Building your application inventory
The quality and completeness of your organization’s application definitions are essential
for IBM®
Concert ’s ability to surface
vulnerabilities, compliance issues, and other details about your operational health. You can define
your applications and environments from ingested components or generate SBOM files in the supported
formats. With this information, Concert provides a
holistic view of your application and environment topology.
Generating ConcertDef SBOMs
To build your application topology, you can generate and import three SBOM files using the custom ConcertDef (Concert -defined) schema containing details about your application components and dependencies.
Importing data to Concert
There are multiple methods you can use to import application and dimensional data to your Concert instance.
Defining an application from components
One method for defining your applications is to select relevant images and repositories from your component library. The component library is populated based on existing data ingestion jobs or SBOM files that pull application component and lifecycle data from your third-party tools and services.
Defining an environment from components
One method for defining your environments is to select relevant images from a library of ingested components. The component library is populated based on existing data ingestion jobs that pull application and environment data from your third-party tools and services.
Creating a data ingestion job
The quality and completeness of your organization’s application definitions are essential to Concert 's ability to surface vulnerabilities, compliance issues, and other valuable insights. One way to share your application-related data with Concert is by creating an ingestion job.
Exporting and importing an application data
You can export and download your application data and import it into a new Concert instance to migrate or replicate an environment. The output of the export will be a .tar
file and the output is stored in LZ bucket. The data is then reassessed when imported back into a Concert instance. You can export the application SBOM, Build SBOM, Deploy SBOM, and Package SBOM.
Exporting and importing a environment data
You can export and download your environment data and import it into a new Concert instance to migrate or replicate an environment. The output of the export will be a .tar
file and the output is stored in LZ bucket. You can export the basic environment details and related certificate data. The data is then reassessed when imported back into a Concert instance.