Scanning IBM Cloud with Aikido

Aikido fully supports protecting workloads on IBM Cloud through specific integrations. A native integration may be added in the future, but you can already achieve full coverage by combining:

Features

Container image scanning

IBM Cloud’s container registry and most third-party registries you use from IBM Cloud are OCI-compatible, so they can be scanned using Aikido.

Create a read-only or pull-only user in IBM Cloud registry: https://cloud.ibm.com/docs/Registry?topic=Registry-registry_access&interface=ui

Follow the OCI guide below to configure container image scanning

Generic OCI-Compatible Registry

Kubernetes cluster scanning

If you use IBM Cloud Managed Kubernetes or run your own Kubernetes clusters on IBM Cloud VMs, you can connect them as generic Kubernetes clusters.

Kubernetes Cluster Scanning

Kubernetes cluster image scanning

If you use IBM Cloud Managed Kubernetes or run your own Kubernetes clusters on IBM Cloud VMs, you can scan the images of running containers with Kubernetes image scanning.

Kubernetes In-Cluster Image Scanning

Virtual Machine scanning

To scan Virtual Machines on IBM Cloud, use the Local VM Scanner. It inspects packages, system dependencies and configuration directly on the instance.

Local VM Scanning

You can roll this out centrally using your usual automation tooling (e.g. Ansible, Terraform-provisioned scripts, or cloud-init) so that new IBM Cloud instances are automatically enrolled.

Last updated

Was this helpful?