For the complete documentation index, see llms.txt. This page is also available as Markdown.

CI/CD instance as an asset

Cortex Cloud Application Security discovers CI/CD platform instances through active CI/CD integrations. Each instance is a platform-level asset that hosts and executes CI/CD pipelines.

Prerequisites

Before viewing and managing CI/CD instance assets, verify the following:

Prerequisite
Description

License

An active Cortex Cloud license with Application Security entitlements.

RBAC role

The AppSec Admin or SOC Analyst role, or an equivalent custom role.

CI/CD integration

An active GitHub Actions, GitLab CI, Jenkins, Azure Pipelines, or CircleCI integration.

Completed scan

A completed periodic scan with CI/CD configuration results.

Core capabilities and scope

  • Discovery and visibility: Identifies platform instances, their providers, versions, URLs, and hosted pipelines.

  • Aggregated posture: Aggregates CI/CD configuration risks across pipelines into an instance health profile.

  • Scope constraints: Represents a CI/CD platform instance. It does not represent pipelines, pipeline runs, build logs, or VCS organizations.

Key achievements

  • Instance discovery and identity: Registers each integrated platform with a persistent identity record.

  • Platform-level risk assessment: Surfaces systemic configuration risks using aggregated severity findings.

  • Pipeline visibility: Displays pipelines hosted by the instance for cross-pipeline assessment.

  • Coverage measurement: Helps identify platforms that are not actively monitored for configuration risks.

Relationship model

The CI/CD instance provides organizational context and aggregates platform security posture.

  • Parent - VCS organization: Provides the associated organization, provider type, and organizational context.

  • Child - CI/CD pipeline: Pipelines inherit provider context. Their CI/CD configuration risks aggregate into instance health.

Next steps

Last updated

Was this helpful?