Integrate Your AssetsSupply ChainCI/CD Platforms

Scan in Jenkins

Integrate Mondoo with Jenkins and CloudBees CI to scan infrastructure code and container images.

Integrate Mondoo with Open Source Jenkins and CloudBees CI to scan Kubernetes manifests, Terraform configurations, and Docker images during your build pipeline. Finding security issues before deployment makes them easier to fix and prevents them from reaching production.

Configure Jenkins security

To set up a Jenkins integration with Mondoo:

  • Create Mondoo credentials

  • Store those credentials in Jenkins

Create credentials in Mondoo

Configure a Mondoo service account to fetch policies and send scan results to Mondoo Platform:

  1. In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL.

  2. On the integrations page, under CI/CD, select Jenkins (or search by name).

  3. Copy the value in the Copy the Mondoo Platform credentials box to use it as a variable in your pipeline.

The credential is a base64-encrypted code that contains all the information needed to send the results of the scan to Mondoo. You can decrypt and check the content easily using this command:

echo <Credentials> | base64 -d

Securely store credentials in Jenkins

Configure Jenkins to store the credentials for cnspec in the MONDOO_CONFIG_BASE64 environmental variable.

Paste the configuration as GCP substitution variable

Example configuration

Jenkinsfile
pipeline {
      environment {
        REGISTRY = "jenkins-docker-example"
      }
      agent any
      stages {
        stage('Cloning Git Repository') {
          steps {
            // be sure to change this to your project repository
            git 'https://github.com/lunalectric/backend.git'
          }
        }
        stage('Building image') {
          steps{
            script {
              dockerImage = docker.build("${REGISTRY}:${env.BUILD_ID}")
            }
          }
        }
        stage('Scan image') {
          environment {
            MONDOO_CONFIG_BASE64 = credentials('MONDOO_CONFIG_BASE64')
          }
          steps{
            sh 'bash -c "$(curl -sSL https://install.mondoo.com/sh)"'
            sh 'cnspec version'
            // the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
            sh "cnspec scan docker ${REGISTRY}:${env.BUILD_ID} --risk-threshold 90"
          }
        }
        stage('Deploy Image') {
          // For a Docker Registry which requires authentication,
          // add a "Username/Password" Credentials intro-item from the Jenkins home page and use the
          // Credentials ID as a second argument to withRegistry():
          environment {
            REGISTRY_CREDS = credentials('REGISTRY_CREDS')
          }
          steps{
            script {
              docker.withRegistry( '', REGISTRY_CREDS ) {
                dockerImage.push()
              }
            }
          }
        }
        stage('Remove Unused docker image') {
          steps{
            sh "docker rmi ${REGISTRY}:${env.BUILD_ID}"
          }
        }
      }
    }

--risk-threshold 90 fails the job only on critical risks (90 or higher). To also fail on high risks, set it to 70. To fail on medium risks too, set it to 40. To learn more, read Exit code handling.

You can view the results directly in the Jenkins UI or in the Mondoo CI/CD view.

Run a mondoo scan in Jenkins

Scan infrastructure as code

To scan every infrastructure as code entry point in the repository in one step, run cnspec scan iac. It finds and scans Ansible, Bicep, CloudFormation, Dockerfile, Helm, Kubernetes manifest, and Kustomize files, plus Terraform when you name it in --discover. New charts, templates, and modules are picked up without changing the pipeline. The iac provider requires cnspec 14.0 or later.

This stage runs against the repository that Jenkins checked out into the workspace, and publishes the report with the JUnit plugin:

Jenkinsfile
stage('Scan infrastructure as code') {
  environment {
    MONDOO_CONFIG_BASE64 = credentials('MONDOO_CONFIG_BASE64')
  }
  steps {
    sh 'bash -c "$(curl -sSL https://install.mondoo.com/sh)"'
    // the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
    sh 'cnspec scan iac . --discover auto,terraform --risk-threshold 90 --output junit --output-target cnspec-junit.xml'
  }
  post {
    always {
      junit 'cnspec-junit.xml'
    }
  }
}

Add opentofu to --discover if the repository uses OpenTofu. The iac provider is experimental; to learn what it detects and how to tune it, read Scan a Whole Infrastructure as Code Repository.

Once your pipeline reports to Mondoo, head to the security overview to assess and prioritize the findings.

On this page