StackMap
Subscribe
Explore / cartography
cartography-cncf

cartography

CNCF tool that syncs infrastructure assets and relationships (AWS, GCP, Azure, Kubernetes, GitHub, Okta and 30+ more) into a Neo4j graph, then runs security rules and Cypher queries over it.

4,110 578 Python Apache-2.0updated today
View on GitHubDispute this mapping →
Curator's take

Use Cartography when your security questions are really path questions: which identities can reach which datastores, which instances are internet-exposed, which AI agents run in production and with what permissions, across clouds and SaaS. It is mature and CNCF-hosted (born at Lyft), with 30+ modules including AIBOM and Anthropic org and API-key inventory, plus a rules CLI for common misconfigurations. Once the graph exists, an agent with a Cypher tool can investigate it in plain language. The cost is operating Neo4j and scheduled syncs holding broad read credentials, so treat the Cartography host as sensitive as anything it maps. It is an asset graph, not a scanner or runtime monitor: pair it with those, do not replace them.

Mapped by ShipWithAI editors · links verified

Continue your stack

What teams reach for next — and why each earns a place beside cartography. Ranked by curator confidence.

pairs wellpairs wellgeigerflowsintcartography
pairs wellalternativebuilt withpick a node for the why · open it from the panel
Weekly digest
README.md2 min read
Cartography

Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database.

What it connects: AWS, GCP, Azure, Kubernetes, GitHub, Okta, Entra ID, CrowdStrike, and 30+ more platforms.

Questions it answers:

  • Which identities have access to which datastores? How about across multiple tenants, or providers?
  • Am I affected by any critical vulnerabilities or compromised software packages?
  • What are the network paths in and out of my environment?
  • Which compute instances are exposed to the internet?
  • What AI agents are running in production, and what permissions do they have?

Visualization of RDS nodes and AWS nodes

Quick Start

Install Cartography

pip install cartography

Install cartography[neo4j-rust] instead to swap in Neo4j's Rust Bolt codec, which cuts sync time by roughly 20-30%. See Faster Neo4j driver.

Start Neo4j database

docker run -d --publish=7474:7474 --publish=7687:7687 -v data:/data --env=NEO4J_AUTH=none neo4j:5-community

Confirm that http://localhost:7474 is up.

Sync your first data source (AWS example)

Ensure your AWS credentials and default region are configured (e.g. via AWS_PROFILE, AWS_DEFAULT_REGION, or ~/.aws/config). See AWS credentials docs for reference.

Run Cartography:

cartography --neo4j-uri bolt://localhost:7687 --selected-modules aws

See the full install guide for other platforms.

Query the graph

Open http://localhost:7474 and try:

// Find unencrypted RDS instances by account
MATCH (a:AWSAccount)-[:RESOURCE]->(rds:AWSRDSInstance{storage_encrypted:false})
RETURN a.name, rds.id
// Find EC2 instances exposed to the internet
MATCH (instance:AWSEC2Instance{exposed_internet: true})
RETURN instance.instanceid, instance.publicdnsname

See the querying tutorial and data schema for more use-cases.

Run security rules

Once Cartography has populated the reachable Neo4j graph, list, inspect, and run security rules. This quickstart uses the no-auth Neo4j container started above, so no password is required:

cartography-rules list
cartography-rules list object_storage_public
cartography-rules run object_storage_public

For authenticated Neo4j, set NEO4J_PASSWORD or use one of the other secure password options in the rules docs.

Supported platforms

Click to expand full list of 30+ supported platforms
  • Airbyte - Organization, Workspace, User, Source, Destination, Connection, Tag, Stream
  • Amazon Web Services - ACM, API Gateway, Bedrock, CloudWatch, CodeBuild, Config, Cognito, EC2, ECS, ECR (including