Sign inSign up

codefresh/cfstep-paclair

By codefresh

•Updated over 7 years ago

Clair Security Scanning Image for use in Codefresh

Image
0

50K+

codefresh/cfstep-paclair repository overview

⁠cfstep-paclair Codefresh build status

Custom Docker image to support clair image scanning from Codefresh pipeline

⁠Prerequisites:

Codefresh Subscription - https://codefresh.io/⁠

Running Clair Instance - Helm Chart is available to install here: https://github.com/coreos/clair/tree/master/contrib/helm⁠

⁠Documentation:

paclair: https://github.com/yebinama/paclair⁠

⁠Full List of Options

To use an ENVIRONMENT VARIABLE you need to add the variables to your Codefresh Pipeline and also to your codefresh.yml.

Example codefresh.yml build is below with required ENVIRONMENT VARIABLES in place.

ENVIRONMENT VARIABLEDEFAULTTYPEREQUIREDDESCRIPTION
CF_ACCOUNTnullstringNoCodefresh Account Name
CLAIR_URLnullstringYeshttps://clair.domain.com:6060⁠
IMAGEnullstringYesDocker Image Name
REGISTRY_PASSWORDnullstringYesDocker Registry Password
REGISTRY_USERNAMEnullstringYesDocker Registry Username
SEVERITY_THRESHOLDnullstringNocritical, high, medium, low, negligible, unknown
TAGnullstringYesDocker Image Tag
⁠SEVERITY_THRESHOLD

If variable is set step will check that the threshold is not met or exceeded.

For example, high would fail your build if you had high or critical vulnerabilties on your Docker image.

⁠Notes

Right now this is limited to Codefresh Docker Registry. Username is your Codefresh Username and Docker Registry keys can be created here https://g.codefresh.io/user/settings⁠

⁠codefresh.yml

Codefresh Build Step to execute Twistlock scan. All ${{var}} variables must be put into Codefresh Build Parameters codefresh.yml

version: '1.0'
steps:
  BuildingDockerImage:
    title: Building Docker Image
    type: build
    image_name: codefresh/demochat # Replace with your Docker image name
    working_directory: ./
    dockerfile: Dockerfile
    tag: '${{CF_BRANCH_TAG_NORMALIZED}}'
  CheckClair:
    image: codefresh/cfstep-paclair:3.0.0
    environment:
      - CF_ACCOUNT=dustinvanbuskirk
      - IMAGE=example-voting-app/worker # Replace with your Docker image name
      - TAG=${{CF_BRANCH_TAG_NORMALIZED}}
    on_success: # Execute only once the step succeeded
      metadata: # Declare the metadata attribute
        set: # Specify the set operation
          - ${{BuildingDockerImage.imageId}}: # Select any number of target images
            - SECURITY_SCAN: true
    on_fail: # Execute only once the step failed
      metadata: # Declare the metadata attribute
        set: # Specify the set operation
          - ${{BuildingDockerImage.imageId}}: # Select any number of target images
            - SECURITY_SCAN: false
  ArchiveReport:
    image: mesosphere/aws-cli
    commands:
      - aws s3 cp ./reports/clair-scan-example-voting-app-worker-${{CF_BRANCH_TAG_NORMALIZED}}.html s3://${{S3_BUCKETNAME}}/${{CF_BUILD_ID}}/clair-scan-example-voting-app-worker-${{CF_BRANCH_TAG_NORMALIZED}}.html --acl public-read
    on_success:
     metadata:
        set:
          - ${{BuildingDockerImage.imageId}}:
              - CLAIR_REPORT: "https://s3.amazonaws.com/${{S3_BUCKETNAME}}/${{CF_BUILD_ID}}/clair-scan-example-voting-app-worker-${{CF_BRANCH_TAG_NORMALIZED}}.html"

Optional Storage Step Variables:

ENVIRONMENT VARIABLEDEFAULTTYPEREQUIREDDESCRIPTION
AWS_ACCESS_KEY_IDnullstringNoAWS Access Key of S3 Bucket
AWS_DEFAULT_REGIONnullstringYesAWS Region of S3 Bucket
AWS_SECRET_ACCESS_KEYnullstringYesAWS Secret Key of S3 Bucket
S3_BUCKETNAMEnullstringYesName of S3 Bucket to Store Reports

Tag summary

Content type

Image

Digest

Size

103.7 MB

Last updated

over 7 years ago

docker pull codefresh/cfstep-paclair:3.1.0