IaC scans with Wiz
Scan Infrastructure as Code repositories with Wiz. Orchestration and Ingestion modes supported.
You can easily set up a Wiz step to run automated scans in your Harness pipeline. This step scans the IaC repository you specify using the Wiz CLI. Then it correlates, deduplicates, and ingests the scan results into Harness. You can see your scan results in the Vulnerabilities tab of the pipeline execution.
Important notes for running Wiz scans in STO
You can set up your STO scan images and pipelines to run scans as non-root and establish trust for your own proxies using custom certificates. For more information, go to Configure your pipeline to use STO images from private registry.
If you use Wiz for Gov or GovCloud on Linux/macOS, configure
WIZ_ENVenvironment variable in your wiz stage settings.For
app.wiz.us(Wiz for Gov, FedRAMP), setWIZ_ENV=fedramp.For
gov.wiz.io(GovCloud), setWIZ_ENV=gov.
Set-up workflows
Wiz step settings reference
Scan
Scan Mode
Scan Configuration
Select Wiz IaC.
Target
Type
Target and Variant Detection
Name
The identifier for the target such codebaseAlpha. Descriptive target names make it much easier to navigate your scan data in the STO UI.
It is good practice to specify a baseline for every target.
Variant
Workspace
Ingestion File
The path to your scan results when running an Ingestion scan, for example /shared/scan_results/wiz.latest.json.
The data file must be in a supported format for the scanner.
The data file must be accessible to the scan step. It's good practice to save your results files to a shared path in your stage. In the visual editor, go to the stage where you're running the scan. Then go to Overview > Shared Paths. You can also add the path to the YAML stage definition like this:
Authentication
Access ID
This is your client-id to authenticate with the Wiz CLI.
Access Token
This is your client-secret to authenticate with the Wiz CLI.
You should create a Harness text secret with your encrypted token and reference the secret using the format <+secrets.getValue("my-access-token")>. For more information, go to Add and Reference Text Secrets.
Log Level
Additional CLI flags
Passing CLI flags is an advanced feature. Some flags might not work in the context of STO. You should test your flags and arguments thoroughly before you use them in your production environment.
Fail on Severity
Settings
You can add more settings to the scan step as needed.
Additional Configuration
Advanced settings
View Wiz policy failures
Proxy settings
Last updated
Was this helpful?