Back to articles
Technology Insight

Automating Web Vulnerability Scanning: Integrating Nuclei into Your CI/CD Pipeline on a VPS

June 7, 2026

Introduction: The Imperative of Continuous Security in Modern DevOps

In the contemporary digital landscape, web applications are in a state of constant evolution. Continuous Integration and Continuous Deployment (CI/CD) pipelines have enabled development teams to ship code faster than ever before. However, this accelerated velocity often introduces a significant challenge: security regression. Traditional periodic penetration testing is no longer sufficient to secure applications that change on a daily or hourly basis. To bridge this gap, organizations must adopt a DevSecOps approach, embedding security testing directly into the deployment lifecycle.

Among the myriad of security tools available, Nuclei has emerged as a standout solution for modern engineering teams. Developed by ProjectDiscovery, Nuclei is a fast, template-based vulnerability scanner that allows teams to send requests across targets based on templates, offering massive extensibility and ease of use. By integrating Nuclei into a daily CI/CD pipeline hosted on a Virtual Private Server (VPS), businesses can achieve automated, consistent, and proactive vulnerability scanning without draining engineering resources. This article provides a comprehensive, technical blueprint for achieving this integration.

Why Nuclei? The Strategic Advantage for Enterprise Web Security

Before diving into the technical implementation, it is crucial to understand why Nuclei is uniquely suited for CI/CD environments compared to traditional, heavy Web Application Security Testing (DAST) tools.

  • Template-Driven Architecture: Nuclei relies on a community-driven ecosystem of YAML-based templates. This allows it to scan for the latest CVEs (Common Vulnerabilities and Exposures) within hours of their public disclosure.
  • Unmatched Speed and Low Resource Footprint: Written in Go, Nuclei is highly optimized for performance and concurrency. It executes scans rapidly, making it ideal for pipeline stages where build speed is a critical KPI.
  • Customizable and Programmable: Engineering teams can easily write custom templates to check for business-logic flaws, misconfigurations, or specific organizational compliance rules.
  • Minimal False Positives: Because Nuclei templates look for specific, deterministic indicators of a vulnerability, the signal-to-noise ratio is exceptionally high compared to heuristic-based scanners.

Architectural Overview: CI/CD on a VPS

Deploying this solution on a Virtual Private Server (VPS) offers an excellent balance of cost-efficiency, control, and performance. In a typical setup, your VPS acts as the centralized automation hub. It hosts your CI/CD runner (such as GitHub Actions self-hosted runner, GitLab Runner, or Jenkins) and executes the scheduled security cron jobs.

Security Note: Because the VPS will be executing vulnerability scans, it is essential to properly configure network access. Ensure the VPS IP address is whitelisted on your staging or production Web Application Firewall (WAF) to prevent the automated scans from being blocked.

Step-by-Step Implementation Guide

Let us walk through the practical steps required to set up a daily automated Nuclei scan within a CI/CD pipeline on a Linux-based VPS using GitHub Actions and a Cron schedule as our primary reference environment.

Step 1: Preparing the VPS Environment

First, we must ensure that Nuclei is installed and correctly configured on the host machine or within a Docker container. Utilizing Docker is highly recommended to ensure isolation and reproducibility.

To install Nuclei natively on a Debian/Ubuntu-based VPS, execute the following commands:

sudo apt-get update
sudo apt-get install golang -y
GO111MODULE=on go install -v [github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest](https://github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest)
sudo cp ~/go/bin/nuclei /usr/local/bin/

Verify the installation by running nuclei -version. Next, download the latest security templates using nuclei -update-templates.

Step 2: Defining the CI/CD Pipeline Configuration

To achieve daily automated scanning, we leverage the scheduling capabilities of modern CI/CD systems. Below is an enterprise-grade GitHub Actions workflow configuration (.github/workflows/daily-security-scan.yml) designed to run every night at midnight.

name: Daily Automated Security Scan

on:
  schedule:
    - cron: '0 0 * * *'
  workflow_dispatch:

jobs:
  security-scan:
    runs-on: self-hosted-vps
    steps:
      - name: Checkout Code
        uses: actions/checkout@v4

      - name: Initialize and Update Nuclei
        run: |
          nuclei -update-templates

      - name: Execute Core Vulnerability Scan
        run: |
          nuclei -u [https://your-target-website.com](https://your-target-website.com) \
                 -tags cve,vuln,misconfig \
                 -severity critical,high,medium \
                 -o nuclei-report.json -jsonl

      - name: Process and Archive Results
        if: always()
        uses: actions/upload-artifact@v4
        with:
          name: nuclei-security-report
          path: nuclei-report.json

Step 3: Alerting and Incident Response Integration

An automated scan is only as valuable as the action it triggers. Generating a raw JSON file on a server is insufficient; developers need immediate notifications when a critical flaw is detected. Nuclei natively supports reporting integrations via Markdown, Slack, Discord, and Jira.

To integrate Slack notifications directly from your VPS-driven pipeline, modify your execution command to include the reporting configuration:

nuclei -u [https://your-target-website.com](https://your-target-website.com) -config nuclei-reporter-config.yaml

The nuclei-reporter-config.yaml file should structure the webhook target as follows:

slack:
  - slack-webhook-url: "[https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX](https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX)"
    slack-channel: "#security-alerts"
    slack-username: "Nuclei-Bot"

Advanced Best Practices for Enterprise Deployment

When running automated vulnerability scans daily against production or staging environments, adherence to operational best practices is mandatory to maintain system stability and high-quality data.

  1. Rate Limiting and Performance Tuning: By default, Nuclei executes requests concurrently. To prevent overwhelming your VPS network interface or crashing the target application server, use the -rate-limit flag (e.g., -rl 150) to restrict the maximum number of requests per second.
  2. Authenticated Scanning: Many vulnerabilities hide behind login walls. Utilize Nuclei's header manipulation capabilities (-H "Authorization: Bearer ") to pass dynamic authentication tokens during the automated cron execution.
  3. Staging vs. Production Scanning: It is highly recommended to run aggressive vulnerability templates against a replicated staging environment rather than live production environments to prevent accidental data corruption or denial-of-service conditions.

Conclusion: Continuous Assurance in an Insecure World

Integrating Nuclei into a daily CI/CD pipeline on a dedicated VPS bridges the historical divide between rapid software delivery and rigorous security protocols. By transforming security testing from an arbitrary, manual roadblock into an automated, background standard operating procedure, businesses can drastically reduce their time-to-remediation. Implementing this framework ensures that as your codebase scales, your defenses scale dynamically alongside it, protecting your digital assets and maintaining user trust proactively.