Webhook icon
Schedule icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Gate Container Images on Trivy CVE Counts

Pre-deploy Trivy scan that gates on critical/high CVE budgets and alerts Slack on breach.

Categories
CloudInfrastructureinfrastructure

A scanner that runs but nobody reads is decoration. This blueprint puts Trivy in front of the rollout: scan the image, count criticals and highs, breach either budget → Slack with the numbers, clean → logged for the trend. New CVEs against the same image get caught by the nightly schedule.

How it works

  1. run_trivy (io.kestra.plugin.scripts.shell.Commands on Docker) runs the pinned Trivy image against your target with --format json --severity CRITICAL,HIGH, then extracts counts via the ::{"outputs": ...}:: protocol (Python fallback included since the scanner image ships Python, not Node).
  2. check_gate (io.kestra.plugin.core.flow.If) compares both counts to their budgets. Breach → alert_cve_breach; clean → log_clean.
  3. The errors block alerts Slack when the scan itself fails — absence of data never looks like "clean".
  4. Triggers: a Webhook (trivy-scan) for the deploy pipeline plus a disabled nightly Schedule to catch freshly published CVEs.

What you get

  • A release gate backed by real CVE counts.
  • Alerts that state the breach size per category.
  • CVE trend in the execution history; cve_counts JSON for dashboards.

Who it's for

  • Teams that scan in CI but have no release gate.
  • Platform engineers who want one CVE budget across services.
  • Security champions chasing new-CVE drift on the same image.

Why orchestrate this with Kestra

Trivy produces a report; the flow turns it into a decision. The webhook entry point, the branch, the alert, the self-reporting failure channel, and the history are all there — and the next step (fail the deploy, open a ticket, pin the base image) is one task away.

Prerequisites

  • Docker available on the Kestra Worker.
  • The image pullable from wherever the Worker runs (public or credentialed registry).
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for breach and scan-failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set image to your release candidate and the two budgets.
  3. Run once and read cve_counts.
  4. Wire the trivy-scan webhook into your deploy pipeline.

How to extend

  • Add Fail on breach for a hard gate.
  • Loop over several images with a ForEach.
  • Store cve_counts in KV and diff week-over-week.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.