Scan in CircleCI Projects
Integrate Mondoo with CircleCI to scan Kubernetes manifests, Terraform, and Docker images during builds.
Integrate Mondoo with your CircleCI projects to scan Kubernetes manifests, Terraform configurations, and Docker images during your build process. Catching security issues in CI/CD is faster and cheaper than discovering them after deployment.
Configure CircleCI security
To set up a CircleCI integration with Mondoo:
-
Create Mondoo credentials
-
Store those credentials in CircleCI
Create credentials in Mondoo
Configure a Mondoo service account to fetch policies and send scan results to Mondoo Platform:
-
In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL.
-
On the integrations page, under CI/CD, select CircleCI (or search by name).
-
Copy the value in the Copy the Mondoo Platform credentials box to use it as a variable in your pipeline.
The credential is a base64-encrypted code that contains all the information needed to send the results of the scan to Mondoo. You can decrypt and check the content easily using this command:
echo <Credentials> | base64 -dSecurely store credentials in CircleCI
Configure your CircleCI project to store the credentials for cnspec:
-
On your CircleCI project dashboard, select the Project Settings button.

-
In the left navigation, select Environment Variables.
-
Select the Add Environment Variable button.
-
Name the variable
MONDOO_CONFIG_BASE64and then, in the Value box, paste the credentials you copied in the steps above.
-
Select the Add Environment Variable button.
Example configuration
This example lets you build Docker images as part of your CI/CD pipeline. You can use cnspec to verify the Docker image before you push it to the registry. This configuration runs a docker build and a cnspec scan:
version: 2.1
jobs:
build:
docker:
- image: cimg/base:stable
steps:
- setup_remote_docker
- checkout
- run:
name: Install cnspec
command: |
bash -c "$(curl -sSL https://install.mondoo.com/sh)"
cnspec version
# - run: docker login -u $DOCKER_USER -p $DOCKER_PASS
- run: docker build -t yourorg/docker-image:0.1.$CIRCLE_BUILD_NUM .
# the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
- run: cnspec scan docker yourorg/docker-image:0.1.$CIRCLE_BUILD_NUM --risk-threshold 90
# - run: docker push docker yourorg/docker-image:0.1.$CIRCLE_BUILD_NUM--risk-threshold 90 fails the job only on critical risks (90 or higher). To also fail on high risks, set it to 70. To fail on medium risks too, set it to 40. To learn more, read Exit code handling.
You can view the results directly in the CircleCI job or in the Mondoo CI/CD view.

Scan infrastructure as code
To scan every infrastructure as code entry point in the repository in one step, run cnspec scan iac. It finds and scans Ansible, Bicep, CloudFormation, Dockerfile, Helm, Kubernetes manifest, and Kustomize files, plus Terraform when you name it in --discover. New charts, templates, and modules are picked up without changing the pipeline. The iac provider requires cnspec 14.0 or later.
This job installs cnspec, scans the checked-out repository, and stores the report as test results:
version: 2.1
jobs:
iac-scan:
docker:
- image: cimg/base:stable
steps:
- checkout
- run:
name: Install cnspec
command: |
bash -c "$(curl -sSL https://install.mondoo.com/sh)"
cnspec version
- run: mkdir -p test-results
# the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
- run: cnspec scan iac . --discover auto,terraform --risk-threshold 90 --output junit --output-target test-results/cnspec-junit.xml
- store_test_results:
path: test-results
workflows:
scan:
jobs:
- iac-scanAdd opentofu to --discover if the repository uses OpenTofu. The iac provider is experimental; to learn what it detects and how to tune it, read Scan a Whole Infrastructure as Code Repository.
Once your pipeline reports to Mondoo, head to the security overview to assess and prioritize the findings.