For Nebius AI Cloud, Wiz agentless disk scanning is unavailable. Only scanning through API is supported.
Prerequisites
- Web console
- CLI
-
Make sure you are in a group that has the
adminrole within your tenant or project; for example, the defaultadminsgroup. You can check this in the Administration → IAM section of the web console. - Get access to Wiz with a role that has write permissions for deployments. For more details, see the Wiz documentation (requires logging in).
Steps
Create a service account
Create a dedicated service account for Wiz. This way, the access of the connector does not depend on the accounts that you use for other purposes.- Web console
- CLI
- In the sidebar, go to Administration → IAM.
- Click Create resource → Service account.
- In the window that opens, specify the service account name (for example,
wiz-scanner) and select the project. - Click Create and continue.
Add the service account to the group
The group to which you add the connector’s service account manages its access to your resources:-
To let the connector read the configuration of your resources, add the service account to the default
viewersgroup. This group has the tenant-wideviewerrole, so the connector can view the resources of all projects in the tenant. Theviewerrole also provides access to the data in your resources. -
If you want the connector to read the configuration of your resources without access to the data in them, grant the
security-auditorrole to a custom group and add the service account to this group instead. For instructions, see Managing custom groups.
- Web console
- CLI
- In the sidebar, go to Administration → IAM.
- On the Groups tab, click the viewers group.
- On the group page, click Manage → Members.
- In the window that opens, switch to the Service accounts tab.
- Select the project in which you created the service account.
- Find the service account and click Add next to its name.
Create an authorized key
Wiz authenticates as the service account with an authorized key pair: you upload the public key to Nebius AI Cloud and pass the private key to Wiz.-
Create a key pair on your local machine:
This command creates the
public.pemandprivate.pemkey files in the directory where you run it. -
Upload the public key and get the ID of the created authorized key:
- Web console
- CLI
- In the web console, go to Administration → IAM.
- Open the Service accounts tab.
- Open the page of the required service account.
- Click Upload authorized key.
- Click Attach file and then select
public.pem. - (Optional) Set an expiration date.
- Click Upload key.
Create a connector in Wiz
In Wiz, create a connector for Nebius AI Cloud and specify the following values:-
ID of the service account:
- Web console
- CLI
In the sidebar, go to Administration → IAM. On the Service accounts tab, find the service account that you created and copy its ID. - ID of the authorized key. In Wiz, it is referred to as the public key ID.
-
Private key, the
private.pemfile.
Troubleshooting
Wiz can’t access your resources
If you set an expiration date for the authorized key, the connector stops working after this date. To restore access:- In the web console, open the page of the service account and switch to the Authorized keys tab.
- Check the expiration date of the key that the connector uses.
- If the key has expired, create a new authorized key for the same service account.
- In the settings of the connector in Wiz, replace the ID of the authorized key and the private key with the new ones.