How to Run Strix in Headless Mode for Automated CI/CD Pipelines
Run Strix with the -n or --non-interactive flag to disable the Text-User-Interface (TUI) and execute fully headless, streaming findings to stdout and exiting with code 2 when vulnerabilities are detected.
Strix is an AI-powered security scanning tool from the usestrix/strix repository designed for automated vulnerability detection. Running Strix in headless mode eliminates the need for an interactive terminal, making it ideal for integration into CI/CD pipelines, containerized environments, and scheduled security scans.
The Non-Interactive Flag
Strix provides the --non-interactive (short form -n) boolean flag in strix/interface/main.py (lines 336–343) to bypass the interactive TUI. When this flag is present, the application calls asyncio.run(run_cli(args)) instead of launching the TUI, enabling the scanner to operate in environments without a TTY.
Architecture of Headless Execution
CLI Argument Parsing
In strix/interface/main.py (lines 336–343), the argument parser defines --non-interactive as a boolean flag. This setting determines the execution path within the main() function, ensuring that CI environments can invoke the tool without triggering interactive widgets.
Main Entry Point and Exit Codes
The main() function in strix/interface/main.py (lines 557–579) implements the critical logic for automated pipelines. After parsing arguments, it checks args.non_interactive:
- If true: Executes
asyncio.run(run_cli(args))and, upon completion, exits with code 2 when any vulnerability reports are generated - If false: Launches the TUI via
run_tui()
The exit code 2 behavior enables pipelines to automatically fail when security findings are detected, gating deployments based on scan results.
CLI Runner Implementation
The run_cli function in strix/interface/cli.py handles the headless execution flow. Instead of interactive widgets, it prints a static startup panel, streams live statistics to stdout, and outputs a final summary panel. This implementation writes the complete report to strix_runs/<run-name> while maintaining console output suitable for CI logs.
Browser Automation in Headless Mode
When scans require browser automation (e.g., for XSS detection or authentication flows), Strix ensures headless operation at the tooling level. In strix/tools/browser/browser_instance.py (lines 63–66), the Playwright browser instance launches with headless=True, guaranteeing that browser-based tools function in display-less container environments regardless of the CLI mode.
Command-Line Usage Examples
Basic Headless Scan
Execute a quick security scan against a live application without interactive elements:
strix -n -t https://my-app.example.com --scan-mode quick
-n: Enables non-interactive (headless) mode-t: Specifies the target URL (repeatable for multiple targets)--scan-mode quick: Uses lightweight scanning suitable for CI (default isdeep)
The command streams findings to stdout, writes the full report to strix_runs/<run-name>, and exits with code 2 if vulnerabilities are found.
Headless Scan with Custom Instructions
Provide detailed scope, authentication, or vulnerability focus via an instruction file:
strix -n -t ./my-service \
--instruction-file ./ci-instructions.txt \
--scan-mode standard
CI/CD Pipeline Integration
GitHub Actions Workflow
Integrate Strix into pull request checks to block merges with security regressions:
name: Security Scan with Strix
on:
pull_request:
branches: [ main ]
jobs:
strix-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Strix
run: curl -sSL https://strix.ai/install | bash
- name: Run Strix (headless)
env:
STRIX_LLM: ${{ secrets.STRIX_LLM }}
LLM_API_KEY: ${{ secrets.LLM_API_KEY }}
run: |
strix -n -t ./ --scan-mode quick
The workflow sets LLM configuration via repository secrets. Because the CLI runs with -n, the job fails automatically when Strix detects vulnerabilities, preventing insecure code from reaching the main branch.
GitLab CI Configuration
Run Strix in a Python-based container with explicit environment variable exports:
strix_scan:
image: python:3.11-slim
stage: test
script:
- apt-get update && apt-get install -y curl
- curl -sSL https://strix.ai/install | bash
- export STRIX_LLM="anthropic/claude-sonnet-4.6"
- export LLM_API_KEY="${LLM_API_KEY}"
- strix -n -t https://staging.example.com --scan-mode quick
Exit Codes and Automation Gates
Strix uses specific exit codes to communicate scan results to CI systems:
- Exit 0: Scan completed successfully with no vulnerabilities detected
- Exit 2: Scan completed but vulnerability reports were generated (configurable gate failure)
- Other non-zero: Critical errors or crashes during execution
According to the source code in strix/interface/main.py, the exit code 2 is explicitly set when findings exist, allowing pipeline configurations to use set -e or equivalent error-on-failure mechanisms to automatically halt deployments when security issues arise.
Summary
- Use the
-nor--non-interactiveflag instrix/interface/main.pyto disable the TUI and enable headless execution - The
main()function exits with code 2 when vulnerabilities are found, enabling automated pipeline gating - The
run_cliimplementation instrix/interface/cli.pyprovides static console output suitable for CI logs without interactive elements - Browser automation automatically runs headlessly via
headless=Trueinstrix/tools/browser/browser_instance.py, ensuring compatibility with containerized environments - Reports are written to
strix_runs/<run-name>while findings stream to stdout for immediate CI feedback
Frequently Asked Questions
What exit code does Strix return when vulnerabilities are found in headless mode?
Strix exits with code 2 when any vulnerability reports are generated during a headless scan. This behavior is implemented in strix/interface/main.py (lines 557–579) and allows CI/CD systems to automatically fail builds or block deployments when security issues are detected.
Does Strix require a display or browser setup in CI environments?
No. Strix launches Playwright browser instances with headless=True in strix/tools/browser/browser_instance.py (lines 63–66), ensuring all browser automation functions in display-less containers. This is independent of the CLI's --non-interactive flag and guarantees XSS and authentication testing work in pure CI environments.
How do I configure LLM providers when running Strix in CI/CD?
Set the STRIX_LLM and LLM_API_KEY environment variables before invoking the CLI. These variables configure the underlying AI provider without requiring interactive configuration. In GitHub Actions or GitLab CI, store these as repository or project secrets and reference them in your workflow environment blocks.
Can I run Strix headless against multiple targets simultaneously?
Yes. The -t flag accepts multiple targets when repeated. For example: strix -n -t https://api.example.com -t https://app.example.com --scan-mode quick. Strix processes all specified targets in a single headless execution, aggregating findings into the final report and maintaining a single exit code for the entire scan suite.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →