mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
docs: new product family (#11984)
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
title: 'Basic Usage'
|
||||
---
|
||||
|
||||
## Access Prowler App
|
||||
## Access Prowler Local Server
|
||||
|
||||
After [installation](/getting-started/installation/prowler-app), navigate to [http://localhost:3000](http://localhost:3000) and sign up with email and password.
|
||||
|
||||
@@ -28,7 +28,7 @@ This mechanism ensures that the first user in a newly created tenant has adminis
|
||||
</Note>
|
||||
## Log In
|
||||
|
||||
Access Prowler App by logging in with **email and password**.
|
||||
Access Prowler Local Server by logging in with **email and password**.
|
||||
|
||||
<img src="/images/log-in.png" alt="Log In" width="285" />
|
||||
|
||||
@@ -62,7 +62,7 @@ Review findings during scan execution in the following sections:
|
||||
- **Compliance** – Displays compliance insights based on security frameworks.
|
||||
<img src="/images/compliance.png" alt="Compliance" width="700" />
|
||||
|
||||
> For detailed usage instructions, refer to the [Prowler App Guide](/user-guide/tutorials/prowler-app).
|
||||
> For detailed usage instructions, refer to the [Prowler Cloud guide](/user-guide/tutorials/prowler-app), which also applies to Prowler Local Server.
|
||||
|
||||
<Note>
|
||||
Prowler will automatically scan all configured providers every **24 hours**, ensuring your cloud environment stays continuously monitored.
|
||||
|
||||
@@ -10,7 +10,7 @@ Complete reference guide for all tools available in the Prowler MCP Server. Tool
|
||||
|----------|------------|------------------------|
|
||||
| Prowler Hub | 10 tools | No |
|
||||
| Prowler Documentation | 2 tools | No |
|
||||
| Prowler Cloud/App | 32 tools | Yes |
|
||||
| Prowler Cloud & Prowler Local Server | 32 tools | Yes |
|
||||
|
||||
## Tool Naming Convention
|
||||
|
||||
@@ -20,9 +20,9 @@ All tools follow a consistent naming pattern with prefixes:
|
||||
- `prowler_docs_*` - Prowler documentation search and retrieval
|
||||
- `prowler_app_*` - Prowler Cloud and App (Self-Managed) management tools
|
||||
|
||||
## Prowler Cloud/App Tools
|
||||
## Prowler Cloud and Prowler Local Server Tools
|
||||
|
||||
Manage Prowler Cloud or Prowler App (Self-Managed) features. **Requires authentication.**
|
||||
Manage Prowler Cloud or Prowler Local Server features. **Requires authentication.**
|
||||
|
||||
<Note>
|
||||
These tools require a valid API key. See the [Configuration Guide](/getting-started/basic-usage/prowler-mcp) for authentication setup.
|
||||
@@ -145,7 +145,7 @@ Search and access official Prowler documentation. **No authentication required.*
|
||||
- Use natural language to interact with the tools through your AI assistant
|
||||
- Tools can be combined for complex workflows
|
||||
- Filter options are available on most list tools
|
||||
- Authentication is only required for Prowler Cloud/App tools
|
||||
- Authentication is only required for Prowler Cloud and Prowler Local Server tools
|
||||
|
||||
## Additional Resources
|
||||
|
||||
|
||||
@@ -7,10 +7,10 @@ Configure your MCP client to connect to Prowler MCP Server.
|
||||
## Step 1: Get Your API Key
|
||||
|
||||
<Note>
|
||||
**Authentication is optional**: Prowler Hub and Prowler Documentation features work without authentication. An API key is only required for Prowler Cloud and Prowler App (Self-Managed) features.
|
||||
**Authentication is optional**: Prowler Hub and Prowler Documentation features work without authentication. An API key is only required for Prowler Cloud and Prowler Local Server features.
|
||||
</Note>
|
||||
|
||||
To use Prowler Cloud or Prowler App (Self-Managed) features. To get the API key, please refer to the [API Keys](/user-guide/tutorials/prowler-app-api-keys) guide.
|
||||
To use Prowler Cloud or Prowler Local Server features. To get the API key, please refer to the [API Keys](/user-guide/tutorials/prowler-app-api-keys) guide.
|
||||
|
||||
<Warning>
|
||||
Keep the API key secure. Never share it publicly or commit it to version control.
|
||||
@@ -205,7 +205,7 @@ Restart your MCP client and start asking questions:
|
||||
|
||||
## Authentication Methods
|
||||
|
||||
Prowler MCP Server supports two authentication methods to connect to Prowler Cloud or Prowler App (Self-Managed):
|
||||
Prowler MCP Server supports two authentication methods to connect to Prowler Cloud or Prowler Local Server:
|
||||
|
||||
### API Key (Recommended)
|
||||
|
||||
|
||||
@@ -4,9 +4,9 @@ title: "Installation"
|
||||
|
||||
### Installation
|
||||
|
||||
Prowler App offers flexible installation methods tailored to various environments.
|
||||
Prowler Local Server offers flexible installation methods tailored to various environments.
|
||||
|
||||
Refer to the [Prowler App Tutorial](/user-guide/tutorials/prowler-app) for detailed usage instructions.
|
||||
Refer to the [Prowler Cloud guide](/user-guide/tutorials/prowler-app) for detailed usage instructions.
|
||||
|
||||
<Warning>
|
||||
Prowler configuration is based on `.env` files. Every version of Prowler can have differences on that file, so, please, use the file that corresponds with that version or repository branch or tag.
|
||||
@@ -109,17 +109,17 @@ Refer to the [Prowler App Tutorial](/user-guide/tutorials/prowler-app) for detai
|
||||
pnpm start
|
||||
```
|
||||
|
||||
> Enjoy Prowler App at http://localhost:3000 by signing up with your email and password.
|
||||
> Enjoy Prowler Local Server at http://localhost:3000 by signing up with your email and password.
|
||||
|
||||
<Warning>
|
||||
Google and GitHub authentication is only available in [Prowler Cloud](https://prowler.com).
|
||||
Google and GitHub authentication works out of the box in [Prowler Cloud](https://prowler.com). In Prowler Local Server it requires OAuth credentials: see [Social Login Configuration](/user-guide/tutorials/prowler-app-social-login).
|
||||
</Warning>
|
||||
</Tab>
|
||||
</Tabs>
|
||||
|
||||
### Updating Prowler App
|
||||
### Updating Prowler Local Server
|
||||
|
||||
Upgrade Prowler App installation using one of two options:
|
||||
Upgrade Prowler Local Server installation using one of two options:
|
||||
|
||||
#### Option 1: Updating the Environment File
|
||||
|
||||
@@ -133,7 +133,7 @@ PROWLER_API_VERSION="5.33.0"
|
||||
```
|
||||
|
||||
<Note>
|
||||
You can find the latest versions of Prowler App in the [Releases Github section](https://github.com/prowler-cloud/prowler/releases) or in the [Container Versions](#container-versions) section of this documentation.
|
||||
You can find the latest versions of Prowler Local Server in the [Releases Github section](https://github.com/prowler-cloud/prowler/releases) or in the [Container Versions](#container-versions) section of this documentation.
|
||||
</Note>
|
||||
|
||||
|
||||
@@ -172,7 +172,7 @@ docker compose up -d
|
||||
|
||||
### Container Versions
|
||||
|
||||
The available versions of Prowler App are the following:
|
||||
The available versions of Prowler Local Server are the following:
|
||||
|
||||
- `latest`: in sync with `master` branch (please note that it is not a stable version)
|
||||
- `v4-latest`: in sync with `v4` branch (please note that it is not a stable version)
|
||||
@@ -184,6 +184,6 @@ The available versions of Prowler App are the following:
|
||||
|
||||
The container images are available here:
|
||||
|
||||
- Prowler App:
|
||||
- Prowler Local Server:
|
||||
- [DockerHub - Prowler UI](https://hub.docker.com/r/prowlercloud/prowler-ui/tags)
|
||||
- [DockerHub - Prowler API](https://hub.docker.com/r/prowlercloud/prowler-api/tags)
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
---
|
||||
title: 'Prowler Product Families'
|
||||
description: 'Official names for Prowler Open Source projects and Prowler Products, including former product names.'
|
||||
boost: 2
|
||||
---
|
||||
|
||||
Prowler ships two product families: Prowler Products, operated or licensed by the Prowler team, and Open Source projects, free to run and extend. This page is the reference for every official name. If a page or blog post uses a former name, the [Former Names](#former-names) table maps it to the current one.
|
||||
|
||||
## Prowler Products
|
||||
|
||||
| Name | Description |
|
||||
|------|-------------|
|
||||
| [Prowler Cloud](/getting-started/products/prowler-cloud) | Managed cloud security platform operated by the Prowler team. See [pricing](https://prowler.com/pricing). |
|
||||
| Prowler Private Cloud | Prowler Cloud deployed in your own environment. Formerly Prowler Enterprise. See [pricing](https://prowler.com/pricing). |
|
||||
| [Prowler Hub](https://hub.prowler.com) | Free public library of versioned checks, cloud service artifacts, and compliance frameworks. |
|
||||
| [Prowler Lighthouse AI](/getting-started/products/prowler-cloud-lighthouse) | AI security analyst capabilities within Prowler Cloud and Prowler Private Cloud. |
|
||||
| [Prowler MCP](/getting-started/products/prowler-mcp) | MCP server that connects AI assistants and agents to Prowler, including IDE plugins such as [Prowler for Claude Code](/getting-started/products/prowler-claude-code-plugin). |
|
||||
|
||||
{/* Unreleased products. Uncomment these rows in the Prowler Products table when announced:
|
||||
| Prowler Registry | Distribution service for Prowler content such as checks and compliance frameworks. Free and paid tiers. |
|
||||
| Prowler Local Registry | Prowler Registry running in your own environment. Paid. |
|
||||
*/}
|
||||
|
||||
<Info>
|
||||
Throughout this documentation, the green cloud icon in the sidebar marks sections and pages for capabilities that require a Prowler Cloud or Prowler Private Cloud [subscription](https://prowler.com/pricing).
|
||||
</Info>
|
||||
|
||||
Products without a documentation page here are available through the Prowler team. [Contact us](https://prowler.com/contact) for details.
|
||||
|
||||
## Open Source Projects
|
||||
|
||||
| Name | Description |
|
||||
|------|-------------|
|
||||
| [Prowler CLI](/getting-started/products/prowler-cli) | Command line tool to run security scans across all supported providers. |
|
||||
| [Prowler Local Server](/getting-started/products/prowler-app) | Self-hosted web application and API to run scans, visualize findings, and manage cloud providers. Formerly Prowler App. |
|
||||
| [Prowler Local Dashboard](/user-guide/cli/tutorials/dashboard) | Local web dashboard to visualize scan results from Prowler CLI CSV outputs. Shipped with Prowler CLI. |
|
||||
| [Prowler SDK](/getting-started/products/prowler-sdk) | Python library that powers Prowler CLI and Prowler Local Server. Part of the [prowler repository](https://github.com/prowler-cloud/prowler). |
|
||||
|
||||
## Former Names
|
||||
|
||||
| Former name | Current name |
|
||||
|-------------|--------------|
|
||||
| Prowler App | [Prowler Local Server](/getting-started/products/prowler-app) |
|
||||
| Prowler Enterprise | Prowler Private Cloud |
|
||||
|
||||
## Prowler for MSPs and MSSPs
|
||||
|
||||
Prowler partners with managed service providers (MSPs) and managed security service providers (MSSPs) that operate Prowler for their customers. Visit [partners.prowler.com](https://partners.prowler.com) to become a partner.
|
||||
@@ -2,16 +2,16 @@
|
||||
title: 'Overview'
|
||||
---
|
||||
|
||||
Prowler App is a web application that simplifies running Prowler. It provides:
|
||||
Prowler Local Server is a self-hosted web application that simplifies running Prowler. It provides:
|
||||
|
||||
- **User-friendly interface** for configuring and executing scans
|
||||
- Dashboard to **view results** and manage **security findings**
|
||||
|
||||

|
||||

|
||||
|
||||
## Components
|
||||
|
||||
Prowler App consists of four main components:
|
||||
Prowler Local Server consists of four main components:
|
||||
|
||||
- **Prowler UI**: User-friendly web interface for running Prowler and viewing results, powered by Next.js
|
||||
- **Prowler API**: Backend API that executes Prowler scans and stores results, built with Django REST Framework
|
||||
@@ -26,4 +26,42 @@ Supporting infrastructure includes:
|
||||
- **Valkey**: In-memory database serving as message broker for Celery workers
|
||||
- **Neo4j**: Graph database used by the Attack Paths feature to combine cloud inventory with Prowler findings (currently populated by AWS scans)
|
||||
|
||||

|
||||
```mermaid
|
||||
flowchart TB
|
||||
user([User / Security Team])
|
||||
cli([Prowler CLI])
|
||||
|
||||
subgraph APP["Prowler Local Server"]
|
||||
ui["Prowler UI<br/>(Next.js)"]
|
||||
api["Prowler API<br/>(Django REST Framework)"]
|
||||
worker["API Worker<br/>(Celery)"]
|
||||
beat["API Scheduler<br/>(Celery Beat)"]
|
||||
mcp["Prowler MCP Server<br/>(Lighthouse AI tools)"]
|
||||
end
|
||||
|
||||
sdk["Prowler SDK<br/>(Python)"]
|
||||
|
||||
subgraph DATA["Data Layer"]
|
||||
pg[("PostgreSQL")]
|
||||
valkey[("Valkey / Redis")]
|
||||
neo4j[("Neo4j")]
|
||||
end
|
||||
|
||||
providers["Providers"]
|
||||
|
||||
user --> ui
|
||||
user --> cli
|
||||
ui -->|REST| api
|
||||
ui -->|MCP HTTP| mcp
|
||||
mcp -->|REST| api
|
||||
api --> pg
|
||||
api --> valkey
|
||||
beat -->|enqueue jobs| valkey
|
||||
valkey -->|dispatch| worker
|
||||
worker --> pg
|
||||
worker -->|Attack Paths| neo4j
|
||||
worker -->|invokes| sdk
|
||||
cli --> sdk
|
||||
|
||||
sdk --> providers
|
||||
```
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: 'Prowler for Claude Code'
|
||||
sidebarTitle: 'Claude Code'
|
||||
---
|
||||
|
||||
End-to-end cloud security and compliance from inside [Claude Code](https://www.claude.com/product/claude-code), powered by the [Prowler MCP server](/getting-started/products/prowler-mcp). The plugin lets Claude walk a Prowler Cloud-connected account through a compliance assessment and remediate findings until the chosen security or industry framework is compliant.
|
||||
|
||||
@@ -9,12 +9,12 @@ prowler <provider>
|
||||
```
|
||||

|
||||
|
||||
## Prowler Dashboard
|
||||
## Prowler Local Dashboard
|
||||
|
||||
```console
|
||||
prowler dashboard
|
||||
```
|
||||

|
||||

|
||||
|
||||
Prowler includes hundreds of security controls aligned with widely recognized industry frameworks and standards, including:
|
||||
|
||||
|
||||
@@ -75,10 +75,10 @@ No. Lighthouse AI has read-only access to security data and no tools to modify r
|
||||
|
||||
## Looking for the Open Source Version?
|
||||
|
||||
Lighthouse AI is also available in the self-hosted, open-source Prowler App. For its capabilities, FAQs, and limitations, see the open-source documentation.
|
||||
Lighthouse AI is also available in the open-source Prowler Local Server. For its capabilities, FAQs, and limitations, see the open-source documentation.
|
||||
|
||||
<Card title="Lighthouse AI (Open Source)" icon="github" href="/getting-started/products/prowler-lighthouse-ai">
|
||||
Capabilities, FAQs, and limitations for Lighthouse AI in the open-source Prowler App
|
||||
Capabilities, FAQs, and limitations for Lighthouse AI in the open-source Prowler Local Server
|
||||
</Card>
|
||||
|
||||
## Getting Help
|
||||
|
||||
@@ -8,6 +8,10 @@ title: "Overview"
|
||||
**Preview Feature**: This MCP server is currently under active development. Features and functionality may change. We welcome your feedback—please report any issues on [GitHub](https://github.com/prowler-cloud/prowler/issues) or join our [Slack community](https://goto.prowler.com/slack) to discuss and share your thoughts.
|
||||
</Warning>
|
||||
|
||||
<Note>
|
||||
Prowler MCP Server can run as a local instance, or as the hosted **Prowler MCP** at `https://mcp.prowler.com/mcp`. The hosted server also provides tools for Prowler Cloud-specific features such as [Alerts](/user-guide/tutorials/prowler-alerts), [Scan Scheduling](/user-guide/tutorials/prowler-scan-scheduling), and [Findings Triage](/user-guide/tutorials/prowler-app-findings-triage). See [Deployment Options](#deployment-options).
|
||||
</Note>
|
||||
|
||||
## What is the Model Context Protocol?
|
||||
|
||||
The [Model Context Protocol (MCP)](https://modelcontextprotocol.io) is an open standard developed by Anthropic that enables AI assistants to securely connect to external data sources and tools. It functions as a universal adapter enabling AI assistants to interact with various services through a standardized interface.
|
||||
@@ -16,9 +20,9 @@ The [Model Context Protocol (MCP)](https://modelcontextprotocol.io) is an open s
|
||||
|
||||
The Prowler MCP Server provides three main integration points:
|
||||
|
||||
### 1. Prowler Cloud and Prowler App (Self-Managed)
|
||||
### 1. Prowler Cloud and Prowler Local Server
|
||||
|
||||
Full access to Prowler Cloud platform and self-managed Prowler App for:
|
||||
Full access to Prowler Cloud and Prowler Local Server for:
|
||||
- **Findings Analysis**: Query, filter, and analyze security findings across all your cloud environments
|
||||
- **Provider Management**: Create, configure, and manage your configured Prowler providers (AWS, Azure, GCP, etc.)
|
||||
- **Scan Orchestration**: Trigger on-demand scans and schedule recurring security assessments
|
||||
@@ -29,7 +33,7 @@ Full access to Prowler Cloud platform and self-managed Prowler App for:
|
||||
### 2. Prowler Hub
|
||||
|
||||
Access to Prowler's comprehensive security knowledge base:
|
||||
- **Security Checks Catalog**: Browse and search **over 1000 security checks** across multiple cloud providers.
|
||||
- **Security Checks Catalog**: Browse and search **over 2,000 security checks** across multiple cloud providers.
|
||||
- **Check Implementation**: View the Python code that powers each security check.
|
||||
- **Automated Fixers**: Access remediation scripts for common security issues.
|
||||
- **Compliance Frameworks**: Explore mappings to **over 70 compliance standards and frameworks**.
|
||||
@@ -49,7 +53,7 @@ The following diagram illustrates the Prowler MCP Server architecture and its in
|
||||

|
||||
|
||||
The architecture shows how AI assistants connect through the MCP protocol to access Prowler's three main components:
|
||||
- Prowler Cloud/App for security operations
|
||||
- Prowler Cloud and Prowler Local Server for security operations
|
||||
- Prowler Hub for security knowledge
|
||||
- Prowler Documentation for guidance and reference.
|
||||
|
||||
@@ -136,15 +140,16 @@ Prowler MCP Server can be used in three ways:
|
||||
|
||||
- No installation required.
|
||||
- Managed and maintained by Prowler team.
|
||||
- Authentication to Prowler Cloud or Prowler App (self-managed) via API key or JWT token.
|
||||
- Authentication to Prowler Cloud or Prowler Local Server via API key or JWT token.
|
||||
- Includes tools for Prowler Cloud-specific features such as Alerts, Scan Scheduling, and Findings Triage.
|
||||
|
||||
### 2. Local STDIO Mode
|
||||
|
||||
**Run the server locally on your machine**
|
||||
|
||||
- Runs as a subprocess of your MCP client.
|
||||
- Possibility to connect to a self-hosted Prowler App (e.g. self-hosted Prowler App).
|
||||
- Authentication to Prowler Cloud or Prowler App (self-managed) via environment variables.
|
||||
- Runs as a subprocess of the MCP client.
|
||||
- Possibility to connect to Prowler Local Server.
|
||||
- Authentication to Prowler Cloud or Prowler Local Server via environment variables.
|
||||
- Requires Python 3.12+ or Docker.
|
||||
|
||||
### 3. Self-Hosted HTTP Mode
|
||||
@@ -152,8 +157,8 @@ Prowler MCP Server can be used in three ways:
|
||||
**Deploy your own remote MCP server**
|
||||
|
||||
- Full control over deployment.
|
||||
- Possibility to connect to a self-hosted Prowler App (e.g. self-hosted Prowler App).
|
||||
- Authentication to Prowler App (self-managed) via API key or JWT token.
|
||||
- Possibility to connect to Prowler Local Server.
|
||||
- Authentication to Prowler Local Server via API key or JWT token.
|
||||
- Requires Python 3.12+ or Docker.
|
||||
|
||||
## Requirements
|
||||
@@ -161,17 +166,17 @@ Prowler MCP Server can be used in three ways:
|
||||
Requirements vary based on deployment option:
|
||||
|
||||
**For Prowler Cloud MCP Server:**
|
||||
- Prowler Cloud account and API key (only for Prowler Cloud/App features)
|
||||
- Prowler Cloud account and API key (only for Prowler Cloud and Prowler Local Server features)
|
||||
|
||||
**For self-hosted STDIO/HTTP Mode:**
|
||||
- Python 3.12+ or Docker
|
||||
- Network access to:
|
||||
- `https://hub.prowler.com` (for Prowler Hub)
|
||||
- `https://docs.prowler.com` (for Prowler Documentation)
|
||||
- Prowler Cloud API or self-hosted Prowler App API (for Prowler Cloud/App features)
|
||||
- Prowler Cloud API or Prowler Local Server API (for Prowler Cloud and Prowler Local Server features)
|
||||
|
||||
<Note>
|
||||
**No Authentication Required**: Prowler Hub and Prowler Documentation features work without authentication in both deployment options. A Prowler API key is only required to access Prowler Cloud or Prowler App (Self-Managed) features.
|
||||
**No Authentication Required**: Prowler Hub and Prowler Documentation features work without authentication in both deployment options. A Prowler API key is only required to access Prowler Cloud or Prowler Local Server features.
|
||||
</Note>
|
||||
|
||||
## Next Steps
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
---
|
||||
title: 'Prowler SDK'
|
||||
---
|
||||
|
||||
Prowler SDK is the Python library that powers Prowler CLI and Prowler Local Server. It implements the providers, services, and security checks that every Prowler product runs.
|
||||
|
||||
To use or extend Prowler SDK, start with the Developer Guide:
|
||||
|
||||
<Card title="Developer Guide" icon="code" href="/developer-guide/introduction">
|
||||
Providers, services, checks, and testing: everything needed to work with Prowler SDK.
|
||||
</Card>
|
||||
Reference in New Issue
Block a user