Docker discoveries

The Docker discoveries let you list the set of Docker images available from a registry, or pulled into an existing Docker deployment. The discovered Docker images can then be added to Cyberwatch with a grouped action for scanning.

Rancher

Prerequisites

  • A user with a Global role that can list all the clusters
  • This user must have on each relevant Kubernetes cluster a Cluster Membership role that can list all pods
  • A Rancher API key (usable as a Bearer token) generated for this user

If you have one or more Kubernetes clusters managed by Rancher, you can scan them with Cyberwatch to list all the images deployed on it.

Rancher discoveries require a Rancher credential set that you can create from menu Stored credentials.

You must specify the Rancher server address, for example https://rancher.example.com, and not the API endpoint, such as https://rancher.example.com/v3.

Once the credential set is created, you can create the Rancher discovery by going to Discoveries, then clicking Add and Rancher in the Docker images category.

Add the discovered Docker images

From the discovery assets list, you may see and filter the Docker images without any associated assets. To add them to Cyberwatch, pick the images you wish to scan and click Bulk actions > Scan as Docker images.

To scan an images, you will need a Docker engine. If you have not configured one yet, please refer to Add a Docker image.

Newly discovered Docker images can be automatically added to Cyberwatch as they are discovered. To enable this feature, you need to go to the discovery edition form and specify a Docker engine.

The registry is automatically selected based on the name of the discovered image. For instance, the image example.com/library/hello would automatically use the registry example.com, provided it has been added as a stored credential. New registries are automatically added as stored credentials, and you can manually edit them if they require authentication. You may in certain contexts select a preferred registry, but it will only be selected when the registry in the name of the discovered image matches the entry point of the registry.


Back to top