Terraform Enterprise (Run Tasks)
Integrate Cortex Cloud Application Security with Terraform Enterprise (Run Tasks) to enable dynamic, automated, and context-specific scans in your Terraform workspace. Cortex Cloud Application Security scans Terraform (TF) frameworks for misconfigurations based on default and custom policies whenever changes are triggered, ensuring seamless security checks. It identifies infrastructure-as-code (IaC) misconfigurations, Software Composition Analysis (SCA ) vulnerabilities^(*), exposed secrets, and license non-compliance issues, depending on the security scanners that you have subscribed to.
Note
For container image vulnerabilities, Cortex Cloud Application Security performs 'Image Referencer' scans within Terraform Enterprise (Run Tasks), as full SCA scans are not currently supported.
You can monitor and remediate issues directly in the Cortex Cloud Application Security console. Run statuses and violation details can be tracked in both Cortex Cloud Application Security and Terraform Enterprise through streamlined run task reviews. For more information about streamlined tasks, refer to https://www.hashicorp.com/blog/terraform-cloud-adds-streamlined-run-task-reviews.
Prerequisite
Before you begin:
Ensure access to a Terraform Enterprise console to enable you to provide a user or team token that authorizes Cortex Cloud Application Security to access workspaces and helps regulate run configurations
Terraform Enterprise version compatibility: Ensure Run Tasks for workspaces on is compatible with version 1.1.9 and above
Terraform Enterprise user or team permissions: For a workspace integration of run tasks you need to ensure that the token used has the following permissions. These permissions enable Cortex Cloud to configure run tasks in the environment and scan plan files from your runs:
Manage run tasks permissions at the organizational level. These permissions are required to create and manage the run task in the organization
Manage Workspaces permissions at the organization level. These permissions are required to attach and manage the run task on workspaces or:
Administrator permissions on the workspace(s)
Note
For more on Terraform Run Task permissions refer to Manage Run Tasks permissions.
Create a Terraform Organization. For more information, refer to theTerraform documentation
Create a Terraform Workspace: For more information, refer to the Terraform documentation
Egress path: Create an egress path to establish the designated route for outbound data transmission from Cortex Cloud to third party services. For more information about configuring egress paths, refer to Egress configurations
Onboarding steps
On your Terraform Enterprise platform, create a Terraform api token.
Select your user/profile icon → User Settings.
Select the Tokens section from the left side menu.
Click Create an API token → provide a description → Create API token .
For more information about Terraform API tokens, refer to the Terraform API Tokens documentation.
On the Cortex Cloud console:
Navigate to Settings → Data Sources & Integrations → + Add New.
Search for and hover over Terraform Enterprise (Run Tasks) and click Add, or Add Another Instance if an instance is already onboarded.
Provide your Terraform user or team API token on the Configure Account step of the wizard → Next.
Select an organization from the Select Organization step of the wizard → Next.
On theSelect Workspace step of the wizard:
Select repositories from the Selection Options field.
Permit all existing repositories
Permit all existing and future repositories
Choose from repository list
Click Save.
Click Save and then Close in the final verification step of the wizard.
Verify integration
On the Data Sources & Integrations page, search for Terraform Enterprise (Run Tasks).
Select the resulting data source.
Locate your instance and verify that the status is Connected.
Next steps
View scan results and mitigate issues.
Terraform workflow for Run Tasks enforcement
Use the Terraform workflow for Run Tasks enforcement reference to configure policy-based enforcement.
Manage the integration
Instance-level actions
Navigate to Settings → Data Sources & Integrations and search for Terraform Enterprise (Run Tasks).
Select the matching result.
Locate your instance from the displayed list. Right-click it, then select an option:
Edit instance: Opens the onboarding wizard, where you can change the instance configuration.
Delete instance: Deletes the instance and previous scan data.
Copy entire row: Copies all row values to the clipboard.
Repository-level actions
Locate your instance. See Instance-level actions.
Select the instance. A list of connected repositories appears.
Right-click a repository, select the required action, then select Save.
Last updated
Was this helpful?
