From e67d227e559010b465ac616c68578572e4a9d219 Mon Sep 17 00:00:00 2001 From: Cody Maffucci <46459665+Maffooch@users.noreply.github.com> Date: Mon, 17 Aug 2026 21:24:18 -0600 Subject: [PATCH] docs(sensei): CSPM is gated on the Sensei license, not a feature flag MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Cloud Security Posture page and the Sensei reference described CSPM as requiring a "Cloud Posture" feature flag. That flag has been removed — CSPM is part of Sensei and is unlocked by the Sensei license alone, like AppSec. Update the Requirements and Troubleshooting on the CSPM page and the Onboarded Cloud Accounts note in the reference to drop the flag, and point users at enabling the Locations feature on the Feature Flags page (the only remaining onboarding prerequisite). Co-Authored-By: Claude Opus 5 --- docs/content/sensei/cloud_posture.md | 4 ++-- docs/content/sensei/sensei_reference.md | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/content/sensei/cloud_posture.md b/docs/content/sensei/cloud_posture.md index 1ba9ee23c5..6eb7847271 100644 --- a/docs/content/sensei/cloud_posture.md +++ b/docs/content/sensei/cloud_posture.md @@ -23,7 +23,7 @@ Sensei has two capabilities that share one hub. **AppSec** scans and fixes sourc ## Requirements - A **DefectDojo Pro** license that includes the **Sensei** feature, with a **cloud-account quota** (`sensei_cloud_account_limit`). -- The **Cloud Posture** feature flag enabled, and the **Locations** feature enabled — a cloud finding is identified by the cloud *resource* it concerns rather than a file and line, and Locations is what records that. Without Locations, cloud onboarding is not offered (see [Troubleshooting](#troubleshooting)). +- The **Locations** feature enabled — a cloud finding is identified by the cloud *resource* it concerns rather than a file and line, and Locations is what records that. Without Locations, cloud onboarding is not offered (see [Troubleshooting](#troubleshooting)). CSPM itself needs no feature flag: it is part of Sensei, so the Sensei license unlocks it. - A **read-only scan credential** for each provider (details below). - To **onboard** accounts and **manage connections**: a global **Maintainer** or **Owner** role. To **run a direct fix or revert one**: at least **Writer** access to the finding's Asset — a direct fix mutates live cloud state, so it is an edit of the finding. @@ -128,7 +128,7 @@ CSPM meters against two quotas, both shown as cards at the top of the hub: ## Troubleshooting -- **Cloud onboarding is not offered / the CSPM capability is missing.** CSPM requires both the **Cloud Posture** feature flag and the **Locations** feature. A cloud finding has no identity without a resource location, so with Locations off, onboarding is refused. Ask a DefectDojo administrator to enable them. +- **Cloud onboarding is not offered.** CSPM requires the **Locations** feature. A cloud finding has no identity without a resource location, so with Locations off, onboarding is refused (the CSPM capability itself still appears). Enable Locations on the **Settings > Feature Flags** page — the Sensei hub links there from the prompt — then onboard a cloud account. - **"No cloud-account quota is available."** Your license carries no `sensei_cloud_account_limit`, or it is used up. Contact your DefectDojo administrator to raise it. - **The fix button shows "Fix" or "Configure Asset" on a cloud finding, not "Fix in Cloud."** The finding is not directly remediable — either the account has no write credential / remediation is not enabled, or the finding's check has no v1 direct action. It can still be fixed by an IaC pull request. - **A revert failed with a drift error.** The live resource changed out-of-band since the fix was applied, so the recorded prior state no longer matches. Reconcile the resource manually; Sensei refuses to overwrite an unexpected state. diff --git a/docs/content/sensei/sensei_reference.md b/docs/content/sensei/sensei_reference.md index b107be5c1e..d70394bcc8 100644 --- a/docs/content/sensei/sensei_reference.md +++ b/docs/content/sensei/sensei_reference.md @@ -52,7 +52,7 @@ Sensei is metered against your DefectDojo Pro license, shown as meters at the to - **Fixes:** remediations applied against your prepaid limit. Approving a candidate or triggering a fix consumes from this quota; when it is exhausted, further fixes are blocked (a warning banner appears) until the limit is raised. - **Onboarded Repositories:** repositories onboarded against your repository limit. When it is reached, onboarding new repositories is blocked. -- **Onboarded Cloud Accounts:** cloud accounts onboarded against your cloud-account limit (`sensei_cloud_account_limit`), shown when CSPM is enabled. When it is reached, onboarding new accounts is blocked. The Fixes quota is **shared** — an AppSec fix and a cloud remediation both spend `sensei_fix_limit` — and the Fixes card breaks its total down by capability. See [CSPM → Quotas](/sensei/cloud_posture/#quotas). +- **Onboarded Cloud Accounts:** cloud accounts onboarded against your cloud-account limit (`sensei_cloud_account_limit`), shown when Sensei is licensed (CSPM has no feature flag of its own). When it is reached, onboarding new accounts is blocked. The Fixes quota is **shared** — an AppSec fix and a cloud remediation both spend `sensei_fix_limit` — and the Fixes card breaks its total down by capability. See [CSPM → Quotas](/sensei/cloud_posture/#quotas). To raise a limit, contact your DefectDojo account team.