Integrate Your AssetsSupply ChainCI/CD Platforms

Scan in CircleCI Projects

Integrate Mondoo with CircleCI to scan Kubernetes manifests, Terraform, and Docker images during builds.

Integrate Mondoo with your CircleCI projects to scan Kubernetes manifests, Terraform configurations, and Docker images during your build process. Catching security issues in CI/CD is faster and cheaper than discovering them after deployment.

Configure CircleCI security

To set up a CircleCI integration with Mondoo:

  • Create Mondoo credentials

  • Store those credentials in CircleCI

Create credentials in Mondoo

Configure a Mondoo service account to fetch policies and send scan results to Mondoo Platform:

  1. In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL.

  2. On the integrations page, under CI/CD, select CircleCI (or search by name).

  3. Copy the value in the Copy the Mondoo Platform credentials box to use it as a variable in your pipeline.

The credential is a base64-encrypted code that contains all the information needed to send the results of the scan to Mondoo. You can decrypt and check the content easily using this command:

echo <Credentials> | base64 -d

Securely store credentials in CircleCI

Configure your CircleCI project to store the credentials for cnspec:

  1. On your CircleCI project dashboard, select the Project Settings button.

    CircleCI project dashboard

  2. In the left navigation, select Environment Variables.

  3. Select the Add Environment Variable button.

  4. Name the variable MONDOO_CONFIG_BASE64 and then, in the Value box, paste the credentials you copied in the steps above.

    Mondoo credentials in a CircleCI environment variable

  5. Select the Add Environment Variable button.

Example configuration

This example lets you build Docker images as part of your CI/CD pipeline. You can use cnspec to verify the Docker image before you push it to the registry. This configuration runs a docker build and a cnspec scan:

.circleci/config.yml
version: 2.1
jobs:
  build:
    docker:
      - image: cimg/base:stable
    steps:
      - setup_remote_docker
      - checkout
      - run:
          name: Install cnspec
          command: |
            bash -c "$(curl -sSL https://install.mondoo.com/sh)"
            cnspec version
      # - run: docker login -u $DOCKER_USER -p $DOCKER_PASS
      - run: docker build -t yourorg/docker-image:0.1.$CIRCLE_BUILD_NUM .
      # the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
      - run: cnspec scan docker yourorg/docker-image:0.1.$CIRCLE_BUILD_NUM --risk-threshold 90
      # - run: docker push docker yourorg/docker-image:0.1.$CIRCLE_BUILD_NUM

--risk-threshold 90 fails the job only on critical risks (90 or higher). To also fail on high risks, set it to 70. To fail on medium risks too, set it to 40. To learn more, read Exit code handling.

You can view the results directly in the CircleCI job or in the Mondoo CI/CD view.

Run a mondoo scan in CircleCI

Scan infrastructure as code

To scan every infrastructure as code entry point in the repository in one step, run cnspec scan iac. It finds and scans Ansible, Bicep, CloudFormation, Dockerfile, Helm, Kubernetes manifest, and Kustomize files, plus Terraform when you name it in --discover. New charts, templates, and modules are picked up without changing the pipeline. The iac provider requires cnspec 14.0 or later.

This job installs cnspec, scans the checked-out repository, and stores the report as test results:

.circleci/config.yml
version: 2.1
jobs:
  iac-scan:
    docker:
      - image: cimg/base:stable
    steps:
      - checkout
      - run:
          name: Install cnspec
          command: |
            bash -c "$(curl -sSL https://install.mondoo.com/sh)"
            cnspec version
      - run: mkdir -p test-results
      # the job fails if any risk meets or exceeds the risk-threshold value; lower it to fail on less severe risks
      - run: cnspec scan iac . --discover auto,terraform --risk-threshold 90 --output junit --output-target test-results/cnspec-junit.xml
      - store_test_results:
          path: test-results
workflows:
  scan:
    jobs:
      - iac-scan

Add opentofu to --discover if the repository uses OpenTofu. The iac provider is experimental; to learn what it detects and how to tune it, read Scan a Whole Infrastructure as Code Repository.

Once your pipeline reports to Mondoo, head to the security overview to assess and prioritize the findings.

On this page