Orca Security
Integrate Orca Security with Cloudaware to ingest cloud security posture and risks for unified reporting.
info
- Audience: Cloudaware administrators, SecOps teams, cloud security teams, and risk management teams
- Outcome: Orca Security findings, risks, and asset context are available in CMDB for security posture reporting, prioritization, and asset correlation
Capabilities
The integration supports:
- Read-only discovery of Orca Security findings, risks, and assets
- Relationship mappings between Orca Security risks, Cloudaware Applications, and assets in the CMDB
- Search and reporting for Orca Security objects using CMDB Navigator, CMDB list views, and reports
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Orca API URL or region.
- Orca API token with
Viewerrole or equivalent read access.
Add Orca Security Details to Cloudaware
- In Cloudaware, go to Admin.
- Find Orca Security, then click + ADD.
- Enter the following values:
- Name: Enter a display name for the Orca Security integration.
- API URL/Region: Enter the Orca API URL or region for your environment.
- API Token: Enter the Orca API token.
- Click Save.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View Orca Security Data in CMDB
- In Cloudaware, open CMDB Navigator.
- In the left pane, select ORCA SECURITY.
- Open the Orca Security findings, risks, or asset object list to view records.
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Failed or Integration Shows Red Status
- Verify that the Orca API URL or region is correct for your Orca environment.
- Confirm that the API token is valid, active, and has Viewer role or equivalent read access.
- Check whether the account associated with the token is active in Orca Security.
- Re-enter the API token by editing the integration in Cloudaware.
Orca Security Data Is Missing
- Allow the initial discovery cycle to complete.
- Confirm that the API token has access to the missing findings, risks, and assets in Orca Security.
- Review the Orca account scope and permissions for the affected cloud accounts or assets.
- In CMDB Navigator, verify that you are viewing the ORCA SECURITY section and related resources.
Changes in Orca Security Are Not Yet Visible in Cloudaware
- Synchronization is periodic. Wait for the next collection cycle.
- Confirm that the API token can still access the changed findings, risks, or assets.
- Review the integration status and error messages in Cloudaware Admin.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate API tokens, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Orca Security.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Orca Security.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated Orca API token with the minimum read permissions required for Cloudaware discovery.
- Avoid using personal administrator tokens for long-running integrations.
- Store Orca API tokens only in approved credential stores and avoid sharing them through tickets, chat, or documentation.
- Rotate API tokens according to your organization's credential-rotation policy and immediately after suspected exposure.
- Review the Orca token scope regularly to confirm that Cloudaware can access only the required findings, risks, and assets.
- Update the Cloudaware integration immediately if the API token is revoked, regenerated, or replaced in Orca Security.