> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd.md).

# CI/CD for Panther Content

Panther customers can automate their [detection pipeline](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd/detections-repo.md), work with custom logs via [pantherlog](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/pantherlog.md), and improve security with a CI/CD workflow. Learn about other non-web application-based workflows in the [Panther Developer Workflows Overview](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/overview.md).&#x20;

For information on web application-based workflows to manage your detections and custom logs directly in the Panther Console, see the [Writing and Editing Detections](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/detections/rules/python.md) and [Custom Logs](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/data-onboarding/custom-log-types.md) documentation pages.

To learn how to migrate from Console workflows to CI/CD, see the section below: [Migrating to a CI/CD workflow](#migrating-to-a-ci-cd-workflow).

Panther's CI/CD documentation walks through setting up a workflow such as the following:&#x20;

1. Forking or cloning the [panther-analysis](https://github.com/panther-labs/panther-analysis) repo to leverage Panther-managed Python detections.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Currently, only Python Panther-managed detections are available for you to clone, modify, and upload. YAML Panther-managed detections are planned for a future release.</p></div>

   * The Python detections in panther-analysis are broadly applicable, and can be customized to ensure that you are receiving only the alerts that are most important to your organization.&#x20;
   * See [Using the Panther detections repo](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd/detections-repo.md) for instructions.
2. Pulling updates from panther-analysis to take advantage of new Python detections and other content updates.&#x20;
   * This process allows you to sync to the upstream panther-analysis repository in order to receive new Python detections and other detection content updates.
   * See [Public fork](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd/detections-repo/public-fork.md) or [Private cloned repo](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd/detections-repo/private-cloned-repo.md) for instructions, depending on your organization's chosen method.
3. Adapting the detections to fit within your CI/CD workflow and uploading them to your Panther Console.
   * See [Deployment workflows using Panther Analysis Tool](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd/deployment-workflows.md) for instructions on using PAT and managing Panther content via CircleCI or GitHub Actions.
   * If you choose to manually upload your content to the Panther Console, see [Uploading content in the Panther Console](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd/deployment-workflows/pat/pat-commands.md#uploading-content-in-the-panther-console).

## Migrating to a CI/CD workflow

If you are migrating from managing detections in the Panther Console to managing them via a CI/CD workflow, follow the process below.

<details>

<summary>Step 1: Download content created in the Console</summary>

CI/CD overwrites anything included on upload, which includes rules, policies, global helpers, and data models. If you have created your own copy of Panther-managed enrichment provider helpers, global helpers or data models, you will need to download these as well.

There are two options available: Bulk-download all entities at once, or download entities individually.

#### Option 1: Bulk-download all entities.

When you use this option, you can download all detections, global helpers, saved queries, and data models from your Panther Console. Note that this download will include everything that is enabled (including Panther standard rules) and outputs every file under one folder. You will need to move files to the proper repo structure.

1. In the Panther Console, navigate to Build > Bulk Uploader.
2. In the upper right corner, click **Download all entities**.&#x20;

***

#### Option 2: Download entities separately&#x20;

#### Download detections

1. In the left-hand navigation bar of your Panther Console, click **Build** > **Detections**.
2. Click **Filters** in the upper-right. Filter for **Created by:** then select **Created by team**.
3. Click **Apply Filters**.
4. Download each page of detections.
   1. Check the bulk **Select All** box in the upper-left corner of the list.
   2. At the top of the list, click **Download**.

The detections will be downloaded in a zip that you can incorporate into your version control system.

#### Download helpers

1. In the left-hand navigation bar of your Panther Console, click **Build** > **Helpers**.
2. On the right side of a helper tile, click **...** then click **Download**.
3. Repeat for each separate helper.

#### Download data models

1. In the left-hand navigation bar of your Panther Console, click **Build** > **Data Models**.
2. On the right side of a data model tile, click **...** then click **Download**.
3. Repeat for each separate data model.

</details>

<details>

<summary>Step 2: Enable the Developer Workflow option</summary>

To ensure that you only manage detections via CI/CD, we recommend you enable the Developer Workflow option and mark your users as read-only in the Panther Console:

To prevent Panther detection Packs from being enabled from the Console, you can self-declare as a developer workflow account:&#x20;

1. In the Panther Console, navigate to **Settings > General**.
2. Click **Developer Workflow**.
3. Toggle the option to **ON** to disallow Panther Detection Packs from being enabled in the Console.  \
   ![Under the "Developer Workflows" tab, there is an option called "We use the Panther Analysis Tool to manage our detections." There is a toggle switch next to it, which is enabled.](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FrRNbLoTPdVsJOKIDtDPt%2Fread-only-users.png?alt=media\&token=91fdd742-c29f-4b79-9326-784d75d03004)

</details>

<details>

<summary>Step 3: Mark users as read-only</summary>

To prevent users from making edits in the Panther Console that may conflict with your source control, mark them as read-only:&#x20;

1. In the Panther Console, navigate to **Settings > Users**.&#x20;
2. In the user list, locate your developers who are using a CI/CD workflow.&#x20;
3. Click **...** on the right side of a user tile. In the dropdown menu that appears, click **Edit**.
4. Change the user's role to Read Only.
5. Click **Update**.
6. Repeat these steps for each developer who is using a CI/CD workflow.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/~/changes/Dd8nx2iqd1Pp2OzWJaWk/panther-developer-workflows/ci-cd.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
