Metadata-Version: 2.5
Name: replimap
Version: 0.6.0
Summary: AWS Infrastructure Intelligence Engine — Scan, Understand, Transform
Project-URL: Homepage, https://www.replimap.com
Project-URL: Documentation, https://www.replimap.com/docs
Project-URL: Repository, https://github.com/RepliMap/replimap-community
Project-URL: Issues, https://github.com/RepliMap/replimap-community/issues
Project-URL: Changelog, https://github.com/RepliMap/replimap-community/blob/main/CHANGELOG.md
Author-email: David Lu <david@replimap.com>
Maintainer-email: David Lu <david@replimap.com>
License: Proprietary
License-File: LICENSE
Keywords: audit,aws,compliance,devops,infrastructure,replication,security,soc2,staging,terraform
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: System Administrators
Classifier: License :: Other/Proprietary License
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Programming Language :: Python :: 3.14
Classifier: Topic :: Software Development :: Code Generators
Classifier: Topic :: System :: Systems Administration
Requires-Python: >=3.10
Requires-Dist: aiobotocore>=2.5.0
Requires-Dist: boto3>=1.28.0
Requires-Dist: cryptography>=42.0.0
Requires-Dist: httpx>=0.25.0
Requires-Dist: jinja2>=3.1.0
Requires-Dist: networkx>=3.0
Requires-Dist: pyyaml>=6.0.0
Requires-Dist: rich>=13.0.0
Requires-Dist: structlog>=24.0.0
Requires-Dist: typer[all]>=0.9.0
Requires-Dist: zstandard>=0.21.0
Provides-Extra: dev
Requires-Dist: beautifulsoup4>=4.12.0; extra == 'dev'
Requires-Dist: boto3-stubs[ec2,rds,s3,sts]>=1.28.0; extra == 'dev'
Requires-Dist: html5lib>=1.1; extra == 'dev'
Requires-Dist: lxml>=5.0.0; extra == 'dev'
Requires-Dist: mypy>=1.0.0; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.21.0; extra == 'dev'
Requires-Dist: pytest-cov>=4.0.0; extra == 'dev'
Requires-Dist: pytest>=7.0.0; extra == 'dev'
Requires-Dist: ruff>=0.1.0; extra == 'dev'
Requires-Dist: types-pyyaml>=6.0.0; extra == 'dev'
Requires-Dist: vcrpy>=6.0.0; extra == 'dev'
Description-Content-Type: text/markdown

<!--
<p align="center">
  <img src="docs/assets/logo.png" alt="RepliMap Logo" width="120" />
</p>
-->

<h1 align="center">RepliMap</h1>

<p align="center">
  <strong>AWS Infrastructure Intelligence Engine</strong>
</p>

<p align="center">
  Scan existing AWS infrastructure, generate Terraform code, and detect compliance drift against SOC 2, HIPAA, and PCI DSS.
</p>

<p align="center">
  <a href="#quick-start">Quick Start</a> •
  <a href="#features">Features</a> •
  <a href="#compliance-coverage">Compliance</a> •
  <a href="#installation">Installation</a> •
  <a href="#documentation">Docs</a>
</p>

<p align="center">
  <a href="https://pypi.org/project/replimap/">
    <img src="https://img.shields.io/pypi/v/replimap?color=blue&label=PyPI" alt="PyPI" />
  </a>
  <img src="https://img.shields.io/badge/python-3.10+-blue.svg" alt="Python 3.10+" />
  <a href="https://github.com/RepliMap/replimap/actions/workflows/auto-release.yml">
    <img src="https://github.com/RepliMap/replimap/actions/workflows/auto-release.yml/badge.svg?branch=main" alt="Build" />
  </a>
  <a href="https://github.com/RepliMap/replimap/blob/main/LICENSE">
    <img src="https://img.shields.io/badge/license-BSL--1.1-green.svg" alt="License" />
  </a>
</p>

<p align="center">
  <img src="docs/assets/demo.gif" alt="RepliMap Demo" width="700" />
</p>

---

## Features

- **Reverse Terraform** — Scan any AWS account and generate clean, modular HCL
- **Drift Detection** — Compare Terraform state against actual AWS configuration
- **Compliance Lens** — Map infrastructure drift to SOC 2, HIPAA, PCI DSS controls
- **[compliance.tf](https://compliance.tf/) Integration** — Generate Terraform with compliance-ready module sources (16 verified frameworks, 21 modules) — prevention at `terraform apply` paired with RepliMap's runtime drift detection
- **Audit-Ready Reports** — Generate markdown reports your auditor can read directly
- **Risk Exemptions** — Document and track accepted risks with expiry dates
- **Data Sovereignty** — Everything runs locally. No data leaves your machine.

---

## Quick Start

### Installation

```bash
# Using pipx (recommended)
pipx install replimap

# Using pip
pip install replimap

# Verify
replimap --version
```

### Scan and Generate Terraform

```bash
# Scan your AWS account
replimap -p prod -r us-east-1 scan

# Generate Terraform from scanned infrastructure
replimap -p prod -r us-east-1 codify -o ./terraform
```

### Check Compliance Drift

```bash
# Compare TF state against AWS and check SOC 2 compliance
replimap drift -s terraform.tfstate --compliance soc2

# Generate audit-ready markdown report
replimap drift -s terraform.tfstate -c soc2 -f markdown -o compliance-report.md

# Check all frameworks at once
replimap drift -s terraform.tfstate -c all

# Use risk exemptions
replimap drift -s terraform.tfstate -c all --ignore-file .replimap-ignore.yml
```

### Generate SOC 2 Evidence Report

```bash
# Full evidence report with PASS/FAIL for every resource
replimap audit -s terraform.tfstate --company "Acme Corp" --period "2026-Q1" -o soc2-evidence.md
```

### Generate Compliance-Ready Terraform (compliance.tf Integration)

```bash
# Codify with SOC 2-compliant module sources
replimap codify -p prod -r us-east-1 -c soc2 -o ./terraform

# Other frameworks (16 verified): hipaa, pci-dss, nist, fedramp,
# iso27001, gdpr, nis2, cis, and versioned variants
replimap codify -p prod -c pci-dss -o ./terraform
replimap codify -p prod -c nist    -o ./terraform

# After apply, verify no drift from the compliance baseline
cd ./terraform
terraform login soc2.compliance.tf      # or: tofu login soc2.compliance.tf
terraform init && terraform apply
replimap drift -s terraform.tfstate --compliance soc2
```

RepliMap covers the **detection layer** (what's drifted in production);
[compliance.tf](https://compliance.tf/) covers the **prevention layer**
(what gets deployed). Together they form a complete infrastructure control
stack.

Generated `.tf` files use the canonical subdomain (`pcidss.compliance.tf`,
`nist80053.compliance.tf`, ...), verified via
`scripts/verify_compliance_tf_subdomains.py`. Friendly CLI slugs like
`pci-dss` and `nist` are resolved to their canonical form before URL
construction — `terraform init` never sees a short slug.

---

## Compliance Coverage

RepliMap maps 18 infrastructure checks to SOC 2, HIPAA, and PCI DSS controls.

| Rule | Resource | Check | SOC 2 | HIPAA | PCI DSS |
|------|----------|-------|-------|-------|---------|
| s3-encryption-enabled | S3 Bucket | Default encryption | CC6.1 | §164.312(a)(2)(iv) | 3.4.1 |
| rds-encryption-enabled | RDS Instance | Storage encryption | CC6.1 | §164.312(a)(2)(iv) | 3.4 |
| kms-key-rotation-enabled | KMS Key | Key rotation | CC6.1 | — | — |
| ebs-encryption-enabled | EBS Volume | Volume encryption | CC6.1 | §164.312(a)(2)(iv) | 3.4.1 |
| elasticache-at-rest-encryption | ElastiCache Cluster | At-rest encryption | CC6.1 | §164.312(a)(2)(iv) | — |
| elasticache-transit-encryption | ElastiCache Cluster | In-transit encryption | CC6.7 | §164.312(e)(1) | — |
| cloudwatch-log-encryption | CloudWatch Log Group | KMS encryption configured | CC6.1 | — | — |
| sns-encryption-enabled | SNS Topic | KMS encryption configured | CC6.1 | — | — |
| sqs-encryption-enabled | SQS Queue | KMS encryption configured | CC6.1 | — | — |
| s3-no-public-acl | S3 Bucket | ACL not public | CC6.6 | §164.312(e)(1) | 1.3 |
| rds-not-publicly-accessible | RDS Instance | Not publicly accessible | CC6.6 | — | 1.3 |
| sg-no-unrestricted-ingress | Security Group | No 0.0.0.0/0 on sensitive ports | CC6.6 | — | 1.2.1 |
| sg-no-unrestricted-egress | Security Group | No unrestricted egress (0.0.0.0/0 all protocols) | CC6.6 | — | — |
| iam-trust-policy | IAM Role | No wildcard or root principals | CC6.1 | — | — |
| s3-logging-enabled | S3 Bucket | Access logging | CC7.1 | §164.312(b) | 10.1 |
| s3-versioning-enabled | S3 Bucket | Versioning enabled | CC8.1 | — | — |
| rds-multi-az-enabled | RDS Instance | Multi-AZ availability | CC7.1 | — | — |
| rds-backup-retention | RDS Instance | Backup >= 7 days | CC7.1 | — | — |

### How It Works

1. `DriftEngine` compares your Terraform state against actual AWS resources
2. `ComplianceMappingEngine` maps attribute diffs to framework controls
3. Value-aware checking prevents false positives (e.g., fixing `publicly_accessible: True → False` is not a violation)
4. Port-aware SG analysis: 0.0.0.0/0 on SSH/RDP/DB ports is critical; HTTP/HTTPS is acceptable

---

## Risk Exemptions

Document accepted risks in `.replimap-ignore.yml`:

```yaml
exceptions:
  - resource: aws_s3_bucket.public_website
    attribute: acl
    reason: "Public website bucket, approved by CISO"
    approved_by: "jane@acme.com"
    expires: "2026-12-31"
```

Exemptions appear as "Accepted Risks" in reports. Expired exemptions are automatically flagged and restored as active findings.

---

## Commands

RepliMap has 23 commands, grouped as shown in `replimap --help`:

**Core**

| Command | Description |
|---------|-------------|
| `replimap scan` | Scan AWS resources and build dependency graph |
| `replimap graph` | Generate visual dependency graph of AWS infrastructure |
| `replimap load` | Load and display a saved graph |
| `replimap profiles` | List available AWS profiles |

**Infrastructure as Code**

| Command | Description |
|---------|-------------|
| `replimap codify` | Transform ClickOps AWS infrastructure into a Terraform adoption starting point |
| `replimap remediate` | Generate Terraform remediation code from an audit JSON file |

**Analysis**

| Command | Description |
|---------|-------------|
| `replimap analyze` | Analyze a resource dependency graph for critical infrastructure |
| `replimap deps` | Explore dependencies for a resource (Pro+) |
| `replimap drift` | Detect infrastructure drift between Terraform state and AWS |
| `replimap drift-offline` | Offline drift detection |
| `replimap validate` | Validate infrastructure against topology constraints |

**Security & Compliance**

| Command | Description |
|---------|-------------|
| `replimap audit` | Run security audit on AWS infrastructure (Checkov-based, or SOC 2 evidence with `--state`) |
| `replimap residency` | Validate data residency compliance for NZ/AU sovereignty |
| `replimap iam` | Generate least-privilege IAM policies from graph analysis |
| `replimap trust-center` | Trust Center API auditing for compliance |

**Configuration & Utility**

| Command | Description |
|---------|-------------|
| `replimap doctor` | Run environment health checks |
| `replimap cache` | Credential cache management |
| `replimap scan-cache` | Scan result cache management |
| `replimap license` | License management commands |
| `replimap upgrade` | Upgrade your RepliMap plan |
| `replimap completion` | Generate shell completion scripts |

**Help & Debugging**

| Command | Description |
|---------|-------------|
| `replimap explain` | Get detailed information about an error code |
| `replimap errors` | List all error codes |

Run `replimap <command> --help` for full flags and examples.

---

## Architecture

RepliMap is built around a **Graph Engine** powered by NetworkX. It transforms discrete cloud resources into a connected dependency graph, enabling impact analysis, visualization, and intelligent code generation.

```
┌──────────────────────────────────────────────────────────────────┐
│                         RepliMap Architecture                    │
├──────────────────────────────────────────────────────────────────┤
│                                                                  │
│   ┌─────────────┐     ┌─────────────┐     ┌─────────────┐       │
│   │  Scanners   │────>│   Graph     │────>│  Renderers  │       │
│   │  (AWS API)  │     │   Engine    │     │  (Terraform)│       │
│   └─────────────┘     └──────┬──────┘     └─────────────┘       │
│                              │                                   │
│         ┌────────────────────┼────────────────────┐             │
│         │                    │                    │             │
│         v                    v                    v             │
│   ┌───────────┐      ┌─────────────┐      ┌───────────┐        │
│   │ Compliance │      │ Right-Sizer │      │   Drift   │        │
│   │   Engine   │      │   Engine    │      │  Detector │        │
│   └───────────┘      └─────────────┘      └───────────┘        │
│                                                                  │
└──────────────────────────────────────────────────────────────────┘
```

### Supported Resources

Resources are listed here only if RepliMap scans them from the AWS API. Types
marked **graph only** appear in the dependency graph, `graph` and `deps`, but
`codify` does not emit them as Terraform (it would need data RepliMap refuses to
read, such as function code or secret values, or the type is not generated yet).
Everything else is generated as Terraform (`scan` → `codify`).

`codify` also skips resources owned by a CloudFormation stack (tagged
`aws:cloudformation:stack-id` / `stack-name`): importing them would make
Terraform and CloudFormation fight over the same resource. The summary shows how
many were skipped; pass `--include-cfn-managed` to generate them anyway. They
stay in the scan graph, and `--coverage-state` reports them as auto-created
rather than actionable. AWS-reserved `aws:` tags are never written to the
generated Terraform.

<details>
<summary>View all 39 codified resource types (+ 12 graph-only)</summary>

| Category | Resources |
|----------|-----------|
| **Network** | VPC, Subnet, Security Group, Route Table, Internet Gateway, NAT Gateway, VPC Endpoint, Network ACL, Elastic IP |
| **Compute & Load Balancing** | EC2 Instance, Launch Template, Auto Scaling Group, Application/Network Load Balancer (+ target groups, listeners) |
| **Database** | RDS Instance, Aurora Cluster (+ Cluster Instance), DB Subnet Group, DB Parameter Group, ElastiCache Cluster, ElastiCache Subnet Group, DynamoDB Table |
| **Storage** | S3 Bucket, S3 Bucket Policy, EBS Volume |
| **Messaging & Monitoring** | SQS Queue, SNS Topic, CloudWatch Log Group, CloudWatch Metric Alarm |
| **IAM** | IAM Role, IAM Instance Profile |
| **DNS, CDN & Certificates** | Route53 Hosted Zone, Route53 Record (incl. alias, weighted and latency records), ACM Certificate, CloudFront Distribution |
| **Containers** (ECS / ECR) | ECS Cluster, ECR Repository; **graph only:** ECS Service, ECS Task Definition (environment variable values are never stored) |
| **Serverless** | Lambda Event Source Mapping; **graph only:** Lambda Function (no code download; environment variable values are never stored) |
| **Secrets & Encryption** | Secrets Manager Secret (metadata only, never the value), KMS Key (customer-managed, including its key policy), KMS Alias; **graph only:** SSM Parameter (never the value) |
| **API Gateway** (graph only) | REST API, REST Stage, REST Custom Domain, REST VPC Link, HTTP/WebSocket API, HTTP/WebSocket Stage, HTTP/WebSocket Custom Domain, HTTP/WebSocket VPC Link |

</details>

---

## Configuration

### AWS Credentials

RepliMap uses standard AWS credential chain:

```bash
# AWS CLI profile (recommended)
replimap -p my-profile scan

# Environment variables
export AWS_ACCESS_KEY_ID=xxx
export AWS_SECRET_ACCESS_KEY=xxx
replimap scan

# IAM role (EC2/ECS/Lambda)
replimap scan  # Auto-detects instance role
```

### Required IAM Permissions

RepliMap only needs **read-only** access. See [IAM_POLICY.md](IAM_POLICY.md) for the minimal policy.

---

## Security & Privacy

**Your data never leaves your machine.**

- RepliMap runs entirely client-side
- No cloud account required
- Read-only AWS access (no modifications)
- Sensitive data (passwords, keys) automatically redacted
- SOC 2-compliant design

See [SECURITY.md](SECURITY.md) for details.

---

## Roadmap

- [x] compliance.tf integration for codify output (16 verified core frameworks, 21 modules, shared `--compliance` alias resolution across codify/drift/audit)
- [ ] Not yet supported: EKS, EFS, CloudTrail, VPC Flow Logs (Lambda functions, ECS services/task definitions, API Gateway and SSM parameters are graph only)
- [ ] CI/CD integration templates (GitHub Actions, Azure DevOps)

---

## Pricing

| | Community (Free) | Pro ($29/mo) | Team ($99/mo) | Sovereign ($2,500/mo) |
|---|---|---|---|---|
| Unlimited scans | ✅ | ✅ | ✅ | ✅ |
| Graph / dependency map | ✅ | ✅ | ✅ | ✅ |
| Generate Terraform (resource `.tf` files, full account) | ✅ | ✅ | ✅ | ✅ |
| Compliance audit | Full scan + score | Full scan + score + report file | Full scan + score + report file | Full scan + score + report file |
| Drift detection | ✅ (experimental) | ✅ (experimental) | ✅ (experimental) | ✅ (experimental) |
| Import scaffold (`imports.tf` / `imports.sh`) | — | ✅ | ✅ | ✅ |
| Dependency Explorer (`deps`) | — | ✅ | ✅ | ✅ |
| Coverage summary (unmanaged resources) | Counts only | Full list | Full list | Full list |
| CI/CD blocking (`--fail-on-*`) + Trust Center report | — | — | ✅ | ✅ |
| APRA/RBNZ/NZISM regional compliance | — | — | — | ✅ |
| Offline activation / digital signatures / white-label | — | — | — | ✅ |

[View full pricing](https://replimap.com/pricing)

---

## Contributing

We welcome contributions. See [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.

```bash
git clone git@github.com:RepliMap/replimap.git
cd replimap
pip install -e ".[dev]"
pytest
```

---

## Documentation

- [IAM Policy](IAM_POLICY.md)

## Support

| Purpose | Contact |
|---------|---------|
| General inquiries | [hello@replimap.com](mailto:hello@replimap.com) |
| Technical support | [support@replimap.com](mailto:support@replimap.com) |
| Enterprise & Sales | [david@replimap.com](mailto:david@replimap.com) |
| Bug reports | [GitHub Issues](https://github.com/RepliMap/replimap/issues) |

---

## License

RepliMap is licensed under the [Business Source License 1.1](LICENSE).

[View full pricing](https://replimap.com/pricing)

---

<p align="center">
  <a href="https://replimap.com">Website</a> •
  <a href="https://docs.replimap.com">Docs</a> •
  <a href="https://twitter.com/replimap">Twitter</a>
</p>

<p align="center">
  Made with ☕ in New Zealand
</p>
