Onboard GitHub Enterprise (On-Prem)
Connect GitHub Enterprise Server repositories to Cortex Cloud.
Prerequisites
Cortex Cloud requirements
User permissions: You need View/Edit permissions for Data Sources and Integrations. Use the AppSec Admin or Instance Administrator role
Onboarding port: Allow port
443for outbound HTTPS communication to Cortex Cloud. A Transporter uses port443for its WSS tunnelEgress path: Create an egress path for outbound data transmission from Cortex Cloud. Refer to Egress configurations
Allow list: Add the applicable Reference B: Egress proxy IP addresses to your allow list
GitHub Enterprise requirements
Organization permissions: You need Organization Owner permissions to install the Cortex application. Repository administrators require explicit organization approval to install GitHub Apps.
OAuth scopes: Review Reference A: GitHub Enterprise OAuth scopes.
Onboarding steps
In Cortex Cloud, navigate to Settings → Data Sources & Integrations → + Add New.
Search for GitHub Self Managed (On-Prem) → Select Add or Add Another Instance.
Enter your domain in Configure Domain.
Optional: Select your Broker VM and Transporter applet.
Select Register. Copy the Application Name, Homepage URL, and Authorization Callback URL.
In GitHub Enterprise, register a new OAuth application with those values. Copy its Client ID and Client Secret.
In Cortex Cloud, paste the client credentials and select Authorize.
Select the repositories to connect. Select Save, then Close.
Verify integration
On Data Sources & Integrations, search for GitHub Self Managed (On-Prem).
Select the instance and confirm its status is Connected.
Next steps
View repository assets and mitigate detected issues.
Manage the integration
Instance-level actions
Navigate to Settings → Data Sources & Integrations and search for GitHub Self Managed (On-Prem).
Select the matching result.
Locate your instance from the displayed list, right-click it, then select an option:
Edit instance: Opens the onboarding wizard, where you can change the instance configuration.
Delete instance: Deletes the instance and previous scan data.
Copy entire row: Copies all row values to the clipboard.
Repository-level actions
Right-click a connected repository to Set Scanned Branches, run a manual scan through Scan Repository, modify the Scan Configuration, or Remove Repository entirely. You can toggle specific scanners and manage PR behavior in Scan Configuration.
Locate your instance. See Verify integration above.
Select the instance. A list of connected repositories appears.
Right-click a repository, select the required action, then click Save.
Last updated
Was this helpful?
