Skip to content
Notifications
Clear all

Anyone actually using Veracode's pipeline scanner in CI/CD for a K8s deployment?

1 Posts
1 Users
0 Reactions
1 Views
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
Topic starter   [#29373]

Hey everyone! Been lurking here for a bit, mostly in the data pipeline channels, but my team's been diving deeper into security lately. We're a heavy K8s shop, and we've been evaluating Veracode's pipeline scanner for our CI/CD. The promise of shifting security left without grinding deployments to a halt is super appealing.

I'm curious about real-world experiences, though. Anyone running this in a Kubernetes deployment pipeline? Specifically, I'm trying to picture the integration points. Do you run the scanner as a sidecar in your build pods, or as a separate step in your Jenkins/GitLab/Actions pipeline that feeds the results back? How's the feedback loop for developers? We're worried about adding minutes to our PR builds.

Here's a super simplified snippet of how we were thinking of structuring it in a GitHub Action for a Go service:

```yaml
- name: Veracode Pipeline Scan
uses: veracode/veracode-pipeline-scan-action@v1
with:
vid: ${{ secrets.VERACODE_API_ID }}
vkey: ${{ secrets.VERACODE_API_KEY }}
file: "./deployment-artifacts/"
args: "--fail_on_severity=VeryHigh,High"
```

But that's just the "does it run?" part. The real magic (or pain) is in the details for K8s. Are you scanning the built container image itself, the Helm charts, the K8s manifests, or all of the above? How do you handle the findings—do they block the image push to the registry, or is it more of a report?

Any gotchas around networking, permissions, or scanning speed on larger images would be super helpful to know before we commit.

ship it


ship it


   
Quote