requirement.Id, diff --git a/prowler/lib/outputs/compliance/universal/universal_output.py b/prowler/lib/outputs/compliance/universal/universal_output.py index 5cca376482..9c7c76da47 100644 --- a/prowler/lib/outputs/compliance/universal/universal_output.py +++ b/prowler/lib/outputs/compliance/universal/universal_output.py @@ -30,6 +30,9 @@ PROVIDER_HEADER_MAP = { "e2enetworks": ("ProjectId", "account_uid", "Location", "region"), } _DEFAULT_HEADERS = ("AccountId", "account_uid", "Region", "region") +PROVIDER_EXTRA_HEADER_MAP = { + "kubernetes": (("Cluster", "account_uid"),), +} class UniversalComplianceOutput: @@ -88,11 +91,19 @@ class UniversalComplianceOutput: "Provider": (str, ...), "Description": (str, ...), acct_header: (str, ...), - loc_header: (str, ...), - "AssessmentDate": (str, ...), - "Requirements_Id": (str, ...), - "Requirements_Description": (str, ...), } + for header, _ in PROVIDER_EXTRA_HEADER_MAP.get( + (self._provider or "").lower(), () + ): + fields[header] = (str, ...) + fields.update( + { + loc_header: (str, ...), + "AssessmentDate": (str, ...), + "Requirements_Id": (str, ...), + "Requirements_Description": (str, ...), + } + ) # Dynamic attribute columns from metadata if framework.attributes_metadata: @@ -154,13 +165,17 @@ class UniversalComplianceOutput: self._acct_header: ( getattr(finding, self._acct_field, "") if not is_manual else "" ), - self._loc_header: ( - getattr(finding, self._loc_field, "") if not is_manual else "" - ), "AssessmentDate": str(timestamp), "Requirements_Id": requirement.id, "Requirements_Description": requirement.description, } + for header, field in PROVIDER_EXTRA_HEADER_MAP.get( + (self._provider or "").lower(), () + ): + row[header] = getattr(finding, field, "") if not is_manual else "" + row[self._loc_header] = ( + getattr(finding, self._loc_field, "") if not is_manual else "" + ) # Add dynamic attribute columns if framework.attributes_metadata: diff --git a/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py b/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py index 74d85c094b..fa1cd71180 100644 --- a/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py +++ b/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py @@ -34,6 +34,7 @@ class TestKubernetesCIS: assert output_data.Framework == CIS_1_8_KUBERNETES.Framework assert output_data.Name == CIS_1_8_KUBERNETES.Name assert output_data.Context == KUBERNETES_CLUSTER_NAME + assert output_data.Cluster == KUBERNETES_CLUSTER_NAME assert output_data.Namespace == KUBERNETES_NAMESPACE assert output_data.Description == CIS_1_8_KUBERNETES.Description assert output_data.Requirements_Id == CIS_1_8_KUBERNETES.Requirements[0].Id @@ -101,6 +102,7 @@ class TestKubernetesCIS: assert output_data_manual.Framework == CIS_1_8_KUBERNETES.Framework assert output_data_manual.Name == CIS_1_8_KUBERNETES.Name assert output_data_manual.Context == "" + assert output_data_manual.Cluster == "" assert output_data_manual.Namespace == "" assert output_data_manual.Description == CIS_1_8_KUBERNETES.Description assert ( @@ -190,5 +192,5 @@ class TestKubernetesCIS: mock_file.seek(0) content = mock_file.read() - expected_csv = f"PROVIDER;DESCRIPTION;CONTEXT;NAMESPACE;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_SUBSECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;REQUIREMENTS_ATTRIBUTES_DEFAULTVALUE;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED;FRAMEWORK;NAME\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;test-cluster;test-namespace;{datetime.now()};1.1.3;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1. Control Plane;1.1 Control Plane Node Configuration Files;Level 1;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;PASS;;;;service_test_check_id;False;CIS;CIS Kubernetes Benchmark v1.8.0\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;;;{datetime.now()};1.1.4;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1.1 Control Plane Node Configuration Files;;Level 1;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;MANUAL;Manual check;manual_check;Manual check;manual;False;CIS;CIS Kubernetes Benchmark v1.8.0\r\n" + expected_csv = f"PROVIDER;DESCRIPTION;CONTEXT;CLUSTER;NAMESPACE;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_SUBSECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;REQUIREMENTS_ATTRIBUTES_DEFAULTVALUE;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED;FRAMEWORK;NAME\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;test-cluster;test-cluster;test-namespace;{datetime.now()};1.1.3;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1. Control Plane;1.1 Control Plane Node Configuration Files;Level 1;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;PASS;;;;service_test_check_id;False;CIS;CIS Kubernetes Benchmark v1.8.0\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;;;;{datetime.now()};1.1.4;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1.1 Control Plane Node Configuration Files;;Level 1;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;MANUAL;Manual check;manual_check;Manual check;manual;False;CIS;CIS Kubernetes Benchmark v1.8.0\r\n" assert content == expected_csv diff --git a/tests/lib/outputs/compliance/iso27001/iso27001_kubernetes_test.py b/tests/lib/outputs/compliance/iso27001/iso27001_kubernetes_test.py new file mode 100644 index 0000000000..dc33869b51 --- /dev/null +++ b/tests/lib/outputs/compliance/iso27001/iso27001_kubernetes_test.py @@ -0,0 +1,78 @@ +from prowler.lib.check.compliance_models import ( + Compliance, + Compliance_Requirement, + ISO27001_2013_Requirement_Attribute, +) +from prowler.lib.outputs.compliance.iso27001.iso27001_kubernetes import ( + KubernetesISO27001, +) +from prowler.lib.outputs.compliance.iso27001.models import KubernetesISO27001Model +from tests.lib.outputs.fixtures.fixtures import generate_finding_output +from tests.providers.kubernetes.kubernetes_fixtures import ( + KUBERNETES_CLUSTER_NAME, + KUBERNETES_NAMESPACE, +) + +ISO27001_2013_KUBERNETES = Compliance( + Framework="ISO27001", + Name="ISO/IEC 27001 Information Security Management Standard 2013", + Provider="Kubernetes", + Version="2013", + Description="ISO 27001 controls mapped to Kubernetes findings.", + Requirements=[ + Compliance_Requirement( + Id="A.10.1", + Description="Protect Kubernetes workload configuration", + Name="Cryptographic Controls", + Attributes=[ + ISO27001_2013_Requirement_Attribute( + Category="A.10 Cryptography", + Objetive_ID="A.10.1", + Objetive_Name="Cryptographic Controls", + Check_Summary="Protect Kubernetes workload configuration", + ) + ], + Checks=["service_test_check_id"], + ), + Compliance_Requirement( + Id="A.10.2", + Description="Manual Kubernetes control", + Name="Cryptographic Controls", + Attributes=[ + ISO27001_2013_Requirement_Attribute( + Category="A.10 Cryptography", + Objetive_ID="A.10.2", + Objetive_Name="Cryptographic Controls", + Check_Summary="Manual Kubernetes control", + ) + ], + Checks=[], + ), + ], +) + + +class TestKubernetesISO27001: + def test_output_transform_includes_cluster(self): + findings = [ + generate_finding_output( + provider="kubernetes", + compliance={"ISO27001-2013": "A.10.1"}, + account_name="context: kind-dev", + account_uid=KUBERNETES_CLUSTER_NAME, + region=KUBERNETES_NAMESPACE, + ) + ] + + output = KubernetesISO27001(findings, ISO27001_2013_KUBERNETES) + + output_data = output.data[0] + assert isinstance(output_data, KubernetesISO27001Model) + assert output_data.Context == "context: kind-dev" + assert output_data.Cluster == KUBERNETES_CLUSTER_NAME + assert output_data.Namespace == KUBERNETES_NAMESPACE + + manual = output.data[1] + assert manual.Context == "" + assert manual.Cluster == "" + assert manual.Namespace == "" diff --git a/tests/lib/outputs/compliance/prowler_threatscore/prowler_threatscore_kubernetes_test.py b/tests/lib/outputs/compliance/prowler_threatscore/prowler_threatscore_kubernetes_test.py new file mode 100644 index 0000000000..b0b5775017 --- /dev/null +++ b/tests/lib/outputs/compliance/prowler_threatscore/prowler_threatscore_kubernetes_test.py @@ -0,0 +1,84 @@ +from prowler.lib.check.compliance_models import ( + Compliance, + Compliance_Requirement, + Prowler_ThreatScore_Requirement_Attribute, +) +from prowler.lib.outputs.compliance.prowler_threatscore.models import ( + ProwlerThreatScoreKubernetesModel, +) +from prowler.lib.outputs.compliance.prowler_threatscore.prowler_threatscore_kubernetes import ( + ProwlerThreatScoreKubernetes, +) +from tests.lib.outputs.fixtures.fixtures import generate_finding_output +from tests.providers.kubernetes.kubernetes_fixtures import ( + KUBERNETES_CLUSTER_NAME, + KUBERNETES_NAMESPACE, +) + +PROWLER_THREATSCORE_KUBERNETES = Compliance( + Framework="ProwlerThreatScore", + Name="Prowler ThreatScore Compliance Framework for Kubernetes", + Version="1.0", + Provider="Kubernetes", + Description="Prowler ThreatScore controls mapped to Kubernetes findings.", + Requirements=[ + Compliance_Requirement( + Id="1.1.1", + Description="Kubernetes workload hardening", + Attributes=[ + Prowler_ThreatScore_Requirement_Attribute( + Title="Workload hardening", + Section="1. Kubernetes", + SubSection="1.1 Workloads", + AttributeDescription="Kubernetes workload hardening control.", + AdditionalInformation="", + LevelOfRisk=5, + Weight=1000, + ) + ], + Checks=["service_test_check_id"], + ), + Compliance_Requirement( + Id="1.1.2", + Description="Manual Kubernetes review", + Attributes=[ + Prowler_ThreatScore_Requirement_Attribute( + Title="Manual review", + Section="1. Kubernetes", + SubSection="1.1 Workloads", + AttributeDescription="Manual Kubernetes review control.", + AdditionalInformation="", + LevelOfRisk=3, + Weight=10, + ) + ], + Checks=[], + ), + ], +) + + +class TestProwlerThreatScoreKubernetes: + def test_output_transform_includes_cluster(self): + findings = [ + generate_finding_output( + provider="kubernetes", + compliance={"ProwlerThreatScore-1.0": "1.1.1"}, + account_name="context: kind-dev", + account_uid=KUBERNETES_CLUSTER_NAME, + region=KUBERNETES_NAMESPACE, + ) + ] + + output = ProwlerThreatScoreKubernetes(findings, PROWLER_THREATSCORE_KUBERNETES) + + output_data = output.data[0] + assert isinstance(output_data, ProwlerThreatScoreKubernetesModel) + assert output_data.Context == "context: kind-dev" + assert output_data.Cluster == KUBERNETES_CLUSTER_NAME + assert output_data.Namespace == KUBERNETES_NAMESPACE + + manual = output.data[1] + assert manual.Context == "" + assert manual.Cluster == "" + assert manual.Namespace == "" diff --git a/tests/lib/outputs/compliance/universal/universal_output_test.py b/tests/lib/outputs/compliance/universal/universal_output_test.py index d0fdf0f178..dd951cf272 100644 --- a/tests/lib/outputs/compliance/universal/universal_output_test.py +++ b/tests/lib/outputs/compliance/universal/universal_output_test.py @@ -493,9 +493,11 @@ class TestProviderHeaders: ) row_dict = output.data[0].dict() assert "Context" in row_dict + assert "Cluster" in row_dict assert "Namespace" in row_dict # Kubernetes Context maps to account_name assert row_dict["Context"] == "test-account" + assert row_dict["Cluster"] == "123456789012" assert row_dict["Namespace"] == "us-east-1" def test_github_headers(self, tmp_path): @@ -562,17 +564,17 @@ class TestProviderHeaders: assert "ACCOUNTID" not in content def test_column_order_matches_legacy(self, tmp_path): - """Verify that the base column order matches the legacy per-provider models. + """Verify that the base column order matches per-provider models. - Legacy models all define: Provider, Description, , , AssessmentDate, ... - The universal output must preserve this exact order for backward compatibility. + Most models define: Provider, Description, , , AssessmentDate. + Kubernetes includes the dedicated Cluster column between Context and Namespace. """ # Expected column order per provider (positions 3 and 4 after Provider, Description) legacy_order = { "aws": ("AccountId", "Region"), "azure": ("SubscriptionId", "Location"), "gcp": ("ProjectId", "Location"), - "kubernetes": ("Context", "Namespace"), + "kubernetes": ("Context", "Cluster", "Namespace"), "m365": ("TenantId", "Location"), "github": ("Account_Name", "Account_Id"), "oraclecloud": ("TenancyId", "Region"), @@ -580,7 +582,7 @@ class TestProviderHeaders: "nhn": ("AccountId", "Region"), } - for provider_name, (expected_col3, expected_col4) in legacy_order.items(): + for provider_name, expected_columns in legacy_order.items(): fw = _simple_framework() findings = [_make_provider_finding(provider_name)] output = UniversalComplianceOutput( @@ -594,12 +596,12 @@ class TestProviderHeaders: assert ( keys[1] == "Description" ), f"{provider_name}: col 2 should be Description" - assert ( - keys[2] == expected_col3 - ), f"{provider_name}: col 3 should be {expected_col3}, got {keys[2]}" - assert ( - keys[3] == expected_col4 - ), f"{provider_name}: col 4 should be {expected_col4}, got {keys[3]}" - assert ( - keys[4] == "AssessmentDate" - ), f"{provider_name}: col 5 should be AssessmentDate" + for index, expected_column in enumerate(expected_columns, start=2): + assert keys[index] == expected_column, ( + f"{provider_name}: col {index + 1} should be " + f"{expected_column}, got {keys[index]}" + ) + assert keys[2 + len(expected_columns)] == "AssessmentDate", ( + f"{provider_name}: col {3 + len(expected_columns)} should be " + "AssessmentDate" + )