Source archiving
Source archiving
Edition: Enterprise only
Archiving stops TruffleHog from scanning an integration source while keeping every finding it has already reported. Alternatively, you can permanently delete a source if you don't want to retain data associated with that integration source.
Overview
Leverage integration source archiving when you want to retire an integration. Archiving preserves and retains the secrets associated with that source.
Archiving is permanent. If you need the source scanned again, you will need to setup a new integration.
| Archive | Delete |
|---|---|---|
Scanning | Stops | Stops |
Findings | Preserved | Destroyed |
Reversible | No | No |
When to use | Retire the integration but keep the findings | Remove the integration and its data |
Archiving is available in TruffleHog Enterprise only.
How it works
Archiving moves a source into an Archived state. Three things follow from that.
- Scanning stops. No new scans are scheduled, and a scan already in progress is stopped rather than left to finish. This occurs whether the source runs on TruffleHog's hosted scanners or a self-hosted scanner.
- Verification freezes, but only when every source for a finding is archived. A single secret is often reported by more than one source. TruffleHog stops re-verifying a finding only when all of the sources that surfaced it are archived. If the same secret is still visible to an active source, it keeps re-verifying and behaves normally. A frozen finding keeps its last known verification status and shows a Verification frozen badge on the finding and in the secrets list. Frozen means that status is historical and won't update, not that the secret is invalid. Frozen findings are excluded from MTTR.
- Archiving is recorded in the activity log.
Archive a source
Archiving requires the Admin or Editor role. Viewers cannot archive a source.
- Go to Integrations.
- Find the source you want to archive and click the three-dot menu at the right of its row.
- Click Archive.
- Read the confirmation dialog, which states that scanning stops permanently and findings are preserved, then confirm.
The source now shows a gray Archived badge and drops out of the list, which hides archived sources by default. If the request fails, the dialog stays open and shows the error inline.
View archived sources
Archived sources are hidden from Integrations by default. Select Show archived in the filter bar to include them. They appear dimmed with a gray Archived badge.
Findings from archived sources are never hidden. They stay visible and searchable in Secrets whether or not archived sources are shown.
Delete an archived source
You can delete a source that you have already archived.
- Go to Integrations and select Show archived.
- Click the three-dot menu on the archived source's row and click Delete.
Deleting is permanent and destroys the source's findings.
Notes
- Archived sources are excluded from active integration counts.
- An archived source cannot be edited, re-authorized, or scanned on demand. Scan now, Edit, and any reauthorization option are removed from its three-dot menu.
- The Verification frozen badge doesn't show a date. The archive time is in the activity log entry.
- Creating a new source for the same system rescans it and surfaces the same secrets, but it starts with fresh triage state and does not inherit the archived source's history.
Troubleshooting
Error | Cause | Solution |
|---|---|---|
Archive does not appear in the three-dot menu | Your role is Viewer | Ask an Admin or Editor to archive the source. |
A self-hosted source keeps scanning after being archived | The scanner is running a version that predates archive support | Upgrade the scanner. No new scans are dispatched to it in the meantime, so the source stops scanning once the scanner recycles. |