Sign inSign up

rapid7/insightvm_scan_engine

By rapid7

•Updated about 6 hours ago

Base image for the Rapid7 InsightVM Scan Engine.

Image
8

1M+

rapid7/insightvm_scan_engine repository overview

InsightVM Scan Engines are used to scan for vulnerabilities and policy compliance.

⁠Quick reference

  • latest, (product-version), (product-version)-content(content-version)

⁠Quick Reference (cont.)

  • Where to file issues:

    Rapid7⁠

  • Supported architectures:

    amd64

  • Published image artifact details:

    N/A

  • Image updates:

    N/A

  • Source of this description:

    N/A

⁠What is InsightVM Scan Engine?

Scan engines are the workhorses of the scanning process and operate solely at the discretion of the Security Console. They are responsible for discovering assets during a scan, checking them for vulnerabilities, and assessing their level of policy compliance (if your selected scan template is configured to do so). Although scan engines serve as data collectors, they only temporarily store this data on their respective host machines. Instead, the Security Console integrates scan engine data into the PostgreSQL database for you to see and report on. This is why the Scan Engine’s host machine storage requirements are far lower than what the Security Console requires.

Scan Engine Documentation⁠

⁠How to use this image

Start a container connecting to a console

docker run \
 --env CONNECT_TO_SHARED_SECRET=<SHARED_SECRET> \
 --env CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS> \
 rapid7/insightvm_scan_engine:latest

Start a container with accepting connection from a console

docker run \
 --env ACCEPT_FROM_ADDRESS=<CONSOLE_ADDRESS> \
 --env ACCEPT_FROM_SHARED_SECRET=<SHARED_SECRET> \
 -p 40814:40814 \
 rapid7/insightvm_scan_engine:latest

Start a container with external mounts

docker run \
 --env CONNECT_TO_SHARED_SECRET=<SHARED_SECRET> \
 --env CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS> \
 -v /var/docker/nse-container/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf \
 -v /var/docker/nse-container/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores \
 -v /var/docker/nse-container/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs \
 -v /var/docker/nse-container/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans \  
 rapid7/insightvm_scan_engine:latest

⁠... via docker-compose⁠ or docker stack deploy⁠

Run a single container with Docker Compose with connecting to a console

version: "3"
services:
  nse-1:
    image: rapid7/insightvm_scan_engine
    volumes:
      - /var/docker/nse-1/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
      - /var/docker/nse-1/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
      - /var/docker/nse-1/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
      - /var/docker/nse-1/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
    environment:
      - CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
      - CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>

Run a single container with accepting connections from a console

version: "3"
services:
  nse-1:
    image: rapid7/insightvm_scan_engine
    ports:
      - "40814:40814"
    volumes:
      - /var/docker/nse-1/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
      - /var/docker/nse-1/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
      - /var/docker/nse-1/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
      - /var/docker/nse-1/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
    environment:
      - ACCEPT_FROM_ADDRESS=<CONSOLE_ADDRESS>
      - ACCEPT_FROM_SHARED_SECRET=<SHARED_SECRET>

Run multiple engines connecting to a console

version: "3"
services:
  nse-1:
    image: rapid7/insightvm_scan_engine
    volumes:
      - /var/docker/nse-1/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
      - /var/docker/nse-1/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
      - /var/docker/nse-1/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
      - /var/docker/nse-1/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
    environment:
      - CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
      - CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>
  nse-2:
    image: rapid7/insightvm_scan_engine
    volumes:
      - /var/docker/nse-2/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
      - /var/docker/nse-2/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
      - /var/docker/nse-2/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
      - /var/docker/nse-2/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
    environment:
      - CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
      - CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>
  nse-3:
    image: rapid7/insightvm_scan_engine
    volumes:
      - /var/docker/nse-3/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
      - /var/docker/nse-3/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
      - /var/docker/nse-3/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
      - /var/docker/nse-3/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
    environment:
      - CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
      - CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>

⁠Environment Variables

The following four environment variables exist:

CONNECT_TO_ADDRESS
CONNECT_TO_SHARED_SECRET

These are used for the reverse engine pairing.

ACCEPT_FROM_ADDRESS
ACCEPT_FROM_SHARED_SECRET

These are used for standard pairing engines.

The CONNECT_TO_ADDRESS is the IP address the Security Console will wait for connections from the Scan Engine. If no shared secret CONNECT_TO_SHARED_SECRET is provided, the Scan Engine must be added on the Scan Engine management page under the Administration tab in the Security Console’s UI. If a shared secret is provided, the Scan Engine will add itself to the Security Console. The shared secret must be the same shared secret generated on the Scan Engine management page.

The accept from address ACCEPT_FROM_ADDRESS is the IP address the Security Console will use when it connects to the Scan Engine. If no shared secret ACCEPT_FROM_SHARED_SECRET is provided, the Scan Engine will not challenge the Security Console and will trust the first console that connects to it from the accept from address. If a shared secret is provided, the Scan Engine will challenge the Security Console and will not trust the Security Console if the response from the Security Console is not correct. The shared secret must be the same shared secret generated on the Scan Engine management page.

⁠Mount Points

  • /opt/rapid7/nexopse/nse/conf

The configuration directory stores the Containerized Scan Engine, logger configuration properties, and a list of trusted consoles. The configuration directory can be optional if auto-pairing environment variables are used, since the Containerized Scan Engine will auto-pair each time it starts. However, we do recommend that an external configuration directory be used.

  • /opt/rapid7/nexpose/nse/keystores

The keystores directory stores the private identity of the Containerized Scan Engine, and is used to establish trust with the Security Console. This directory is optional if you do not intend to keep the Containerized Scan Engine up to date or paired to the Security Console. Otherwise, the keystores directory must be mounted or the Containerized Scan Engine will generate a new private identity each time it is started.

  • /opt/rapid7/nexpose/nse/logs

The logs directory stores logs on an eternal volume. This directory is optional. The file system performance of this directory can have an impact on the performance of individual scans.

  • /opt/rapid7/nexpose/nse/scans

The scans directory is where the Containerized Scan Engine temporarily writes logs and results to. The Security Console will ask the Containerized Scan Engine to remove scan data associated with completed scans when the data associated with it is transferred to the Security Console. Though, if the Containerized Scan Engine is upgraded before all the scan data is transferred to the Security Console, and the scans directory is not a persisted volume, the scan data will be lost. This directory is recommended. The file system performance of this directory can have an impact on scan performance.

Tag summary

Content type

Image

Digest

sha256:243478b73…

Size

2.2 GB

Last updated

about 6 hours ago

docker pull rapid7/insightvm_scan_engine