Exposure Path Management
Visualize the hidden connections between simple misconfigurations and critical data breaches.
Last updated on
Sovereign data and AI foundation trail: build a robust, compliant data platform on STACKIT using sovereign AI assets, from ingestion to governed operation.
Establish the strategic baseline for your data journey and understand the core principles of sovereign AI.
STACKIT
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
The STACKIT SDK for Go provides a secure, structured modular toolkit for interacting with STACKIT cloud ecosystem APIs. The application programming interface is split into an independent core utility module and dedicated service sub-modules to keep deployment footprints minimal.
Follow these steps to integrate the STACKIT SDK for Go modules into your development workspace.
Download the core module: Execute the package manager dependency retrieval command to install shared functionality, authentication systems, and fundamental client configuration structures.
go get github.com/stackitcloud/stackit-sdk-go/coreDownload required services: Install individual service resource clients independently to enforce clean dependency coupling. For example, download the DNS management client.
go get github.com/stackitcloud/stackit-sdk-go/services/dnsInitialize the engine code: Import the downloaded client structures into your software application logic to start orchestration.
The following production-ready example demonstrates initializing an API controller client to read and create zone resource definitions within the STACKIT DNS framework.
package main
import ( "context" "fmt" "os"
"github.com/stackitcloud/stackit-sdk-go/services/dns")
func main() { // Specify target project context scoping identification projectId := "YOUR_STACKIT_PROJECT_ID_UUID"
// Instantiate a resilient service client infrastructure using default configurations dnsClient, err := dns.NewAPIClient() if err != nil { fmt.Fprintf(os.Stderr, "[STACKIT Go SDK] Failed to initialize client session: %v\n", err) os.Exit(1) }
// Retrieve a collection of available DNS zones associated with the project scope ctx := context.Background() getZoneResp, err := dnsClient.GetZones(ctx, projectId).Execute() if err != nil { fmt.Fprintf(os.Stderr, "[STACKIT Go SDK] Error calling GetZones: %v\n", err) } else { fmt.Printf("[STACKIT Go SDK] Discovered active zone count: %v\n", len(getZoneResp.Zones)) }
// Declare payload variables for target state instantiation createZonePayload := dns.CreateZonePayload{ Name: "production-zone-alpha", DnsName: "infra.alpha-sovereign.com", }
// Dispatch request context to execute real-world infrastructure allocation createZoneResp, err := dnsClient.CreateZone(ctx, projectId).CreateZonePayload(createZonePayload).Execute() if err != nil { fmt.Fprintf(os.Stderr, "[STACKIT Go SDK] Zone allocation failed: %v\n", err) } else { createdZone := createZoneResp.Zone fmt.Printf("[STACKIT Go SDK] Provisioned zone \"%s\" mapping to ID: %s\n", createdZone.Name, createdZone.Id) }}The STACKIT SDK for Go demands an instantiated service account equipped with precise permission mappings (such as project.owner) to perform automated changes.
The configuration manager automatically parses environment structures in a defined sequence to locate matching credentials:
Explicit in-code declarations: Overrides fallback patterns using programmatic parameters specified directly in the software application initialization.
System environment variables: Inspects execution machine variables inside the running shell context.
Local file storage configuration: Evaluates the standardized path file located at HOME/.stackit/credentials.json.
Select your preferred implementation vector to inject variables into the automated authentication engine.
Open Contributors
The shared entry for everyone contributing to the STACKIT Cloud Framework in a personal capacity, without a company profile standing behind their work.
Unlike traditional on-premise environments (“Boundary Security”), the cloud operates on the Shared Responsibility Model:
Code & Supply Chain Security * 4-Eye-Principle: Mandatory reviews for every Pull Request. * Vulnerability Scanning: Using Snyk to identify vulnerabilities in libraries.
ACLs & Encryption * SKE ACLs: Strictly restrict access to the
Control Plane (No 0.0.0.0/0!). * TLS & Ingress: Certificate management
via Cert-Manager for all entry points.
Runtime Security & Zero Trust * SentinelOne: EDR protection directly on the Kubernetes nodes. * ‘Istio’ (Service Mesh): mTLS for encrypted pod-to-pod communication and Zero Trust enforcement.
Security is defined as code and rolled out automatically:
| Layer | Measure | Policy / Tool |
|---|---|---|
| Code | Snyk, Reviews | Vulnerability Management |
| Control Plane | STACKIT SKE ACLs | SKE Access Control |
| Network | TLS, mTLS | Cert-Manager / Istio |
| Workload | SentinelOne | Endpoint Protection |
TM Solutions Corp. Inc.
Core contributor and technical product owner of the framework, focused on sovereign cloud architecture, automation, and production-ready DevOps pipelines.
Traditional vulnerability scanning provides long lists of CVEs but lacks context. XM Cyber adds the “So what?” by showing if a vulnerability actually leads to a business-critical asset.
Your Benefits:
XM Cyber acts as a virtual security assessment, constantly simulating potential breach points and lateral movement.
This asset provides a comprehensive toolkit to move from reactive patching to proactive exposure management.
Exposure Path Management
Visualize the hidden connections between simple misconfigurations and critical data breaches.
Choke Point Discovery
Identify the most efficient points to apply security fixes, maximizing the impact of your security team.
Hybrid Monitoring
Consolidate your security posture across the STACKIT Cloud and your existing infrastructure.
Agentless AdvantageXM Cyber integrates into the STACKIT ecosystem with minimal friction, utilizing modern collection methods.
Agentless Collection: High-speed discovery without installing software on every single workload.