HTTP Action
HTTP action makes an HTTP request.
apiVersion: mission-control.flanksource.com/v1
kind: Playbook
metadata:
name: log-component-status
spec:
description: Post component name and status to webhook
components:
- types:
- KubernetesCluster
actions:
- name: Post a message to webhook
http:
url: https://webhook.site/9f1392a6-718a-4ef5-a8e2-bfb55b08afca
method: POST
body: |
{
"component": {
"name": "{{.component.name}}",
"status": "{{.component.status}}"
}
}
templateBody: true
headers:
- name: X-Postgres-User
value: admin@local
- name: X-Flanksource-Token
value: secret123
| Field | Description | Scheme |
|---|---|---|
name* | Step Name |
|
http | HTTP Action | |
delay | A delay before running the action e.g. |
|
filter | Conditionally run an action | CEL with Playbook Context |
runsOn | Which runner (agent) to run the action on | |
templatesOn | Where templating (and secret management) of actions should occur |
|
timeout | Timeout on this action. |
HTTP
| Field | Description | Scheme |
|---|---|---|
url* | Url to make the request to |
|
awsSigV4 | Sign the request with AWS Signature Version 4 | |
bearer | Bearer token to authenticate with | |
body | Request Body Contents |
|
connection | Connection name. e.g. connection://http/google | |
digest | Use digest authentication |
|
headers | Header fields to be used in the request | |
method | HTTP method to use. Defaults to |
|
ntlm | Use NTLM authentication |
|
ntlmv2 | Use NTLMv2 authentication |
|
oauth | Authenticate using the OAuth client credentials flow | |
password | Password to authenticate with | |
templateBody | When set to true the request body is templated |
|
tls | TLS settings for the request | |
username | Username to authenticate with |
OAuth
| Field | Description | Scheme |
|---|---|---|
clientID | OAuth client ID | |
clientSecret | OAuth client secret | |
params | Additional parameters sent to the token endpoint |
|
scope | Scopes to request |
|
tokenURL | URL of the token endpoint |
|
AWS SigV4
Accepts every field of an AWSConnection, plus:
| Field | Description | Scheme |
|---|---|---|
service | AWS service the request is signed for e.g. |
|
TLS
| Field | Description | Scheme |
|---|---|---|
ca | PEM encoded certificate of the CA used to verify the server certificate | |
cert | PEM encoded client certificate | |
handshakeTimeout | TLS handshake timeout. Defaults to 10 seconds | |
insecureSkipVerify | Do not verify the server's certificate chain and host name |
|
key | PEM encoded client private key |
Output
| Field | Description | Scheme |
|---|---|---|
code | Response status code |
|
content | Response Body Contents |
|
headers | Response headers |
|
Templating
CEL Expressions
The following variables can be used within the CEL expressions of filter, if, delays and parameters.default:
| Field | Description | Schema |
|---|---|---|
config | Config passed to the playbook | ConfigItem |
check | Canary Check passed to the playbook | Check |
playbook | Playbook passed to the playbook | Playbook |
run | Current run | Run |
params | User provided parameters to the playbook | map[string]any |
request | Webhook request | Webhook Request |
env | Environment variables defined on the playbook | map[string]any |
user.name | Name of the user who invoked the action | string |
user.email | Email of the user who invoked the action | string |
agent.id | ID of the agent the resource belongs to. | string |
agent.name | Name of the agent the resource belongs to. | string |
Conditionally Running Actions
Playbook actions can be selectively executed based on CEL expressions. These expressions must either return
- a boolean value (
trueindicating run the action & skip the action otherwise) - or a special function among the ones listed below
| Function | Description |
|---|---|
always() | run no matter what; even if the playbook is cancelled/fails |
failure() | run if any of the previous actions failed |
skip() | skip running this action |
success() | run only if all previous actions succeeded (default) |
timeout() | run only if any of the previous actions timed out |
delete-kubernetes-pod.yaml---
apiVersion: mission-control.flanksource.com/v1
kind: Playbook
metadata:
name: notify-send-with-filter
spec:
parameters:
- name: message
label: The message for notification
default: '{{.config.name}}'
configs:
- types:
- Kubernetes::Pod
actions:
- name: Send notification
exec:
script: notify-send "{{.config.name}} was created"
- name: Bad script
exec:
script: deltaforce
- name: Send all success notification
if: success() # this filter practically skips this action as the second action above always fails
exec:
script: notify-send "Everything went successfully"
- name: Send notification regardless
if: always()
exec:
script: notify-send "a Pod config was created"
Defaulting Parameters
delete-kubernetes-pod.yamlapiVersion:
mission-control.flanksource.com/v1
kind: Playbook
metadata:
name: edit
spec:
title: 'Edit Kustomize Resource'
icon: flux
parameters:
- default: 'chore: update $(.config.type)/$(.config.name)'
name: commit_message
Go Templating
When templating actions with Go Templates, the context variables are available as fields of the template's context object . eg .config, .user.email
Templating Actions
delete-kubernetes-pod.yamlapiVersion: mission-control.flanksource.com/v1
kind: Playbook
metadata:
name: scale-deployment
spec:
description: Scale Deployment
configs:
- types:
- Kubernetes::Deployment
parameters:
- name: replicas
label: The new desired number of replicas.
actions:
- name: kubectl scale
exec:
script: |
kubectl scale --replicas={{.params.replicas}} \
--namespace={{.config.tags.namespace}} \
deployment {{.config.name}}
Functions
| Function | Description | Return |
|---|---|---|
getLastAction() | Returns the result of the action that just run | Action Specific |
getAction({action}) | Return the result of a specific action | Action Specific |
Reusing Action Results
action-results.yamlapiVersion: mission-control.flanksource.com/v1
kind: Playbook
metadata:
name: use-previous-action-result
spec:
description: Creates a file with the content of the config
configs:
- types:
- Kubernetes::Pod
actions:
- name: Fetch all changes
sql:
query: SELECT id FROM config_changes WHERE config_id = '{{.config.id}}'
driver: postgres
connection: connection://postgres/local
- name: Send notification
if: 'last_result().count > 0'
notification:
title: 'Changes summary for {{.config.name}}'
connection: connection://slack/flanksource
message: |
{{$rows:=index last_result "count"}}
Found {{$rows}} changes