> ## Documentation Index
> Fetch the complete documentation index at: https://docs.backline.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Inspector Integration

> Import container image vulnerabilities from Amazon Inspector on a recurring schedule

## Overview

Connect Amazon Inspector so Backline imports the container image vulnerabilities it finds in your ECR repositories — automatically, on a recurring schedule.

Connect each AWS account once, choose the regions it covers, and Backline keeps that part of your backlog current.

<Note>
  This integration imports **container image findings only**. Amazon Inspector findings for EC2 hosts, Lambda functions, code, and network reachability are not imported.
</Note>

## What You Can Do

* Import container image vulnerabilities from Amazon Inspector
* Cover several AWS accounts by adding one connection per account
* Choose exactly which AWS regions each connection covers
* Keep the Backline backlog tracking what you see in the Inspector console — fixed vulnerabilities stop being open work

## Prerequisites

Before connecting AWS Inspector, ensure you have:

* Amazon Inspector enabled, with **ECR scanning** switched on, in each region you want to connect
* Permissions to deploy CloudFormation stacks in that AWS account (requires IAM role creation)
* Your 12-digit AWS Account ID

## Connecting AWS Inspector

<Steps>
  <Step title="Go to Integration Hub">
    Navigate to Integrations from the main menu.
  </Step>

  <Step title="Select AWS Inspector">
    Find and click on the AWS Inspector integration card.
  </Step>

  <Step title="Deploy CloudFormation Stack">
    Click the CloudFormation link in Backline, or use the direct link below, to create the integration role in your AWS account:

    [Deploy CloudFormation Stack](https://console.aws.amazon.com/cloudformation/home?region=us-east-1#/stacks/create/review?templateURL=https://backline-integration-templates.s3.amazonaws.com/backline-aws-inspector-integration-role.yaml\&stackName=BacklineInspectorIntegration)

    Enter a unique **External ID** in the `ExternalId` stack parameter when prompted. You choose this value yourself — it must be at least 8 characters — and it secures the cross-account trust relationship. Keep it handy: you enter the same value in Backline in a later step.

    The stack creates an IAM Role in your account with read-only access to Amazon Inspector, and nothing else. See [What Backline is allowed to do](#what-backline-is-allowed-to-do) below.
  </Step>

  <Step title="Get Stack Outputs">
    After the stack completes, go to the **Outputs** tab and copy the **Role ARN**.
  </Step>

  <Step title="Enter Connection Details">
    In Backline, enter:

    * **Account ID**: Your 12-digit AWS Account ID
    * **External ID**: The value you provided during stack creation
    * **Role ARN**: The ARN from the CloudFormation outputs
    * **AWS Regions**: The regions this connection should import findings from. Leave empty to use the default region only.
  </Step>

  <Step title="Connect">
    Click **Connect**. Backline verifies that it can read Amazon Inspector findings in **every region you chose** before saving the connection.

    If a region cannot be read — the role is missing, the External ID does not match, or Inspector ECR scanning is not enabled there — the connection is refused and Backline names the region that failed. Fix that region, or remove it from the connection, and try again.
  </Step>

  <Step title="Set the In-Use Window">
    On the Configuration step, set the **In-Use Window (days)** — how recently Amazon Inspector must have seen an image in use for its vulnerabilities to count as open work. It defaults to **30 days**. See [Images that are not running](#images-that-are-not-running).
  </Step>
</Steps>

## What Backline is allowed to do

The CloudFormation template grants exactly two read-only Amazon Inspector actions and no others:

| Action | Why it is needed |
| - | - |
| `inspector2:ListFindings` | Reads the container image findings themselves. |
| `inspector2:BatchGetAccountStatus` | Tells a region where Inspector is switched off apart from a region that is genuinely clean. |

No write permission of any kind is requested. Backline never suppresses, closes, re-scores, or otherwise changes anything in your AWS account or in Amazon Inspector.

<Note>
  `BatchGetAccountStatus` matters more than it looks. When Inspector is disabled in a region, `ListFindings` succeeds and returns nothing — indistinguishable from a region with no vulnerabilities. Without the status check, switching Inspector off in a region would look to Backline like every vulnerability there had been fixed.
</Note>

## Connecting Multiple AWS Accounts

One AWS Inspector connection covers **one AWS account** and the regions you chose for it. To cover more accounts, add another connection.

<Steps>
  <Step title="Open Integration Details">
    Go to the AWS Inspector integration card in the Integration Hub and click **Configure**.
  </Step>

  <Step title="Add Connection">
    At the bottom of the integration details, click **Add Connection**.
  </Step>

  <Step title="Enter the New Account's Details">
    Provide the Account ID, External ID, Role ARN and Regions for the additional AWS account, then set its In-Use Window on the Configuration step. Deploy the CloudFormation stack in that account first.
  </Step>

  <Step title="Save">
    Click **Save**. The connection appears in the list alongside your existing accounts.
  </Step>
</Steps>

Each AWS account can be connected once. Submitting a second connection for an account that already has one is refused.

## What Is and Isn't Imported

Backline imports a finding when all of the following hold:

* it is a package vulnerability in a container image in an ECR repository;
* the image is in an AWS account and region one of your connections covers;
* Amazon Inspector reports it as **active**.

Everything else is left alone.

## Keeping the Backlog Current

Backline re-reads each connection on a recurring schedule, the same one it uses for every other connected scanner. Each sync works one region at a time:

* A vulnerability that Inspector no longer reports **stops being open work**.
* A region Inspector reports as clean **resolves everything Backline previously imported from it**.
* A region Backline **could not read** is left exactly as it is. Its findings are never resolved on the strength of a failed read, so a broken connection can never look like a clean bill of health.

That last rule is why the setup check names the specific region it could not read: a region that stops being readable stops refreshing, quietly.

## Images That Are Not Running

Amazon Inspector reports every image it has ever scanned, including images that were replaced months ago. Left alone, those vulnerabilities bury the ones you are actually exposed to.

So Backline keeps them out of your working backlog. **Vulnerabilities in an image Amazon Inspector has not seen in use within the connection's in-use window are dismissed automatically**, and **return to open work by themselves once Inspector sees the image in use again**. They appear as ordinary automatically dismissed findings — the same kind Backline shows elsewhere — and you cannot return one to open work by hand; it comes back when the image does.

The in-use window is set per connection, on the connection's **Configuration** step, and **defaults to 30 days**. Change it to match how often you actually redeploy. A change takes effect from that connection's next sync.

<Note>
  **An image Amazon Inspector reports no in-use information for is never treated as unused.** That covers both an image that was never deployed and an account where Inspector's in-use detection is not enabled — in either case the findings stay in your backlog. Backline only acts on evidence that an image has stopped running, never on the absence of it.
</Note>

Two consequences worth knowing:

* An image that was **already unused the first time Backline saw it** has its vulnerabilities left out rather than imported and dismissed, so they are not listed among your dismissed findings either. They are imported as open work once Inspector sees the image in use again.
* A vulnerability that Inspector **stops reporting** while its image is unused does **not** come back when the image is redeployed. Only findings that a sync actually re-reports return.
* Use is judged per repository, not per image build. A repository with one image still running keeps its findings open, because those are that running image's findings too.

<Warning>
  If you **delete a connection**, or **remove a region** from one, Backline stops reading that scope. Findings already imported from it stay open and nothing will resolve them, because no future sync will ever revisit them. Resolve or dismiss them in Backline if you no longer want them in your backlog.
</Warning>

## Troubleshooting

**The connection is refused and names a region.** Backline could not read Amazon Inspector there. Check that Inspector is enabled with ECR scanning switched on in that region, that the CloudFormation stack deployed successfully, and that the External ID in Backline matches the one you gave the stack. If you do not need that region, remove it from the connection.

**The connection saved but no findings arrived.** Confirm Amazon Inspector has actually scanned images in the connected regions, and that the findings are container image findings rather than EC2 or Lambda ones. Findings appear after the first scheduled sync completes.

**Findings I fixed are still open.** Resolution happens on the next sync of whichever region the finding came from. If that region has become unreadable, nothing will resolve — run **Test Connection** on the integration to check.
