DivvyCloud

Welcome to the DivvyCloud Docs!

DivvyCloud is a Cloud Security Posture Management (CSPM) platform that provides real-time analysis and automated remediation across leading cloud and container technologies.

For questions about documentation reach out to us [email protected]

Take Me to the Docs!    Release Notes

Harvesting Strategies

DivvyCloud provides a way to create and modify harvesting strategies by cloud, by region, and by resource. In this way, you can better match your harvesting resources with your harvesting needs. For example, you can lower the harvesting cadence in regions where you do not deploy, while not leaving open blindspots to unauthorized usage in regions where you do not deploy.

Previously, the harvesting cadences were fairly limited because users couldn't specify resource types to harvest faster or slower than another resource type, or even specify the multiplier. Configuring all resources in a single region was the only way to adjust harvesting times, and only region-based services were configurable.

Now, DivvyCloud is putting this power capability in the hands of Administrators to allow these fine-tuned configurations on harvesting strategies for each resource type, either per region or globally, for any cloud provider.

📘

Note:
Existing customers who have utilized the previous way of overriding harvesting cadences via the Clouds page will have a blue banner at the top of their screen after logging in.
This is meant to be a call to action to configure harvesting strategies quickly, as this new feature will override those configurations and have all resources in all regions, harvesting at default speed.

We recommend setting up a harvesting strategy when you are connecting and configuring your cloud accounts. Harvesting Strategies can be accessed by those with appropriate permissions from the navigation menu under Administration.

Creating a Harvesting Strategy

To create a harvesting strategy:

  1. Select the New Strategy button on the upper right of the Harvesting Strategy page.
  2. Give your strategy a name, select a provider and click Create.

Creating a New Harvesting Strategy

  1. The Strategy Configuration page will open and allow you to select the harvesting parameters you would like to employ.
  • Select the region to which a new strategy applies (from the Region dropdown box at the top right of the page).
  • Select an overall percentage change (faster or slower) to the default cadence (from the Cadence slide bar).
  • Select overrides (in minutes) for specific resource types or harvesters. Default overrides (in minutes) are shown for reference.

📘

Overrides cannot be less than 1 minute, nor greater than 24 hours.

For AWS EDH-enabled resources and regions, DivvyCloud sets a maximum harvesting frequency of four hours.

Strategy Configuration for a New Harvesting Strategy

  1. Click Save & Copy to Regions to apply your strategy to other regions for easier configuration. (This applies when a region other than 'Global Harvest' was initially selected.)

🚧

Limiting Regions

If you want to create a custom strategy, or modify the default strategy in order to exclude a specific region or regions (e.g. working backwards by removing rather than adding regions) you can also create or copy an existing strategy and modify that strategy using the Admin option.

Copying Harvesting Strategies From One Region to Others

  1. Once you have completed your changes click Save Changes, note this page will also auto-save your changes.
  2. Click Harvesting Strategies to return to the main page and assign resources.
  • Select the 'Assign' (clipboard) icon next to your strategy to open the "Strategy Assignment" window.
  1. Select the cloud accounts to be harvested by this strategy. You can scope the strategy by cloud account, or by badge.

Assigning Cloud Accounts to a Harvesting Strategy

❗️

Note: Any existing strategy previously assigned to selected accounts will be overwritten.

Modifying an Existing Strategy

🚧

Permissions

Domain Admin permissions are required for the majority of these changes. Contact your administrator or [email protected] if you have issues or questions.

To modify an existing harvesting strategy:

  1. Find the strategy of interest from the list on the Harvesting Strategy page. Note: You can scope this list by cloud or by strategy name.
  2. From the Harvesting Strategy page you can:
    • Reconfigure the strategy (the wrench icon) - This takes you to the Strategy Configuration page (shown above).
    • Assign (or reassign) this strategy to a cloud account.
    • Exclude specific regions from harvesting (the pencil icon) Currently, the ability to limit regions is only available for AWS.
    • Delete the strategy (with permissions and confirmation).

Modifying an Existing Harvesting Strategy

Selecting Harvesting Strategy For Newly Added Accounts

Once a strategy has been set up an administrator can assign any cloud account to it, including new
accounts as they are added.

  1. When adding a cloud account via the UI, click Show Advanced
    (at the bottom), and a drop down will appear with the strategies applicable to the type of cloud you are adding.
  2. Click the desired strategy; select Submit when the remainder of the "Add Cloud" pane is complete.
  • Note: the "Harvesting Strategy" drop-down option will only appear for organizations that have additional harvesting strategies configured, otherwise the default is applied and no drop-down appears.

Selecting a Harvesting Strategy While Adding a Cloud Account

📘

Note: If you don't specify a harvest strategy when adding the cloud account, it will be
assigned to the default strategy for that cloud provider.

Harvesting Strategy Example

In the following example, harvesting times are slowed for Amazon Web Services (AWS) outside the Continental US.

1. First, we create a new harvesting strategy, named "New Strategy" for AWS.

Example - Creating a New Harvesting Strategy

2. Second, we decrease the cadence of all harvesting in one region by:

  • Choosing one region outside the US (ap-northeast-1)
  • Using the slide bar to decrease the overall harvesting cadence; in this case we have decreased the cadence by 1000% from default values.
  • We can also override harvesting times for specific resources by entering those numbers (minutes) into the boxes next to the specific resource.

3. Select Apply to save the changes.

Example - Decreasing the Harvesting Cadence for One Region

4. Next, we apply this newly created strategy to all regions except the Continental US, by copying that strategy to everything except regions within the Continental US (us-east-1 & 2, us-west-1 & 2).

  • We've used the copy icon, next to the Region box, to open the "Region to Copy to" pane, and select (or deselect) the appropriate regions.

Example - Copying a Harvesting Strategy to all Regions Except the Continental US

5. Finally, we return to the Harvesting Strategy listing, to assign cloud accounts to the new strategy.

  • On first return to this listing, you will see that 'New Strategy' is assigned to no clouds.
  • Clicking the clipboard icon opens the "Assign Strategy" pane, where we have added one of our AWS cloud accounts.

Example - "New Strategy" After One Cloud Account Added

Updated 8 months ago

Harvesting Strategies


Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.