mlab docs

Verify Your Infrastructure

Declare the domains, IP networks, code repositories and S3 buckets your organization operates, and prove you own them to unlock RedKit audits and scheduled scans.

Your organization's infrastructure lists what it operates: domains, IP networks, code repositories and S3 buckets. Each asset has to be proven before it counts as yours. Proven assets unlock RedKit audits, scheduled scans and sign-ups from your company domain.

Assets belong to the organization. Every member can see them in Organization → Infrastructure; the owner and admins add, prove and remove them.

AssetHow it is proven
DomainA DNS TXT record you add
Code repository on GitHub or GitLabConnecting the GitHub App or GitLab, or a .mlab file
Bucket (Amazon S3, Scaleway Object Storage)A .mlab object in the bucket
IP networkValidated by the mlab.sh team

Domains

Add your domain

In Organization → Infrastructure, click Add an asset, choose Domain and enter it (for example example.com).

Add a DNS TXT record

The asset page shows a token like mlab-domain-xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. In your DNS provider (Cloudflare, OVH, AWS Route 53...), add it as a TXT record on the root of the domain.

Example DNS record

Type: TXT - Name: @ - Value: mlab-domain-abc123...

Check

Back on the asset page, click Check the DNS record. DNS can take a few minutes to propagate.

The .mlab file

Code repositories and S3 buckets are proven with the same file: a plain text file named .mlab, holding a line VERIF_CODE=<token>. The token is shown on the asset's page. The file can hold other KEY=value lines and # comments for other tools; only VERIF_CODE is read, and you can keep the line after the check.

# .mlab
VERIF_CODE=mlab-repo-3f2a9c1e-5b7d-4e2a-9c1f-0a8b7d6e5f43

Code repositories

Connect GitHub or GitLab: it is the recommended way. Connecting your account proves every repository you give mlab.sh access to in one go, private ones included, keeps the list in sync, and lets them be scanned automatically:

They are all in Organization → Infrastructure → Integrations.

With a .mlab file

A public repository on GitHub or GitLab.com can also be proven on its own with a .mlab file, without connecting anything. It is then scanned by hand only. Another forge (Bitbucket, Codeberg...)? Ask for it on GitHub Discussions.

Add the repository

Choose Code repository and paste the repository: its web address (https://github.com/acme/website), its clone address ([email protected]:acme/website.git) or the raw URL of its .mlab. GitLab subgroups are supported.

Commit the .mlab file

Add .mlab with your VERIF_CODE= line at the root of the default branch, then commit and push.

Check

Click Check the .mlab file. mlab.sh reads it at https://raw.githubusercontent.com/<owner>/<repo>/HEAD/.mlab (GitHub) or https://gitlab.com/<path>/-/raw/HEAD/.mlab (GitLab).

The file is on another branch? Paste its raw URL in the optional field before checking, for example https://raw.githubusercontent.com/acme/website/release/.mlab. It must be the .mlab at the root of that same repository.

Buckets

Amazon S3 and Scaleway Object Storage are supported. Another provider (Google Cloud Storage, Azure Blob, OVHcloud, Cloudflare R2, MinIO...)? Ask for it on GitHub Discussions.

Add the bucket

Choose S3 bucket and enter it:

  • Amazon S3: its name, or its s3:// or https:// address.
  • Scaleway: its address, which carries the region, for example my-bucket.s3.fr-par.scw.cloud or https://s3.fr-par.scw.cloud/my-bucket.

Upload a public .mlab object

Put .mlab with your VERIF_CODE= line at the root of the bucket, readable by anyone. Only that one object has to be public; the rest of the bucket stays private.

aws s3 cp .mlab s3://acme-public-assets/.mlab --content-type text/plain

On Amazon S3, allow public read on that single key with a bucket policy statement:

{
  "Effect": "Allow",
  "Principal": "*",
  "Action": "s3:GetObject",
  "Resource": "arn:aws:s3:::acme-public-assets/.mlab"
}

On Scaleway, an object ACL is enough:

aws s3 cp .mlab s3://acme-public-assets/.mlab --acl public-read --content-type text/plain \
    --endpoint-url https://s3.fr-par.scw.cloud

Check

Click Check the .mlab file. Every Amazon S3 region is supported. If the check fails, the message says why: no such bucket (on Scaleway, check the region in the address), no .mlab object, or an object that is not publicly readable.

IP networks

An IP address or range cannot prove itself with a record, so each IP network is validated by hand by the mlab.sh team.

  • Declare one public IPv4 or IPv6 address, or a CIDR range up to /16 (IPv4) or /32 (IPv6). A host inside a range is saved as its network (203.0.113.7/24 becomes 203.0.113.0/24). Private and reserved ranges are refused.
  • The network stays Pending mlab review until it is validated.
  • Contact us and show that your organization owns or operates it: the RIR or WHOIS allocation, your own ASN, or a hosting contract naming the range.

On this page