Buildkite
6 min
Buildkite
Edition: Enterprise only
The Buildkite integration scans build logs and artifacts for credentials and other sensitive data.
Configuration
The Buildkite integration can be configured in TruffleHog under Integrations, or via a local configuration file (below).
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need a Buildkite API access token with GraphQL API access enabled and the following scopes:
- Organization Access — read access to your Buildkite organization.
- Read Artifacts — read access to build artifacts.
- Read Builds — read access to build metadata.
- Read Build Logs — read access to build log output.
- Read Pipelines — read access to pipeline configuration.
Tokens without GraphQL API access enabled will fail to authenticate even when the scopes are correct.
Local configuration
sources:
- connection:
"@type": type.googleapis.com/sources.Buildkite
# Token must have GraphQL API access enabled.
# Token requires Organization Access, Read Artifacts,
# Read Builds, Read Build Logs, and Read Pipelines.
token: XXXXXXXXXXXXXXXXXXXXXXXXXX
name: Buildkite logs and artifacts
scanPeriod: 12h
type: SOURCE_TYPE_BUILDKITE
verify: true
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
token | string | Yes | A Buildkite API access token with GraphQL API access enabled and the scopes listed above. |
Capabilities
Feature | Supported |
|---|---|
Scan build logs | ✅ |
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Auto-resume | ✅ |
Notes
- Objects larger than 10 MB are not scanned.
- Include and exclude filters are not supported. The scanner covers all builds, artifacts, and logs the token has access to.