Playbook
| Field | Description | Scheme |
|---|---|---|
description | A short description | string |
title | Title shown on the UI. Defaults to the playbook's name | string |
icon | Icon for the playbook | Icon |
category | Group the playbook under a category on the UI | string |
timeout | Maximum duration to let the playbook run before cancellation. Valid time units are "s", "m", "h", "d", "w", "y". Defaults to 30 minutes. | string |
on.canary | Run a playbook when a health check fails or passes | EventTrigger |
on.component | Run a playbook when a part becomes heathy/unhealthy | EventTrigger |
on.config | Run a playbook when someone creates/updates/deletes a config item or changes its state | EventTrigger |
on.webhook | Run a playbook when someone calls a webhook | Webhook |
on.schedule | Run a playbook on a recurring cron schedule | []Schedule |
runsOn | Which runner (agent) to run the playbook on | []Agent |
templatesOn | Where the templating of actions occurs For host the templating occurs on the mission control instance before sending to the agent For agent the templating occurs on the agent/runner where there might be secrets not accessible by the primary instance. | host or agent |
checks | Which health checks this playbook can run on | []ResourceSelector |
configs | Which config items this playbook can run on | []ResourceSelector |
components | Which parts this playbook can run on | []ResourceSelector |
filters | CEL expressions that decide whether the playbook can run on the selected resource | []Expression |
env | Variables to lookup, available as env map in templating/filters | []EnvVar |
parameters | Variables that users need to enter. Do not use parameters for sensitive values. | []Parameter |
jsonSchema | A JSON schema, or a URL to one, to use for the run form instead of parameters | string |
ui | Properties applied to the UI form | map[string]any |
actions | Individual actions or steps to perform | []Action |
approval | Optional approvals required before a playbook runs | Approval |
permissions | Roles and teams that are allowed to run this playbook | []Permission |
mcp | How this playbook is presented to LLM clients as an MCP tool | MCP |
Run
| Field | Description | Scheme |
|---|---|---|
agent_id | ID of the agent that executed the playbook run |
|
check_id | ID of the check associated with the playbook run |
|
component_id | ID of the component associated with the playbook run |
|
config_id | ID of the config associated with the playbook run |
|
created_by | ID of the user who created the playbook run |
|
id | ID of the playbook run |
|
playbook_id | ID of the playbook |
|
status | Status of the playbook run |
|
Actions
| Field | Description | Scheme | Required |
|---|---|---|---|
name | Step Name | string | true |
runsOn | Which runner (agent) to run the action on | []Agent | |
templatesOn | Where templating (and secret management) of actions occurs | host or agent | |
delay | A delay before running the action e.g. 8h | Duration or CEL with Playbook Context | |
if | Conditionally run an action | CEL with Playbook Context | |
timeout | Timeout on this action. | Duration | |
retry | Retry the action when it fails | Retry | |
contentType | How the action's primary output is rendered on the UI | text/plain, text/markdown, text/x-shellscript, application/json, application/yaml, application/log+json or application/sql | |
ai | Prompt an LLM with the context of the resource | AI | |
azureDevopsPipeline | Trigger a pipeline run | AzureDevops | |
catalog | Create a config item in the catalog | Catalog | |
exec | Run a script e.g. to use kubectl or aws CLIs | Exec | |
github | Trigger Github Action | Github Action | |
gitops | Update a git repository (directly or via pull request) | Gitops | |
http | Call an HTTP Endpoint | Http | |
logs | Fetch logs from Loki, CloudWatch, OpenSearch or Kubernetes | Logs | |
notification | Specify notification of action. | Notification | |
pod | Run a kubernetes pod. | Pod | |
prometheus | Run a PromQL query | PrometheusQuery | |
report | Render a catalog report from a view or a config selector | Report | |
sql | Execute a SQL query | Sql |
Only 1 action should be specified per step
Retry
| Field | Description | Scheme |
|---|---|---|
duration* | Duration to wait before retrying the action | |
exponent.multiplier* | Exponential backoff multiplier applied to the duration on every retry |
|
limit* | Number of times to retry the action. With a limit of 3 there is a max of 4 attempts (initial attempt + 3 retries) |
|
jitter | Random factor, from 0 to 100, applied to the wait duration |
|
Approvals
Approvals allow requiring one or more people to approve before a playbook runs.
scale-deployment.yamlapiVersion: mission-control.flanksource.com/v1
kind: Playbook
metadata:
name: delete-pv
spec:
description: Delete Persistent Volume
configs:
- types:
- Kubernetes::PersistentVolume
approval:
type: any
approvers:
teams:
- DevOps
actions:
- name: kubectl delete pv
exec:
script: kubectl delete persistentvolume {{.config.name}}
| Field | Description | Scheme | Required |
|---|---|---|---|
type | How many approvals required. Defaults to all | any or all | false |
approvers.[]people | Login or id of a person | People | false |
approvers.[]teams | Name or id of a team | Team | false |
Permissions
Permissions grant roles and teams the ability to run this playbook, in addition to the global permissions.
| Field | Description | Scheme | Required |
|---|---|---|---|
role | Name of a role | string | false |
team | Name of a team | string | false |
ref | Name of a Permission resource | string | false |
MCP
Mission Control exposes playbooks to LLM clients as MCP tools. The mcp field controls how a playbook is presented to those clients.
| Field | Description | Scheme | Required |
|---|---|---|---|
title | Tool title shown to the LLM. Defaults to the playbook's title | string | false |
description | Additional context for the LLM, beyond spec.description | string | false |
tags | Keywords used to categorize the tool for LLM discovery | []string | false |
readOnlyHint | The playbook does not modify any state | bool | false |
destructiveHint | The playbook may perform destructive operations | bool | false |
idempotentHint | Repeated runs with the same arguments have no additional effect | bool | false |
openWorldHint | The playbook interacts with entities outside Mission Control | bool | false |