HashiCorp Cloud Platform
Scan Azure DevOps for secrets
Connect Azure DevOps as a data source to HCP Vault Radar to scan your Azure DevOps projects for sensitive data and secrets. Vault Radar supports scanning Azure DevOps Server and Azure DevOps Cloud.
If you are new to HCP Vault Radar, checkout the HCP Vault Radar quickstart series.
Prerequisites
HCP IAM user with the HCP owner, or admin role
Vault Radar agent deployed and running (agent scan only)
Access to an Azure DevOps organization and project
A personal access token with access scoped to All accessible organizations with the following permission scopes:
Code > Read Entitlements > Read Graph > Read Identity > Read Member Entitlement Management > Read Notifications > Read, Write, Manage Project and Team > Read Service Connections > Read User Profile > Read Work Items > Read, Write
Add an Azure DevOps data source
You can add and scan Azure DevOps Cloud or Azure DevOps Server using the HCP Vault Radar cloud scan or HCP Vault Radar agent scan.
Add Azure DevOps Cloud as a data source to scan your Azure DevOps projects for secrets.
Log into the HCP Portal with an HCP IAM user that has the HCP owner or admin role.
Click Vault Radar.
Click Settings.
Click Data Source Hosts.
Click Add data source host.
Select HCP Vault Radar Scan.
Select Azure DevOps Cloud.
Enter the personal access token in the Enter your Azure DevOps personal access token field.
Click Next.
Select either All data sources or Select data sources.
Click Finish
Assign a group to a resource
Once you add a data source, an HCP user with the admin role must assign
a group to each of the monitored resources within each data source. You can
assign each resource to only one group.
If you do not already have a group, refer to the Identity and Access Management groups documentation to create a group.
Navigate to the Project dashboard.
Click Access control (IAM).
Click Add new assignment.
Search the name of the group in the Search for an assignee search field.
Click the group name in the search results.
Click the Select service pulldown menu and select Vault Radar.
Click the Select role pulldown menu and select the Vault Radar Developer role.
Click Save.
Click Back to Dashboard.
Click Vault Radar.
Click Resources.
Select the resource you want to assign to a group and click Assign groups.
Click the Assign resoruce to group pulldown menu.
Select the group that requires access to the resource.
Select either the Viewer or Contributor role.
Click OK.
Update data source host
Navigate to Settings, and then Data Source Hosts, and click the three dots to the right.
To update the monitored data sources, click Edit data sources
To update the token, click Edit data source host details
Tutorials
If you are new to HCP Vault Radar, checkout the HCP Vault Radar quickstart series.