Snyk
Integrate Snyk with Cloudaware to inventory organizations, projects, and application security findings for AppSec reporting.
info
- Audience: Cloudaware administrators, AppSec teams, vulnerability management teams, and cloud operations teams
- Outcome: Snyk organizations and projects are available in CMDB for application security visibility, vulnerability context, and reporting
Capabilities
The integration supports:
- Read-only discovery of Snyk organizations and projects
- AppSec context in CMDB for Snyk-managed projects and related findings
- Reporting for application security posture across Snyk organizations and projects
- Search and reporting for Snyk objects using CMDB Navigator, CMDB list views, and reports
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Snyk Enterprise plan.
- Snyk API key with read access to organizations, projects, and issues.
Add a Snyk Account to Cloudaware
- In Cloudaware, go to Admin.
- Find Snyk, then click + ADD.
- Enter the following values:
- Name: A display name for the Snyk integration.
- API Token: The Snyk API token with read access.
- Click Save.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View Snyk Data in CMDB
- In Cloudaware, open CMDB Navigator.
- In the left pane, select SNYK.
- Open an object list, e.g., Snyk Organizations or Snyk Projects, to view discovered records.
Supported Objects
Cloudaware ingests the following Snyk objects:
| Snyk Object | CMDB Object API Name |
|---|---|
| Snyk Account | CA10SK__CaSnykAccount__c |
| Snyk Organization | CA10SK__CaSnykOrganization__c |
| Snyk Project | CA10SK__CaSnykProject__c |
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Verify that the Snyk API token is correct and active.
- Confirm that the API token belongs to a Snyk user or service account with read access to the expected organizations.
- Re-enter the API token by editing the integration in Cloudaware.
No Snyk Data Appears in CMDB
- Allow the initial discovery cycle to complete.
- Confirm that the Snyk API token can access the organizations and projects expected to appear in Cloudaware.
- In CMDB Navigator, verify that you are viewing the SNYK section and related resources.
Some Projects or Findings Are Missing
- Confirm that the projects are visible to the Snyk API token.
- Check whether the projects belong to organizations outside the API token scope.
- Review recent changes after the next discovery cycle completes.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate the Snyk API token, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Snyk.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Snyk.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated Snyk API token for Cloudaware discovery where possible.
- Grant the API token only the read access required for organizations, projects, and issues that Cloudaware must discover.
- Do not reuse personal administrator tokens for production integrations.
- Rotate the Snyk API token according to your organization's credential management policy.
- Review Snyk project and issue visibility with your AppSec team, because project names, repository references, and vulnerability context may contain sensitive application details.
- Remove or revoke unused API tokens when the integration is retired.