Sign inSign up

dsbaha/docker_registry_push_scanner

By dsbaha

•Updated about 8 years ago

This container will listen for Registry Notifications and launch Clair scans on newly pushed images.

Image
0

902

dsbaha/docker_registry_push_scanner repository overview

Environment Variable configurations;

SCANNER_LISTEN: Listen on a specific IP address, defaults to 0.0.0.0 SCANNER_PORT: Listen on a specific port, defaults to 8080 SCANNER_CLAIR_URL: The Clair Scanner URL, defaults to http://127.0.0.1:6060⁠ SCANNER_REGISTRY_TOKEN: The registry token for Clair to do authenticated pulls (if necessary), defaults to None SCANNER_SECRET: The webhook secret you configure with the Registry Notification Endpoint, defaults to None

To get started, enable Docker Registry notifications. For instance, to quickly run a Registry you can use;

docker run --rm --name registry -p 5000:5000 -e REGISTRY_NOTIFICATIONS_ENDPOINTS="
- name: listener
  url: http://172.31.14.34:8080/
  headers:
    Authorization: [thisisageneratedsecret]
" -ti registry

Notice the Authorization header. Then you can run;

docker run -t -p 8080:8080 -e SCANNER_CLAIR_URL=http://172.31.14.34:6060 -e SCANNER_SECRET=thisisageneratedsecret dsbaha/docker_registry_push_scanner

Some output

[Mon Oct  1 03:03:58 2018] Using Scanner Webhook Secret [thisisageneratedsecret]
[Mon Oct  1 03:03:58 2018] Using Clair Scanner at [http://172.31.14.34:6060]
[Mon Oct  1 03:03:58 2018] Started Listening On [0.0.0.0:8080]
[Mon Oct  1 03:04:04 2018] Detected New Image [172.31.14.34:5000/centos:latest]
[Mon Oct  1 03:04:04 2018] Retrieved Manifest at  http://172.31.14.34:5000/v2/centos/manifests/sha256:fc2476ccae2a5186313f2d1dadb4a969d6d2d4c6b23fa98b6c7b0a1faad67685]
[Mon Oct  1 03:04:04 2018] Submitting Scan [256b176beaff7815db2a93ee2071621ae88f451bb1e198ca73010ed5bba79b65]
[Mon Oct  1 03:04:14 2018] Completed Scan [256b176beaff7815db2a93ee2071621ae88f451bb1e198ca73010ed5bba79b65]
[Mon Oct  1 03:04:14 2018] Completed Scan of [http://172.31.14.34:5000/centos:latest]
[Mon Oct  1 03:04:14 2018] Results located at [http://172.31.14.34:6060/v1/layers/256b176beaff7815db2a93ee2071621ae88f451bb1e198ca73010ed5bba79b65?features&vulnerabilities]

Don't forget to set --insecure-registry for your Docker Daemon if you're getting "server gave HTTP response to HTTPS client" push errors.

Tag summary

Content type

Image

Digest

Size

23.4 MB

Last updated

about 8 years ago

docker pull dsbaha/docker_registry_push_scanner