Run ReportsContinuous Data Exports

Export Data to Google BigQuery

Set up continuous export of assets, vulnerabilities, and scan results from Mondoo to a Google BigQuery dataset using Workload Identity Federation or a service account key.

Export your Mondoo security data to Google BigQuery so you can run SQL queries across your assets, vulnerabilities, and scan results. BigQuery is ideal for custom dashboards, trend analysis, and joining Mondoo data with other datasets in your warehouse. For how exports work in general, read Continuous Data Exports.

Requirements

  • A GCP project with the BigQuery API enabled

  • Editor or Owner access to the Mondoo space from which you want to export data

  • Permission in GCP to create service accounts, Workload Identity Pools, and IAM policy bindings

Create a BigQuery dataset

Your BigQuery integration needs a dataset to which Mondoo exports data. To learn about BigQuery datasets, read Introduction to datasets in the Google documentation.

Create a new GCP BigQuery dataset for the Mondoo integration to use. For instructions, read Creating datasets in the Google documentation.

Note the dataset ID (in the format PROJECT_ID.DATASET_ID). You need it when you configure the integration.

Choose an authentication method

Mondoo can authenticate to GCP in two ways:

  • Workload Identity Federation (WIF) (recommended): Keyless. You create a Workload Identity Pool, an OIDC provider for Mondoo, and a service account in GCP, then paste the audience URL and service account email into Mondoo. Nothing to rotate.

  • Service account key: A static JSON key file. Simplest to set up, but you're responsible for securely storing and regularly rotating the key.

With WIF, Mondoo acts as an OIDC identity provider. When it's time to export, Mondoo issues a short-lived OIDC token and presents it to GCP. GCP validates the token against Mondoo's public signing keys (fetched from Mondoo's OIDC discovery endpoint), then issues temporary GCP credentials that Mondoo uses to write data to BigQuery. No static keys are stored or transmitted.

Step 1: Create a GCP service account

Create a GCP service account that Mondoo will impersonate to write data to BigQuery. Do not create a key for this service account; WIF replaces the need for static keys.

  1. In the GCP Console, navigate to IAM & Admin > Service Accounts.

  2. Select Create Service Account.

  3. Give the service account a name (for example, mondoo-bq-export) and select Create and Continue.

  4. Grant the service account the following roles:

    • BigQuery Data Editor (roles/bigquery.dataEditor)
    • BigQuery Job User (roles/bigquery.jobUser)

    For dataset-level permissions instead of project-level, grant BigQuery Data Editor on the specific dataset. To learn how, read Grant access to a dataset in the Google documentation.

  5. Select Done. Note the service account email address (for example, mondoo-bq-export@PROJECT_ID.iam.gserviceaccount.com).

Step 2: Create a Workload Identity Pool

A Workload Identity Pool is a GCP resource that manages external identities. You create one pool and add Mondoo as an OIDC provider within it.

  1. In the GCP Console, navigate to IAM & Admin > Workload Identity Federation.

  2. Select Create Pool.

  3. Enter a name for the pool (for example, mondoo-export-pool) and an optional description.

  4. Make sure the pool is Enabled and select Continue.

Step 3: Add Mondoo as an OIDC provider to the pool

Within the Workload Identity Pool, add Mondoo as a trusted OpenID Connect (OIDC) identity provider. GCP uses Mondoo's OIDC discovery endpoint to fetch the public keys it needs to validate the tokens Mondoo presents during export.

  1. In the pool you just created, select Add Provider.

  2. For Select a provider, choose OpenID Connect (OIDC).

  3. Enter a provider name (for example, mondoo-provider).

  4. Set the Issuer (URL) to the Mondoo STS endpoint for your environment:

    EnvironmentIssuer URL
    Mondoo (US)https://sts.us.mondoo.com
    Mondoo (EU)https://sts.eu.mondoo.com
    Mondoo Edgehttps://sts.edge.mondoo.com
    Dedicated deploymenthttps://sts.mondoo.CUSTOMER.com

    GCP automatically fetches the OIDC discovery document from <issuer>/.well-known/openid-configuration to obtain Mondoo's signing keys. To learn more about Mondoo's OIDC endpoints, see Mondoo as an OIDC identity provider.

  5. Under Audiences, select Allowed audiences and leave the default value. The audience is the full provider resource name, which you note in the next step.

  6. Under Attribute Mapping, add this mapping:

    Google attributeOIDC attribute
    google.subjectassertion.sub
  7. Select Save.

Step 4: Note the WIF audience URL

After creating the provider, note the full audience URL. It follows this format:

https://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/providers/PROVIDER_ID

You can find this on the provider details page in the GCP Console. You enter this value in Mondoo in the next step.

PROJECT_NUMBER is a numeric value, not the project ID string. Find it on your GCP project's dashboard or by running:

gcloud projects describe PROJECT_ID --format='value(projectNumber)'

Step 5: Create the BigQuery export integration in Mondoo

  1. In the Mondoo App, navigate to the space from which you want to export data.

  2. In the side navigation bar, select Integrations, then select INSTALL. Under Data Exports, select BigQuery.

  3. In the Integration name box, enter a name for the integration.

  4. In the Dataset ID box, enter your BigQuery dataset ID (in the format PROJECT_ID.DATASET_ID). To find this value, read Listing datasets in the Google documentation.

  5. Select the Workload Identity Federation (recommended) tab.

  6. In the WIF Audience URL box, enter the audience URL from Step 4.

  7. In the Service Account Email (for impersonation) box, enter the email of the service account you created in Step 1 (for example, mondoo-bq-export@PROJECT_ID.iam.gserviceaccount.com).

  8. Select Create Integration.

Creating the integration immediately attempts a first export, but the GCP binding that authorizes Mondoo doesn't exist yet, so that attempt fails. That's expected. Complete Steps 6 and 7, then run a fresh export in Step 8.

Alternative: Create the integration using the GraphQL API
mutation {
  createClientIntegration(
    input: {
      scopeMrn: "//captain.api.mondoo.app/spaces/YOUR_SPACE_ID"
      name: "BigQuery WIF Export"
      type: BIGQUERY
      longLivedToken: false
      configurationOptions: {
        bigqueryConfigurationOptions: {
          datasetId: "PROJECT_ID.DATASET_ID"
          wifAudience: "https://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/providers/PROVIDER_ID"
          wifServiceAccountEmail: "mondoo-bq-export@PROJECT_ID.iam.gserviceaccount.com"
        }
      }
    }
  ) {
    integration {
      mrn
      configurationOptions {
        ... on BigqueryConfigurationOptions {
          datasetId
          wifSubject
          wifAudience
        }
      }
    }
  }
}

Step 6: Copy the WIF subject value

After you create the integration, Mondoo computes a WIF subject value that uniquely identifies this integration. You need this value to authorize Mondoo in GCP.

  1. On the integration details page in the Mondoo App, find the WifSubject field.

  2. Copy the subject value. It has the format INTEGRATION_ID@integrations.SPACE_ID.spaces.iam.REGION.mondoo.app, where REGION is the short name of your Mondoo region (for example, us).

If you created the integration using the API, the subject is in the wifSubject field of the response.

The WIF subject is a computed, read-only value. Mondoo generates it automatically when you create the integration; you cannot set or change it.

Step 7: Authorize the WIF subject to impersonate the service account

Back in GCP, you must grant the WIF subject the Workload Identity User role on the service account you created in Step 1. This allows Mondoo's OIDC-validated identity to impersonate the service account and write to BigQuery.

Run this gcloud command, substituting your own values:

gcloud iam service-accounts add-iam-policy-binding \
  mondoo-bq-export@PROJECT_ID.iam.gserviceaccount.com \
  --project=PROJECT_ID \
  --role="roles/iam.workloadIdentityUser" \
  --member="principal://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/subject/SUBJECT_VALUE"
PlaceholderReplace with
PROJECT_IDYour GCP project ID (the string identifier, not the number)
PROJECT_NUMBERYour GCP project number (numeric)
POOL_IDThe Workload Identity Pool ID from Step 2
SUBJECT_VALUEThe WIF subject value you copied in Step 6

Step 8: Verify the integration

The export runs on its configured schedule (approximately every 24 hours). To verify the setup works immediately:

  1. Return to the integration details page in the Mondoo App.

  2. Select RUN to trigger an immediate export.

  3. Wait for the export to complete. If the status changes to active, the setup is working correctly.

If the export fails, double-check:

  • The WIF audience URL matches the full provider resource name in GCP exactly (including project number, pool ID, and provider ID).
  • The service account email is correct.
  • The gcloud iam service-accounts add-iam-policy-binding command completed successfully with the correct subject value.
  • The service account has the required BigQuery roles (BigQuery Data Editor and BigQuery Job User).

Manage this integration

After it's created, find your integration under Integrations in your space's side navigation. Select it to open the detail page, where you can:

  • Trigger a manual export. Exports run automatically about every 24 hours. To export immediately, select RUN.
  • Check the status. ACTIVE means the integration is healthy and exporting on schedule. PENDING means Mondoo hasn't attempted the first export yet. ERROR means the last export failed. The Export Details section shows when the last export succeeded and when Mondoo last attempted one.
  • Review the activity log. Most Recent Activity lists each export run's messages, such as when a job started, finished, or failed and why. Filter it to errors, warnings, or info messages.
  • Change the settings. Select the pencil icon to edit the integration, for example to update credentials.
  • Remove the integration. Select the trash can icon and confirm. Mondoo stops future exports but does not delete data that has already been exported.

Next steps

On this page