Scanning IBM Cloud with Aikido

Aikido fully supports protecting workloads on IBM Cloud through specific integrations. A native integration may be added in the future, but you can already achieve full coverage by combining:

Features

Container image scanning

IBM Cloud’s container registry and most third-party registries you use from IBM Cloud are OCI-compatible, so they can be scanned using Aikido.

Create a read-only or pull-only user in IBM Cloud registry: https://cloud.ibm.com/docs/Registry?topic=Registry-registry_access&interface=uiarrow-up-right

Follow the OCI guide below to configure container image scanning

Generic OCI-Compatible Registrychevron-right

Kubernetes cluster scanning

If you use IBM Cloud Managed Kubernetes or run your own Kubernetes clusters on IBM Cloud VMs, you can connect them as generic Kubernetes clusters.

Kubernetes Cluster Scanningchevron-right

Kubernetes cluster image scanning

If you use IBM Cloud Managed Kubernetes or run your own Kubernetes clusters on IBM Cloud VMs, you can scan the images of running containers with Kubernetes image scanning.

Kubernetes In-Cluster Image Scanningchevron-right

Virtual Machine scanning

To scan Virtual Machines on IBM Cloud, use the Local VM Scanner. It inspects packages, system dependencies and configuration directly on the instance.

Local VM Scanningchevron-right

You can roll this out centrally using your usual automation tooling (e.g. Ansible, Terraform-provisioned scripts, or cloud-init) so that new IBM Cloud instances are automatically enrolled.

Last updated

Was this helpful?