diff --git a/.github/workflows/dockerhub-descriptions.yml b/.github/workflows/dockerhub-descriptions.yml new file mode 100644 index 0000000000..ab3ed83c73 --- /dev/null +++ b/.github/workflows/dockerhub-descriptions.yml @@ -0,0 +1,92 @@ +name: 'Tools: Sync Docker Hub Descriptions' + +on: + push: + branches: + - 'master' + paths: + - 'docs/dockerhub/README.md' + - '.github/workflows/dockerhub-descriptions.yml' + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +env: + OVERVIEW_FILE: docs/dockerhub/README.md + +permissions: {} + +jobs: + prowlercloud: + if: github.repository == 'prowler-cloud/prowler' && github.ref == 'refs/heads/master' + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: read + strategy: + fail-fast: false + matrix: + include: + - repository: prowlercloud/prowler + short_description: 'Prowler CLI: the Open Cloud Security tool for AWS, Azure, Google Cloud, Kubernetes, M365 and GitHub' + - repository: prowlercloud/prowler-api + short_description: 'Prowler Local Server - API: the JSON API and Task Runner components of Prowler' + - repository: prowlercloud/prowler-ui + short_description: 'Prowler Local Server - UI: the web interface to run Prowler scans and explore findings' + - repository: prowlercloud/prowler-mcp + short_description: 'Prowler MCP: the interface for agents, including IDE plugins and agent integrations' + + steps: + - name: Harden Runner + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 + with: + egress-policy: block + allowed-endpoints: > + github.com:443 + hub.docker.com:443 + + - name: Checkout repository + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Update Docker Hub description for ${{ matrix.repository }} + uses: peter-evans/dockerhub-description@1b9a80c056b620d92cedb9d9b5a223409c68ddfa # v5.0.0 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + repository: ${{ matrix.repository }} + short-description: ${{ matrix.short_description }} + readme-filepath: ${{ env.OVERVIEW_FILE }} + + toniblyx: + if: github.repository == 'prowler-cloud/prowler' && github.ref == 'refs/heads/master' + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: read + + steps: + - name: Harden Runner + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 + with: + egress-policy: block + allowed-endpoints: > + github.com:443 + hub.docker.com:443 + + - name: Checkout repository + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Update Docker Hub description for toniblyx/prowler + uses: peter-evans/dockerhub-description@1b9a80c056b620d92cedb9d9b5a223409c68ddfa # v5.0.0 + with: + username: ${{ secrets.TONIBLYX_DOCKERHUB_USERNAME }} + password: ${{ secrets.TONIBLYX_DOCKERHUB_PASSWORD }} + repository: toniblyx/prowler + short-description: 'Prowler CLI (legacy repository, mirrors prowlercloud/prowler)' + readme-filepath: ${{ env.OVERVIEW_FILE }} diff --git a/docs/dockerhub/README.md b/docs/dockerhub/README.md new file mode 100644 index 0000000000..773a21b896 --- /dev/null +++ b/docs/dockerhub/README.md @@ -0,0 +1,120 @@ +

+ Prowler is the Open Cloud Security platform trusted by thousands to automate security and compliance in any cloud environment — AWS, Azure, Google Cloud, Kubernetes, M365, GitHub and more. +

+

+ Learn more at prowler.com · Join our Slack community +

+ +

+ GitHub + Version + PyPI + License +

+ +--- + +# Prowler container images + +All Prowler images are built from a single repository — [github.com/prowler-cloud/prowler](https://github.com/prowler-cloud/prowler) — and published together on every release. + +| Image | What it is | Dockerfile | +|---|---|---| +| [`prowlercloud/prowler`](https://hub.docker.com/r/prowlercloud/prowler) | **Prowler CLI.** Runs scans from your terminal, a CI job, a Kubernetes Job or any container platform. | [`Dockerfile`](https://github.com/prowler-cloud/prowler/blob/master/Dockerfile) | +| [`prowlercloud/prowler-api`](https://hub.docker.com/r/prowlercloud/prowler-api) | **Prowler Local Server — API.** Django REST backend plus the Celery worker and scheduler that run scans and store results. | [`api/Dockerfile`](https://github.com/prowler-cloud/prowler/blob/master/api/Dockerfile) | +| [`prowlercloud/prowler-ui`](https://hub.docker.com/r/prowlercloud/prowler-ui) | **Prowler Local Server — UI.** Next.js web interface for launching scans and exploring findings. | [`ui/Dockerfile`](https://github.com/prowler-cloud/prowler/blob/master/ui/Dockerfile) | +| [`prowlercloud/prowler-mcp`](https://hub.docker.com/r/prowlercloud/prowler-mcp) | **Prowler MCP.** Gives AI assistants access to the Prowler ecosystem over the Model Context Protocol. | [`mcp_server/Dockerfile`](https://github.com/prowler-cloud/prowler/blob/master/mcp_server/Dockerfile) | +| [`toniblyx/prowler`](https://hub.docker.com/r/toniblyx/prowler) | **Legacy home of the Prowler CLI image.** Still mirrored on every release for backwards compatibility. New deployments should use `prowlercloud/prowler`. | [`Dockerfile`](https://github.com/prowler-cloud/prowler/blob/master/Dockerfile) | + +All images are published for `linux/amd64` and `linux/arm64`. + +## Tags + +| Tag | Meaning | +|---|---| +| `stable` | Always points to the latest stable release. **Recommended for production.** | +| `` | A specific release, e.g. `5.14.0`. Immutable. | +| `latest` | Built from the `master` branch on every merge. Not a stable version. | +| `` | A specific `master` commit (`prowler-api`, `prowler-ui` and `prowler-mcp` only). | + +`v3-*` and `v4-*` tags on `prowlercloud/prowler` are frozen historical artifacts of Prowler v3/v4 and no longer receive updates. + +## Other registries + +The Prowler CLI image is also available on AWS Public ECR: [`public.ecr.aws/prowler-cloud/prowler`](https://gallery.ecr.aws/prowler-cloud/prowler). + +--- + +# Quick start + +## Prowler Local Server (UI + API) + +```console +curl -LO https://raw.githubusercontent.com/prowler-cloud/prowler/refs/heads/master/docker-compose.yml +curl -LO https://raw.githubusercontent.com/prowler-cloud/prowler/refs/heads/master/.env +docker compose up -d +``` + +Then open http://localhost:3000 and sign up with your email and password. + +Full guide: [Prowler Local Server installation](https://docs.prowler.com/getting-started/installation/prowler-app) + +## Prowler CLI + +```console +docker run -ti --rm \ + -v /your/local/dir/prowler-output:/home/prowler/output \ + --name prowler \ + --env AWS_ACCESS_KEY_ID \ + --env AWS_SECRET_ACCESS_KEY \ + --env AWS_SESSION_TOKEN \ + prowlercloud/prowler:stable aws +``` + +Swap `aws` for `azure`, `gcp`, `kubernetes`, `m365` or `github` to scan another provider. The CLI is also on PyPI: `pip install prowler`. + +Full guide: [Prowler CLI installation](https://docs.prowler.com/getting-started/installation/prowler-cli) + +## Prowler MCP + +```console +# STDIO mode (for local MCP clients) +docker run --rm -i prowlercloud/prowler-mcp + +# HTTP mode (for remote access) +docker run --rm -p 8000:8000 prowlercloud/prowler-mcp \ + --transport http --host 0.0.0.0 --port 8000 +``` + +Full guide: [Prowler MCP installation](https://docs.prowler.com/getting-started/installation/prowler-mcp) + +> **Note on architecture:** if your workstation's architecture is incompatible, set `DOCKER_DEFAULT_PLATFORM=linux/amd64` or pass `--platform linux/amd64` to your Docker command. + +--- + +# What Prowler covers + +Hundreds of built-in checks mapped to the frameworks you get audited against — CIS, NIST 800 / CSF, CISA, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, FedRAMP, RBI, AWS Well-Architected (Security Pillar), AWS FTR, ENS — plus your own custom frameworks. + +For live check, service, framework and category counts, see [**Prowler Hub**](https://hub.prowler.com). + +List what's available for any provider: + +```console +prowler --list-checks +prowler --list-services +prowler --list-compliance +prowler --list-categories +``` + +# Documentation and support + +- **Documentation:** [docs.prowler.com](https://docs.prowler.com/) +- **Source:** [github.com/prowler-cloud/prowler](https://github.com/prowler-cloud/prowler) +- **Issues:** [github.com/prowler-cloud/prowler/issues](https://github.com/prowler-cloud/prowler/issues) +- **Community:** [Prowler Slack](https://goto.prowler.com/slack) +- **Troubleshooting:** [docs.prowler.com/troubleshooting](https://docs.prowler.com/troubleshooting) + +# License + +Prowler is licensed under the Apache License 2.0. A copy is available at http://www.apache.org/licenses/LICENSE-2.0.