Skip to main content

Install in Docker with the Contrast CLI

Use this workflow to install and configure a Contrast Contrast CVE Shield agent with the Contrast CLI that attaches to your own application. CVE Shield only supports Java applications currently. Check that your application uses Java before you continue.

Contrast CLI commands for CVE Shield support Free tier prospects who find instrumenting their first application challenging. Paid customers can use them too, but they are intended for temporary debugging, troubleshooting, and evaluation. For production rollouts, keep using your usual agent deployment method.

You'll need an active CVE Shield account. Learn more about CVE Shield, signing up for CVE Shield and trying Contrast for free.

Before you begin

Make sure you have everything you need before you start.

  • macOS or Linux with a UI and browser

  • Homebrew

  • A Java application

  • Docker Engine

  • Docker Desktop (optional)

  • A Contrast account and the URL of your Contrast instance

  • A web browser on the same machine for signing in to Contrast

Get started

  1. In NorthstarNorthstar, under Use your own app, select Add application.

  2. Under Select an installation method, select In Docker, with the Contrast CLI.

Instrument a Dockerfile

If you don't already have a Docker container, you can instrument a Dockerfile using the Agent Wizard. The CVE Shield agent survives rebuilds, redeploys, and new instances without needing to run these actions repeatedly.

  1. Under Install with the Contrast CLI, select Install a new agent.

  2. In a terminal window, run the CLI commands displayed in the agent wizard.

  3. Rebuild the container to deploy the agent.

  4. Open your Java application. Click a few links or send a few requests. This gives the agent something to detect.

Attach an agent to an already-running Docker container

If you already have a running Docker container, you can attach a CVE Shield agent to it without rebuilding the container using the Agent Wizard.

  1. Under Install with the Contrast CLI, select Install a new agent.

  2. In a terminal window, run the CLI commands displayed in the agent wizard.

  3. Open your Java application. Click a few links or send a few requests. This gives the agent something to detect.

Verify agent deployment

Select View agent activity. If your application appears, the agent is working.

Your application should appear in NorthstarNorthstar on the Agent management screen soon after you start using it. When your application appears, CVE Shield starts finding vulnerabilities in that application.