Sysdig step configuration
Scan container images with Sysdig.
You can scan container images using Sysdig Vulnerability engine. Add a Sysdig step to a Build or Security stage and then configure it as described below.
Important notes for running Sysdig scans in STO
You need to run the scan step with root access if either of the following apply:
You need to run a Docker-in-Docker background service.
You need to add trusted certificates to your scan images at runtime.
You can set up your STO scan images and pipelines to run scans as non-root and establish trust for your own proxies using custom certificates. For more information, go to Configure your pipeline to use STO images from private registry.
Sysdig step settings for STO scans
The recommended workflow is to add a Sysdig step to a Security or Build stage and then configure it as described below.
Scan
Scan Mode
Scan Configuration
Target
Type
Target and Variant Detection
Name
Variant
Container image
Type
Domain
Name
Tag/Digest
Access ID
Access Token
Region
Ingestion File
Log Level
Fail on Severity
Additional Configuration
Advanced settings
Proxy settings
Sysdig pipeline examples
Sysdig orchestration pipeline
If you copy this example, replace the placeholder values with appropriate values for your project, organization, connectors, and access token.
Sysdig ingestion pipeline
If you copy this example, replace the placeholder values with appropriate values for your project, organization, connectors, and access token.
Last updated
Was this helpful?