-
CMDB calls GetCategories to get a list of all the categories to make a tree.
GetCategories -
When the user selects a category, CMDB calls GetRunbooks to get a list of all runbooks using the --cat parameter to return only ones in that category. GetRunbooks also requires AWS user access data passed in 3 parameters
GetRunbooks --cat=ec2 --key_id=XXXXXXX --key_secret=XXXXXXXX --region==us-east-2
-
CMDB user selects a runbook/document and CMDB calls RunbookDetails with the --runbook param filled with the name. This returns JSON that contains the details of the runbook including options. RunbookDetails also requires the 3 AWS access parameters
RunbookDetails --name="AWS-AttachEBSVolume" --key_id=XXXXXXX --key_secret=XXXXXXXX --region==us-east-2{ "name": "AWS-AttachEBSVolume", "version": "1", "status": "Active", "description": "Attach EBS Volume", "doctype": "Automation", "owner": "Amazon", "createdDate": "2022-05-12T20:05:02.195Z", "platforms": "Windows,Linux,MacOS", "format": "JSON", "target": "/AWS::EC2::Volume", "category": "", "tags": "", "options": [ { "name": "Device", "type": "string", "required": "yes", "default": "", "description": "(Required) The device name (for example, /dev/sdh or xvdh )" }, { "name": "InstanceId", "type": "string", "required": "yes", "default": "", "description": "(Required) The ID of the instance" }, { "name": "VolumeId", "type": "string", "required": "yes", "default": "", "description": "(Required) The ID of the EBS volume. The volume and instance must be within the same Availability Zone" }, { "name": "AutomationAssumeRole", "type": "string", "required": "no", "default": "", "description": "(Optional) The ARN of the role that allows Automation to perform the actions on your behalf. " } ] }Note: the SSM satellite should pull out the InstanceID from the options and use the sourceId data passed in the job data.
-
CMDB uses Channel to run Runner with the Job Id
Runner --job_id=123456789abcdef -
Runner uses CMDB API to get Job info and do some sanity checking then calls Player and exits allowing CMDB to continue
-
Player calls CMDB API again to get Job info. Job info should look something like:
{
"job_id": "691cbefa2b601d4916633d46",
"playbook": "AWS-AttachEBSVolume",
"playbookDetails": { <--- this is a new section, really required elements are name and type
"name": "AWS-AttachEBSVolume",
"owner": "Amazon",
"version": "1",
"type": "Automation",
"format": "JSON",
"platform": "Windows,Linux"
"target": "/AWS::EC2::Volume"
}
"provider": "oracle",
"ci": {
"compute": {
"id": "69025563ec2f990705acb49e",
"name": "gtestvm3",
"sourceId": "ocid1.instance.oc1.phx.anyhqljtprqegxacbmaijtsj6pz2ko3d7wwkqhxaq6wvrwymamwzdghhr5pa",
"osFamily": "linux",
"ipAddress": "10.0.0.241",
"macAddress": "02:00:17:0E:BD:38",
"authMethod": "ssh",
"port": "22",
"user": "opc"
}
},
"credentials": {
"aws": {
"config": "access_key_id: AKIAS2CIS3YQCV6TH7WF\naccess_key_secret: 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\naws_region: us-east-2\n\n"
}
},
"options": {}
}
- Player executes the Automation or Command writes a log file and PUTs to the CMDB jobs endpoint to indicate it is finished:
“https://{cfg.Host}/api/v1/automation/jobs/{JobId}”