By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.
18px_cookie
e-remove

Endor Outpost: Deploy Endor Labs Behind Your Firewall

Endor Outpost extends the full capabilities of the Endor Labs AppSec platform to Self-Hosted SCMs like Bitbucket Datacenter and GitLab Self-Managed.

Endor Outpost extends the full capabilities of the Endor Labs AppSec platform to Self-Hosted SCMs like Bitbucket Datacenter and GitLab Self-Managed.

Endor Outpost extends the full capabilities of the Endor Labs AppSec platform to Self-Hosted SCMs like Bitbucket Datacenter and GitLab Self-Managed.

Written by
A photo of Ron Harnik — VP Marketing at Endor Labs.
Ron Harnik
Published on
July 16, 2025

Endor Outpost extends the full capabilities of the Endor Labs AppSec platform to Self-Hosted SCMs like Bitbucket Datacenter and GitLab Self-Managed.

Endor Outpost extends the full capabilities of the Endor Labs AppSec platform to Self-Hosted SCMs like Bitbucket Datacenter and GitLab Self-Managed.

Today we’re announcing Endor Outpost, a deployment option that lets customers use the full capabilities of the Endor Labs Application Security Platform with self-hosted Source Code Managers (SCMs). All code is scanned on-prem, and never leaves your network. We built this because customers with sensitive code repositories and strict security requirements face challenges using standard cloud-based scanning solutions:

  • Security & Compliance Concerns: Many regulated industries and security-conscious organizations cannot send source code outside their network perimeter
  • Firewall Restrictions: Corporate firewalls and network policies often prevent direct integration with external scan services
  • Operational Overhead: Implementing manual scanning processes or integrating scanners into multiple CI/CD pipelines is expensive and complex
  • Access to Internal Resources: Many customers need to scan against private artifact registries and internal services

Endor Outpost solves these challenges by bringing Endor Labs' scanning capabilities inside the customer's network perimeter. It allows Application Security teams to schedule, monitor and administer scans across their entire on-prem environments from a central place. Most recently we had a customer from the Fintech industry and another in the Tax Compliance Software business use Endor Outpost to scan their code in the self-hosted instance of Gitlab.

How it works

1. Endor Scheduler (Deployed On-Prem)

At the heart of Outpost is the Endor Scheduler, which is deployed into the customer’s Kubernetes cluster using a Helm chart. This scheduler is the orchestration engine that manages scan jobs 

2. Endorctl Jobs 

For each scan, the scheduler launches ephemeral Endorctl (command line tool to integrate Endor Labs into customer environments) jobs to carry out the analysis. These jobs:

  • Pull and analyze source code all inside your environment]
  • perform SCA scans,  reachability analysis,  etc - everything endorctl in the agentless app can do
  • Report scan results (not source code) back to the SaaS platform

These jobs are fully isolated within the user’s environment and require no inbound access 

3. Helm based deployment

Deploying the scheduler is easy:

  • Users create an OnPremScheduler object via UI or CLI, and define specific parameters
    1.  For example -  choosing auth methods like API key, GCP service account or Azure Identity.
  • The Endor platform generates a base64-encoded values.yaml file with all necessary config
  • Users deploy  the yaml file via a Helm chart

4. Endor SaaS (metadata only)

The SaaS platform:

  • Tracks connection status and health of the on-prem scheduler
  • Receives scan metadata and results only,  not the source code and you can see the findings in the UI 

Endor Outpost is a private instance of the Endor scheduler that you deploy inside your own Kubernetes cluster using an easy-to use helm chart. It manages a pool of scanning minions and offers the same set of capabilities available in our SaaS platform, but with no code leaving your network. All scanning (from Software Composition Analysis to static code analysis, secrets scanning etc.) happens entirely on-premises. Unlike other tools, which require their entire platform to be hosted on-prem, Outpost is quick to deploy and easy to manage.

As a refresher on how Endor Labs works, we build a complete graph of your software estate, spanning first-party code, open source dependencies, containers, and AI-generated components. This deep program analysis powers consolidated scanning across SCA, SAST, secrets, and containers, allowing us to filter out false positives and surface only the risks that matter. Our platform integrates directly with SCMs, CI/CD pipelines, IDEs, and AI coding tools, embedding security into the development workflow. Capabilities like reachability analysis, Upgrade Impact Analysis, and Endor Patches accelerate remediation without breaking builds. With flexible policies and a unified API, Endor Labs gives AppSec teams the precision and automation needed to secure modern software.

Endor Outpost expands the number of flexible deployment options available to customers, giving teams more control over where and how they integrate security. That includes support for cloud-hosted source control platforms like GitHub, GitLab, Bitbucket, and Azure DevOps, delivered as native apps that simplify setup and policy management. It also offers deep integration into CI/CD pipelines such as GitHub Actions, Jenkins, CircleCI, and more, ensuring that security checks can be embedded directly into developer workflows without slowing them down.

Ready to learn more about Endor Labs? Book time with a specialist!

The Challenge

The Solution

The Impact

Welcome to the resistance
Oops! Something went wrong while submitting the form.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.