Verify Your Infrastructure
Declare the domains, IP networks, code repositories and S3 buckets your organization operates, and prove you own them to unlock RedKit audits and scheduled scans.
Your organization's infrastructure lists what it operates: domains, IP networks, code repositories and S3 buckets. Each asset has to be proven before it counts as yours. Proven assets unlock RedKit audits, scheduled scans and sign-ups from your company domain.
Assets belong to the organization. Every member can see them in Organization → Infrastructure; the owner and admins add, prove and remove them.
| Asset | How it is proven |
|---|---|
| Domain | A DNS TXT record you add |
| Code repository on GitHub or GitLab | Connecting the GitHub App or GitLab, or a .mlab file |
| Bucket (Amazon S3, Scaleway Object Storage) | A .mlab object in the bucket |
| IP network | Validated by the mlab.sh team |
Domains
Add your domain
In Organization → Infrastructure, click Add an asset, choose Domain and enter it (for example example.com).
Add a DNS TXT record
The asset page shows a token like mlab-domain-xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. In your DNS provider (Cloudflare, OVH, AWS Route 53...), add it as a TXT record on the root of the domain.
Example DNS record
Type: TXT - Name: @ - Value: mlab-domain-abc123...
Check
Back on the asset page, click Check the DNS record. DNS can take a few minutes to propagate.
The .mlab file
Code repositories and S3 buckets are proven with the same file: a plain text file named .mlab, holding a line VERIF_CODE=<token>. The token is shown on the asset's page. The file can hold other KEY=value lines and # comments for other tools; only VERIF_CODE is read, and you can keep the line after the check.
# .mlab
VERIF_CODE=mlab-repo-3f2a9c1e-5b7d-4e2a-9c1f-0a8b7d6e5f43Code repositories
Connect GitHub or GitLab: it is the recommended way. Connecting your account proves every repository you give mlab.sh access to in one go, private ones included, keeps the list in sync, and lets them be scanned automatically:
- GitHub: install the mlab GitHub App.
- GitLab (Cloud): connect a GitLab.com group or your personal namespace.
- GitLab (Self-Managed): connect your own GitLab instance.
They are all in Organization → Infrastructure → Integrations.
With a .mlab file
A public repository on GitHub or GitLab.com can also be proven on its own with a .mlab file, without connecting anything. It is then scanned by hand only. Another forge (Bitbucket, Codeberg...)? Ask for it on GitHub Discussions.
Add the repository
Choose Code repository and paste the repository: its web address (https://github.com/acme/website), its clone address ([email protected]:acme/website.git) or the raw URL of its .mlab. GitLab subgroups are supported.
Commit the .mlab file
Add .mlab with your VERIF_CODE= line at the root of the default branch, then commit and push.
Check
Click Check the .mlab file. mlab.sh reads it at https://raw.githubusercontent.com/<owner>/<repo>/HEAD/.mlab (GitHub) or https://gitlab.com/<path>/-/raw/HEAD/.mlab (GitLab).
The file is on another branch? Paste its raw URL in the optional field before checking, for example https://raw.githubusercontent.com/acme/website/release/.mlab. It must be the .mlab at the root of that same repository.
Buckets
Amazon S3 and Scaleway Object Storage are supported. Another provider (Google Cloud Storage, Azure Blob, OVHcloud, Cloudflare R2, MinIO...)? Ask for it on GitHub Discussions.
Add the bucket
Choose S3 bucket and enter it:
- Amazon S3: its name, or its
s3://orhttps://address. - Scaleway: its address, which carries the region, for example
my-bucket.s3.fr-par.scw.cloudorhttps://s3.fr-par.scw.cloud/my-bucket.
Upload a public .mlab object
Put .mlab with your VERIF_CODE= line at the root of the bucket, readable by anyone. Only that one object has to be public; the rest of the bucket stays private.
aws s3 cp .mlab s3://acme-public-assets/.mlab --content-type text/plainOn Amazon S3, allow public read on that single key with a bucket policy statement:
{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::acme-public-assets/.mlab"
}On Scaleway, an object ACL is enough:
aws s3 cp .mlab s3://acme-public-assets/.mlab --acl public-read --content-type text/plain \
--endpoint-url https://s3.fr-par.scw.cloudCheck
Click Check the .mlab file. Every Amazon S3 region is supported. If the check fails, the message says why: no such bucket (on Scaleway, check the region in the address), no .mlab object, or an object that is not publicly readable.
IP networks
An IP address or range cannot prove itself with a record, so each IP network is validated by hand by the mlab.sh team.
- Declare one public IPv4 or IPv6 address, or a CIDR range up to
/16(IPv4) or/32(IPv6). A host inside a range is saved as its network (203.0.113.7/24becomes203.0.113.0/24). Private and reserved ranges are refused. - The network stays Pending mlab review until it is validated.
- Contact us and show that your organization owns or operates it: the RIR or WHOIS allocation, your own ASN, or a hosting contract naming the range.