For the complete documentation index, see llms.txt. This page is also available as Markdown.

IaC scans with Wiz

Scan Infrastructure as Code repositories with Wiz. Orchestration and Ingestion modes supported.

You can easily set up a Wiz step to run automated scans in your Harness pipeline. This step scans the IaC repository you specify using the Wiz CLI. Then it correlates, deduplicates, and ingests the scan results into Harness. You can see your scan results in the Vulnerabilities tab of the pipeline execution.

Wiz CLI Upgrade Notice

The Wiz CLI will be upgraded from version 0.x to 1.x. Harness STO supports this upgrade transparently, and no pipeline changes are required. CLI version 0.x will continue to work with existing credentials, while CLI version 1.x requires new credentials. Credentials used with CLI 0.x are not supported in CLI v1.x.

Important notes for running Wiz scans in STO

  • You can set up your STO scan images and pipelines to run scans as non-root and establish trust for your own proxies using custom certificates. For more information, go to Configure your pipeline to use STO images from private registry.

  • If you use Wiz for Gov or GovCloud on Linux/macOS, configure WIZ_ENV environment variable in your wiz stage settings.

    • For app.wiz.us (Wiz for Gov, FedRAMP), set WIZ_ENV=fedramp.

    • For gov.wiz.io (GovCloud), set WIZ_ENV=gov.

Set-up workflows

Orchestration scans for IaC repositories

Prerequisites

Add the Wiz scanner

Do the following:

  1. Add a Security, Build, or Infrastructure stage to your pipeline.

  2. Add a Wiz step to the stage.

Set up the Wiz scanner

Required settings

1. [Scan mode](#scan-mode) = **Orchestration**
2. [Scan configuration](#scan-configuration) = **Wiz IaC**

3. Target type = Repository 4. Target and Variant Detection = Auto 5. Authentication: 1. Wiz access ID as a Harness secret. This is your client-id to authenticate with the Wiz CLI. 2. Wiz access token as a Harness secret. This is your client-secret to authenticate with the Wiz CLI.

Optional settings

  • Fail on Severity — Stop the pipeline if the scan detects any issues at a specified severity or higher

  • Log Level — Useful for debugging

Ingestion scans for IaC repositories

Harness STO can ingest both JSON and SARIF data from Wiz, but Harness recommends publishing to JSON because this format includes more detailed information.

Add a shared path for your scan results

  1. Add a Security, Build, or Infrastructure stage to your pipeline. 2. In the stage Overview, add a shared path such as /shared/scan_results.

Copy scan results to the shared path

There are two primary workflows to do this:

  • Add a Run step that runs a Wiz scan from the command line and then copies the results to the shared path.

  • Copy results from a Wiz scan that ran outside the pipeline.

    For more information and examples, go to Ingestion scans.

Set up the Wiz scanner

Add a Wiz step to the stage and set it up as follows.

Required settings

1. [Scan mode](#scan-mode) = **Ingestion**

2. Scan configuration = Wiz IaC 3. Target type = Repository 4. Target name — Usually the repo name 5. Target variant — Usually the scanned branch. You can also use a runtime input and specify the branch at runtime. 6. Ingestion file — For example, /shared/scan_results/wiz-iac-scan.json

Optional settings

  • Fail on Severity — Stop the pipeline if the scan detects any issues at a specified severity or higher.

  • Log Level — Useful for debugging

Wiz step settings reference

Scan

Scan Mode

Scan Configuration

Select Wiz IaC.

Target

Type

Target and Variant Detection

Name

The identifier for the target such codebaseAlpha. Descriptive target names make it much easier to navigate your scan data in the STO UI.

It is good practice to specify a baseline for every target.

Variant

Workspace

Ingestion File

The path to your scan results when running an Ingestion scan, for example /shared/scan_results/wiz.latest.json.

  • The data file must be in a supported format for the scanner.

  • The data file must be accessible to the scan step. It's good practice to save your results files to a shared path in your stage. In the visual editor, go to the stage where you're running the scan. Then go to Overview > Shared Paths. You can also add the path to the YAML stage definition like this:

Authentication

Access ID

This is your client-id to authenticate with the Wiz CLI.

Access Token

This is your client-secret to authenticate with the Wiz CLI.

You should create a Harness text secret with your encrypted token and reference the secret using the format <+secrets.getValue("my-access-token")>. For more information, go to Add and Reference Text Secrets.

Log Level

Additional CLI flags

Fail on Severity

Settings

You can add more settings to the scan step as needed.

Additional Configuration

Advanced settings

View Wiz policy failures

Proxy settings

Last updated

Was this helpful?