CLI Commands

cnspec providers install

Install a new provider or update an existing one to add connectivity to a specific asset type.

Manually install or update a provider to add connectivity to a specific asset type. This is useful in air-gapped environments or when you need a specific provider version. In most cases, cnspec automatically installs the providers it needs.

Install the latest version of the AWS provider:

cnspec providers install aws

Install a specific version of a provider:

cnspec providers install aws@9.2.0

Install a provider from a local file (useful in air-gapped environments):

cnspec providers install --file /path/to/provider.tar.xz

Install only a provider's config and resource schema, skipping the much larger binary download. That's enough to compile queries against the provider's resources, but not to connect to assets. To scan or query assets, install the provider fully. You can't combine --schema-only with --file:

cnspec providers install aws --schema-only

Install a provider from the preview release channel for this one command, without changing your configured channel. --channel has no effect when you pin a version (NAME@VERSION) or install with --file or --url. To learn more, read Release channels:

cnspec providers install notion --channel preview

Options

      --channel string   Release channel to resolve from: stable or preview (default: the configured update_channel, or the channel this build belongs to)
  -f, --file string      Install a provider via a file
  -h, --help             help for install
      --schema-only      Install only the provider's config and resource schema, without its binary
      --url string       Install a provider via a URL

Options inherited from parent commands

      --api-proxy string        Set the proxy for communications with Mondoo Platform API
      --auto-update             Enable automatic provider installation and update (default true)
      --config string           Set config file path (default $HOME/.config/mondoo/mondoo.yml)
      --log-level string        Set the log level: error, warn, info, debug, trace (default "info")
      --logging-config string   Path to a logging configuration file (YAML or JSON) that selects the log writer, level, and writer-specific options
      --strict                  Default MQL strict mode for policies that do not declare one: every link in an MQL chain must resolve
  -v, --verbose                 Enable verbose output

SEE ALSO

On this page