Skip to main content

Redhat Advanced Cluster Security

Red Hat Advanced Cluster Security (RHACS) for Kubernetes is a comprehensive Kubernetes-native security platform that provides visibility, vulnerability management, configuration management, network segmentation, threat detection, and incident response capabilities across containerized environments and Kubernetes clusters. This enterprise-grade security solution helps organizations secure their container pipelines, Kubernetes infrastructure, and cloud-native applications throughout the entire application lifecycle from build to deploy to runtime.

CategoryVulnerability management, Containers
DirectionQuery source
Sign-inAPI Token
Query languagesSTIX
Websitehttps://www.redhat.com

Before you start​

Huntbase signs in to Redhat Advanced Cluster Security with API Token. Create the credential in Redhat Advanced Cluster Security first, then keep it to hand for the Connect step.

  1. In the RHACS portal, go to Platform Configuration › Integrations.
  2. Scroll to the Authentication Tokens category, click API Token, then click Generate Token.
  3. Enter a name for the token and select a role. For read-only querying, choose Analyst.
  4. Click Generate, then copy the token. You can't view it again.

Permissions:

  • Analyst system role (read-only access for all resources)
Watch out for
  • API tokens expire one year after creation. RHACS warns you in the portal a week before a token expires.
  • You can't give a token more permissions than your own role has, so generate it as a user who holds at least the Analyst role.

For the vendor's own instructions, see RHACS API token documentation.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Redhat Advanced Cluster Security​

  1. Go to Connections and click New connection, or click New connection on the Redhat Advanced Cluster Security product page.
  2. On Product, pick Redhat Advanced Cluster Security and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Redhat Advanced Cluster Security lives:

FieldRequiredNotes
Server AddressYesThe hostname of your RHACS Central instance, without https:// or a path.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.
Self-Signed Cert (PEM)NoOnly needed when Central uses a self-signed certificate. Paste the PEM certificate. Leave it empty for a certificate issued by a trusted CA.

Credentials​

The only Method is API Token. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
API TokenYesToken with readonly access required for data source authentication. Secret — not shown again after you save it.

Query it​

Once connected, Redhat Advanced Cluster Security can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​