All integrations

Fairwinds Insights Integration with DefectDojo

Fairwinds Insights Integration with DefectDojo

Fairwinds Insights is a Kubernetes governance and security platform from Fairwinds, the company behind open source projects such as Polaris and Goldilocks. Insights runs a set of reports across your clusters, including Polaris, Trivy, OPA, kube-bench, and Goldilocks, and collects their results into a single stream of action items covering container image vulnerabilities, workload misconfigurations, and policy violations. Action items are available through the Fairwinds Insights REST API as JSON, which DefectDojo can import as a file or sync with the DefectDojo Pro connector.

Fairwinds Insights Integration with DefectDojo

We use Fairwinds Insights to see what is wrong across our Kubernetes clusters, and DefectDojo to make sure someone fixes it. Insights already pulls together image scanning, manifest checks, and admission policy events. Bringing those action items into DefectDojo puts them on the Asset that owns each cluster, with SLAs and owners, next to the application findings for the services running there. On DefectDojo Pro the connector syncs every active cluster without per-cluster setup. Teams that cannot grant API access can upload an export instead, and both routes share a scan type so they deduplicate.

Why Fairwinds Insights Matters

Kubernetes risk comes from two directions at once: vulnerable images and risky configuration. Fairwinds Insights reports both.

  • It aggregates several scanners into one feed, so a team does not have to run and parse each tool separately.
  • Image findings and manifest findings arrive with the namespace, kind, workload name, and container they apply to.
  • Admission controller events show policy violations at the point a change was attempted.
  • Fairwinds tracks whether each action item has been fixed, which is useful state to carry into a central platform.
  • Inside Insights, these findings are separate from application security results. Leadership reporting needs them in the same place.

Advantages of This Integration

What running Fairwinds Insights through DefectDojo provides:

  • One scan type for file and API. The parser uses Fairwinds Insights - Connectors Import, the string the connector reports, so exports and syncs produce one set of findings.
  • Stable deduplication. Each finding carries the Fairwinds action-item ID as its unique ID, with a fallback hash on title, severity, and component name.
  • Fixed items arrive closed. Action items Fairwinds marks as fixed are imported mitigated and inactive, so resolved work does not reappear in the open queue.
  • Severity from Fairwinds' own scale. Fairwinds scores severity from 0.0 to 1.0. DefectDojo applies Fairwinds' breakpoints rather than treating the number as CVSS, which would push everything to Info.
  • Filter by originating scanner. The report that produced each item (for example Polaris or Trivy) becomes a tool: tag, alongside category, cluster, namespace, and event tags.
  • Image or workload as the component. The container image and tag are the component when present, otherwise the Kubernetes resource name, so findings group the way teams fix them.

How This Integration Works

Both routes use the Fairwinds Insights - Connectors Import scan type.

Option 1: File import (Community Edition and DefectDojo Pro). This path exists for organizations that cannot grant Fairwinds API credentials. Save the JSON response from Fairwinds' action-items API endpoint. The parser accepts a bare array of action items, or an object wrapping them under ActionItems, items, or data. Fairwinds uses PascalCase keys such as Title, Severity, and ResourceKind.

In the UI, open the Engagement, choose Import Scan Results, select Fairwinds Insights - Connectors Import, and upload the file. To automate it:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Fairwinds Insights - Connectors Import" 
  -F "file=@fairwinds-action-items.json" 
  -F "product_name=prod-cluster-east" 
  -F "engagement_name=Kubernetes Security" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Fairwinds Insights - Connectors Import" 
  --report-path "./fairwinds-action-items.json" 
  --product-name "prod-cluster-east" 
  --engagement-name "Kubernetes Security" 
  --auto-create-context

Send later exports to /api/v2/reimport-scan/ against the same Test so items no longer reported are mitigated.

Option 2: Fairwinds Insights connector (DefectDojo Pro). Create an API token in the Insights app under Organization Settings, Tokens. A read_only token is sufficient, and it is sent as a bearer token. In the DefectDojo Pro UI:

  1. Keep the pre-filled Location, https://insights.fairwinds.com, or enter your Insights host.
  2. Enter your Insights Organization name, the slug shown in your dashboard URL.
  3. Enter the API token in the Secret field.
  4. Optionally set a Minimum Severity.

DefectDojo enumerates every active cluster, creates a Record for each, and imports that cluster's Security action items as findings. There is no per-cluster configuration. Map each Record to the DefectDojo Asset that owns the cluster.

Data Granularity: What Gets Imported

DefectDojo Field Source in Fairwinds Data Notes
Title Title Flattened to plain text; falls back to "Fairwinds action item" plus ID
Severity Severity (0.0 to 1.0) 0.9+ Critical, 0.7+ High, 0.4+ Medium, 0.1+ Low, otherwise Info
Description Description, resource, image, EventType, Notes Resource shown as namespace/kind/name, with container when known
Mitigation Remediation Flattened to plain text
Component Name ImageName, else ResourceName Image for scanner findings, workload for manifest findings
Component Version ImageTag Only when an image is named
Vulnerability IDs CVEs in Title and Description Fairwinds has no dedicated CVE field
Active / Mitigated Fixed Fixed items import as mitigated and inactive
Unique ID from Tool ID The action-item ID
Tags ReportType, Category, Cluster, namespace, EventType, Tags For example tool:trivy, category:security
Finding type Static Fairwinds reads manifests and images
Deduplication Unique ID, then hashcode Fallback hash: title, severity, component name

Repeated action-item IDs within one file are imported once.

Use Cases

Across a cluster fleet: A platform team with a dozen clusters enables the connector, and each active cluster becomes a Record mapped to its Asset. Security leads report open Critical and High Kubernetes findings by cluster without exporting anything by hand.

For image vulnerability follow-up: Trivy results from Insights arrive with the image and tag as the component, so a team can see every workload running a vulnerable image and track the rebuild to closure.

For configuration hardening: Polaris findings such as missing resource limits or privileged containers land on the cluster's Asset with Fairwinds' remediation text, and can be assigned to the team that owns each namespace.

In a restricted environment: An organization still reviewing outbound API access exports action items and imports them as files. When the connector is approved, action-item IDs keep the findings aligned.

Operational Tips

  • Filter on the tool: tag to separate image CVEs from configuration findings in dashboards and SLA reports.
  • Items without a cluster still receive a bare cluster: tag. This mirrors the connector, so leave it rather than cleaning it up by hand.
  • Review the severity breakpoints before setting SLAs. A Fairwinds score of exactly 0.9 is Critical, and anything under 0.1 is Info.
  • Use the namespace tags to assign findings to the owning team when one cluster hosts several teams' workloads.
  • Use Minimum Severity on the connector, or minimum_severity on import, to keep low-scored hygiene items out of the queue.
  • Map each cluster to a stable Asset and keep it. Changing the mapping later splits a cluster's history across Assets.