Using ScanSuite
ScanSuite is the resource for batch management of compliance scans. It associates multiple profiles and creates child Scan resources from one shared template.
TOC
When to Use ScanSuiteBasic ScanSuite ExampleScheduled ScanSuite ExampleScanSuite with Email NotificationScanSuite ParametersScan Template ParametersReport Delivery ParametersScanSuite AnnotationsMonitoring ScanSuite ExecutionWhen to Use ScanSuite
Use ScanSuite when you need to:
- manage multiple profiles together
- schedule recurring compliance scans
- apply the same scan template to a group of child
Scanresources - pause, resume, or trigger a batch of related scans as one unit
Use Using Scan instead when you only need one profile and one Scan resource.
Basic ScanSuite Example
Scheduled ScanSuite Example
ScanSuite with Email Notification
ScanSuite Parameters
The following table describes the top-level parameters of the ScanSuite resource:
Scan Template Parameters
The following table describes the parameters available under spec.scanTemplate:
For ScanSuite, the node selection and scheduling fields are configured under spec.scanTemplate, not directly under spec.
See Node Selection and Scheduling for the shared behavior and profile-specific limits.
Report Delivery Parameters
If spec.reportDelivery is configured, the following fields are used for email delivery:
ScanSuite Annotations
The following annotation can be used to control ScanSuite execution:
Monitoring ScanSuite Execution
Use ScanSuite to inspect the batch resource, and use Scan to inspect the child executions created from it.