Base image for the Rapid7 InsightVM Scan Engine.
1M+
InsightVM Scan Engines are used to scan for vulnerabilities and policy compliance.
Maintained by:
Where to get help:
Dockerfile linkslatest, (product-version), (product-version)-content(content-version)Where to file issues:
Supported architectures:
amd64
Published image artifact details:
N/A
Image updates:
N/A
Source of this description:
N/A
Scan engines are the workhorses of the scanning process and operate solely at the discretion of the Security Console. They are responsible for discovering assets during a scan, checking them for vulnerabilities, and assessing their level of policy compliance (if your selected scan template is configured to do so). Although scan engines serve as data collectors, they only temporarily store this data on their respective host machines. Instead, the Security Console integrates scan engine data into the PostgreSQL database for you to see and report on. This is why the Scan Engine’s host machine storage requirements are far lower than what the Security Console requires.
Start a container connecting to a console
docker run \
--env CONNECT_TO_SHARED_SECRET=<SHARED_SECRET> \
--env CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS> \
rapid7/insightvm_scan_engine:latest
Start a container with accepting connection from a console
docker run \
--env ACCEPT_FROM_ADDRESS=<CONSOLE_ADDRESS> \
--env ACCEPT_FROM_SHARED_SECRET=<SHARED_SECRET> \
-p 40814:40814 \
rapid7/insightvm_scan_engine:latest
Start a container with external mounts
docker run \
--env CONNECT_TO_SHARED_SECRET=<SHARED_SECRET> \
--env CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS> \
-v /var/docker/nse-container/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf \
-v /var/docker/nse-container/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores \
-v /var/docker/nse-container/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs \
-v /var/docker/nse-container/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans \
rapid7/insightvm_scan_engine:latest
docker-compose or docker stack deployRun a single container with Docker Compose with connecting to a console
version: "3"
services:
nse-1:
image: rapid7/insightvm_scan_engine
volumes:
- /var/docker/nse-1/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
- /var/docker/nse-1/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
- /var/docker/nse-1/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
- /var/docker/nse-1/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
environment:
- CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
- CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>
Run a single container with accepting connections from a console
version: "3"
services:
nse-1:
image: rapid7/insightvm_scan_engine
ports:
- "40814:40814"
volumes:
- /var/docker/nse-1/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
- /var/docker/nse-1/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
- /var/docker/nse-1/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
- /var/docker/nse-1/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
environment:
- ACCEPT_FROM_ADDRESS=<CONSOLE_ADDRESS>
- ACCEPT_FROM_SHARED_SECRET=<SHARED_SECRET>
Run multiple engines connecting to a console
version: "3"
services:
nse-1:
image: rapid7/insightvm_scan_engine
volumes:
- /var/docker/nse-1/data/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
- /var/docker/nse-1/data/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
- /var/docker/nse-1/data/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
- /var/docker/nse-1/data/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
environment:
- CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
- CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>
nse-2:
image: rapid7/insightvm_scan_engine
volumes:
- /var/docker/nse-2/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
- /var/docker/nse-2/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
- /var/docker/nse-2/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
- /var/docker/nse-2/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
environment:
- CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
- CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>
nse-3:
image: rapid7/insightvm_scan_engine
volumes:
- /var/docker/nse-3/rapid7/nexpose/nse/conf:/opt/rapid7/nexpose/nse/conf
- /var/docker/nse-3/rapid7/nexpose/nse/keystores:/opt/rapid7/nexpose/nse/keystores
- /var/docker/nse-3/rapid7/nexpose/nse/logs:/opt/rapid7/nexpose/nse/logs
- /var/docker/nse-3/rapid7/nexpose/nse/scans:/opt/rapid7/nexpose/nse/scans
environment:
- CONNECT_TO_ADDRESS=<CONSOLE_ADDRESS>
- CONNECT_TO_SHARED_SECRET=<SHARED_SECRET>
The following four environment variables exist:
CONNECT_TO_ADDRESS
CONNECT_TO_SHARED_SECRET
These are used for the reverse engine pairing.
ACCEPT_FROM_ADDRESS
ACCEPT_FROM_SHARED_SECRET
These are used for standard pairing engines.
The CONNECT_TO_ADDRESS is the IP address the Security Console will wait for connections from the Scan Engine. If no shared secret CONNECT_TO_SHARED_SECRET is provided, the Scan Engine must be added on the Scan Engine management page under the Administration tab in the Security Console’s UI. If a shared secret is provided, the Scan Engine will add itself to the Security Console. The shared secret must be the same shared secret generated on the Scan Engine management page.
The accept from address ACCEPT_FROM_ADDRESS is the IP address the Security Console will use when it connects to the Scan Engine. If no shared secret ACCEPT_FROM_SHARED_SECRET is provided, the Scan Engine will not challenge the Security Console and will trust the first console that connects to it from the accept from address. If a shared secret is provided, the Scan Engine will challenge the Security Console and will not trust the Security Console if the response from the Security Console is not correct. The shared secret must be the same shared secret generated on the Scan Engine management page.
/opt/rapid7/nexopse/nse/confThe configuration directory stores the Containerized Scan Engine, logger configuration properties, and a list of trusted consoles. The configuration directory can be optional if auto-pairing environment variables are used, since the Containerized Scan Engine will auto-pair each time it starts. However, we do recommend that an external configuration directory be used.
/opt/rapid7/nexpose/nse/keystoresThe keystores directory stores the private identity of the Containerized Scan Engine, and is used to establish trust with the Security Console. This directory is optional if you do not intend to keep the Containerized Scan Engine up to date or paired to the Security Console. Otherwise, the keystores directory must be mounted or the Containerized Scan Engine will generate a new private identity each time it is started.
/opt/rapid7/nexpose/nse/logsThe logs directory stores logs on an eternal volume. This directory is optional. The file system performance of this directory can have an impact on the performance of individual scans.
/opt/rapid7/nexpose/nse/scansThe scans directory is where the Containerized Scan Engine temporarily writes logs and results to. The Security Console will ask the Containerized Scan Engine to remove scan data associated with completed scans when the data associated with it is transferred to the Security Console. Though, if the Containerized Scan Engine is upgraded before all the scan data is transferred to the Security Console, and the scans directory is not a persisted volume, the scan data will be lost. This directory is recommended. The file system performance of this directory can have an impact on scan performance.
Content type
Image
Digest
sha256:243478b73…
Size
2.2 GB
Last updated
about 6 hours ago
docker pull rapid7/insightvm_scan_engine