Beers With Cloud Engineers - Episode 13 - Service Graph Connector Update w/AWS 2.0 and GCP
recording started excellent so welcome and thanks everybody to beers with Engineers session 13 right how crazy that is we've we're up to 13 already um super appreciate it you guys joining um really excited about what we have to share today um and uh and we'll always jump through kind of at the high level um kick off the um the the slide around hey everything that we say here might be you know um new and or forward-looking statements and may not actually get get deployed exactly as how we're talking about today so you know don't go and make stock purchasing decisions based on any of the conversations we have here um so excellent now we can move on to here's the fun stuff so typical agenda um we always try and keep it light and informal um as you guys all know please don't hesitate to come off of mute and jump in ask questions um this is really for you guys um so but let's we make the best use of the time for you that we can so why are we here right will and I started this early um last year to really talk about you know that intersection between servicenow and kubernetes and Cloud native capabilities and understand how customers are working through that what challenges that they're having and really build a forum for us to all kind of share together and help grow along that like Continuum of of cloud native adoption so who are we right if you don't know us by now um I am Mike Gallagher Enterprise Apps Manager uh here at drw Holdings um I am uh heavily focused in I.T operations Management kubernetes Service now in general and all things you know technology and Automation and um I love what I get to do every day and this is my favorite day of the month um I did actually probably drink more beers than I should have last night so instead of beer today I'm having cold brew excellent practice and moderation hey everyone I'm will I'm a advisory solution architect in service at service now focusing on on it operations management um similar to Mike doing a lot of stuff with Cloud native Technologies with a particular focus on kubernetes which is kind of I would say that's probably the top um the the top topic that comes up when we talk Cloud native these days and um yeah my spare time I like to hang out with my family play a little uh pickup hockey and play video games today I will be drinking an all-day haze from Founders uh it's kind of one of my go-to's I really enjoy that like a hazy IPA yeah but it's it's light it's uh pretty low ABV it's like about four and a half so it's good for like summer days where you don't want to turn into a puddle too early in the day and just kind of enjoy a refreshing adult beverage um okay so uh we've got a special guest today we've got merly from the team that brings you all of our or many of our awesome service graph connectors and uh today um just to kind of set expectations there's uh it's it's an action-packed episode this month because we're talking about two big developments in the service graph connector um Arena around AWS and and gcp and so we do expect this will go over our normal one hour we are recording this you know we want to be respectful of people's time so if you do have to you know jet because you're you're used to beers taking right about an hour um we'll have the recording available afterwards on YouTube as per usual so you'll be able to catch up on on whatever content you might have to miss because of other other time commitments okay um so merly I'll give you the stop sharing and give you the the share and you can kind of take it from here yeah thank you very well yeah so can you see my screen yes representation right yeah yeah so yeah my name is murli Reddy and uh I was working in as I work for service now I was senior staff staff engineer so one of the architect uh to design AWS and gcp so I'll be talking about uh these two uh projects which I became I was coming to live in first week of May okay so service was there for more than a year now and we have a lot of customers using it and uh So based upon a lot of feedbacks so we made a major update so that's why you see as a 2.0 release so so what are the features we are using it uh so releasing it safe we're going to start supporting multi-org support and for some customers who want to test it so they will have they can do a standalone testing with one account and uh corresponding to these changes we have made changes to the dynasty tool and the next one is one of the key feature where customers want to rotate the keys periodically so that feature and then as part of this we are introducing server classification and we made some performance Improvement uh on uh two areas where there are seeing uh perform issues with large customers having thousand plus accounts so for them they were seeing some slowness in these two areas so we made some significant performance improvements and the last one is say the livestock State status which got introduced recently with the platform yeah so these Eight Features we are going to talk one by one so the very first one I say multi of support say so far uh until currently we supported a single lock where we can have a master account and then a bunch of member accounts and we are passing all the accounts on getting the data and we've seen some customers barely need for multi-acon support where multi art supper where they have one hour for different businesses right where they want to scan all the Arts and then get all the data into one CB database so for that we made some significant changes and this is what is going to support so so how are we going to support the shape each hour will have its own credential credentials and then they need to give all these details for each Arc as part of the guided setup so once they have this and then they should be able to run so this is a detailed level details so one essay for each or we need the org account ID and our name this is just for naming uh say Drive some logic and there is no business logic behind this but just naming logic to show uh to the customer saying okay we are working on this particular Arc so that you know what is the context behind that and along with that you can go and select the list of regions whatever you're interested in so if you leave it empty so we will go and select all the regions and if you select some subset of the regions so we focus on those regions and next one is say for each org you need to have a assumed role the permissions are almost same like previous one but there is no much change in this and the next one is the management account so you put all uh you set up the service now account in the designated account right so then you need to enter it so this is similar to what we have in the current version and also of the aggregated information which is also there in the current version merly or we provide um do we provide cloud formation code for that role to propagate yeah great yeah so those are everything is there as per the current uh release so yeah we have a bunch of lower permission script which is there uh given as part of this uh download script in the guided sector so along with that say uh we need to give this some details so let's say what all you want to do a deep Discovery uh we need to have these details and uh and this one is say next was for the key rotation this is what uh newly reduced as part of this release so I'll be going to deeply talk on the uh on this one so one essay say let's say you you want to rotate the keys yes then go and enable it if at all you're not interested you can just leave it uh say don't enable it so that you don't change the keys and let's say if you want to enable it say what does it rotation period time so by System we default 30 to 90 days so if at all you want to have say 30 days or 60 days or 180 days so you can go and change this value and then you can set it up and uh last one is say the rotation status say as soon as we run the process we go and update the state is okay if it is good good it was not good we just go and say put the error message there and so this one will have the when was the last rotated right so that you know that okay so 30 days before it was rotated and it was due 60 more days so that's where the system will automatically go and rotate it question about the key rotation is is that currently that the the key that key resides in uh uh standard credential table it's not the the table that contains the AWS API Keys it's not unique to the the SG connector but the rotation capability right now that's going to be only for credentials that are used by the SG connector right right okay yeah so what we do is say uh we have a master table uh so I can show you first so this is a complete application properties table right so whatever these are the credentials always uh say Associated to service graph right we pick only these records not anybody else let's say we have a catcher application X application Y and we don't even touch that so so that's one tie to that cred Alias yeah yeah well hopefully hopefully you have lunch with the regular Discovery guys or something and you can you can offer to share your code because I'm sure if anybody's out there still discovering you know just running traditional pattern Discovery with um AWS API Keys the ability to rotate those would be would probably be of interest to those folks as well yeah so now I move to that team so I'll be the advisor for the team so yeah perfect yeah so yeah that's where uh yeah this this context is uh so we are changing only the context within status graph connector right so the feature is not available as part of the platform so uh we return on our own so that once platform is available we switch to platform feature okay so in the last one which uh introduced as part of this release where let's say uh yeah we get a new customer right and they want to test uh what are the features right so they don't want to they don't want to uh test with all the accounts right so for those type of people they can just come and uh put that one account number and then the whole driving logic will be done on one account so that they can learn from that setup and then they can propagate to the rest of the accounts so this was one of the long-standing asks from new customers so to be introduced as part of this release so it was it was also a request from the servicenow solution Consultants because we couldn't uh we couldn't easily demonstrate this capability because we didn't have org level access within our our demo AWS accounts so this is going to make it much easier to demonstrate this uh this SG connector for for all the solution Consultants in the proof of Concepts when you need to go right on prod only right this was the thing that really helped us with before yeah awesome yeah yeah so yeah so one of the frequest questions I'm getting let's say I have three orgs uh can I create one service account and have an assumed role in all the three orgs uh that is not currently supported okay uh so uh so you need to have individual uh service account for each R so that uh the architecture Works uh seamlessly the reason is say there are certain apis which works at the hard level right so they where there are a lot of classes over there right so if at all we want to support it we need to have a different uh version to handle that type of uh Logics So currently we support uh each individual or with their members member accounts okay that is uh one frequent question I was asking I was getting when I was demoing to some of the customers who are part of DBP okay and uh let's say one particular customer uh even though they are in what is it they have the one org and multiple member accounts uh what is happening is let me show you the diagrams so what is happening is uh they not able to trust between each other trust uh does the uh the roles between each account right even though if we created a service account here we are not able to hop into other accounts because they don't want to give the trust between two different accounts right right in that case say what are we suggesting is go with the Standalone account so basically you are going to have one connection for each account right so that way you can fulfill your the needs of uh with this current architecture now how does that work with the credential Alias do you create children underneath that Alias for each of those standalones each one will have its own credential areas okay yeah so yeah I'll say uh account one you have a credential Alias one according to traditionally S2 that way okay and each of those could be automatically rotated yes yeah okay so as soon as it comes to the stable right say let's see they have 10 accounts there will be 10 entries here right so each differently and then say they can enable and disable it as for the needs they wanted fantastic yeah so any questions on Multi art so far okay so the Standalone the the logic everything remains same uh only difference is say you'll be working on a one single account right as will said uh this will be helpful for uh solution consultants for the clients who want to do a POC right for those type of people this particular feature was introduced as part of the series I need to tell you one thing here and did you say this is going to hit the store the first week of May yeah yeah and the next one is the diagnostic tool uh so uh we update to the dynasty Tool uh to support the multi-out right so where you say you select the what are the art you want to test it so you can just do a drop down and then for that particular context you will get all the dynasties which was run earlier right with that the context is different so that you can know for which are the problem is there and then you can sort it up right so this is where we are asking for that our name and the our guiding okay so if you want to see uh oh so if you go here initially if the page will be loaded empty once you select the context of for which Arc you want it then you can load the corresponding the results so this way everything is on their own and then you can load all the details and then the rest of the logic remains in uh one thing what we have done as part of this release is say for some customers they are not interested in doing SSM setup they just want to have the hardware details in right so we're just trying to give the details okay you can just if you want to if you're not setting up SSN you can just click this check button check box and then if you run the diagnosis test so this test will be skipped right so that the whole test can be done in a faster man so that's one of the update we are done as part of the release so rest of the logic will remain same can I ask a question on the Diagnostics so does it does it check to see like one of the um dependencies is on assumed roles for sub-accounts to get updates and somewhere does it do any checks on that to make sure you have the proper access in terms of any other roles or anything yeah so if you go here right up uh say what we do is we hop into each every account with an assumed role right uh say we hop into all these accounts from the master account or the designated account right so what we do is we go and check each and every account and see whether that assume role has all the access if it is not there you will get uh say 400 403. let's say you have a thousand accounts and you want to see which APA is giving 403 or foreign error you can filter out and then you can select that particular account uh reach out to that particular admin and then you can go and say talk to them and then fix that issue and then you can just come back and then run the tennis tool and see whether everything is giving 200 in that way uh you can do a test multiple times until the issues are sorted off so this way it will reduce the complete burden from servicenow set and also the client side so where you know what is going to work yeah that diagnostic tool is a big help absolutely one quick question so is this if when we upgrade to this does the existing configuration that we have stay in place or do we have to reconfigure it because of the changes made for the multi-work yeah um good question so what happens is say the current uh config is everything sitting in assist properties table as soon as you upgraded those properties will be moved to the table which I showed you earlier okay awesome thank you but that's automatically get ported foreign So currently the platform doesn't support the rotation feature so we introduce this feature as part of this plugin and then by default we rotate by 90 days and uh so you need to enable it in order to get it worked okay so here's the high level flow diagram so what we do is say we go and check for each connection whether that key rotation is enabled if it is enabled then we go and make an um request to a AWS to create a new key right and then Happy path let's say I I got the new key then I go and delete the whole key and then update the new key in the table and then the rest of the process is remain same right and let's say for example if the user is not given proper IM permissions or let's say by default uh I am I am allows only two keys per user right so key keys are there it doesn't allow you to create a new key in those case what happens is uh we get an error message and we store it in that properties table so that uh you know what is going wrong and also we make an attempt to send an email notification so such a way that okay somebody uh some background process has been free and then we send an email uh saying that okay uh you need to go and take an action that is that is that email um is that destination email address configured in the properties somewhere yeah so yeah so that is part of the guided setup [Music] I think I have a slides in the Dom and is the account that it's trying to do that with the same account that you've or the same key in like secret key you've put in to manage or to get access for the infrastructure that have its own key or basically how are you what account are you using or what user are you using to rotate the key okay so how it works is say when you log in so when you gain the credentials right so we take this key right and then make an atom to rotate the key so is there an addition to or did you change the the scripts the glove formation piece to include this role okay yep got it all right thank you that's oh that's a good point so if somebody's already got the roles provisioned they would have to adjust them so that it includes the new permissions required because you'd have to IM piece yeah yeah so we need to basically have the create access key and also delete access key right so the reason why we want delete access key is say uh we need to delete the old key as soon as we are using not using it the reason is next time when let's say after 90 days if you want to rotate again uh then I'll be put getting into trouble again right so to avoid that so what we do is as soon as we create the new key we go and delete the whole keys that way we can continuously rotate every uh rotation period I'm I'm guessing that we may get feedback from customers that they want to make that permission a little more fine-grained because as it sits the the template that you that you shared basically gives the servicenow service account the ability to create and delete access keys for any IAM user and it's not it will not work so how it works is say uh I when I try to do the uh what are the term penetration testing right so I took some other key and then try to rotate the keys it doesn't work oh yeah that way they made a so strict so okay the uh AWS APA takes the context of the credentials whatever is same thing right so for the accident nice rotate it so let's say you try to uh say send it to so if you try to Let's I try to rotate for keys for you it doesn't works kudos to AWS nice so they are because I when I was trying to do all these previous and say make sure that okay I will be getting this question as part of Security review right right I'll try to demonstrate and then make sure that it is it is not getting messed up that's awesome awesome cool yeah so yeah so what we do is say as part of the credit setup uh we ask you to go and set up the email notification so here's how it looks going to look like [Music] um when you come here as part of the email to be set up so you you need to go and uh get your credentials uh sorry email so you can put our either your email or email group anything so you can just go and configure here okay so based upon that say the email you descent okay the one assumption is say uh what we assume and say you need to have the email setup done with your email provider right so that the whole end-to-end process works fine if not uh what do you have as a contingency plan is to say uh let's say you not set up the email properly right so in that case what we do is we go to this table and then so we go to this table and then say we have all the record what happened if something goes wrong so we put the status here the operation strategy so we go and record the status so the same message will go as part of the uh email message so what will contain so we send an email saying that okay we try to rotate and then that could be a couple of reasons one could be the user not having this permission and then for which role which account right we put all the details on them so that it will help you for you to go and uh diagnose issue and fix it so that way you have the complete information what to do if something goes wrong nice okay so yeah so thing is uh it is not necessary to uh so let's say for example you have 10 different accounts and you don't want to do for all the cons right so basically you go and enable disable and then based upon them we'll go and rotate the keys right say for example you have 10 accounts and then you would interested only in five accounts you can just go and do for fire cons will not be touching it so next one is save the server classification now many people are asking for a long time so since we introduced the service web AWS so we are putting all the server records in server as cmdb server class right so going forward uh so we will be populating it in less sort of Windows server to be in sync with a discovery product right so for that we need to have a SSM setup to drive whatever server type the reason is save from the existing ecd apis we never get towards the OS type so because of that we are populating here so after enabling SSM so we'll be populating it in respective server class right so if at all you're not enabled system so we'll still populate the server class in server class so that's one of the major change we're doing to be in sync with Discovery product and many were asking for this feature quite some time yeah this is going to be a big change for a lot of folks and towards the positive and after the upgrade I'm assuming this will go through and reclass on the next Discovery and move those into the appropriate classes now right yeah so yeah so the reason I say these two classes are child class of this right so we are going to mark them as Linux or Windows so there is no change in the existing data will change to the others and right and Shuffle it yeah the society everything is going to remain same but only thing is uh it does you're going to have a clear uh server demarcation that's great yeah so the next one is the life cycle stage and Status so this one I say mainly used say it was recently introduced by the platform where they introduce two more columns in the ca table where they are live city stage and Status so so what is happening is say uh as soon as let's say you go and change the uh server to retire status right so what we do is we uh these two status will be automatically updated so for that you need to go and activate the plugin so I'll just show you one example here so here uh so yeah so we populate uh this let's see if the server is active we go and populate as installed and let's say if the server is this terminated right so in that case we go and change status to retired so when you change it so these two operations status will automatically update it in the fly retail right so this was recently introduced by platform and some of the customers they wanted so we went ahead and implemented this feature okay any questions on this so how would that handle an ec2 instance that's only powered on based on a certain schedule in other words if it's a you know AWS provides they they actually provide some um scheduling tools that allow you to have you know development servers that are only powered up um during business hours How would would that have any um undesired side effects if if the uh the SG import runs when it's powered off and it would mark it as retired when it's actually just turned off temporarily yeah so if it is power documents it will be in a shutdown state right yep right so in that case the the resource will be still active okay so the laundry any change in that so you'll be having say something called installed but the status got off perfect okay so we say let's say that uh resources completely VM is completely tournament from AWS yeah so that's where this will get into action okay great yeah so the next is the performance Improvement on the delete resource so let me talk about briefly on this right uh so we mainly depend on the config API which gives all the hardware metadata right so um so we encourage customers to use the central aggregator uh which improves the performance very low but what happens for uh in case of the deleted resource they don't get that information in a central aggregator so instead we are forced to go to each individual account and then make the cop call it the region account level say okay give me the list of accounts sorry resources which got deleted so when you ask for the information so there are some challenges behind that what is happening is this is the only API available which can give me the information about delete resources so uh one the issue main issue is say by default the config is enabled for seven years and many customers want to have that seven years retention period so for some mainly for audit purpose right and also the AP has been designed in such a way that there is no uh filtration of date so that we can okay I want to get data from uh so April 1st to April 15th I cannot do that filtration right instead it gives me all the data so uh so what happened is for One customer who's having around 1300 accounts and uh they were getting around 45 000 APA calls per resource time so what is happening is it was taking very long time for them to get the job done right so uh and there is no other alternative for us so what we did was say uh um say we introduced a new table called uh [Music] so we introduce a new table where uh so what we do is say instead of making a blank blanket API call to jpa so we know from our side what are the instance which are active right so we go and select all the accounts VMS which are resource which are installed and then for those resource we go and check whether they are active or not so if we uh if we don't get their active then we go and mark the resource type as say deleted that way we're making a predetermined fixed number of APA calls so that we're significantly reducing the API calls on them getting getting the job done so that is a one of the major update we are done uh to improve the performance on this particular feature okay so how do we do a safe we have a table which have all the metadata so this table will have all the metadata for making respite APA calls you'll have the account number uh the connection Alias and all the details so with this what we do is we pick by resource type and then make a specific AP call to that particular account and check whether the code is active or not so uh for to do this process say we request you to say go and run the bootstrap once you updated it so what we do is say as you know in the from the previous discussions say we uh we mainly depend on all our logic based upon this logic in the data source we have something called last requested last run date right so we depend on all this uh the last runding so the fixed script will run and then goes and clears everything if once you operate update the version so that we go and we do a bootstrap again so that we populate this table so once we have this table this table is tied to the ca table uh with this configuration item okay so when you go and delete the hard delete the ca This Record will also get deleted so in that way we are making this table using this table automatic optimistically and is also indexed based upon account type and region so that we go and make a we make a fast query in our site and also make a specific call to the customer sorry AP side so that we can get the job done in a faster moment so that is one of the major update we have done any questions on this particular so in an upgrade scenario that new table gets populated yep automatically yeah yeah how about this getting populated as uh we go on delete uh this last run day time okay so when you do the upgrade it blanks out that last run yep so that uh this table will be operated automatically yeah okay so the next one I'll say uh the tagging API so for uh some uh so we mainly depend on config API to give get all the tags information but for some resource type let's say S3 dynamodb elb1 V2 uh we're not getting the tag information as part of the config API so what we're doing is we're directly going to the respective uh resource apis in getting the tags so what is happening is again for customers with thousand accounts right so we're making fixed number of calls every day and making the uh say system it's taking long time to complete the job right so for that okay we came with an idea okay how can we improve the performance okay reduce the time so what we've done is say whenever a new resource getting created it comes to a table called request table so let's say you create a new ca it comes to the cmdb and makes an entry into CA table and also it will make a request to this tag request table so what we do is at the end of the whole process so we introduced a new data source called that tax tags uh new data source so which will go and pick the records from this table and then it makes a call to the APA and get the data so once we are done with the schedule we go into Power the table so that we work on a new jobs new request coming forward right so this way also we are trying to reduce the number of EPA calls to the AWS and then we can get the job done faster so for small customers like say 50 or 100 accounts they don't see much issue in current version but for large customers it's taking instead of doing the job in one hour it is like the four hours so with this optimization it is going to take say one hour okay so the other update on AWS is safe so so far if you see in the current release say you have that uh uh what are the guidance instructions as part of The Graduate setup so where we got some feedback from customers where uh having trouble in sharing the document with uh AWS person so so far we are having everything those setup instructions as part of here and then we add a separate page where it tells all the setup instructions so what we've done is say we moved that particular item to this section to the KB article so that uh say the service no admin can share this KB article to the AWS person where they can go and make uh they can refer to the documentation and then they can do all the setup so these are one so whatever there is in the um instance is all moved to the KB article so that the AWS person can just come here and read this documentation and then they can go and set it up so everything is same but I have been as per we introduced a new sections right for key rotational we added a a new new sections so rest everything is same so this way it is a cleaner Handover from service no admin to this one I've seen some customers struggling copying this document into a Word document where it is not formatted properly and then we are getting questions a lot so I thought okay this is better to move to KB article so that people know there is no formatting issues are there so that they don't get confused so that way we can reduce the case task right so because of this I think it could help better to the customers that is one of the other changes we have done and the last one on this particular AWS you say [Music] so big yeah so we given all the documentation what was coming up as part of the uh 2.0 list as a KB article so that you get prepared what is going to come and what need to be changed so as a KB document so that it may be helpful for you guys okay are those Community articles um public at this point so people can consume them today yep because they have our last one month I'll throw the links to those in the chat and we'll include those in our wrap up email as well yeah yeah before I ship to gcp just want to know any other questions about AWS I had one and I don't want a derail so if we want to talk about it a different time it's fine but we were having some confusion around why ec2 instances when they're ingested they get split and put into two different tables right so they create a VM machine instance record and a server right thanks guy is there a reasoning behind that [Music] well so that's the standard format has been followed in all service graph I think in Discovery the property only the server class right because it causes right from an Su standpoint it causes you 2su cost for the same ec2 instance and I don't want to get into the little license apart they should get YouTube I mean if it's creating a server CI that that should be tied to that should have like a runs on relationship with the ec2 instance VM record so you're not going to get double charged for that the the Su logic says something along the lines of um where there's an ec2 and uh a server CI that are related they together count as one one Su you're not gonna the so the only issue would be if for some reason the SG is creating kind of Orphan server instances that aren't tied to an ec2 um so if you're seeing that that would be good I'll look for that we'd want to dig into okay awesome that's good news though we didn't realize the Su calculation for that differed versus just the standard a server CI costs one Su a VM instance yeah it's that's common across all of those you know whether it's public cloud or VMware um it does have specific logic as long as there's a runs on that ties the the VM and and the server to each other then that's a single Su yeah good news thanks yeah so yeah if you're good with uh AWS I'll shift my gears to gcp okay so gcp is there in a lab for a couple of months and uh coming to GA as part of this may release and uh so so what we do is say uh okay standard of uh SGC AWS approach so simplifying your onboarding experience so there is a minimal credential requirement and there is uh end-to-end data coverage so we cover all the hardware assets software and then process data right so there is no required for any mid server okay so there's no agents required and also there is no mids are required to get all this information okay so so what we do is say as part of this 100 release so we are importing all the hardware kubernetes data and in the future release we are going to do an incremental update which is a Delta one and also the software inventory so that is a plan for future loans okay and if you see here uh this is a complete gcpr picture right so you have all say folders in a parental relationship and then you have a projects under each folder and then you have resource types and each project right so with this hierarchy we go on the say pass in each and every project and get all the details Okay so so what you're asking yourself uh say what are the key components we're using the shape one is the cloud asset inventory which is nothing but a same DB of gcp which is having all the asset information and then so we are also going to integrate with asset monitoring events with two for the Delta which is coming as part of the next release okay and we're going to do the Deep Discovery uh to get the serial number hardware which you don't get as part of the uh uh the apis so that will be coming as part of the now is there a Target for those uh those features yet and and just FYI it looks like Egbert raised his hand so Edward feel free to come off mute and jump in and ask you a question no nothing very particular I just I don't know actually lower my hands I was just asking if I will gonna have access to the deck oh yeah right Marley that's standard not concerned to you perfect thank you sorry yeah no great question thank you so yeah we'll be going to pull in the say eks details uh which is coming as part of the very first videos itself uh so yeah that is one of the good news because uh this e case details has available as part of this API so we're able to easily get without any complex Integrations so yeah that's primarily do you mean gke the Google kubernetes engine [Laughter] no no worries just checking yeah hey uh murali maybe we'll already cover this um this is Jack covert um will you be documenting the different classes and attributes that are going to be discovered in gcp um as you do okay perfectly perfect thanks and what about the apis that are that are that are used yeah so I think I documented if it's there then that's fine and I'll look it up yeah yeah kudos to gcp for including those kubernetes components in there their Cloud config API it just like definitely makes discovering gke stuff a lot easier yeah it's so good yeah so this is a standard uh Sarasota architecture right so we have data source RT ird and cmdb right so what we do is we get authenticated the Google or listen AP then we make it um use that session token to make an APA call to okay so this is the high level end-to-end flow how it works okay and then what are the different components we're using it uh one is the asset inventory P which is a cmdb of DCP next one is the cloud resource manager API so which will have uh what are the folders are there what are the projects are there so those metadata information we get it from this API and next one is the cloud service account which we use it for uh the integration between SGC and gcp so so the cloud asset inventory is available as part of this EPA and then so we call the list and batch API which is going to give the list is going to give me the list of resource IDs and the batch will give me the complete CA details and we're using these two apis to input all the data into cmdb okay and uh right and the software information uh so this is also available as part of the ca but this will be available as part of the next release even though it's available now that it has not been developed from outside so it will be available as part of the next service okay so for us to get um those details right so we're asking customers to give us the very minimal uh data permissions for us to integrate right so it's it's all uh permissions are tied to the service account which is all are readingly permissions so these read-only permissions give us very minimal access to specific apis right so that we don't make any changes to your system so that way you are confident on giving the access to us with the minimal permissions okay so um the cloud resource manager gives us say metadata of ordination folder and project information so so that we can build the hierarchy of data in cmdb type so for that we need to have permissions to get these apis to get all those metadata so any questions on this permissions before I jump into next topic so the resource manager permissions or so can walk through the org and Traverse the folder structure is that so this will give me what is the r metadata right so there's an automation ID those metadata okay this will give me okay what are the folders under this arm okay and projects what are the projects under the folders so this permissions we need to have need to generate the useful hierarchical information uh to represent which resource belong to which four different project okay and so it doesn't require a single credent that it all be tied to a single um gcp token or service account yes uh yeah there are some complexities over there I will be going in next two slides okay yeah yeah so we basically request for uh one service account right so with all the permissions given we can go and pull all the data right so how do we integrate uh so we ask you to go and create a p12 file uh to do a certificate based authentication right so the speed wall file is created in gcp uh either you can do it uh say use the gcp feature to generate this file or you can use the steps given in the uh our setup instruction to generate the file so this file is saved in servicenow instance with that we make an API call to get the temporary token and then we make an APA calls based upon that right so we are going to come up with the new feature using the token sorry the credentials so that will be coming as part of the upcoming releases not for next release but for upcoming releases right so that way uh customers who are interested doing a certificate based authentication they can use this feature somebody who's interested in credential based they can use that feature so both will be supported in upcoming lasers Okay so uh so service account created right so they can uh the customer can give access save or weight access say the service account can access to any folder any project in the automation so they can give all the access to one service account that way we need only one service account uh some customers who are very much strict in their security policies say they want to give you a specific project access they can also configure it in a uh say project level right so how does going to work let's say here in our level access right so you're going to create a service account in any of the project you want and then you create a one single role with all the permissions we discussed earlier so you create a role at the org level and then bind that role to the service account so that we get access to all the projects and all the folders in the automation so this way it's this is very simple setup you need only one service account where you can integrate it right so for some customers say so for that the hard role will have all these permissions try to and then this role and then this role is bound to the service account that way it's a very simple setup for some customers right they don't want to give permission at our level because of the security nature right so for that say they can pick and choose specific projects let's say for example they are not interested in doing uh say uh say for customers who are supporting uh both commercial and federal customers right so they don't want to mix and match all those permissions so that uh in that case what they can do is they can create multiple service accounts based upon their needs and then they can tie to individual roles so that let's say I I'm interested in say project one and two I can create a role in two projects then bind that role to no service account so that I can scan only these two projects so so that I don't need to scan on the project 3 which you are not interested so that way the setup is getting little bit complicated because you need to create multiple service account right so with this feature say very interesting the multi instance as part of the first release itself so that this particular use case is getting satisfied so you create one connection per uh service account and then you can go and scan all the projects whichever way you want okay so this gets a little bit complicated because of you need to create a role in each and every project and then you need to bind it either you create a role in the project level or in the further level then you need to bind it to the service account that way uh we Focus only on those equipments okay so this is one level of complexity so the next level of complexity what you're saying is say uh okay I just want to bring it back so here you're going to create one role at the org level and one low role at the project level okay so what are the differences say at our level uh we can say these rules right one is getting the folder and the arc metadata this this permissions are set only at our level it cannot be set in the project or folder level so because of that you have to create the role of the org level for rest of the permissions you can create the project level roles right so at the end of the day we need to have both this our role and also the project role bound to this service account each and every service account such a way that uh we get the metadata whatever we want from our level okay so any questions on there's a general question in the Q a about um is there a Target for the and the road map for the SG gcp is there a Target for the the next release yet um maybe next quarter next quarter next quarter next quarter okay so the next complexity what you're seeing is for One customer uh so they introduced a service parameter so what it mean is say even though they have um in the project structure like this so they put a strong boundary line uh they put a perimeter over around some projects and folders such a way that they cannot talk each other right so for that what we suggest to say for each perimeter you go and set up one service account for each perimeter such a way that the service account gets a scope of the projects under that perimeter right so this also we are supporting it as for the first release itself okay so for that you need to make sure that say we having appropriate service loop service permit access at the odd level so that we we're able to get the DP data properly okay so the next one is say uh on the update and delete use case I just want to talk about this but it is not uh planned as part of this list okay so one of the observation what we've done uh while doing the previous uh what you notice they say the cloud doesn't inventory APA doesn't have a proper stack of giving the later data some resource types have can give the Delta information but most of them doesn't use the Delta information so for that the whole plan is to say whenever you um so we're going to create an Cloud asset inventory monitoring feed such a way that whenever you create a resource or updated resource or delete a resource all the data will be fitted to the monitoring feed which will come into our Pub sub queue so this will feed the data require data to our data source so that we go and make uh either it say if we created a new resource we go and create it uh let's say if you go and if you deleted it we go on the market uh results right so this is the high level uh flow of uh for the delete uh Delta cases right so this uh in architecture plan right now it will be coming up in upcoming releases not in the next release maybe in the featureless so until then we'll be doing a bootstrap every day so any questions on this when that gets implemented is it still going to be a pull uh the feed uh the uh the winner let's say when you make a changes right so the fee will have all the complete CA data so I don't need to come back and make an APA call so what we've done is say uh the feed will be published to individual uh Pub sub type titles okay so you need to create um for each resource type you need to create a pops up and then uh that information will be available there in the queue and then when you run the schedule on periodically we go and pick that data from the pub sub and then we published it'll it'll empty out the queue when it runs yeah so initially I had a plan of having one pops up for the entire log uh but there are some glitches out there in their architecture request so the reason I say uh in order for me to go and separate what is a VM sorry the resource type right you don't know that metadata information as part of the purpose of information so I raised a feature request to them and uh still here to get implemented so once it has get implemented then we can go and merge it to one pops up for the whole connection so that we can reduce the setup complexities further right right so that's a plan so that's why we're just waiting for them to go and implement it because uh with multi-instance and then uh multi accounts right it is this whole setup is going to get further complicated oh yeah yeah so that's the reason we don't want to have a bombarded setup so we're just trying to reduce it so that's the reason uh we are going to have we're just waiting for them and then once they've done it so we should be able to easily have instead of multiple pops up we're going to have one cups yeah so how are we getting authenticated uh say you will be uploading the video certificate in our instance with that certificate we go and make a uh get a temporary token and once we get the temporary token then we make an APA call so that's the end-to-end flow so I can just show you how it looks like when you go to um sorry gcp you can create a petrol file right and then once you get the p12 file you can upload into servicenow instance and be given a detailed step-by-step instruction how to do that so we need to go to uh x509 and then upload the certificate here it's all encrypted right and then so we make a sequence of steps to uh set up the whole setup then uh with that uh say our whole code will be able to run and then able to get the session token so with that the end-to-end flow of authentication Works in this manner so feature uh there's a plan to come up with uh say using the credential so that will be coming up in maybe upcoming releases not in the next release okay um so so what are the classes we are importing so these are the list of uh classes um it is very difficult to show here so I've been I put this picture in the comment article where you can see uh what are the different types of classes we are importing it all the information is given in the community article yeah it's a very big list so yeah this is how it looks like I think I saw that in the did I see that in the community article that chart okay so I'll show you get this one so it has all the information what we are trying to pull in right so whatever I described so far and then um next one and say how to set it studied right so we uh so we are providing a set of instructions as part of the KB article uh where we [Music] okay so we're given all the different ways to set it up and then what are the gcloud commands has been placed here okay so in my AWS we had uh what are the term CFT templates but here we're having a uh command line setup right so based upon your company needs you can just say change it to an appropriate format and then you can test it yeah so is there a link to that support article if you are if you do go to the guided setup within the instance yes yeah so even in the commit article uh I given the links to this KB article too here perfect it's also available so these are the steps right so you upload the certificate and then you follow uh the key generation process and then uh so we map uh Suite bound bind the data source to this credential so that whenever the schedule runs it will use this credential right so we also have the multiple instance setup where uh we'll be doing the same process for a different uh service account so you can create as many services code you have you can go and replicate this process so that uh you you're bound to each enable or government account so each and every service account okay it can be a DOT level or it can be at the old reposit level So based upon your needs you can create as many uh steps you want good so unfortunately we don't have the dimension Tool uh like in AWS but that said there's no plan to introduce in future users you're going to get it yeah so yeah I can change this presentation to well so that you can share with you guys yeah that would be great yeah that's perfect uh there's a question in the Q a about how the CI life cycle is applied to the cloud resources so I guess that's um like okay and Eggbert feel free to come off mutant and clarify but it sounds like you're asking if a cloud resource is deleted what happens in the scene yeah exactly yeah the the CI status right um does that get automatically reflected on the CIA yeah so you are talking about the gcp term or um just in general the cloud assets okay yeah so in general right so let's say we get an information saying that this particular Source got deleted so be common market either as rated or absent so this trade is getting updated right similarly for uh let's say you're doing it for S3 or doing for Lambda so you're going to get the status updated uh the status okay yeah so for you to get this life cycle status enabled uh there's a special setup as required that also be documented the setup document you go to your feed line saw somebody else raise their hand yeah Shane we can hear you talking about your really your volumes really low oh actually hey I didn't start talking yet um cool so maybe this background noise you heard so is it safe to uh I don't want to use the a word but um when you mark the life cycle on the VM that that life cycle change trickles Downstream so um you'll get the guest OS you know the Linux server or the Windows server and and all the components underneath it as well uh so as part of the current release uh this was introduced only in the VM table not in the server class oh so we could have that's interesting okay is that envisioned for the next release um maybe because it's it's more critical on a day-to-day operations for the for people viewing the the guest OS right to know the actual life cycle that gets the rest than the VM that it's running and you can infer it but okay let me go to that table now once again I'm making a note to kind of take that as a question as a takeaway as well how yeah and I think there's some of the newer like life cycle management components where we can have that status kind of automatically trickle down to dependency eyes like at the platform level yeah that's what I have to but yeah double check on that before anybody goes and um operates on that assumption yeah so far we got instructions from our product manager to work only on the VM right and not on the horizontal not on the server TV right yeah probably yeah I mean pretty sure that that behavior in many cases controlled via now since it was enabled at the scale level cmdvca even this also got uh impacted here when we've gone up two years yeah but I was looking for uh as I was looking for the service graph connector just set that status yeah so we do that okay so uh let's say I'll show you the documentation [Music] well if you do it that's fine yeah you don't need to you can move on so what you need to do is you need to go to the cmdb activation csdm activation and then you need to improve it so once you activate it then you can see perfect that's great yeah so that's it from my side uh any questions uh feel free to ask me well thank you for that truckload of content merley any are there any other any other questions okay silence is golden um so yeah we'll include uh the Decks that merly shared when we send out our our wrap up email which will include the uh the direct recording link on YouTube and all the other kind of ancillary links um that uh that we've exchanged in the chat uh a couple quick shout outs um for those who might not have been on the call right at the very beginning when we were talking about it if you are going to knowledge we are going to have uh the May installment of beers with engineering beers with Engineers is going to be live at knowledge uh it's going to be the Wednesday evening at 4 30 Pacific uh there's a link in the chat you can use to indicate your interest in attending and we'll also include that when we send out the wrap-up email um looking forward to meeting a bunch of folks in person and having actual beers instead of kind of virtual beers which is what we've been doing for the last 13 months there's also a link to our Discord server which um is uh one one way that we're using to kind of keep conversation going and post follow-ups to uh questions that we couldn't answer live that kind of thing so we do encourage folks to hop on that Discord server to kind of um as another way of of staying in the staying in the loop um so I'm going to shut off the recording at this point and uh if there's any
https://www.youtube.com/watch?v=gXTu63Qk-dE