Aqua Blog

Integrate Aqua and Jira to Turn Security Findings Into Action

Integrate Aqua and Jira to Turn Security Findings Into Action

TL;DR Finding a security issue is only the beginning. Teams still need to get that issue to the people who can investigate and remediate it without adding another manual handoff. Aqua integrates with Jira to automatically open tickets when image scanning or rescanning discovers vulnerabilities, sensitive data or malware. That puts Aqua security findings into an established work management process, helping security and application teams move from detection to remediation without manually recreating findings in Jira.


What does the Aqua integration with Jira do?

Cloud native environments can generate security findings across large numbers of container images. Identifying those findings is important, but remediation depends on getting the information into the workflow where the responsible team can act.

Aqua connects image scanning with Jira so that when Aqua discovers a security issue during an image scan or rescan, it can automatically create a ticket on a specified Jira board. The integration supports security issues including vulnerabilities, sensitive data and malware.

That creates a direct path from detection to remediation workflow. Security teams can use Aqua to identify issues in container images while application and platform teams can manage the resulting work in Jira, without requiring someone to manually translate a finding into a ticket.

The integration is configurable by Jira project and board. Organizations that need findings routed to more than one board can define multiple Jira configuration blocks, with each block specifying its own project, board and related settings.

The distinction matters: Jira manages the work associated with the finding. Aqua remains responsible for identifying the security issue. The integration does not turn Jira into a security control or enforcement point.

How does the Aqua and Jira integration work?

The integration uses the Aqua Webhook Server to connect image scan results with Jira.

An administrator first creates a jira.yaml configuration file on the host running the Aqua Webhook Server container. The configuration identifies the Jira environment, project and board where Aqua should create tickets. Required settings include the Jira URL, user credentials, project name, project ID and board. Administrators can also specify an issue type such as Bug or Task.

Optional settings provide additional control over the resulting Jira issue. These include priority, assignee, affected versions, fix versions and labels. Aqua also supports custom description and summary values, although the documentation recommends leaving those values undefined in most cases because Aqua’s defaults include useful information about the finding, including the image name.

For credentials, the configuration supports a Jira user and password. The documentation recommends using the JIRA_PASSWORD environment variable when starting the webhook container to avoid storing the password in clear text in jira.yaml.

The Aqua Webhook Server container runs on the same host as the configuration file. The Aqua Server is then configured under Settings, Image Scan Results Webhook to send image scan results to the webhook server. The documented endpoints use /scan, with HTTPS on port 8444 or HTTP on port 8084.

From there, the workflow is straightforward: Aqua scans or rescans an image, identifies a supported security issue and the integration opens a Jira ticket on the board defined in the configuration. The example shown on page 13 of the documentation illustrates a Jira vulnerability ticket populated from an Aqua image scan.

What does this integration mean for Aqua customers?

The value of the integration is in connecting security detection to an established remediation process.

Security findings become assigned work. Aqua can identify vulnerabilities, sensitive data and malware during image scanning. The Jira integration turns those findings into tickets where teams can manage ownership and remediation using the Jira processes they already have.

Routing can reflect how teams are organized. Each Jira configuration template targets a single board, and administrators can add multiple configuration blocks when tickets need to reach multiple boards. Jira fields such as priority, assignee, versions and labels provide additional ways to fit tickets into an organization’s existing workflow.

Security and remediation retain clear responsibilities. Aqua discovers the issue and provides the security information. Jira provides the workflow for managing the resulting task. That separation lets teams incorporate Aqua findings into their existing operating model without treating the ticketing system itself as a security control.

This integration addresses one part of the broader security lifecycle: moving image scan findings into remediation. Aqua’s runtime security controls remain separate from this Jira ticket creation workflow.

Where does this matter most?

  • Vulnerability remediation. When Aqua discovers a vulnerability during image scanning, the integration can create a Jira ticket so the responsible team can incorporate remediation into its existing work queue.
  • Sensitive data findings. When image scanning discovers sensitive data, the same workflow can bring the finding into Jira for investigation and follow up.
  • Malware findings. Malware discovered during an image scan or rescan can generate a Jira ticket, giving the team responsible for the affected image a defined item to investigate.
  • Multiple application teams. Organizations using different Jira boards can define more than one configuration block in jira.yaml, allowing the integration to create tickets against different Jira projects and boards as configured.

What do you need to get started?

The integration requires access to your Jira project details and credentials, a host for the Aqua Webhook Server container and a jira.yaml file containing the appropriate Jira configuration. The Aqua Server must also be configured to send image scan results to the webhook endpoint.

After configuration, you can validate the integration by adding an image in Images & Functions, Images. Aqua scans the image and, when one or more security issues are found, a ticket should appear on the Jira board specified in the configuration. If troubleshooting is required, Aqua recommends checking both the Aqua Webhook Server container logs and Aqua Server logs using docker logs.

Customers can follow Aqua’s Jira integration guide on Aqua Docs (login required) to configure the integration, or request a demo to see it in action.

FAQ
What security findings can Aqua create Jira tickets for?

According to the Aqua documentation, the integration can open Jira tickets when image scanning or rescanning discovers a vulnerability, sensitive data or malware.

Can Aqua create tickets on more than one Jira board?

Yes. Each configuration template targets one Jira board, but administrators can put multiple YAML blocks in jira.yaml to configure additional projects and boards.

Can I control the fields Aqua sets in Jira?

Yes. The documented configuration supports settings including issue type, priority, assignee, affected versions, fix versions and labels. Custom descriptions and summaries are also supported, although Aqua recommends retaining its default values because they contain useful information about the finding.

Does the Jira integration replace Aqua's security controls?

No. The integration creates Jira tickets from security issues Aqua discovers during image scanning. Jira provides the workflow for managing those tickets. Aqua’s security capabilities remain responsible for detecting and controlling security risk.

How can I verify that the integration is working?

You can add an image through Aqua to trigger an image scan. If the scan finds one or more security issues, a Jira ticket should be opened on the board configured in jira.yaml. For troubleshooting, check the Aqua Webhook Server and Aqua Server logs.

Aqua Team
Aqua Security is the pioneer in securing containerized cloud native applications from development to production. The Aqua full lifecycle solution prevents attacks by enforcing pre-deployment hygiene and mitigates attacks in real time in production, reducing mean time to repair and overall business risk. The Aqua Platform, a Cloud Native Application Protection Platform (CNAPP), integrates security from Code to Cloud, combining the power of agent and agentless technology into a single solution. With enterprise scale that doesn’t slow development pipelines, Aqua secures your future in the cloud. Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL protecting over 500 of the world’s largest enterprises.
Need to secure enterprise workloads?

Aqua Cloud Native Application Protection Platform (CNAPP)

Go cloud native with the experts!