Cloud scans
Queue a public HTTPS scan in QualityGate, track its progress and recover from target or quota errors.
Use cloud scans for an on-demand check without adding a CI job. QualityGate runs the browser on its own worker and records the result under your project. Manual cloud scans use the normal monthly allowance, not the scheduled scan allowance.
Queue a scan
- Sign in to the app and select the organization that owns the project.
- Open Projects and find Run in QualityGate Cloud on the project’s card.
- Enter a public HTTPS Target URL whose hostname matches the project’s Allowed domains.
- Choose a Scan bundle included in your package, then select Run cloud scan.
- The app opens the run detail page after the scan is queued. Keep it open to follow progress and read the findings when the scan finishes.
One queued scan reserves one normal run. Free includes a11y; paid packages
include all ten bundles. A completed scan counts even if the gate fails. A
failed browser scan releases the reservation. See
Packages and usage.
Targets and allowed hosts
Cloud targets must be reachable publicly over HTTPS. Localhost, private network addresses, embedded credentials and URLs outside your project’s allowed hosts are refused. Redirects and browser network requests are also guarded; an allowed hostname does not grant access to internal services.
For private or authenticated targets, run QualityGate in your own CI environment with the needed network access. See Preview deployments. Do not put credentials in the target URL.
Owners and admins can update allowed domains under Projects. Hosts are
entered without a scheme or path, and *.example.com matches subdomains,
not example.com itself. See Project setup.
Progress and results
The run history and detail page label these runs Cloud scan. They are manual runs: no commit, branch or pull request is attached. They do not post a PR comment or establish a default-branch regression baseline.
While the run is in progress, the detail page polls automatically, beginning at two seconds and slowing to at most ten seconds between requests. When it finishes, review the verdict, findings and reports just like a CI run.
Recovering from errors
| Problem | What to do |
|---|---|
| The domain is not allowed | Ask an owner or admin to update Allowed domains for this project |
| The target must be public | Use a public HTTPS deployment or scan from your own CI environment |
| The target could not be resolved | Check public DNS and retry after the host resolves |
| The bundle is not available | Choose a bundle in your package or ask the owner to review billing |
| The monthly run limit is reached | Review completed and in-progress usage, then wait for reset or ask the owner to upgrade |
| The scan fails after queueing | Open the run’s failure details, check the deployment and retry after fixing the target |
| Progress cannot load | Check your connection and reopen the run; do not queue duplicates just to refresh its status |
Cloud scans are on demand, not a replacement for scheduled checks or pull request gates.