A Docker V2-compliant registry is a registry service that complies with the specifications and requirements outlined in the Docker Registry HTTP API V2. This API defines the protocol for interacting with a Docker registry, a repository where Docker images are stored and from which they can be pulled or pushed.
To scan public and private repositories on Docker Hub, use the Docker Hub registry connector.
Follow the wizard to use the Docker V2 connector in Cortex Cloud to scan and secure container images from any container registry that supports the Docker V2 protocol, ensuring comprehensive security.
Navigate to → .
On the Add Data Source or Integrations page, click + Add New, search for Docker V2, then hover over it and click Add.
The Instance Name is automatically populated. You can change it to a more meaningful name.
Choose the Scan Mode, and then follow the steps for that mode to configure the connection.
In the Initial Scan Configuration, set your scanning process to focus on recently added or modified container images and exclude older ones that do not align with your current scanning objectives. This setting helps avoid unnecessary scans. Choose one of the following options:
All: Scans all container images, including all versions (tags), in all discovered repositories.
Latest Tag: Scans only images tagged 'latest' in all discovered repositories.
Days Modified: Scans container images that have been created in the last few days. You can select a range of up to 90 days for the scan.
Select Save.
When the Docker V2 data source is saved successfully, a new data connector is created, and the initial discovery scan begins. The connection process can take up to 15 minutes.
To check the connector status and scan results, follow these steps:
Navigate to → .
Find the Docker V2 integration from the list of data sources, or filter for it.
Select the Docker V2 instance row. A pane opens with a list of integration instances and their details showing the following information:
Instance Details
Description
Status
Shows the status of the connector: Connected, Error, Warning, Disabled, or Pending.
Applet Status on Broker VM
Shows the status of the Registry Scanner applet on the Broker VM page. This status is visible only when the Scan with Broker VM mode is selected.
Repositories
Shows the number of scanned repositories in the registry.
Scan Mode
Shows the selected scan mode for the data connector, such as Cloud Scan, Scan with Outpost, or Scan with Broker VM.
Security Capabilities
Shows a breakdown of the security capabilities enabled on the instance and their individual statuses. For example, select Registry Scanning when it shows a warning or error status to see the open errors and issues that contributed to the status.
Next Steps
After the scan is complete, you can view the scanned images on the Container Images Inventory page. For more details, see Container Images assets.
If you have selected the Scan with Broker VM option, then a Registry Scanner applet is created on the selected Broker VM or Cluster. For details, see Verify Registry Scanner connection.