CI/CD instance as an asset
Cortex Cloud Application Security discovers CI/CD platform instances through active CI/CD integrations. Each instance is a platform-level asset that hosts and executes CI/CD pipelines.
Prerequisites
Before viewing and managing CI/CD instance assets, verify the following:
License
An active Cortex Cloud license with Application Security entitlements.
RBAC role
The AppSec Admin or SOC Analyst role, or an equivalent custom role.
CI/CD integration
An active GitHub Actions, GitLab CI, Jenkins, Azure Pipelines, or CircleCI integration.
Completed scan
A completed periodic scan with CI/CD configuration results.
Core capabilities and scope
Discovery and visibility: Identifies platform instances, their providers, versions, URLs, and hosted pipelines.
Aggregated posture: Aggregates CI/CD configuration risks across pipelines into an instance health profile.
Scope constraints: Represents a CI/CD platform instance. It does not represent pipelines, pipeline runs, build logs, or VCS organizations.
Key achievements
Instance discovery and identity: Registers each integrated platform with a persistent identity record.
Platform-level risk assessment: Surfaces systemic configuration risks using aggregated severity findings.
Pipeline visibility: Displays pipelines hosted by the instance for cross-pipeline assessment.
Coverage measurement: Helps identify platforms that are not actively monitored for configuration risks.
Relationship model
The CI/CD instance provides organizational context and aggregates platform security posture.
Parent - VCS organization: Provides the associated organization, provider type, and organizational context.
Child - CI/CD pipeline: Pipelines inherit provider context. Their CI/CD configuration risks aggregate into instance health.
Next steps
Last updated
Was this helpful?
