docs: new product family (#11984)

This commit is contained in:
Pepe Fagoaga authored and GitHub committed 2026-07-15 12:28:50 +02:00
1 parent c53acd4184
commit cc6c731af6
91 files changed
+900 -506

No files matched your search

@@ -9,9 +9,9 @@ The tool, `aws_org_generator.py`‎, complements the [Bulk Provider Provisioning
<Note>
**Native AWS Organizations support is now available in Prowler Cloud.** You can onboard all accounts via the UI wizard — with automatic discovery, hierarchical tree selection, connection testing, and bulk scan launch — without any scripts or YAML files.
See [AWS Organizations in Prowler Cloud](/user-guide/tutorials/prowler-cloud-aws-organizations).
See [AWS Organizations](/user-guide/tutorials/prowler-cloud-aws-organizations) in Prowler Cloud.
The CLI-based tool below remains useful for self-hosted Prowler App and advanced automation scenarios.
The CLI-based tool below remains useful for Prowler Local Server and advanced automation scenarios.
</Note>
{/* TODO: Add screenshot of the tool in action */}
@@ -32,9 +32,9 @@ The AWS Organizations Bulk Provisioning tool simplifies multi-account onboarding
* Python 3.7 or higher
* AWS credentials with Organizations read access
* ProwlerRole (or custom role) deployed across all target accounts
* Prowler API key (from Prowler Cloud or self-hosted Prowler App)
* For self-hosted Prowler App, remember to [point to your API base URL](./bulk-provider-provisioning#custom-api-endpoints)
* Learn how to create API keys: [Prowler App API Keys](../tutorials/prowler-app-api-keys)
* Prowler API key (from Prowler Cloud or Prowler Local Server)
* For Prowler Local Server, remember to [point to your API base URL](./bulk-provider-provisioning#custom-api-endpoints)
* Learn how to create API keys: [Prowler Cloud API Keys](../tutorials/prowler-app-api-keys)
### Deploying ProwlerRole Across AWS Organizations
@@ -97,13 +97,13 @@ export PROWLER_API_KEY="pk_example-api-key"
To create an API key:
1. Log in to Prowler Cloud or Prowler App
1. Log in to Prowler Cloud or Prowler Local Server
2. Click **Profile** → **Account**
3. Click **Create API Key**
4. Provide a descriptive name and optionally set an expiration date
5. Copy the generated API key (it will only be shown once)
For detailed instructions, see: [Prowler App API Keys](../tutorials/prowler-app-api-keys)
For detailed instructions, see: [Prowler Cloud API Keys](../tutorials/prowler-app-api-keys)
## Basic Usage
@@ -324,7 +324,7 @@ python aws_org_generator.py \
</Step>
<Step title="Run Bulk Provisioning">
Provision all accounts to Prowler Cloud or Prowler App:
Provision all accounts to Prowler Cloud or Prowler Local Server:
```bash
# Set Prowler API key
@@ -487,7 +487,7 @@ grep "provider: aws" aws-org-accounts.yaml | wc -l
<Card title="Bulk Provider Provisioning" icon="terminal" href="/user-guide/tutorials/bulk-provider-provisioning">
Learn how to bulk provision providers in Prowler.
</Card>
<Card title="Prowler App" icon="pen-to-square" href="/user-guide/tutorials/prowler-app">
<Card title="Prowler Cloud" icon="pen-to-square" href="/user-guide/tutorials/prowler-app">
Detailed instructions on how to use Prowler.
</Card>
</Columns>
@@ -10,7 +10,7 @@ The tool is available in the Prowler repository at: [util/prowler-bulk-provision
## Overview
The Bulk Provider Provisioning tool automates the creation of cloud providers in Prowler App or Prowler Cloud by:
The Bulk Provider Provisioning tool automates the creation of cloud providers in Prowler Cloud or Prowler Local Server by:
* Reading provider configurations from YAML files
* Creating providers with appropriate authentication credentials
@@ -26,9 +26,9 @@ The Bulk Provider Provisioning tool automates the creation of cloud providers in
### Requirements
* Python 3.7 or higher
* Prowler API key (from Prowler Cloud or self-hosted Prowler App)
* For self-hosted Prowler App, remember to [point to your API base URL](#custom-api-endpoints)
* Learn how to create API keys: [Prowler App API Keys](../tutorials/prowler-app-api-keys)
* Prowler API key (from Prowler Cloud or Prowler Local Server)
* For Prowler Local Server, remember to [point to your API base URL](#custom-api-endpoints)
* Learn how to create API keys: [Prowler Cloud API Keys](../tutorials/prowler-app-api-keys)
* Authentication credentials for target cloud providers
### Installation
@@ -51,13 +51,13 @@ export PROWLER_API_KEY="pk_example-api-key"
To create an API key:
1. Log in to Prowler Cloud or Prowler App
1. Log in to Prowler Cloud or Prowler Local Server
2. Click **Profile** → **Account**
3. Click **Create API Key**
4. Provide a descriptive name and optionally set an expiration date
5. Copy the generated API key (it will only be shown once)
For detailed instructions, see: [Prowler App API Keys](../tutorials/prowler-app-api-keys)
For detailed instructions, see: [Prowler Cloud API Keys](../tutorials/prowler-app-api-keys)
## Configuration File Structure
@@ -261,7 +261,7 @@ python prowler_bulk_provisioning.py providers.yaml --concurrency 10
### Custom API Endpoints
For self-hosted Prowler App installations:
For Prowler Local Server installations:
```bash
python prowler_bulk_provisioning.py providers.yaml \
@@ -1,5 +1,6 @@
---
title: 'Alerts'
sidebarTitle: 'Alerts'
description: 'Create email alerts from Prowler Cloud findings to monitor relevant security changes after scans or in daily digests.'
---
@@ -3,14 +3,17 @@ title: 'API Keys'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.13.0" />
API key authentication in Prowler App provides an alternative to JWT tokens and empowers automation, CI/CD pipelines, and third-party integrations. This guide explains how to create, manage, and safeguard API keys when working with the Prowler API.
<AppliesTo />
API key authentication in Prowler Cloud provides an alternative to JWT tokens and empowers automation, CI/CD pipelines, and third-party integrations. This guide explains how to create, manage, and safeguard API keys when working with the Prowler API.
## API Key Advantages
- **Programmatic access:** Enables automated workflows and scripts to interact with Prowler App.
- **Programmatic access:** Enables automated workflows and scripts to interact with Prowler Cloud.
- **Long-lived authentication:** Allows optional expiration dates, with a default of 1 year.
- **Granular control:** Supports multiple keys with distinct names and purposes.
- **Secure automation:** Simplifies safe integration into CI/CD pipelines and infrastructure-as-code tooling.
@@ -19,7 +22,7 @@ API key authentication in Prowler App provides an alternative to JWT tokens and
API keys provide a secure authentication mechanism for accessing the Prowler API:
1. API keys are created through Prowler App with a user-defined name and optional expiration date.
1. API keys are created through Prowler Cloud with a user-defined name and optional expiration date.
2. The full API key appears only once upon creation and cannot be retrieved later.
3. Each API key consists of a prefix (visible in the interface) and an encrypted secret portion.
4. Requests include the API key in the header as `Authorization: Api-Key <api-key>`.
@@ -63,13 +66,13 @@ Creating, viewing, or managing API keys requires the **MANAGE_ACCOUNT** RBAC per
Without this permission, the API Keys section remains hidden. Access requests should be routed through the tenant administrator.
For more information about RBAC permissions, refer to the [Prowler App RBAC documentation](/user-guide/tutorials/prowler-app-rbac).
For more information about RBAC permissions, refer to the [Prowler Cloud RBAC documentation](/user-guide/tutorials/prowler-app-rbac).
## Creating API Keys
Follow these steps to create an API key in Prowler App:
Follow these steps to create an API key in Prowler Cloud:
1. Navigate to **Profile** → **Account** in Prowler App.
1. Navigate to **Profile** → **Account** in Prowler Cloud.
2. Select the **Create API Key** button.
![API Keys list](/images/cli/api-keys/list.png)
@@ -206,7 +209,7 @@ When using API keys in CI/CD pipelines:
* Ensure the key has not been revoked by checking the Revoked column in the API Keys list.
* Confirm that the key has not expired by reviewing the expiration date.
* Confirm that the correct API key format is in use, including both prefix and secret portions.
* Verify that the key prefix matches what is displayed in Prowler App.
* Verify that the key prefix matches what is displayed in Prowler Cloud.
### API Key Not Working After Creation
@@ -4,9 +4,12 @@ description: "Identify privilege escalation chains and security misconfiguration
---
import { VersionBadge } from "/snippets/version-badge.mdx";
import { AppliesTo } from "/snippets/applies-to.mdx";
<VersionBadge version="5.17.0" />
<AppliesTo />
Attack Paths analyzes relationships between cloud resources, permissions, and security findings to detect how privileges can be escalated and how misconfigurations can be exploited by threat actors.
By mapping these relationships as a graph, Attack Paths reveals risks that individual security checks cannot detect on their own, such as an IAM role that can escalate its own permissions, or a chain of policies that grants unintended access to sensitive resources.
@@ -20,7 +23,7 @@ By mapping these relationships as a graph, Attack Paths reveals risks that indiv
The following prerequisites are required for Attack Paths:
- **An AWS provider is configured** with valid credentials in Prowler App. For setup instructions, see [Getting Started with AWS](/user-guide/providers/aws/getting-started-aws).
- **An AWS provider is configured** with valid credentials in Prowler Cloud. For setup instructions, see [Getting Started with AWS](/user-guide/providers/aws/getting-started-aws).
- **At least one scan has completed** on the configured AWS provider and produced graph data. Attack Paths scans run automatically alongside regular security scans, no separate configuration is required.
## How Attack Paths Scans Work
@@ -1,12 +1,16 @@
---
title: 'Finding Groups'
sidebarTitle: 'Groups'
description: 'Organize and triage security findings by check to reduce noise and prioritize remediation effectively.'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.23.0" />
<AppliesTo />
Finding Groups transforms security findings triage by grouping them by check instead of displaying a flat list. This dramatically reduces noise and enables faster, more effective prioritization.
## Triage Challenges with Flat Finding Lists
@@ -112,7 +116,7 @@ This provides full context without leaving the drawer.
## Getting Started
1. Navigate to the **Findings** section in Prowler Cloud/App.
1. Navigate to the **Findings** section in Prowler Cloud.
2. Toggle to the **Grouped View** to see findings organized by check.
3. Select any group row to expand and see affected resources.
4. Select a resource to open the detail drawer with full context.
@@ -1,5 +1,6 @@
---
title: "Findings Triage"
sidebarTitle: 'Triage'
description: "Track finding review status and team notes in Prowler Cloud."
---
@@ -113,7 +114,7 @@ Make sure the row is an individual finding row. Finding Groups rows do not show
### Changes cannot be saved
Confirm that the user role has **Manage Scans** permission. Self-hosted Prowler App does not support Findings Triage writes.
Confirm that the user role has **Manage Scans** permission. Prowler Local Server does not support Findings Triage writes.
### Resolved or Reopened is missing from the selector
@@ -1,13 +1,17 @@
---
title: "Jira Integration"
sidebarTitle: 'Jira'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.12.0" />
Prowler App enables automatic export of security findings to Jira, providing seamless integration with Atlassian's work item tracking and project management platform. This comprehensive guide demonstrates how to configure and manage Jira integrations to streamline security incident management and enhance team collaboration across security workflows.
<AppliesTo />
Integrating Prowler App with Jira provides:
Prowler Cloud enables automatic export of security findings to Jira, providing seamless integration with Atlassian's work item tracking and project management platform. This comprehensive guide demonstrates how to configure and manage Jira integrations to streamline security incident management and enhance team collaboration across security workflows.
Integrating Prowler Cloud with Jira provides:
* **Streamlined management:** Convert security findings directly into actionable Jira work items
* **Enhanced team collaboration:** Leverage existing project management workflows for security remediation
@@ -22,9 +26,9 @@ When enabled and configured:
## Configuration
To configure Jira integration in Prowler App:
To configure Jira integration in Prowler Cloud:
1. Navigate to **Integrations** in the Prowler App interface
1. Navigate to **Integrations** in Prowler Cloud
2. Locate the **Jira** card and click **Manage**, then select **Add integration**
![Integrations tab](/images/prowler-app/jira/integrations-tab.png)
@@ -50,7 +54,7 @@ Once configured successfully, the integration is ready to send findings to Jira.
To manually send individual findings to Jira:
1. Navigate to the **Findings** section in Prowler App
1. Navigate to the **Findings** section in Prowler Cloud
2. Select one finding you want to export
3. Click the action button on the table row and select **Send to Jira**
4. Select the Jira integration and project
@@ -1,5 +1,6 @@
---
title: 'Using Multiple LLM Providers with Lighthouse'
sidebarTitle: 'Multiple LLM Providers'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
@@ -19,7 +19,7 @@ Behind the scenes, Lighthouse AI works as follows:
- The agent accesses Prowler data through [Prowler MCP](https://docs.prowler.com/getting-started/products/prowler-mcp), which exposes tools from multiple sources, including:
- Prowler Hub
- Prowler Docs
- Prowler App
- Prowler Local Server
- Instead of calling every tool directly, the agent uses two meta-tools:
- `describe_tool` to retrieve a tool schema and parameter requirements.
- `execute_tool` to run the selected tool with the required input.
@@ -1,12 +1,16 @@
---
title: 'Managing Organizations (Multi-Tenant)'
sidebarTitle: 'Organizations'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.23.0" />
Prowler App supports multi-tenancy through **Organizations**, allowing users to belong to multiple isolated environments within a single account. Each organization maintains its own providers, scans, findings, and user memberships, ensuring complete data separation between teams or business units.
<AppliesTo />
Prowler Cloud supports multi-tenancy through **Organizations**, allowing users to belong to multiple isolated environments within a single account. Each organization maintains its own providers, scans, findings, and user memberships, ensuring complete data separation between teams or business units.
## Key Concepts
@@ -128,7 +132,7 @@ When invited to join an organization, the invited user receives a link to accept
1. Open the invitation link.
2. If already authenticated, the invitation is accepted automatically and the user is redirected to Prowler App.
2. If already authenticated, the invitation is accepted automatically and the user is redirected to Prowler Cloud.
3. If not authenticated, choose **I have an account -- Sign in**, authenticate with existing credentials, and the invitation is accepted upon sign-in.
@@ -1,11 +1,14 @@
---
title: 'Advanced Mutelist (YAML)'
title: 'Advanced Mutelist'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.9.0" />
Prowler App allows users to mute specific findings to focus on the most critical security issues. This guide demonstrates how to use the Advanced Mutelist feature with YAML configuration for complex, pattern-based muting rules.
<AppliesTo />
Prowler Cloud allows users to mute specific findings to focus on the most critical security issues. This guide demonstrates how to use the Advanced Mutelist feature with YAML configuration for complex, pattern-based muting rules.
<Note>
For muting individual findings without YAML configuration, use [Simple Mutelist](/user-guide/tutorials/prowler-app-simple-mutelist) to mute findings directly from the Findings table.
@@ -31,8 +34,8 @@ Advanced Mutelist requires the **Manage Account** permission. See [RBAC Administ
Before muting findings, ensure:
- Valid access to Prowler App with appropriate permissions
- A provider added to the Prowler App
- Valid access to Prowler Cloud with appropriate permissions
- A provider added to Prowler Cloud
- Understanding of the security implications of muting specific findings
<Warning>
@@ -43,7 +46,7 @@ Muting findings does not resolve underlying security issues. Review each finding
To configure Advanced Mutelist:
1. Log into Prowler App
1. Log into Prowler Cloud
2. Navigate to the Providers page
![Add provider](/images/mutelist-ui-1.png)
3. Connect a provider to enable Mutelist configuration
@@ -423,7 +426,7 @@ Mutelist:
### Priority: Advanced vs. Simple Mutelist
When both Advanced Mutelist (YAML) and [Simple Mutelist](/user-guide/tutorials/prowler-app-simple-mutelist) rules match the same finding, the **Advanced Mutelist takes higher priority**. The finding will be muted with the reason "Muted by mutelist". If a finding is not matched by the Advanced Mutelist but matches a Simple Mutelist rule, the Simple rule's custom justification is used instead.
When both Advanced Mutelist and [Simple Mutelist](/user-guide/tutorials/prowler-app-simple-mutelist) rules match the same finding, the **Advanced Mutelist takes higher priority**. The finding will be muted with the reason "Muted by mutelist". If a finding is not matched by the Advanced Mutelist but matches a Simple Mutelist rule, the Simple rule's custom justification is used instead.
### Best Practices
@@ -436,7 +439,7 @@ When both Advanced Mutelist (YAML) and [Simple Mutelist](/user-guide/tutorials/p
### Validation
Prowler App validates your mutelist configuration and will display errors for:
Prowler Cloud validates the mutelist configuration and will display errors for:
- Invalid YAML syntax
- Missing required fields
@@ -1,12 +1,16 @@
---
title: 'Managing Users and Role-Based Access Control (RBAC)'
sidebarTitle: 'Users & RBAC'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.1.0" />
**Prowler App** supports multiple users within a single tenant, enabling seamless collaboration by allowing team members to easily share insights and manage security findings.
<AppliesTo />
**Prowler Cloud** supports multiple users within a single tenant, enabling seamless collaboration by allowing team members to easily share insights and manage security findings.
[Roles](#roles) help you control user permissions, determining what actions each user can perform and the data they can access within Prowler. By default, each account includes an immutable **admin** role, ensuring that your account always retains administrative access.
@@ -1,12 +1,16 @@
---
title: 'Amazon S3 Integration'
sidebarTitle: 'Amazon S3'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.10.0" />
**Prowler App** allows automatic export of scan results to Amazon S3 buckets, providing seamless integration with existing data workflows and storage infrastructure. This comprehensive guide demonstrates configuration and management of Amazon S3 integrations to streamline security finding management and reporting.
<AppliesTo />
**Prowler Cloud** allows automatic export of scan results to Amazon S3 buckets, providing seamless integration with existing data workflows and storage infrastructure. This comprehensive guide demonstrates configuration and management of Amazon S3 integrations to streamline security finding management and reporting.
When enabled and configured, scan results are automatically stored in the configured bucket. Results are provided in `csv`, `html` and `json-ocsf` formats, offering flexibility for custom integrations:
@@ -201,7 +205,7 @@ Replace `<SOURCE ACCOUNT ID>` with the AWS account ID that contains the IAM role
</Note>
### Available Templates
**Prowler App** provides Infrastructure as Code (IaC) templates to automate IAM role setup with S3 integration permissions.
**Prowler Cloud** provides Infrastructure as Code (IaC) templates to automate IAM role setup with S3 integration permissions.
<Note>
Templates are optional. Custom IAM roles or static credentials can be used instead.
@@ -278,7 +282,7 @@ If using Prowler's CloudFormation template, execute the following command to upd
3. Edit `terraform.tfvars` with your specific values:
```hcl
# Required: External ID from Prowler App
# Required: External ID from Prowler Cloud
external_id = "your-unique-external-id-here"
# S3 Integration Configuration
@@ -310,7 +314,7 @@ For detailed information, refer to the [Terraform README](https://github.com/pro
## Configuration
Once the required permissions are set up, proceed to configure the S3 integration in **Prowler App**.
Once the required permissions are set up, proceed to configure the S3 integration in **Prowler Cloud**.
1. Navigate to "Integrations"
![Navigate to integrations](/images/prowler-app/s3/s3-integration-ui-1.png)
@@ -1,5 +1,6 @@
---
title: 'Scan Configuration'
sidebarTitle: 'Configuration'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
@@ -1,13 +1,17 @@
---
title: "AWS Security Hub Integration"
sidebarTitle: 'AWS Security Hub'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.11.0" />
Prowler App enables automatic export of security findings to AWS Security Hub, providing seamless integration with AWS's native security and compliance service. This comprehensive guide demonstrates how to configure and manage AWS Security Hub integrations to centralize security findings and enhance compliance tracking across AWS environments.
<AppliesTo />
Integrating Prowler App with AWS Security Hub provides:
Prowler Cloud enables automatic export of security findings to AWS Security Hub, providing seamless integration with AWS's native security and compliance service. This comprehensive guide demonstrates how to configure and manage AWS Security Hub integrations to centralize security findings and enhance compliance tracking across AWS environments.
Integrating Prowler Cloud with AWS Security Hub provides:
* **Centralized security visibility:** Consolidate findings from multiple AWS accounts and regions
* **Native AWS integration:** Leverage existing AWS security workflows and compliance frameworks
@@ -30,7 +34,7 @@ Refer to [AWS Security Hub pricing](https://aws.amazon.com/security-hub/pricing/
</Note>
## Prerequisites
Before configuring AWS Security Hub Integration in Prowler App, complete these steps:
Before configuring AWS Security Hub Integration in Prowler Cloud, complete these steps:
### AWS Security Hub Setup
@@ -42,9 +46,9 @@ Configure AWS credentials by following the [AWS authentication setup guide](/use
## Configuration
To configure AWS Security Hub integration in Prowler App:
To configure AWS Security Hub integration in Prowler Cloud:
1. Navigate to **Integrations** in the Prowler App interface
1. Navigate to **Integrations** in Prowler Cloud
2. Locate the **AWS Security Hub** card and click **Manage**, then select **Add integration**
![Integrations tab](/images/prowler-app/security-hub/integrations-tab.png)
@@ -3,10 +3,13 @@ title: "Simple Mutelist"
---
import { VersionBadge } from "/snippets/version-badge.mdx";
import { AppliesTo } from "/snippets/applies-to.mdx";
<VersionBadge version="5.16.0" />
Prowler App provides Simple Mutelist, an intuitive way to mute findings directly from the Findings page without writing YAML configuration. This feature streamlines the muting workflow by allowing individual or bulk muting with just a few clicks.
<AppliesTo />
Prowler Cloud provides Simple Mutelist, an intuitive way to mute findings directly from the Findings page without writing YAML configuration. This feature streamlines the muting workflow by allowing individual or bulk muting with just a few clicks.
## What Is Simple Mutelist?
@@ -1,12 +1,16 @@
---
title: 'Social Login Configuration'
sidebarTitle: 'Social Login'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.5.0" />
**Prowler App** supports social login using Google and GitHub OAuth providers. This document guides you through configuring the required environment variables to enable social authentication.
<AppliesTo />
Prowler supports social login using Google and GitHub OAuth providers. In **Prowler Cloud** social login is available out of the box. In **Prowler Local Server**, enable it by configuring the environment variables described in this guide.
<img src="/images/prowler-app/social-login/social_login_buttons.png" alt="Social login buttons" width="700" />
## Configuring Social Login Credentials
@@ -2,7 +2,11 @@
title: 'Entra ID Configuration'
---
This page provides instructions for creating and configuring a Microsoft Entra ID (formerly Azure AD) application to use SAML SSO with Prowler App.
import { AppliesTo } from "/snippets/applies-to.mdx"
<AppliesTo />
This page provides instructions for creating and configuring a Microsoft Entra ID (formerly Azure AD) application to use SAML SSO with Prowler Cloud.
You can find a walkthrough video [here](https://www.youtube.com/watch?v=zegqm55oJVk).
@@ -28,7 +32,7 @@ You can find a walkthrough video [here](https://www.youtube.com/watch?v=zegqm55o
![Edit](/images/prowler-app/saml/saml-sso-azure-5.png)
6. Enter the "Identifier (Entity ID)" and "Reply URL (Assertion Consumer Service URL)". These values can be obtained from the SAML SSO integration setup in Prowler App. For detailed instructions, refer to the [SAML SSO Configuration](/user-guide/tutorials/prowler-app-sso) page.
6. Enter the "Identifier (Entity ID)" and "Reply URL (Assertion Consumer Service URL)". These values can be obtained from the SAML SSO integration setup in Prowler Cloud. For detailed instructions, refer to the [SAML SSO Configuration](/user-guide/tutorials/prowler-app-sso) page.
![Enter data](/images/prowler-app/saml/saml-sso-azure-6.png)
@@ -44,4 +48,4 @@ You can find a walkthrough video [here](https://www.youtube.com/watch?v=zegqm55o
![Metadata XML](/images/prowler-app/saml/saml-sso-azure-9.png)
10. Save the downloaded Metadata XML to a file. To complete the setup, upload this file during the Prowler App integration. (See the [SAML SSO Configuration](/user-guide/tutorials/prowler-app-sso) page for details).
10. Save the downloaded Metadata XML to a file. To complete the setup, upload this file during the SAML SSO integration setup in Prowler Cloud. (See the [SAML SSO Configuration](/user-guide/tutorials/prowler-app-sso) page for details).
@@ -2,20 +2,24 @@
title: 'SAML SSO: Google Workspace'
---
This page explains how to configure SAML-based Single Sign-On (SSO) in Prowler App using **Google Workspace** as the Identity Provider (IdP). The setup is divided into two parts: create a custom SAML app in Google Admin Console, then complete the configuration in Prowler App.
import { AppliesTo } from "/snippets/applies-to.mdx"
<AppliesTo />
This page explains how to configure SAML-based Single Sign-On (SSO) in Prowler Cloud using **Google Workspace** as the Identity Provider (IdP). The setup is divided into two parts: create a custom SAML app in Google Admin Console, then complete the configuration in Prowler Cloud.
<Info>
**Parallel Setup Required**
Google Admin Console requires the ACS URL and Entity ID from Prowler App, while Prowler App displays these values only after opening the SAML configuration dialog. To work around this, open Prowler App in a separate browser tab, navigate to the profile page, open the "Configure SAML SSO" dialog, and copy the ACS URL and Entity ID before proceeding with the Google configuration.
Google Admin Console requires the ACS URL and Entity ID from Prowler Cloud, while Prowler Cloud displays these values only after opening the SAML configuration dialog. To work around this, open Prowler Cloud in a separate browser tab, navigate to the profile page, open the "Configure SAML SSO" dialog, and copy the ACS URL and Entity ID before proceeding with the Google configuration.
</Info>
## Prerequisites
- **Google Workspace**: Super Admin access (or delegated admin with app management permissions).
- **Prowler App**: Administrator access to the organization (role with "Manage Account" permission).
- Prowler App version **5.9.0** or later.
- **Prowler Cloud**: Administrator access to the organization (role with "Manage Account" permission).
- Prowler version **5.9.0** or later.
---
@@ -44,7 +48,7 @@ On the **Google Identity Provider details** screen:
1. Google displays two options:
- **Option 1**: Click "Download Metadata" to save the XML file directly. This is the recommended approach.
- **Option 2**: Manually copy the **SSO URL**, **Entity ID**, and **Certificate**.
2. Download the metadata. This file is required to complete the Prowler App configuration in Part B.
2. Download the metadata. This file is required to complete the configuration in Prowler Cloud (Part B).
3. Click "Continue".
![Google Identity Provider details - Download metadata](/images/prowler-app/saml/saml-sso-gw-3.png)
@@ -52,18 +56,18 @@ On the **Google Identity Provider details** screen:
<Warning>
**Save the Metadata File**
Download and save the IdP metadata XML file before proceeding. This file cannot be easily retrieved later and is required to complete the SAML configuration in Prowler App.
Download and save the IdP metadata XML file before proceeding. This file cannot be easily retrieved later and is required to complete the SAML configuration in Prowler Cloud.
</Warning>
### Step 4: Configure the Service Provider Details
Enter the following values obtained from the SAML SSO configuration dialog in Prowler App (see [Part B, Step 1](#step-1-open-the-saml-configuration-dialog) for details on where to find them):
Enter the following values obtained from the SAML SSO configuration dialog in Prowler Cloud (see [Part B, Step 1](#step-1-open-the-saml-configuration-dialog) for details on where to find them):
| Google Workspace Field | Value |
|------------------------|-------|
| **ACS URL** | The Assertion Consumer Service (ACS) URL displayed in Prowler App (e.g., `https://api.prowler.com/api/v1/accounts/saml/your-domain.com/acs/`). Self-hosted deployments use a different base URL. |
| **Entity ID** | The Audience URI displayed in Prowler App (e.g., `urn:prowler.com:sp`). |
| **ACS URL** | The Assertion Consumer Service (ACS) URL displayed in Prowler Cloud (e.g., `https://api.prowler.com/api/v1/accounts/saml/your-domain.com/acs/`). Prowler Local Server deployments use a different base URL. |
| **Entity ID** | The Audience URI displayed in Prowler Cloud (e.g., `urn:prowler.com:sp`). |
| **Name ID format** | Select `EMAIL` from the dropdown. |
| **Name ID** | Select `Basic Information > Primary email` from the dropdown. |
@@ -82,7 +86,7 @@ Click "Add mapping" for each entry:
| `Basic Information > First name` | `firstName` | Yes | |
| `Basic Information > Last name` | `lastName` | Yes | |
| `Employee Details > Department` | `userType` | No | Determines the Prowler role. **Case-sensitive.** |
| `Employee Details > Organization` | `organization` | No | Company name displayed in Prowler App profile. |
| `Employee Details > Organization` | `organization` | No | Company name displayed in the user profile in Prowler Cloud. |
<Info>
**Remember the Mapped Fields**
@@ -98,7 +102,7 @@ Click "Finish" to create the SAML app.
<Info>
**Dynamic Updates**
Prowler App updates user attributes each time a user logs in. Any changes made in Google Workspace are reflected on the next login.
Prowler Cloud updates user attributes each time a user logs in. Any changes made in Google Workspace are reflected on the next login.
</Info>
@@ -108,7 +112,7 @@ Prowler App updates user attributes each time a user logs in. Any changes made i
The `userType` attribute controls which Prowler role is assigned to the user:
- If `userType` matches an existing Prowler role name, the user receives that role automatically.
- If `userType` does not match any existing role, Prowler App creates a new role with that name **with read-only access** (visibility over all providers, no management permissions). A Prowler administrator can adjust its permissions afterward through the [RBAC Management](/user-guide/tutorials/prowler-app-rbac) tab.
- If `userType` does not match any existing role, Prowler Cloud creates a new role with that name **with read-only access** (visibility over all providers, no management permissions). A Prowler administrator can adjust its permissions afterward through the [RBAC Management](/user-guide/tutorials/prowler-app-rbac) tab.
- If `userType` is not set, the user's existing roles are left unchanged.
The `userType` value is **case-sensitive** - for example, `Backend` and `backend` are treated as different roles.
@@ -148,13 +152,13 @@ If attempting to use the "Test SAML login" option in Google Admin Console and re
---
## Part B - Prowler App Configuration
## Part B - Prowler Cloud Configuration
### Step 1: Open the SAML Configuration Dialog
1. Navigate to the profile settings page:
- **Prowler Cloud**: `https://cloud.prowler.com/profile`
- **Self-hosted**: `http://{your-domain}/profile`
- **Prowler Local Server**: `http://{your-domain}/profile`
2. Find the "SAML SSO Integration" card and click "Enable" (or "Update" if already configured).
3. The "Configure SAML SSO" dialog opens, displaying:
- **ACS URL**: The Assertion Consumer Service URL (copy this value for Part A, Step 4). This URL updates dynamically when the email domain is entered.
@@ -162,21 +166,21 @@ If attempting to use the "Test SAML login" option in Google Admin Console and re
- **Name ID Format**: The expected format (`urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`).
- **Supported Assertion Attributes**: The list of accepted attributes (`firstName`, `lastName`, `userType`, `organization`).
![Prowler App - Configure SAML SSO dialog (initial state)](/images/prowler-app/saml/saml-sso-gw-prowler-1.png)
![Prowler Cloud - Configure SAML SSO dialog (initial state)](/images/prowler-app/saml/saml-sso-gw-prowler-1.png)
### Step 2: Enter the Email Domain and Upload Metadata
1. Enter the **email domain** for the organization (e.g., `prowler.cloud`). Prowler App uses this domain to identify users who should authenticate via SAML. The ACS URL updates automatically to reflect the configured domain.
1. Enter the **email domain** for the organization (e.g., `prowler.cloud`). Prowler Cloud uses this domain to identify users who should authenticate via SAML. The ACS URL updates automatically to reflect the configured domain.
2. Upload the **metadata XML file** downloaded in Part A, Step 3.
3. Click "Save".
![Prowler App - Configure SAML SSO dialog (domain entered and ready to save)](/images/prowler-app/saml/saml-sso-gw-prowler-2.png)
![Prowler Cloud - Configure SAML SSO dialog (domain entered and ready to save)](/images/prowler-app/saml/saml-sso-gw-prowler-2.png)
### Step 3: Verify the Enabled Status
The "SAML SSO Integration" card should now display a **"Status: Enabled"** indicator with a checkmark, confirming that the configuration is complete.
![Prowler App - SAML SSO Integration status showing "Enabled"](/images/prowler-app/saml/saml-sso-gw-prowler-3.png)
![Prowler Cloud - SAML SSO Integration status showing "Enabled"](/images/prowler-app/saml/saml-sso-gw-prowler-3.png)
---
@@ -214,13 +218,13 @@ To test the `userType` → role mapping, set the **Department** attribute in the
1. Navigate to the Prowler login page.
2. Click "Continue with SAML SSO".
3. Enter an email from the configured domain (e.g., `adrian@prowler.cloud`).
4. Click "Log in". The browser redirects to Google for authentication and returns to Prowler App upon success.
4. Click "Log in". The browser redirects to Google for authentication and returns to Prowler Cloud upon success.
![Prowler App - Sign in with SAML SSO](/images/prowler-app/saml/saml-sso-gw-prowler-4.png)
![Prowler Cloud - Sign in with SAML SSO](/images/prowler-app/saml/saml-sso-gw-prowler-4.png)
### Verify User Profile and Role Mapping
After a successful SSO login, the user profile in Prowler App reflects the attributes sent by Google Workspace:
After a successful SSO login, the user profile in Prowler Cloud reflects the attributes sent by Google Workspace:
- **Name**: Populated from the `firstName` and `lastName` attributes.
- **Role**: Created automatically from the `userType` attribute (e.g., `Backend`). If the role did not exist previously, it is created with read-only access by default.
@@ -230,14 +234,14 @@ After a successful SSO login, the user profile in Prowler App reflects the attri
For more details on role assignment behavior and attribute mapping, refer to the [SAML SSO Configuration](/user-guide/tutorials/prowler-app-sso#configure-attribute-mapping-in-the-idp) page.
![Prowler App - User profile showing role "Backend" created from userType mapping](/images/prowler-app/saml/saml-sso-gw-prowler-5.png)
![Prowler Cloud - User profile showing role "Backend" created from userType mapping](/images/prowler-app/saml/saml-sso-gw-prowler-5.png)
### IdP-Initiated SSO (from Google)
1. Sign in to Google Workspace with an account that has access to the Prowler SAML app.
2. Open the Google Workspace app launcher (the grid icon in the top-right corner of any Google page).
3. Click the Prowler app tile.
4. The browser redirects directly to Prowler App, authenticated.
3. Click the Prowler tile.
4. The browser redirects directly to Prowler Cloud, authenticated.
For more information on the SSO login flows, refer to the [SAML SSO Configuration](/user-guide/tutorials/prowler-app-sso#idp-initiated-sso) page.
@@ -270,7 +274,7 @@ Prowler does not allow two tenants to share the same email domain. If the domain
<Info>
**Just-in-Time Provisioning**
Users who authenticate via SAML for the first time are automatically created in Prowler App. No prior invitation is needed. User attributes (`firstName`, `lastName`, `userType`) are updated on every login from the Google directory.
Users who authenticate via SAML for the first time are automatically created in Prowler Cloud. No prior invitation is needed. User attributes (`firstName`, `lastName`, `userType`) are updated on every login from the Google directory.
</Info>
@@ -278,10 +282,10 @@ Users who authenticate via SAML for the first time are automatically created in
## Quick Summary
1. In **Google Admin Console**, create a custom SAML app using the ACS URL and Entity ID from Prowler App.
1. In **Google Admin Console**, create a custom SAML app using the ACS URL and Entity ID from Prowler Cloud.
2. Configure **attribute mapping**: `firstName`, `lastName`, and optionally `userType` and `organization`.
3. **Download the metadata XML** from Google.
4. **Enable the app** in Google Workspace for the relevant users or groups.
5. In **Prowler App**, enter the email domain, upload the metadata XML, and save.
5. In **Prowler Cloud**, enter the email domain, upload the metadata XML, and save.
6. Verify the SAML SSO Integration shows **"Status: Enabled"**.
7. Test login via "Continue with SAML SSO" on the Prowler login page.
+30 -26
View File
@@ -1,18 +1,22 @@
---
title: 'SAML Single Sign-On (SSO)'
sidebarTitle: 'SAML SSO'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
import { AppliesTo } from "/snippets/applies-to.mdx"
<VersionBadge version="5.9.0" />
This guide provides comprehensive instructions to configure SAML-based Single Sign-On (SSO) in Prowler App. This configuration allows users to authenticate using the organization's Identity Provider (IdP).
<AppliesTo />
This guide provides comprehensive instructions to configure SAML-based Single Sign-On (SSO) in Prowler Cloud. This configuration allows users to authenticate using the organization's Identity Provider (IdP).
This document is divided into two main sections:
- **[User Guide](#user-guide-configuration)**: For organization administrators to configure SAML SSO through Prowler App.
- **[User Guide](#user-guide-configuration)**: For organization administrators to configure SAML SSO through Prowler Cloud.
- **[Developer and Administrator Guide](#developer-and-administrator-guide)**: For developers and system administrators running self-hosted Prowler App instances, providing technical details on environment configuration, API usage, and testing.
- **[Developer and Administrator Guide](#developer-and-administrator-guide)**: For developers and system administrators running Prowler Local Server instances, providing technical details on environment configuration, API usage, and testing.
---
@@ -43,7 +47,7 @@ If the SAML configuration is removed, users who previously authenticated via SAM
#### Step 1: Access Profile Settings
To access the account settings, click the "Account" button in the top-right corner of Prowler App, or navigate directly to `https://cloud.prowler.com/profile` (or `http://localhost:3000/profile` for local setups).
To access the account settings, click the "Account" button in the top-right corner of Prowler Cloud, or navigate directly to `https://cloud.prowler.com/profile` (or `http://localhost:3000/profile` for local setups).
![Access Profile Settings](/images/prowler-app/saml/saml-step-1.png)
@@ -63,12 +67,12 @@ Choose a Method:
<Tabs>
<Tab title="Generic Method">
Prowler App displays the SAML configuration information needed to configure the IdP. Use this information to create a new SAML application in the IdP.
Prowler Cloud displays the SAML configuration information needed to configure the IdP. Use this information to create a new SAML application in the IdP.
1. **Assertion Consumer Service (ACS) URL**: The endpoint in Prowler that will receive the SAML assertion from the IdP.
2. **Audience URI (Entity ID)**: A unique identifier for the Prowler application (Service Provider).
To configure the IdP, copy the **ACS URL** and **Audience URI** from Prowler App and use them to set up a new SAML application.
To configure the IdP, copy the **ACS URL** and **Audience URI** from Prowler Cloud and use them to set up a new SAML application.
![IdP configuration](/images/prowler-app/saml/idp_config.png)
@@ -81,13 +85,13 @@ Choose a Method:
**Configure Attribute Mapping in the IdP**
For Prowler App to correctly identify and provision users, configure the IdP to send the following attributes in the SAML assertion:
For Prowler Cloud to correctly identify and provision users, configure the IdP to send the following attributes in the SAML assertion:
| Attribute Name | Description | Required |
|----------------|---------------------------------------------------------------------------------------------------------|----------|
| `firstName` | The user's first name. | Yes |
| `lastName` | The user's last name. | Yes |
| `userType` | Determines which Prowler role the user receives (e.g., `admin`, `auditor`). If a role with that name already exists, the user receives it automatically; if it does not exist, Prowler App creates a new role with that name with read-only access (visibility over all providers, no management permissions). If `userType` is not defined, the user's existing roles are left unchanged. Role permissions can be edited in the [RBAC Management tab](/user-guide/tutorials/prowler-app-rbac). | No |
| `userType` | Determines which Prowler role the user receives (e.g., `admin`, `auditor`). If a role with that name already exists, the user receives it automatically; if it does not exist, Prowler Cloud creates a new role with that name with read-only access (visibility over all providers, no management permissions). If `userType` is not defined, the user's existing roles are left unchanged. Role permissions can be edited in the [RBAC Management tab](/user-guide/tutorials/prowler-app-rbac). | No |
| `organization` | The user's company name. | No |
<Info>
@@ -100,13 +104,13 @@ Choose a Method:
<Warning>
**Single-Value `userType` Required**
Map `userType` to an IdP attribute that always contains a single value. If the IdP sends multiple values, Prowler App uses only the first value and does not assign multiple roles or select the highest-privilege role.
Map `userType` to an IdP attribute that always contains a single value. If the IdP sends multiple values, Prowler Cloud uses only the first value and does not assign multiple roles or select the highest-privilege role.
</Warning>
<Warning>
**Dynamic Updates**
Prowler App updates these attributes each time a user logs in. Any changes made in the Identity Provider (IdP) will be reflected when the user logs in again.
Prowler Cloud updates these attributes each time a user logs in. Any changes made in the Identity Provider (IdP) will be reflected when the user logs in again.
</Warning>
@@ -138,31 +142,31 @@ Choose a Method:
![Okta App Assignments](/images/prowler-app/saml/okta-app-assignments.png)
7. **Configure User Attributes in Okta**: Okta acts as the central source for user profile information. Prowler App maps the following Okta user profile attributes during each SAML login:
7. **Configure User Attributes in Okta**: Okta acts as the central source for user profile information. Prowler Cloud maps the following Okta user profile attributes during each SAML login:
* **First name** (`firstName`): Maps to the user's first name in Prowler App.
* **Last name** (`lastName`): Maps to the user's last name in Prowler App.
* **First name** (`firstName`): Maps to the user's first name in Prowler Cloud.
* **Last name** (`lastName`): Maps to the user's last name in Prowler Cloud.
![Okta User Profile — First Name and Last Name](/images/prowler-app/saml/okta-user-profile-name.png)
* **Organization** (`organization`): Maps to the company name displayed in Prowler App. This attribute is optional.
* **User type** (`userType`): Determines the Prowler role assigned to the user. This attribute is **case-sensitive**: if it matches the exact name of an existing role in Prowler App the user receives that role; if no role with that name exists, a new one is created with read-only access.
* **Organization** (`organization`): Maps to the company name displayed in Prowler Cloud. This attribute is optional.
* **User type** (`userType`): Determines the Prowler role assigned to the user. This attribute is **case-sensitive**: if it matches the exact name of an existing role in Prowler Cloud the user receives that role; if no role with that name exists, a new one is created with read-only access.
![Okta User Profile — User Type and Organization](/images/prowler-app/saml/okta-user-profile-attributes.png)
To modify these values, edit the user's profile directly in the Okta admin console under the "Profile" tab. Changes are reflected in Prowler App the next time the user logs in via SAML.
To modify these values, edit the user's profile directly in the Okta admin console under the "Profile" tab. Changes are reflected in Prowler Cloud the next time the user logs in via SAML.
<Warning>
**User Type and Role Assignment**
The `userType` attribute controls which Prowler role is assigned to the user:
* If a role with the specified name already exists in Prowler App, the user automatically receives that role.
* If the role does not exist, Prowler App creates a new role with that exact name with read-only access: the user can see all providers and their findings but cannot manage anything. A Prowler administrator (a user whose role includes the "Manage Account" permission) can adjust its permissions afterward through the [RBAC Management tab](/user-guide/tutorials/prowler-app-rbac).
* If `userType` is not defined in the user's Okta profile, the user's existing roles in Prowler App are left unchanged.
* `userType` must contain a single value. If the IdP sends multiple values, Prowler App uses only the first value and does not assign multiple roles.
* If a role with the specified name already exists in Prowler Cloud, the user automatically receives that role.
* If the role does not exist, Prowler Cloud creates a new role with that exact name with read-only access: the user can see all providers and their findings but cannot manage anything. A Prowler administrator (a user whose role includes the "Manage Account" permission) can adjust its permissions afterward through the [RBAC Management tab](/user-guide/tutorials/prowler-app-rbac).
* If `userType` is not defined in the user's Okta profile, the user's existing roles in Prowler Cloud are left unchanged.
* `userType` must contain a single value. If the IdP sends multiple values, Prowler Cloud uses only the first value and does not assign multiple roles.
**Example:** To assign the `IT` role to a user, set the `userType` value to `IT` in Okta. If a role named `IT` already exists in Prowler App, the user receives it automatically upon login. If it does not exist, Prowler App creates a new role called `IT` with read-only access, and a Prowler administrator can adjust its permissions as needed.
**Example:** To assign the `IT` role to a user, set the `userType` value to `IT` in Okta. If a role named `IT` already exists in Prowler Cloud, the user receives it automatically upon login. If it does not exist, Prowler Cloud creates a new role called `IT` with read-only access, and a Prowler administrator can adjust its permissions as needed.
</Warning>
@@ -178,11 +182,11 @@ Choose a Method:
Once the IdP is configured, it provides a **metadata XML file**. This file contains the IdP's configuration information, such as its public key and login URL.
To complete the Prowler App configuration:
To complete the Prowler Cloud configuration:
1. Return to the Prowler SAML configuration page.
2. Enter the **email domain** for the organization (e.g., `mycompany.com`). Prowler App uses this to identify users who should authenticate via SAML.
2. Enter the **email domain** for the organization (e.g., `mycompany.com`). Prowler Cloud uses this to identify users who should authenticate via SAML.
3. Upload the **metadata XML file** downloaded from the IdP.
@@ -225,7 +229,7 @@ Users can also initiate the login process directly from Prowler's login page:
3. Enter their email address from the configured domain
![](/images/prowler-app/saml/saml-signin-2.png)
4. The system redirects users to the IdP for authentication
5. After successful authentication, users are returned to Prowler App
5. After successful authentication, users are returned to Prowler Cloud
This method is useful when users bookmark Prowler or navigate directly to the application.
@@ -233,11 +237,11 @@ This method is useful when users bookmark Prowler or navigate directly to the ap
## Developer and Administrator Guide
This section provides technical details for developers and administrators of self-hosted Prowler instances.
This section provides technical details for developers and administrators of Prowler Local Server instances.
### Environment Configuration
For self-hosted deployments, several environment variables must be configured to ensure SAML SSO functions correctly. These variables are typically set in an `.env` file.
For Prowler Local Server deployments, several environment variables must be configured to ensure SAML SSO functions correctly. These variables are typically set in an `.env` file.
| Variable | Description | Example |
|---------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------|
+6 -5
View File
@@ -1,21 +1,22 @@
---
title: 'Prowler Cloud'
sidebarTitle: 'Getting Started'
---
import { ProviderCards } from "/snippets/provider-cards.mdx"
**Prowler Cloud** is a web application that simplifies running Prowler. This tutorial will guide you through setting up and using it.
We refer to **Prowler App** as the self-hosted version of **Prowler Cloud**.
**Prowler Local Server** is the self-hosted version of **Prowler Cloud**. See [Prowler product families](/getting-started/products) for every official product name.
## Accessing Prowler Cloud and API Documentation
If you are a [Prowler Cloud](https://cloud.prowler.com/sign-in) user, you can access API docs at [https://api.prowler.com/api/v1/docs](https://api.prowler.com/api/v1/docs)
<Note>
**For Prowler App users**
**For Prowler Local Server users**
After [installing](/getting-started/installation/prowler-app) **Prowler App**, access it at [http://localhost:3000](http://localhost:3000).
After [installing](/getting-started/installation/prowler-app) **Prowler Local Server**, access it at [http://localhost:3000](http://localhost:3000).
To view the auto-generated **Prowler API** documentation, navigate to [http://localhost:8080/api/v1/docs](http://localhost:8080/api/v1/docs). This documentation provides details on available endpoints, parameters, and responses.
</Note>
@@ -44,7 +45,7 @@ See [how to configure Social Login for Prowler](/user-guide/tutorials/prowler-ap
</Note>
## Step 2: Log In
Once registered, log in with your email and password to access Prowler App.
Once registered, log in with your email and password to access Prowler Cloud.
<img src="/images/log-in.png" alt="Log In" width="350" />
@@ -84,7 +85,7 @@ For detailed instructions on configuring credentials for each provider, refer to
<ProviderCards />
## Step 5: Test Connection
After adding your credentials of your cloud account, click the `Launch` button to verify that Prowler App can successfully connect to your provider:
After adding your credentials of your cloud account, click the `Launch` button to verify that Prowler can successfully connect to your provider:
<img src="/images/test-connection-button.png" alt="Test Connection" width="700" />
@@ -1,5 +1,5 @@
---
title: 'AWS Organizations in Prowler Cloud'
title: 'AWS Organizations'
description: 'Onboard all AWS accounts in your Organization through a single guided wizard'
---
@@ -464,7 +464,7 @@ Each AWS account you connect through the Organizations wizard counts as one **pr
- **Large organizations**: connecting a 500-account organization will result in up to 500 providers on your subscription. Review your plan limits before proceeding.
- **Deleted providers**: if you later remove an account, the deleted provider no longer counts toward your subscription.
For pricing details, see [Prowler Cloud Pricing](/getting-started/products/prowler-cloud-pricing).
For pricing details, see [Prowler Cloud Pricing](https://prowler.com/pricing).
## Troubleshooting
@@ -505,7 +505,7 @@ No accounts pass the connection test.
- Verify the CloudFormation StackSet was deployed — complete [Step 2](#step-2-deploy-the-cloudformation-stackset) and wait for stack instances to reach **CREATE_COMPLETE**
- Check that the **ExternalId** parameter in the StackSet matches the External ID shown in the Prowler wizard
- If your accounts use IP-based IAM policies, allow [Prowler Cloud public IPs](/user-guide/tutorials/prowler-cloud-public-ips)
- If your accounts use IP-based IAM policies, allow [Prowler Cloud egress IPs](/security/networking)
### Connection Test Fails for Some Accounts
@@ -0,0 +1,11 @@
---
title: 'Azure Management Groups'
description: 'Onboard all Azure subscriptions in your management groups through a single guided wizard'
tag: "Coming Soon"
---
Onboarding Azure management groups through a single guided wizard is coming soon to Prowler Cloud.
Today, Azure subscriptions are onboarded individually. See [Getting Started with Azure](/user-guide/providers/azure/getting-started-azure) and [Bulk Provider Provisioning](/user-guide/tutorials/bulk-provider-provisioning) to automate onboarding multiple subscriptions.
Keep an eye on the [changelog](https://github.com/prowler-cloud/prowler/releases) for updates.
@@ -0,0 +1,11 @@
---
title: 'GCP Organizations'
description: 'Onboard all GCP projects in your organization through a single guided wizard'
tag: "Coming Soon"
---
Onboarding a full GCP organization through a single guided wizard is coming soon to Prowler Cloud.
Today, GCP projects are onboarded individually. See [Getting Started with GCP](/user-guide/providers/gcp/getting-started-gcp) and [Bulk Provider Provisioning](/user-guide/tutorials/bulk-provider-provisioning) to automate onboarding multiple projects.
Keep an eye on the [changelog](https://github.com/prowler-cloud/prowler/releases) for updates.
@@ -1,5 +1,6 @@
---
title: 'Using Multiple LLM Providers'
sidebarTitle: 'Multiple LLM Providers'
---
import { SubscriptionBanner } from "/snippets/subscription-banner.mdx"
@@ -1,29 +0,0 @@
---
title: 'Prowler Cloud Public IPs'
---
## Overview
Prowler Cloud uses a dedicated egress IPv4 address for all outbound connections to customer infrastructure. This enables organizations to implement network-level security controls by whitelisting Prowler's IP address.
## Use Cases
Whitelisting Prowler's egress IP address enables:
- **Credential Usage Control**: Restrict where cloud provider credentials can be used from across AWS, Azure, GCP, and other providers
- **Kubernetes Security**: Limit inbound HTTPS traffic to clusters by allowing only Prowler's IP address
- **Compliance Requirements**: Meet security policies requiring allowlisting of external services
## Query the Egress IP Address
Retrieve Prowler Cloud's current egress IP address using the following command:
```bash
dig egress.prowler.com +short
```
This command returns the IPv4 address that Prowler Cloud uses for all outbound connections to customer infrastructure.
<Note>
The egress IP address is stable, but it is recommended to periodically verify it remains current by querying `egress.prowler.com`.
</Note>
@@ -1,5 +1,6 @@
---
title: 'Import Findings'
sidebarTitle: 'Import Findings'
description: 'Upload OCSF scan results to Prowler Cloud from external sources or the CLI'
---
@@ -133,7 +134,7 @@ Only **Detection Finding** (`class_uid: 2004`) records are accepted. Other OCSF
The **Manage Ingestions** RBAC permission controls access to the ingestion endpoints. Without this permission, findings cannot be submitted via the API or `--push-to-cloud`.
For more information about RBAC permissions, refer to the [Prowler App RBAC documentation](/user-guide/tutorials/prowler-app-rbac).
For more information about RBAC permissions, refer to the [Prowler Cloud RBAC documentation](/user-guide/tutorials/prowler-app-rbac).
## Using the CLI
@@ -1,6 +1,7 @@
---
title: 'Scan Scheduling'
description: 'Create, edit, and monitor recurring scans in Prowler Cloud and Enterprise.'
sidebarTitle: 'Scheduling'
description: 'Create, edit, and monitor recurring scans in Prowler Cloud and Prowler Private Cloud.'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
@@ -21,11 +22,11 @@ Before creating or editing scan schedules, ensure that:
## Schedule Options
A Prowler Cloud or Enterprise subscription supports the following custom recurring schedule options. Prowler self-hosted runs a daily scan automatically and does not expose custom cadence controls.
A Prowler Cloud or Prowler Private Cloud subscription supports the following custom recurring schedule options. Prowler Local Server runs a daily scan automatically and does not expose custom cadence controls.
| Schedule Option | Description | Cloud & Enterprise | Self-Hosted |
|-----------------|-------------|--------------------|-------------|
| Daily | Runs one scan every day at the selected time. | Yes | Yes |
| Schedule Option | Description | Prowler Cloud & Prowler Private Cloud | Prowler Local Server |
|-----------------|-------------|---------------------------------------|----------------------|
| Daily | Runs one scan every day at the selected time. | Yes | Automatic |
| Every 48 hours | Runs one scan every 48 hours, anchored to the selected time. | Yes | — |
| Weekly | Runs one scan every week on the selected day and time. | Yes | — |
| Monthly | Runs one scan every month on the selected day, from day 1 to day 28. | Yes | — |