Skip to main content

Orca Security

Integrate Orca Security with Cloudaware to ingest cloud security posture and risks for unified reporting.

info
  • Audience: Cloudaware administrators, SecOps teams, cloud security teams, and risk management teams
  • Outcome: Orca Security findings, risks, and asset context are available in CMDB for security posture reporting, prioritization, and asset correlation

Capabilities

The integration supports:

  • Read-only discovery of Orca Security findings, risks, and assets
  • Relationship mappings between Orca Security risks, Cloudaware Applications, and assets in the CMDB
  • Search and reporting for Orca Security objects using CMDB Navigator, CMDB list views, and reports

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Orca API URL or region.
  • Orca API token with Viewer role or equivalent read access.

Add Orca Security Details to Cloudaware

  1. In Cloudaware, go to Admin.
  2. Find Orca Security, then click + ADD.
  3. Enter the following values:
    • Name: Enter a display name for the Orca Security integration.
    • API URL/Region: Enter the Orca API URL or region for your environment.
    • API Token: Enter the Orca API token.
  4. Click Save.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View Orca Security Data in CMDB

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select ORCA SECURITY.
  3. Open the Orca Security findings, risks, or asset object list to view records.

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Failed or Integration Shows Red Status

  • Verify that the Orca API URL or region is correct for your Orca environment.
  • Confirm that the API token is valid, active, and has Viewer role or equivalent read access.
  • Check whether the account associated with the token is active in Orca Security.
  • Re-enter the API token by editing the integration in Cloudaware.

Orca Security Data Is Missing

  • Allow the initial discovery cycle to complete.
  • Confirm that the API token has access to the missing findings, risks, and assets in Orca Security.
  • Review the Orca account scope and permissions for the affected cloud accounts or assets.
  • In CMDB Navigator, verify that you are viewing the ORCA SECURITY section and related resources.

Changes in Orca Security Are Not Yet Visible in Cloudaware

  • Synchronization is periodic. Wait for the next collection cycle.
  • Confirm that the API token can still access the changed findings, risks, or assets.
  • Review the integration status and error messages in Cloudaware Admin.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate API tokens, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Orca Security.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Orca Security.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated Orca API token with the minimum read permissions required for Cloudaware discovery.
  • Avoid using personal administrator tokens for long-running integrations.
  • Store Orca API tokens only in approved credential stores and avoid sharing them through tickets, chat, or documentation.
  • Rotate API tokens according to your organization's credential-rotation policy and immediately after suspected exposure.
  • Review the Orca token scope regularly to confirm that Cloudaware can access only the required findings, risks, and assets.
  • Update the Cloudaware integration immediately if the API token is revoked, regenerated, or replaced in Orca Security.