Integrate Your AssetsSupply ChainCI/CD Platforms

Scan in GitLab CI/CD

Integrate Mondoo security scans into GitLab CI/CD pipelines to catch issues before deployment.

Integrate Mondoo security scans with your GitLab projects using GitLab's built-in runner functionality. Scanning your Kubernetes manifests, Terraform configurations, and Docker images during your pipeline helps you catch security issues before deployment, when they're easier and faster to fix.

Configure GitLab CI/CD security

To set up a GitLab CI/CD integration with Mondoo:

  • Create Mondoo credentials

  • Store those credentials in GitLab

Create credentials in Mondoo

To fetch policies and send scan results to Mondoo Platform, first configure a Mondoo service account for use in your CI/CD pipeline:

  1. In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL.

  2. On the integrations page, under CI/CD, select GitLab CI/CD (or search by name).

  3. Copy the value in the Copy the Mondoo Platform credentials box to use it as a variable in your pipeline.

The credential is a base64-encrypted code that contains all the information needed to send the results of the scan to Mondoo. You can decrypt and check the content easily using this command:

echo <Credentials> | base64 -d

Securely store credentials in GitLab

  1. In the GitLab console, select the repository you want to scan with Mondoo.

  2. Go to Settings -> CI/CD and expand the Variables section.

  3. Select Add variable. Store Credentials in GitLab

  4. In the Add Variable dialog box, name the key MONDOO_CONFIG_BASE64.

  5. Paste the Base64-encoded credential you downloaded from Mondoo.com into the Value field.

  6. Keep the default values for Type and Environment scope.

  7. Be sure to uncheck Protect variable so that this secret can be used for tests running in merge requests.

  8. Check Mask variable to hide this secret in logs.

  9. Select Add variable.

Create the GitLab pipeline config

Now that you have Mondoo credentials for running CI security scans, you can set up a GitLab Pipeline by creating a .gitlab-ci.yml configuration file.

Every release of cnspec is published as a Docker image to Docker Hub. Because GitLab makes heavy use of Docker containers as a runtime environment, it is easiest to use Mondoo's Docker image to run your scans.

This example creates a dummy GitLab pipeline configuration with two jobs, build-docker and mondoo-cnspec, as well as two stages, build and test:

.gitlab-ci.yml
stages:
  - build
  - test

# Build docker image
build-docker:
  image: docker:latest
  stage: build
  services:
    - docker:dind
  script:
    - docker build . --tag mondoo_test_image

# Scan docker image
mondoo-cnspec:
  stage: test
  image:
    name: mondoo/cnspec:latest
    entrypoint: ['']
  script:
    - mkdir -p /root/.docker/ && echo "{\"auths\":{\"$CI_REGISTRY\":{\"username\":\"$CI_REGISTRY_USER\",\"password\":\"$CI_REGISTRY_PASSWORD\"}}}" > /root/.docker/config.json
    # the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
    - cnspec scan container ${CI_REGISTRY_IMAGE}:${CI_COMMIT_REF_SLUG} --risk-threshold 90
  dependencies:
    - build-docker

--risk-threshold 90 fails the job only on critical risks (90 or higher). To also fail on high risks, set it to 70. To fail on medium risks too, set it to 40. To learn more, read Exit code handling.

JUnit report

If you prefer to store the report as a JUnit file to use GitLab's JUnit Report view feature, you can use:

.gitlab-ci.yml
mondoo:
  stage: test
  image:
    name: mondoo/cnspec:latest
    entrypoint: ['']
  script:
    - mkdir -p /root/.docker/ && echo "{\"auths\":{\"$CI_REGISTRY\":{\"username\":\"$CI_REGISTRY_USER\",\"password\":\"$CI_REGISTRY_PASSWORD\"}}}" > /root/.docker/config.json
    - cnspec scan container ${CI_REGISTRY_IMAGE}:latest --risk-threshold 90 --output junit --output-target mondoo-junit.xml
  artifacts:
    paths:
      - mondoo-junit.xml
    expire_in: 1 week
    reports:
      junit: mondoo-junit.xml
  # allow_failure: true
  dependencies:
    - build

Scan infrastructure as code

To scan every infrastructure as code entry point in the repository in one job, run cnspec scan iac. It finds and scans Ansible, Bicep, CloudFormation, Dockerfile, Helm, Kubernetes manifest, and Kustomize files, plus Terraform when you name it in --discover. New charts, templates, and modules are picked up without changing the pipeline.

The iac provider requires cnspec 14.0 or later, so pin the image to mondoo/cnspec:14:

.gitlab-ci.yml
mondoo-iac:
  stage: test
  image:
    name: mondoo/cnspec:14
    entrypoint: ['']
  script:
    # the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
    - cnspec scan iac . --discover auto,terraform --risk-threshold 90 --output junit --output-target mondoo-iac-junit.xml
  artifacts:
    when: always
    paths:
      - mondoo-iac-junit.xml
    expire_in: 1 week
    reports:
      junit: mondoo-iac-junit.xml

GitLab checks out the repository into the job's working directory, so . is the root of the repository. Add opentofu to --discover if the repository uses OpenTofu. The iac provider is experimental; to learn what it detects and how to tune it, read Scan a Whole Infrastructure as Code Repository.

Get more example pipeline configs

You can copy example GitLab pipeline configs from the Mondoo App.

  1. In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL.

  2. On the integrations page, under CI/CD, select GitLab CI/CD (or search by name).

  3. Scroll to step 3. Select the tab for the config you want to copy.

  4. In the top-right corner of the sample config, select the copy icon to copy the config to your clipboard.

Set up a pipeline to scan your GitLab instance

You can set up a scan of your GitLab instance itself from within a pipeline configuration. See Scan from a GitLab CI/CD pipeline for more information.

Once your pipeline reports to Mondoo, head to the security overview to assess and prioritize the findings.

On this page