Configure your private JFrog Artifactory Cloud Container Image Registry in the Mend Platform
Overview
The Mend container image registry scanning solution can integrate with your private JFrog Artifactory Cloud using your provided JFrog Artifactory user.
Getting it done
Prerequisites before you scan Artifactory Cloud with Mend Container
Your Mend user must be an organization administrator.
Your JFrog Artifactory user provided for the integration must have/be in a user group that has read permissions to the relevant repositories in your JFrog Artifactory instance. For more information on JFrog’s permissions, please read their documentation here: Introduction to Permissions.
Set up your private JFrog Artifactory Cloud configuration in the Mend Platform UI
In the Mend Platform UI, navigate to → Integrations.
Scroll down to the ‘Registries’ section and click ‘JFrog Artifactory Cloud'
The Setup Wizard
Step 1 - Fill in the General Details fields:
a. Display Name
b. Description (optional)
c. Artifactory URL
d. Environment (multi-selection is supported)
Click the button at the bottom right to move on to Step 2 - Authentication.
Step 2 - Fill in the Authentication information
Option 1 - User Name & Password
Option 2 - User Name & Access Token
Click the button at the bottom right to move on to Step 3 - Configuration.
Step 3 - Fill in the Configuration information to define your scan schedule
a. Scan Time
b. Frequency
Scheduling image registry scans is crucial for maintaining the security and integrity of your container images. By default, a scan interval of 7 days will be applied. You can change the scan interval in 1-day increments or select specific days of the week when you wish for scans to be executed.
Click the button at the bottom right to move on to Step 4 - Summary, to view the summary of your setup as a final step before adding your registry.
Step 4 - Summary
In this step, the summary of your input from steps 1-3 will be displayed. You can go back to the previous screens of the wizard to make changes, by clicking the ‘Back’ button at the bottom right corner of the screen. If you wish to confirm your configuration and add your registry, click the ‘Done’ button:
A Registry Added Successfully message will pop-up once the integration credentials and configuration have been verified:
Note:
Before adding your registry, a connectivity check will be performed automatically, to ensure the credentials are valid and the registry is accessible for the integration.
In order to avoid scanning outdated images, our image registry integration is designed to focus on the most current data by scanning only the latest 10 versions from each repository.
Reference
Private JFrog Artifactory Cloud parameters
Parameter | Description |
---|---|
Display Name | Type the name of your registry. This will be displayed in the Integrations dashboard. |
Description | Optional. Provide any text. We recommend providing information that will help you remember the integration and the relevant registry. |
Artifactory URL | Provide your JFrog Artifactory Registry URL. The format of the URL typically looks like:
|
Environment | Select the type of environment of your private JFrog Artifactory Registry (multiple options can be selected). The environment options are:
|
User Name | Provide your JFrog Artifactory username. |
Password | Provide your JFrog Artifactory password. |