Redhat Advanced Cluster Security
Red Hat Advanced Cluster Security (RHACS) for Kubernetes is a comprehensive Kubernetes-native security platform that provides visibility, vulnerability management, configuration management, network segmentation, threat detection, and incident response capabilities across containerized environments and Kubernetes clusters. This enterprise-grade security solution helps organizations secure their container pipelines, Kubernetes infrastructure, and cloud-native applications throughout the entire application lifecycle from build to deploy to runtime.
| Category | Vulnerability management, Containers |
| Direction | Query source |
| Sign-in | API Token |
| Query languages | STIX |
| Website | https://www.redhat.com |
Before you start
Huntbase signs in to Redhat Advanced Cluster Security with API Token. Create the credential in Redhat Advanced Cluster Security first, then keep it to hand for the Connect step.
- In the RHACS portal, go to Platform Configuration › Integrations.
- Scroll to the Authentication Tokens category, click API Token, then click Generate Token.
- Enter a name for the token and select a role. For read-only querying, choose Analyst.
- Click Generate, then copy the token. You can't view it again.
Permissions:
Analystsystem role (read-only access for all resources)
- API tokens expire one year after creation. RHACS warns you in the portal a week before a token expires.
- You can't give a token more permissions than your own role has, so generate it as a user who holds at least the Analyst role.
For the vendor's own instructions, see RHACS API token documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Redhat Advanced Cluster Security
- Go to Connections and click New connection, or click New connection on the Redhat Advanced Cluster Security product page.
- On Product, pick Redhat Advanced Cluster Security and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Redhat Advanced Cluster Security lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname of your RHACS Central instance, without https:// or a path. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Only needed when Central uses a self-signed certificate. Paste the PEM certificate. Leave it empty for a certificate issued by a trusted CA. |
Credentials
The only Method is API Token. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| API Token | Yes | Token with readonly access required for data source authentication. Secret — not shown again after you save it. |
Query it
Once connected, Redhat Advanced Cluster Security can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog