Adapters
32 adapters in 13 categories. Add one in the console under System > Adapters, or with pando adapter add. Settings marked Credential are stored encrypted and never shown again.
Identity
OpenID Connectoidc
Sign in through any OpenID Connect provider: Okta, Microsoft Entra ID, Google Workspace, Keycloak, Authentik and others.
issuerIssuer URLRequiredThe provider's issuer. Pando reads <issuer>/.well-known/openid-configuration for the rest.
client_idClient IDRequiredThe client ID of the web application you registered for Pando.
client_secretClient secretCredentialThe application's client secret. Stored encrypted and never shown again.
scopesScopesSpace-separated. Add groups if your provider needs a scope to send them.
groups_claimGroups claimThe claim that lists the person's groups. Each one becomes a synced group in Pando.
subject_claimSubject claimThe claim that identifies a person and never changes. Microsoft Entra ID needs oid.
username_claimUsername claimThe claim holding the person's username in Pando.
email_claimEmail claimThe claim holding the person's email address.
name_claimName claimThe claim holding the person's display name. When it is empty, given_name and family_name are used.
hosted_domainGoogle Workspace domainOnly accept Google accounts from this domain. Without it, anyone with a Google account can sign in.
promptPromptAsk the provider to always show its sign-in form or account chooser.
disable_userinfoSkip the userinfo endpointUse only the ID token's claims. By default Pando fills in missing claims from userinfo.
session_max_lifetimeSession lengthHow long a sign-in lasts. Without SCIM this is also how long access can outlive its removal at the provider.
Presets
- Okta In Okta, create an OIDC Web Application, set its sign-in redirect URI to the one Pando shows, and assign it to people. Add a groups claim (Filter: Matches regex .*) to send groups.
- Microsoft Entra ID In Entra, register an application with a Web redirect URI set to the one Pando shows, create a client secret, and add the groups claim under Token configuration. Entra does not vouch for email addresses, so accounts are never linked by email.
- Google Workspace In Google Cloud, create an OAuth client of type Web application with the redirect URI Pando shows. Google sends no groups; use SCIM or Pando groups for access.
- Keycloak In the realm, create an OpenID Connect client with client authentication on and the redirect URI Pando shows. Add a Group Membership mapper named groups, with Full group path off.
- Authentik Create an OAuth2/OpenID Provider with a confidential client and the redirect URI Pando shows, and an application using it. Authentik sends groups in the profile scope.
SAML 2.0saml
Sign in through a SAML 2.0 identity provider. Pando publishes its own metadata for the provider to import.
idp_metadata_urlProvider metadata URLWhere the provider publishes this application's metadata. Pando re-reads it daily, so certificate rollovers are followed.
idp_metadata_xmlProvider metadata XMLOr paste the metadata instead of giving a URL.
name_id_formatNameID formatWhat Pando asks the provider to identify people by. The NameID must never change for a person.
groups_attributeGroups attributeThe attribute listing the person's groups. Empty tries groups, memberOf, member and Microsoft's groups claim.
subject_attributeSubject attributeIdentify people by this attribute instead of the NameID.
email_attributeEmail attributeEmpty tries email, mail and Microsoft's emailaddress claim.
name_attributeName attributeEmpty tries displayName, name, and first and last name.
username_attributeUsername attributeThe attribute holding the person's username in Pando. Empty tries username, uid, login and Microsoft's name claim.
trust_emailThe provider's email addresses are verifiedOnly if people cannot set their own email in the provider. Needed to link accounts by email.
allow_idp_initiatedAllow sign-in from the provider's dashboardOff is safer: a sign-in the provider starts is not tied to the browser that presents it.
session_max_lifetimeSession lengthHow long a sign-in lasts. Without SCIM this is also how long access can outlive its removal at the provider.
Presets
- Okta In Okta, create a SAML 2.0 app. Single sign-on URL is Pando's ACS URL; Audience URI is Pando's entity ID. Add attribute statements email, displayName, and a group attribute statement groups (Matches regex .*). Then paste the app's Metadata URL here.
- Microsoft Entra ID In Entra, create an enterprise application with SAML. Identifier is Pando's entity ID, Reply URL is the ACS URL. Add a group claim. Paste the App Federation Metadata Url here.
- Google Workspace In the Admin console, add a custom SAML app. ACS URL and Entity ID are Pando's. Map Primary email to email and group membership to groups. Download the IdP metadata and paste it here.
- Keycloak Create a SAML client whose Client ID is Pando's entity ID and whose valid redirect URI is the ACS URL. Add a Group list mapper named groups. The metadata is at /realms/<realm>/protocol/saml/descriptor.
- Authentik Create a SAML Provider with Pando's ACS URL and entity ID as audience, and an application using it. Its metadata can be downloaded from the provider page.
Routing
Cloudflare Tunnelcloudflare
Gives apps their own hostnames through a Cloudflare Tunnel. Nothing on this machine needs to be reachable from the internet, and Cloudflare issues the certificates.
api_tokenAPI tokenRequiredCredentialIn Cloudflare, go to My Profile, API Tokens, Create Token, Create Custom Token. Permissions: Account / Cloudflare Tunnel / Edit; Zone / DNS / Edit; Zone / Zone / Read. Account Resources: your account. Zone Resources: the zone below. Pando uses it to create the tunnel and to point each app's hostname at it.
account_idAccount IDRequiredShown on the account's overview page in Cloudflare's dashboard.
zoneZoneRequiredYour domain in Cloudflare. Apps are served at <app>.<zone>.
console_hostnameConsole hostnameWhere the console is served, and the hostname apps on a path are served under. Empty is the zone itself.
tunnel_idExisting tunnelAdvancedLeave empty and Pando creates a tunnel of its own. Or give a tunnel's ID to use that one: Pando adds its rules and leaves the rest alone.
imagecloudflared imageAdvancedSet to run a different cloudflared release than this Pando ships with.
Built inloopback
Serves apps from Pando itself, on a path or a port.
base_urlBase URLThe address apps are reached at.
Traefiktraefik
Gives apps their own hostnames through a Traefik Pando runs on ports 80 and 443, with certificates.
base_domainBase domainApps are served at <app>.<base domain>. Point this domain and *.<base domain> at this machine.
console_hostnameConsole hostnameWhere the console is served over HTTPS. Any hostname pointed at this machine that is not an app's shows the console; this is the one a certificate is issued for.
certificatesCertificatesacme_emailCertificate emailThe address Let's Encrypt registers the certificates to.
dns_providerDNS providerWho hosts the base domain's DNS. Choose Other for any provider Traefik supports, and enter its code, such as gcloud or ovh.
dns_credentialsDNS provider credentialsCredentialOne NAME=value per line. Cloudflare: CF_DNS_API_TOKEN, or CF_API_EMAIL and CF_API_KEY. Amazon Route 53: AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY. DigitalOcean: DO_AUTH_TOKEN. Porkbun: PORKBUN_API_KEY and PORKBUN_SECRET_API_KEY. Namecheap: NAMECHEAP_API_USER and NAMECHEAP_API_KEY. For another provider, the variables Traefik's documentation lists for it.
managedPando runs TraefikOff if this machine already runs a Traefik that should serve Pando's apps. Pando then only writes route files into the directory that Traefik watches.
http_portHTTP portAdvancedThe host port Traefik takes for HTTP.
https_portHTTPS portAdvancedThe host port Traefik takes for HTTPS.
imageTraefik imageAdvancedSet to run a different Traefik release than this Pando ships with.
deliveryRoute deliveryAdvancedHow routes reach Traefik. Use IngressRoutes with the Kubernetes runtime.
namespaceIngressRoute namespaceAdvancedThe namespace Pando writes IngressRoute objects to, which Traefik watches.
kubeconfigKubeconfig fileAdvancedA kubeconfig file, for reaching the cluster from outside it.
api_qpsAPI requests a secondAdvancedThe most requests a second each Pando replica makes to the cluster's API for routes.
api_burstAPI request burstAdvancedHow many requests a replica may make at once above that rate. At least the requests a second.
dirConfiguration directoryAdvancedWhere Pando writes Traefik's route files.
entrypointEntry pointAdvancedThe entry point of your Traefik that apps are served on.
cert_resolverCertificate resolverThe certificate resolver your Traefik has configured.
Builder
BuildKitbuildkit
Builds images from source in an isolated BuildKit daemon.
addressBuildKit addressAdvancedWhere the BuildKit daemon listens. PANDO_BUILDKIT_ADDRESS is used when this is empty.
Runtime
Dockerdocker
Runs apps as containers on a Docker host.
hostDocker hostAdvancedThe Docker endpoint. Empty uses the environment, which the bundled Compose file relies on.
total_cpu_millisCPU availableAdvancedThousandths of a core Pando may allocate.
total_memory_bytesMemory availableAdvancedBytes Pando may allocate.
total_disk_bytesDisk availableAdvancedBytes of disk Pando may allocate.
network_poolApp network rangeAdvancedThe IPv4 range each app's private network takes its addresses from. A /16 holds about 4,000 apps; a wider range such as 10.208.0.0/12 holds more. "off" uses Docker's own pool, which holds about 30 networks.
network_block_bitsApp network sizeAdvancedThe size of each app's private network, as a prefix length from 24 to 29. 28 holds 13 containers; an app with more workloads than fit gets a larger network.
egress_gateway_imageEgress gateway imageAdvancedThe image an app's egress gateway runs from when its egress rules restrict anything: any image with Pando's binary at /usr/local/bin/pando. Without one, and with Pando not running in a container, apps whose egress is restricted cannot be deployed.
oci_runtimeContainer runtimeAdvancedThe runtime Docker starts apps with, by the name it is registered under in daemon.json. "runsc" (gVisor) or a Kata runtime makes this a sandboxed runtime, which host policy can require; the port and file-write checks when an app is added then cannot see inside the sandbox, so Pando asks for the port instead.
Docker on several hostsdocker-hosts
Runs apps as containers on several Docker hosts. Each app is placed on one host and stays there: a new app goes to the host with the most free memory that fits it. Pando reaches each host's apps through a forwarding agent it runs there, which accepts only Pando's certificate. Built images reach the hosts through the install's image registry.
hostsHostsRequiredThe hosts as a JSON list. Each has a name; an endpoint (unix:///var/run/docker.sock, tcp://host:2376 with the Docker TLS credential, or ssh://user@host with the SSH key and the host's ssh_host_key); an agent_address where Pando reaches the host's agent; and optionally no_placement to keep new apps off it. Exactly one is "control": true, the host Pando runs on.
agent_authorityAgent certificate authorityRequiredCredentialThe output of pando host-agent new-authority. Pando issues its own certificate and each agent's from it.
docker_tlsDocker TLS client certificateCredentialFor tcp:// hosts: the CA (ca.pem), the client certificate (cert.pem) and its key (key.pem), pasted together.
ssh_keySSH private keyCredentialFor ssh:// hosts: an unencrypted private key for a user in the docker group, or root.
agent_imageAgent imageAdvancedThe image of Pando each host's agent and each restricted app's egress gateway run. Every host must be able to pull it.
agent_portAgent portAdvancedThe one port each host publishes, for its agent. Restrict it to the control host's address with the host's firewall.
network_poolApp network rangeAdvancedThe IPv4 range each host's app networks take their addresses from. Each host uses the whole range for its own apps. Cannot be "off" here.
network_block_bitsApp network sizeAdvancedThe size of each app's private network, as a prefix length from 24 to 29.
oci_runtimeContainer runtimeAdvancedThe runtime every host's Docker starts apps with, by the name it is registered under in daemon.json, such as runsc.
Kuberneteskubernetes
Runs apps as pods on the Kubernetes cluster Pando runs in, one namespace per app.
pod_cidrPod address rangeRequiredThe range the cluster gives pods. Apps may open connections out of the cluster, never into this range.
service_cidrService address rangeRequiredThe range the cluster gives Services. Apps may not open connections into it.
egress_gateway_imageEgress gateway imageAn image with Pando's binary at /usr/local/bin/pando, run in front of an app whose egress rules restrict anything. Without one, such apps cannot be deployed.
kubeconfigKubeconfig fileAdvancedA kubeconfig file, for running Pando outside the cluster during development. Pando's proxy reaches apps by cluster DNS names, so in production Pando runs inside the cluster.
contextKubeconfig contextAdvancedThe context in the kubeconfig file to use.
pando_namespacePando's namespaceAdvancedWhere Pando's server pods run. Apps admit connections only from Pando's server pods in this namespace.
pando_servicePando's ServiceAdvancedThe Service in front of Pando's server pods, in Pando's namespace. The edge sends traffic to it.
service_accountPando's ServiceAccountAdvancedThe ServiceAccount Pando's server pods run as, in Pando's namespace. It is bound to the app namespace role in each app namespace.
proxy_portProxy portAdvancedThe port Pando's proxy listens on in its pods.
app_roleApp namespace roleAdvancedThe ClusterRole bound to Pando's ServiceAccount in each app namespace.
cluster_domainCluster domainAdvancedThe cluster's DNS domain, which Service names end in.
api_server_cidrAPI server addressAdvancedOnly needed when the API server's address is inside the pod or Service range: the edge reads its routes from it.
storage_classStorage classAdvancedThe StorageClass app volumes are made with.
volume_size_bytesVolume sizeAdvancedBytes for a volume whose app does not say how large it is.
runtime_classRuntimeClassAdvancedA RuntimeClass to run apps under. One whose handler is gVisor (runsc) or Kata makes this a sandboxed runtime, which host policy can require.
node_selectorNode selectorAdvancedRun apps only on nodes with these labels, as key=value pairs separated by commas.
helper_imageHelper imageAdvancedRuns the network policy check, the port observer and volume backups. Any image with a shell, tar, wget and httpd.
api_qpsAPI requests a secondAdvancedThe most requests a second each Pando replica makes to the cluster's API.
api_burstAPI request burstAdvancedHow many requests a replica may make at once above that rate. At least the requests a second.
edge_namespaceEdge namespaceAdvancedThe namespace the edge runs in: the Traefik that takes ports 80 and 443 and passes traffic to Pando.
edge_replicasEdge replicasAdvancedHow many copies of the edge run, spread across nodes. At least 2.
edge_service_typeEdge Service typeAdvancededge_http_node_portEdge HTTP node portAdvancedThe port every node listens on for the edge's HTTP.
edge_https_node_portEdge HTTPS node portAdvancedThe port every node listens on for the edge's HTTPS.
Secrets
Locallocal
Keeps secrets encrypted in Pando’s own database.
key_pathKey fileAdvancedThe file holding the encryption key.
Services
Dockerdocker
Provisions the databases and caches apps declare, as containers.
Notifications
Consoleconsole
Shows notifications in the console.
retain_daysKeep forAdvancedDays a notification is kept.
Discorddiscord
Posts the events a subscription chooses to a Discord channel, through a channel webhook.
webhook_urlWebhook URLRequiredCredentialThe webhook URL from the Discord channel's Integrations settings. Stored encrypted and never shown again.
timeout_secondsTimeoutAdvancedSeconds to wait for Discord to answer.
ntfyntfy
Publishes the events a subscription chooses to an ntfy topic, on ntfy.sh or your own server, for push notifications on a phone or desktop.
topicTopicRequiredCredentialThe topic to publish to. On ntfy.sh anyone who knows a topic's name can read it, so pick one nobody would guess. Stored encrypted.
server_urlServerThe ntfy server.
access_tokenAccess tokenCredentialA token for a server that requires one. Stored encrypted and never shown again.
priorityPriorityAdvancedHow insistently the phone announces a message.
timeout_secondsTimeoutAdvancedSeconds to wait for the server to answer.
Slackslack
Posts the events a subscription chooses to a Slack channel, through an incoming webhook.
webhook_urlWebhook URLRequiredCredentialThe incoming webhook URL Slack gives you for the channel. Stored encrypted and never shown again.
timeout_secondsTimeoutAdvancedSeconds to wait for Slack to answer.
Email (SMTP)smtp
Emails Pando's notifications to the people they are for, at the address on their account, through any SMTP server — SendGrid, Mailgun and Amazon SES included. Event subscriptions can send to it too.
hostServerRequiredThe mail server's host name.
fromFromRequiredThe address email comes from.
usernameUsernameFor SendGrid, apikey.
passwordPasswordCredentialFor SendGrid, an API key. Stored encrypted and never shown again.
securitySecurityAdvancedHow the connection is encrypted.
portPortAdvanced587 for STARTTLS, 465 for TLS.
timeout_secondsTimeoutAdvancedSeconds to wait for the server.
Microsoft Teamsteams
Posts the events a subscription chooses to a Microsoft Teams channel, as an adaptive card, through a Workflows webhook.
webhook_urlWebhook URLRequiredCredentialThe URL of a Teams workflow that posts a webhook's adaptive card to the channel. Stored encrypted and never shown again.
timeout_secondsTimeoutAdvancedSeconds to wait for Microsoft Teams to answer.
Backup
Local disklocal
Writes backups to a directory on the host.
pathDirectoryWhere backups are written.
Scanner
Trivytrivy
Scans source and images for known vulnerabilities and gives each app a security score.
imageImageAdvancedThe Trivy image to run.
hostDocker hostAdvancedWhere to run it.
timeout_secondsTimeoutAdvancedSeconds a scan may take.
AI
Anthropicanthropic
Performs the AI functions assigned to it: repairing a failed plan, answering detection's questions, revising a plan on request, drafting access and policy, searching the audit log, and answering from the reference. Needs an Anthropic API key.
api_keyAPI keyCredentialAn Anthropic API key. Stored encrypted and never shown again. Leave empty to use ANTHROPIC_API_KEY from Pando’s environment.
modelModelThe Claude model each function uses unless its assignment names another.
base_urlBase URLAdvancedA gateway or proxy in front of the Anthropic API. Empty is the API itself.
api_key_envAPI key variableAdvancedThe environment variable to read the key from, instead of a stored one.
Local modellocal
Performs the AI functions assigned to it with a model on your own hardware, through any server that speaks the OpenAI API: Ollama, LM Studio, llama.cpp or vLLM. Nothing is sent to a provider.
base_urlServer URLThe server’s OpenAI-compatible address, ending in /v1. The default is Ollama on the machine running Pando’s container.
modelModelRequiredThe model each function uses unless its assignment names another, as the server names it.
api_keyAPI keyCredentialOnly if your server asks for one. Stored encrypted and never shown again.
timeout_secondsTimeout, in secondsAdvancedHow long one request may take. Local models are slower than hosted ones.
OpenAIopenai
Performs the AI functions assigned to it with OpenAI's models. Uses OpenAI's Responses API, which stores each conversation on OpenAI's servers under OpenAI's retention terms; Pando does not store it. Needs an OpenAI API key.
api_keyAPI keyCredentialAn OpenAI API key. Stored encrypted and never shown again. Leave empty to use OPENAI_API_KEY from Pando’s environment.
modelModelThe model each function uses unless its assignment names another.
base_urlBase URLAdvancedA gateway or proxy in front of the OpenAI API. Empty is the API itself.
api_key_envAPI key variableAdvancedThe environment variable to read the key from, instead of a stored one.
Source connections
Azure DevOpsazuredevops
Clone from Azure DevOps Services or Azure DevOps Server with a personal access token, Microsoft Entra ID or an SSH key, and pick repositories from a list.
methodHow Pando signs inRequiredhostHostThe host repositories are on. Change it for a self-managed server.
scopeOrganizationThe organization, or organization/project to limit the connection to one project. On Azure DevOps Server, the collection, or collection/project.
tokenPersonal access tokenCredentialA personal access token with the Code (Read) scope.
tenant_idDirectory (tenant) IDThe Microsoft Entra tenant. A service principal needs its own tenant's ID; a person's sign-in can use organizations.
client_idApplication (client) IDThe app registration's application (client) ID, from Microsoft Entra ID.
client_secretClient secretCredentialThe app registration's client secret. Required for a service principal and for browser authorization; device authorization works without one.
ssh_private_keySSH private keyCredentialThe private half of a deploy key or access key added to the repository. Pando reads the repository with it and never writes.
ssh_passphraseKey passphraseCredentialOnly if the key has one.
known_hostsKnown hostsThe host's public key, as ssh-keyscan ssh.dev.azure.com (or your server's host) prints it.
api_urlAPI addressAdvancedWhere the host's API is, if not where Pando would look for it.
ca_bundleCertificate authorityAdvancedPEM certificates to trust for a self-managed host on a private certificate authority, beside the system's.
Bitbucketbitbucket
Clone from Bitbucket Cloud or Bitbucket Data Center with an access token, an OAuth consumer or an SSH access key, and pick repositories from a list.
methodHow Pando signs inRequiredhostHostThe host repositories are on. Change it for a self-managed server.
scopeWorkspace or projectBitbucket Cloud: the workspace ID, such as acme. Data Center: the project key, such as PAY. Empty is every repository the credential can read.
token_typeToken typeBitbucket Cloud only. Data Center takes an HTTP access token whichever is chosen.
usernameUsernameBitbucket Cloud API token: your Bitbucket username. Data Center: the account the token belongs to, if git should sign in as it; x-token-auth otherwise.
emailAtlassian account emailBitbucket Cloud API token only: the email of the Atlassian account the token was created under, which Bitbucket's API signs in with. The username when empty.
tokenTokenCredentialRead access to repositories is enough.
client_idOAuth consumer keyFrom the workspace's settings → OAuth consumers. Give the consumer Pando's callback address and the Repositories: Read permission.
client_secretOAuth consumer secretCredentialThe consumer's secret, shown beside its key.
ssh_private_keySSH private keyCredentialThe private half of a deploy key or access key added to the repository. Pando reads the repository with it and never writes.
ssh_passphraseKey passphraseCredentialOnly if the key has one.
known_hostsKnown hostsThe host's public key, as ssh-keyscan bitbucket.org prints it. For Data Center, ssh-keyscan -p 7999 HOST, whose lines begin [HOST]:7999.
ssh_portSSH portAdvancedBitbucket Data Center's SSH port, for turning an HTTPS address into an SSH one. Not used on Bitbucket Cloud.
api_urlAPI addressAdvancedWhere the host's API is, if not where Pando would look for it.
ca_bundleCertificate authorityAdvancedPEM certificates to trust for a self-managed host on a private certificate authority, beside the system's.
Any git hostgit
Clone from any git server with a username and token over HTTPS, or an SSH key. Repositories are entered by address.
methodHow Pando signs inRequiredhostHostRequiredThe host repositories are on. Change it for a self-managed server.
scopePath prefixLimit the connection to repositories under this path, such as acme. Empty is every repository on the host.
usernameUsernameThe account the token belongs to. Defaults to git.
tokenToken or passwordCredentialRead access to the repositories is enough.
ssh_private_keySSH private keyCredentialThe private half of a deploy key or access key added to the repository. Pando reads the repository with it and never writes.
ssh_passphraseKey passphraseCredentialOnly if the key has one.
known_hostsKnown hostsThe host's public key, as ssh-keyscan <host> prints it.
ca_bundleCertificate authorityAdvancedPEM certificates to trust for a self-managed host on a private certificate authority, beside the system's.
Gitea or Forgejogitea
Clone from a Gitea or Forgejo server, Codeberg included, with an access token, an OAuth2 application, or a deploy key, optionally limited to one owner.
methodHow Pando signs inRequiredhostHostRequiredThe host repositories are on. Change it for a self-managed server.
scopeOwnerLimit the connection to one user's or organization's repositories, such as acme. Empty is every repository the credential can read.
usernameUsernameThe account the token belongs to. Defaults to oauth2, which Gitea and Forgejo accept beside a token.
tokenAccess tokenCredentialCreate one under Settings → Applications with read permission on repositories.
client_idOAuth2 client IDThe client ID of an OAuth2 application created under Settings → Applications, with Pando's callback as its redirect URI.
client_secretOAuth2 client secretCredentialThe application's client secret. Gitea and Forgejo authorize only in the browser, so it is required.
ssh_private_keySSH private keyCredentialThe private half of a deploy key or access key added to the repository. Pando reads the repository with it and never writes.
ssh_passphraseKey passphraseCredentialOnly if the key has one.
known_hostsKnown hostsThe host's public key, as ssh-keyscan <host> prints it.
api_urlAPI addressAdvancedWhere the host's API is, if not where Pando would look for it.
ca_bundleCertificate authorityAdvancedPEM certificates to trust for a self-managed host on a private certificate authority, beside the system's.
Presets
- Codeberg Create an access token on Codeberg under Settings → Applications, with read permission on repositories.
GitHubgithub
Clone private repositories from github.com or GitHub Enterprise Server, and pick them from a list, with a GitHub App, an OAuth application, a personal access token or a deploy key.
methodHow Pando signs inRequiredhostHostThe host repositories are on. Change it for a self-managed server.
scopeOwnerThe organization or user on GitHub. Empty is every repository the credential can read.
app_idApp IDThe App's ID, shown on its settings page in GitHub under General → About.
installation_idInstallation IDThe number at the end of the installation's settings address. Empty looks it up from the owner.
app_private_keyApp private keyCredentialThe PEM private key generated on the App's settings page, beginning -----BEGIN RSA PRIVATE KEY-----.
client_idOAuth client IDFrom the OAuth application registered in GitHub under Settings → Developer settings → OAuth Apps, with device flow enabled.
client_secretOAuth client secretCredentialNeeded for browser authorization. Device authorization works without one.
tokenPersonal access tokenCredentialA fine-grained token with read access to contents and metadata, or a classic token with the repo scope.
ssh_private_keySSH private keyCredentialThe private half of a deploy key or access key added to the repository. Pando reads the repository with it and never writes.
ssh_passphraseKey passphraseCredentialOnly if the key has one.
known_hostsKnown hostsThe host's public key, as ssh-keyscan <host> prints it. For github.com it may be left empty: Pando uses the keys GitHub publishes.
api_urlAPI addressAdvancedWhere the host's API is, if not where Pando would look for it.
ca_bundleCertificate authorityAdvancedPEM certificates to trust for a self-managed host on a private certificate authority, beside the system's.
Presets
- GitHub.com Install a GitHub App on the organization, or create a personal access token under Settings → Developer settings.
- GitHub Enterprise Server Enter the server's host. Its API is at https://<host>/api/v3 unless it was moved.
GitLabgitlab
Clone from gitlab.com or a self-managed GitLab with an OAuth application, an access or deploy token, or a deploy key, optionally limited to one group.
methodHow Pando signs inRequiredhostHostThe host repositories are on. Change it for a self-managed server.
scopeGroupLimit the connection to projects in this group and its subgroups, such as acme or acme/platform. Empty is every project the credential can read.
client_idOAuth client IDThe Application ID of a GitLab OAuth application with the read_repository and read_api scopes. Create one under Preferences → Applications, or on a group's or the instance's Applications page.
client_secretOAuth client secretCredentialNeeded for browser authorization. Device authorization works without one.
token_typeToken typeusernameUsernameFor a deploy token, the username GitLab shows beside it, such as gitlab+deploy-token-12. Not used with an access token.
tokenTokenCredentialRead access to repositories is enough: read_repository, and read_api to pick repositories from a list.
ssh_private_keySSH private keyCredentialThe private half of a deploy key or access key added to the repository. Pando reads the repository with it and never writes.
ssh_passphraseKey passphraseCredentialOnly if the key has one.
known_hostsKnown hostsThe host's public key, as ssh-keyscan <host> prints it. Leave empty for gitlab.com; Pando knows its key.
api_urlAPI addressAdvancedWhere the host's API is, if not where Pando would look for it.
ca_bundleCertificate authorityAdvancedPEM certificates to trust for a self-managed host on a private certificate authority, beside the system's.
Image registries
Amazon ECRecr
An ECR repository you created. Every build goes into it, tagged by app and deployment, and Pando gets a registry password from the access key before each push and pull.
urlRegistry addressRequiredThe repository's address, as ECR shows it. It has to exist already.
access_key_idAccess key IDRequiredAn AWS access key that can push to and pull from the repository.
secret_access_keySecret access keyRequiredCredentialStored encrypted, and never shown again.
alwaysSend every build through the registryAdvancedEven on a runtime that can take a built image directly, such as Docker on one host.
OCI registryoci
A registry that signs in with a username and password, or not at all: Distribution, Harbor, GitHub Container Registry, Artifact Registry, Zot. Each app gets a repository of its own.
urlRegistry addressRequiredThe registry, and a path to push under if you want one.
usernameUsernameWhat the registry signs Pando in with. Empty for a registry Pando reaches anonymously.
passwordPasswordCredentialStored encrypted, and never shown again.
layoutWhere images goAdvancedinsecureAllow plain HTTPAdvancedOnly for a registry on a private network. Every host that pulls must also list it as an insecure registry.
alwaysSend every build through the registryAdvancedEven on a runtime that can take a built image directly, such as Docker on one host.
Audit sinks
HTTPShttps
Posts every audit event, in batches as it is written, to a SIEM's HTTPS ingest endpoint: Splunk, Datadog, Elastic, Sumo Logic, Microsoft Sentinel, or anything that takes JSON with a token. A copy of the audit log leaves this installation.
urlURLThe destination's ingest endpoint. Leave empty when the URL itself is the credential, and set secret_url instead.
secret_urlSecret URLCredentialFor a destination whose URL carries its token, such as a Sumo Logic HTTP source: the whole URL, stored encrypted. Only its host is ever shown.
tokenTokenCredentialThe API key or token the destination checks. Stored encrypted and never shown again.
bodyBodyThe shape of each POST's body.
auth_headerAuth headerThe header the token is sent in.
auth_schemeAuth schemeThe word before the token in the header.
ca_certificateCA certificatePEM certificates to trust for a destination on a private certificate authority. Empty trusts the system's.
extra_headersExtra headersHeaders to add, one per line as Name: value. Not encrypted, so not for anything secret.
sourcetypeSplunk sourcetypeAdvancedThe sourcetype each HEC envelope names.
allow_httpAllow httpAdvancedPost over plain http, unencrypted. Only for a destination on a trusted network.
timeout_secondsTimeoutAdvancedSeconds to wait for the destination to answer a batch.
actionsActionsComma-separated action prefixes to send. Empty sends every event.
excludeExcludeComma-separated action prefixes not to send. app.use, a record of each request to an app, is usually most of the volume; exclude it if your SIEM bills by ingest.
formatEvent formatAdvancedHow each event is encoded.
max_batchBatch sizeAdvancedThe most events sent in one delivery.
startStartAdvancedWhere a new destination's first delivery begins. Read once, when Pando first sends to it.
Presets
- Splunk HTTP Event Collector In Splunk, Settings > Data inputs > HTTP Event Collector: create a token and copy its value. The URL is your Splunk host on the HEC port, usually 8088, ending /services/collector/event. On Splunk Cloud the host is http-inputs-<stack>.splunkcloud.com on port 443.
- Datadog Logs In Datadog, Organization Settings > API Keys: create an API key and set it as the token. The URL is for the US1 site; for another site use its intake host, such as http-intake.logs.datadoghq.eu for EU or http-intake.logs.us5.datadoghq.com for US5.
- Elastic In Kibana, Stack Management > API keys: create a key that may write to the data stream and set its encoded value as the token. The URL is your Elasticsearch endpoint, then a data stream name such as logs-pando.audit-default, then /_bulk.
- Sumo Logic HTTP source In Sumo Logic, Manage Data > Collection: add an HTTP Logs and Metrics source to a hosted collector and copy its URL. The URL contains the source's token, so set it as the secret URL credential and leave url and token empty.
- Microsoft Sentinel (Azure Monitor Logs ingestion) In Azure, create a data collection endpoint and a data collection rule with a stream named Custom-PandoAudit_CL whose columns match the events, then use the endpoint's logs ingestion URL and the rule's immutable ID in the URL. The token is a Microsoft Entra ID access token for the https://monitor.azure.com scope. This adapter sends a static token and does not mint or refresh one, so a token that expires stops delivery until it is replaced.
- Generic NDJSON (Google SecOps and others) Any endpoint that takes newline-delimited JSON with a token in a header. Set the URL, the header and scheme it expects, and the token.
Syslogsyslog
Sends every audit event, as it is written, to a syslog collector as an RFC 5424 message over TCP, encrypted with TLS unless you turn it off. A copy of the audit log leaves this installation.
addressAddressRequiredThe collector's host and port. Without a port, 6514 with TLS and 514 without.
tlsTLSWhether the connection is encrypted. Off sends the audit log across the network in the clear.
ca_certificateCA certificatePEM certificates to trust for a collector on a private certificate authority. Empty trusts the system's.
client_certificateClient certificateCredentialA PEM certificate Pando presents, for a collector that requires mutual TLS. Set with its key, or not at all. Stored encrypted.
client_keyClient keyCredentialThe PEM private key for the client certificate. Stored encrypted and never shown again.
server_nameServer nameAdvancedThe name the collector's certificate must carry, when it differs from the address.
app_nameApp nameAdvancedThe APP-NAME each message carries.
facilityFacilityAdvancedThe syslog facility messages are sent as. authpriv is for security messages a collector keeps apart from the general log.
hostnameHostnameAdvancedThe HOSTNAME each message carries.
timeout_secondsTimeoutAdvancedSeconds to wait to connect, and for a batch to be written.
actionsActionsComma-separated action prefixes to send. Empty sends every event.
excludeExcludeComma-separated action prefixes not to send. app.use, a record of each request to an app, is usually most of the volume; exclude it if your SIEM bills by ingest.
formatEvent formatAdvancedHow each event is encoded.
max_batchBatch sizeAdvancedThe most events sent in one delivery.
startStartAdvancedWhere a new destination's first delivery begins. Read once, when Pando first sends to it.