Integrate Your AssetsSupply ChainCI/CD Platforms

Integrate Mondoo with CI/CD Platforms

Integrate Mondoo with major CI/CD platforms to catch security issues before they reach production.

Mondoo integrates with major CI/CD platforms to catch security issues during development and testing, before they reach production. Finding problems early in the development cycle makes them easier and less expensive to fix, and prevents security issues from blocking production deployments at the last minute.

With Mondoo security scanning in CI/CD systems, you can:

Supported platforms

Mondoo supports these CI/CD platforms:

General CI/CD setup

No matter if you want to scan Kubernetes manifests, container images, or deployed VMs, the setup follows a basic pattern:

  1. Install cnspec or use the cnspec Docker image.

  2. Store Mondoo credentials securely in your CI system.

  3. Run cnspec to scan systems or repository files.

Scan infrastructure as code

To scan all the infrastructure as code in a repository in one step, run cnspec scan iac from the root of the checked-out repository:

cnspec scan iac . \
  --discover auto,terraform \
  --risk-threshold 90 \
  --output junit --output-target cnspec-junit.xml

cnspec finds every Ansible, Bicep, CloudFormation, Dockerfile, Helm, Kubernetes manifest, and Kustomize entry point in the repository and scans each one as its own asset. --discover auto,terraform adds Terraform, which is not scanned unless you name it. Name opentofu as well if your repository uses OpenTofu. New charts, templates, and modules are picked up automatically, so you don't need to edit the pipeline as the repository grows.

The iac provider is experimental and requires cnspec 14.0 or later. To learn what it detects and how to tune it, read Scan a Whole Infrastructure as Code Repository. Each CI/CD guide below includes a complete example.

Exit code handling

Exit codes allow CI systems to properly raise failure conditions to users. Mondoo has several methods of controlling how and when a scan causes a CI system to fail a job.

Pass on successful scan

By default, cnspec scan doesn't set a risk threshold, so a low policy score alone never fails the build:

  • 0 indicates a successful scan, regardless of policy score.

  • 1 indicates an asset failed to scan or the scan itself errored.

Fail on a risk threshold

To fail the build when a scan finds risks you consider unacceptable, set --risk-threshold. cnspec exits with status 1 if any risk meets or exceeds the value. Risk scores range from 0 to 100, so the value maps to a severity:

--risk-thresholdFails the build on
90Critical risks
70High and critical risks
40Medium and higher risks
101 (default)Never, based on risk alone

The examples in these guides use --risk-threshold 90, which fails the build only on critical risks. Lower it to enforce a stricter standard as your team resolves findings.

cnspec scan docker a3592cc01fdf --risk-threshold 90

Report results in your CI system

Results always go to Mondoo Platform when the job has Mondoo credentials. To also show them in your CI system, write a report file with --output and --output-target:

cnspec scan iac . --risk-threshold 90 --output junit --output-target cnspec-junit.xml

Most CI systems display JUnit files as test results, with one test suite per scanned asset. cnspec also writes SARIF (--output sarif) and other formats. To learn more, read Report Results.

Store Mondoo credentials

Mondoo uses a private key to encrypt all communication with the Mondoo API. Because CI/CD systems do not allow persistent configuration on build nodes, the configuration must be passed into the CI/CD job.

All CI/CD environments have a way to store environment variables. Some provide extra capabilities to store secrets, which we recommend. Set an environment variable with the content of the agent credentials file.

The JSON configuration file includes the agent's private key and certificate. The PEM format requires proper newlines, and some CI/CD systems interpret the newlines, which causes failures reading the credentials. To prevent this, encode the credentials data using base64 encoding. Mondoo automatically encodes credentials generated for CI integrations to avoid errors.

After you integrate

Once Mondoo is scanning your pipelines, review each pipeline's jobs on the CI/CD page. To learn how, read View CI/CD Scan Results. Then head to Assess and improve your security to review and prioritize the findings.

On this page