Push a Container Image to CS
The following feature is not supported in Tenable.io Federal Risk and Authorization Management Program (FedRAMP) environments. For more information, see the FedRAMP Product Offering.
Required Additional License: Tenable.io Container Security
Required Tenable.io Vulnerability Management User Role: Scan Operator, Standard, Scan Manager, or Administrator
Use Docker commands to download the image from the external registry where it resides and import it to Tenable.io Container Security.
The amount of time Tenable.io Container Security takes to scan the images in your registry and display the results depends on the size and number of images you scan.
Before you begin:
To push container image to Tenable.io Container Security:
In the CLI, run the following command to download the image from an external registry:Copy
docker pull alpine:latest
- In the CLI, run the following command to add the
docker tag alpine:latest registry.cloud.tenable.com/alpine:latest
registry.cloud.tenable.comtag prompts Docker to push the image to Tenable.io Container Security. If you do not add the
registry.cloud.tenable.comtag, Docker automatically pushes the image to the Docker central repository.
In the CLI, run the following command to push the tagged image to Tenable.io Container Security.Copy
docker push registry.cloud.tenable.com/alpine:latest
Docker pushes the image to Tenable.io Container Security. Tenable.io Container Security scans the images for vulnerabilities.
Note: When you import container images to scan, Tenable.io Container Security may abort the scan if the scan has been running for 60 minutes. If this happen, Scan Failed appears on the Images page in the Vulnerabilities and Malware columns for the aborted images.
If Tenable.io Container Security aborts your scan, try simplifying your images before you import them, as described in the Docker Documentation. Alternatively, you can use the Tenable.io CS Scanner to scan your images without importing them to Tenable.io Container Security.
If Tenable.io Container Security still aborts your scan, contact Tenable Support.
What to do next:
- View the results of your scan, as described in View Scan Results for Container Images.