Manage Policies with cnspec
Create, validate, upload, and manage cnspec policies across your infrastructure
Use cnspec commands to create, validate, and manage policies from the command line. You can run policies locally or store and share them using Mondoo Platform. To learn about policies and policy bundles, read About Policies.
This page covers the cnspec CLI workflow. To enable and manage policies in the Mondoo Platform web console instead, read Manage policies in Mondoo Platform.
Connect cnspec to Mondoo Platform
The easiest way to scale cnspec across your infrastructure is to have every asset pull its policies from a central location. Mondoo Platform provides a secure, multi-tenant environment for managing policies and scan results across your fleet.
To connect cnspec to Mondoo Platform, run:
cnspec loginOnce authenticated, every scan reports to both standard output and Mondoo Platform:
cnspec scan <target>Create a policy bundle
Generate a starter bundle with example checks and queries:
cnspec policy init example.mql.yamlTo learn how to modify existing policies or write your own, read the Policy Authoring Guide. You can also find open source policy bundles in Community Policies.
Format and validate a policy bundle
Apply consistent style formatting to a bundle:
cnspec policy format example.mql.yamlThen lint the bundle to make sure it compiles, every MQL query parses, and every UID reference resolves:
cnspec policy lint example.mql.yamlLint reports each finding with a rule ID, a level (error or warning), and the file and line to change. Errors make the bundle invalid and the command exits with a non-zero status. Warnings don't:
RULE ID LEVEL FILE LINE MESSAGE
query-deprecated-symbol warning example.mql.yaml 14 query 'cognito-pw' uses deprecated field 'aws.cognito.userPool.passwordPolicy'
→ valid policy bundle(s)Lint compiles every query and every filter, and warns when one uses a resource or field that's marked deprecated (rules query-deprecated-symbol and filter-deprecated-symbol). Deprecated resources and fields are removed in a later major release, so fix these warnings before you upgrade.
To make CI fail on specific warnings, promote them to errors with --strict-rule. Repeat the flag for each rule ID, or pass all to promote every warning:
cnspec policy lint --strict-rule query-deprecated-symbol --strict-rule filter-deprecated-symbol ./policiesLint can also warn about policies that don't declare strict mode (rule policy-missing-strict). For every lint flag, read the cnspec policy lint CLI reference.
For CI integration, output lint results as SARIF, which you can upload to GitHub code scanning:
cnspec policy lint example.mql.yaml --output sarif --output-file results.sarifUpload policies to Mondoo Platform
With a Mondoo Platform account, you can upload a policy so it's available to every space in your organization:
cnspec policy upload mypolicy.mql.yamlPolicy commands reference
| To... | Use... |
|---|---|
| List enabled policies in the connected space | cnspec policy list |
| Enable a policy in the connected space | cnspec policy enable |
| Disable a policy in the connected space | cnspec policy disable |
| Show more information about a policy from the connected space | cnspec policy info |
| Download a policy to a local bundle file | cnspec policy download |
| Create an example policy bundle | cnspec policy init |
| Apply style formatting to one or more policy bundles | cnspec policy format |
| Lint a policy bundle | cnspec policy lint |
| Upload a policy to the connected space | cnspec policy upload |
| Delete a policy from the connected space | cnspec policy delete |
Learn more
- To find ready-to-use policies before writing your own, read Community Policies.
- To author or customize policy bundles, read the Policy Authoring Guide.
- To enable and manage policies in the Mondoo Platform web console, read Manage policies in Mondoo Platform.