ServiceNow Service Catalog integration for HashiCorp Terraform
it's like we have a good mix of uh service now and terraform experience on the call today um so let's get started everyone um if if anyone joins late obviously uh we hope that they review the ketchup content that'll be posted at YouTube and on the community blog that announced this um that was announcing this event so look for the slides and the other information there so my name is Aaron Bennett I'm with the corporate development team here at servicenow and I'm really proud to present the hashicorp team um Paulina is the senior engineer at Azure Corp who's developed this catalog integration and is going to tell you a little bit more about it today this is a new integration from hashicorp and it's between um hashicorp terraform and servicenow so I'm going to turn it over to Paulina to give you a little bit more information and then uh we'll end this poll so that everyone can see kind of the results so far there we go and uh Paulina take it away thank you Aaron um hi everyone my name is Pauline and I'm a senior software engineer at hashikorp I really want to start off by saying thank you to our servicenow host for inviting me to this webinar it's a great opportunity and I'm excited to share some ideas with all of you I must take a moment to recognize the incredible servicenow Community um I think it's communities like this that shape technology through sharing knowledge so a big thank you to everyone who's joined us for this event um your participation really makes this sessions worthwhile and it's great to see so many guests here today I'm looking forward to a q a session and I'm hoping we can learn a lot from each other thanks for having me on board the results of our poll uh just came in let's review it quickly thank you for participating in our polling session um it's it's very interesting to see the variety of perspectives so we can see from the poll that um the first question was what brought you to today's webinar um most of you actually accepted the invitation from business partners or co-workers which is very interesting so networking uh definitely plays a big part in um in the servicenow community which is awesome and the second question was are you leveraging terraform and service now today and it looks like uh half of you use servicenow and half of you use both servicenow and terraform uh which is also um just amazing to see today we'll be presenting that Better Together story that will show you how you can take your workflows to the next level by using both servicenow and terraform together so I hope everyone learns something new um to start off um I would like to say a few words about hashicorp um hashicorp is a well-known player in the field of cloud infrastructure automation we offer tools designed to streamline and automate the deployment scaling and maintenance of complex distributed applications at the core of Hashi Corps offering are eight Key Products each designed to fulfill a specific need in the cloud infrastructure landscape all of them are listed here on the slide I work on a team that belongs to the terraform ecosystem terraform is no doubt one of hashicorp's most popular offerings it has become an industry standard for infrastructures code by allowing developers to codify their infrastructure terraform makes it possible to manage Cloud resources in a predictable and efficient way it's Cloud agnostic it means that it works with a variety of cloud service providers such as AWS Google Cloud Azure and many more it's flexible it's powerful it's simple and that has made terraform a go-to choice for teams seeking to adopt infrastructure s code practices my team is responsible for the integration layer among other things we own a couple of projects integrating terraform cloud and terraform Enterprise with third-party platforms such as servicenow um we one of these projects that we're working on is the servicenow service catalog for terraform also known as the terraform plugin to describe what it does in a nutshell the app is based on the service catalog and allows you to order terraform based infrastructure from your servicenow instance since I represent engineering My Demo today will be more on the technical side we will of course talk about the product and see what the app looks like from the end user perspective but I will also be providing some technical insights into how this app functions under the hood which will hopefully help you decide whether it's the right field for your technical needs the servicenow service catalog for terraform was initially released in 2019 so it's been a while um and it has since then undergone multiple iterations we've recently released version 2.2 of the app with several new features and version 2.2.1 is about to launch in the next few weeks so we are we've been working on a smaller patch version with a couple of small but impactful updates um who might need this kind of app this application is particularly important and popular among organizations that require limited user access and Tighter controls over infrastructure security these are companies in the banking Finance Insurance sectors we've seen great adoption among players in the public sector as well it is of course not limited to those Industries and sectors but this has been this has been the most um the most important to us the app gives users the opportunity to request infrastructure without needing access to the cloud provider without needing extensive knowledge about terraform or the app's core configuration with all of that said let's jump into the demo as we navigate through the demo I would like to encourage all of you to actively participate by leaving your comments and questions in the chat your feedback helps us understand what's resonating what needs a deeper dive at the end of the webinar we will have a q a section where I will address all the questions that you've posted and perhaps there will be an opportunity for a deep dive as well um so please don't hesitate to share your thoughts as we move along today we'll be talking about the servicenow service catalog for terraform it is an officially certified scoped application developed by hashicorp in partnership with servicenow it is available as a free plugin in the servicenow store to start with I'm sharing a harshikorbe developer portal page with the official documentation for the app as well as the apps listing in the servicenow store the servicenow service catalog for terraform leverages the service catalog technology and provides users with custom catalog items that establish a connection between their terraform cloud or Enterprise instance and servicenow servicenow in Hershey Corp are natural Partners as customers rely on servicenow for self-service flows and ticketing process while terraform is great for infrastructure provisioning by combining terraform cloud with a servicenow service catalog interface Cloud platform teams and servicenow admins can standardize and scale their organization's Cloud adoption the application is based on the servicenow service catalog solution before diving into the terraform plugin let's take a brief overview of the underlying app first you could say that the terraform plugin represents a customized instance of a service catalog we are looking at the service catalog landing page in the service portal since I'm logged in as an admin I have access to editing and customizing the way it looks if you've never worked with a catalog interface before it enables you to set up one or more service catalogs and provides self-service opportunities the home page for a service catalog lists the goods and services available to order from that catalog every user with a login can view and Order items from the service catalog from departments within your organization these catalog items can include Goods services and information anything that can be ordered individually can be ordered as a catalog item for example a laptop can be a catalog item the catalog landing page provides an interface from where you can access the catalog items requests approvals popular items recent items and saved bundles after placing an order a servicenow ticket gets created and its progress can be tracked by the requester the Fulfillment process may require approvals once the order is fulfilled the ticket gets closed or resolved that is the basic idea behind the service catalog application the service catalog for terraform is nothing but a custom version of a service catalog combining terraform cloud with the servicenow service catalog interface makes it easy for developers to focus on building applications without having to worry about complicated infrastructure configurations servicenow admins can offer infrastructure as catalog items it could be anything from virtual machines to kubernetes clusters anything that can be deployed with terraform Downstream users such as app developers and operations teams gain efficiency by using the servicenow catalog request process that is already familiar to them they don't need to understand much about their cloud provider or terraform or even how this app is configured at the core the application supports both terraform cloud and terraform Enterprise many of you know terraform is an open source infrastructure s code software tool it enables users to Define provision and manage infrastructure efficiently and safely using code terraform cloud is an application that helps teams use terraform together terraform cloud is available as a hosted service at app.terraform.io it manages their form runs in a consistent and reliable environment and has many benefits which include easy access to Shared State and secret data access controls for approving deployment changes a private registry for sharing terraform modules policy controls for governing the contents of terraform configurations and more if you're a developer or a small team you can sign up for free and by the way the servicenow service catalog for terraform app that we are talking about today will work fine with the terraform Cloud free tier for the purpose of testing and proof of concept paid editions of terraform Cloud on the other hand allow you to add more than five users create teams with different levels of permissions and just collaborate more efficiently so what is terraform Enterprise it's a self-hosted distribution of terraform Cloud it offers all the advanced features available in terraform Cloud but in a private instance which customers can host themselves it's easy to get started with terraform Cloud there are some great tutorials available on developer.hashicorp.com check it out and give it a try so what do you need to do in order to install the app the app is available in the servicenow store under the name terraform published by hashicorp you can install it to your Enterprise vendor instance for free no special licenses are needed the app depends on a couple of other plugins like flow designer action step script flow designer support for the service catalog and servicenow integration Hub action step rest all these dependencies will be installed automatically when you download the app you don't have to worry about installing them separately once the installation is complete refresh your browser and type terraform in the search menu what I'm showing you right now will be primarily the servicenow administrator experience if you're an admin here's what you will see we'll talk about the end user perspective later because it's a different story the initial app configuration needs to be done by an admin and here it is four Sub menu modules should pop up the first one terraform resources lists all tickets opened through the app it's like a history of your previous orders VCS repositories it's the list of your GitHub gitlab bitbucket repositories or any other version control system you might have configuration this is where you will configure a connection between your terraform cloud or Enterprise and your servicenow instance and contact support as the name suggests there is a link to contact the hashicorp support team the first step is to configure credentials as an admin you will open the configuration page and create a new record in order for servicenow to interact with terraform Cloud you must give it a terraform Cloud API token it is recommended that you create a team token team API tokens allow access to the workspaces that the team has access to without being tied to any specific user team API tokens are designed for performing API operations on workspaces and this is exactly what we need for the catalog to manage the API token for a team in your terraform Cloud go to your organization settings teams select the desired team and use the controls under the team API token header make sure the token has permissions to manage all projects and all workspaces you will only be able to see the token upon creation so make sure you store it in a secure place it back in the catalog form enter your organization name and hit submit we've recently released version 2.2 of the servicenow service catalog for terraform which includes enhancements to terraform configuration testing reopen your record the previously introduced test configuration button now verifies the connectivity between terraform cloud and servicenow this ensures that the terraform credentials provided to your servicenow instance are accurate allowing you to proceed to the terraform catalog orders with confidence a successful 200 response from terraform cloud or Enterprise is something we'd want to see before proceeding to the next step the next step is to configure Version Control repositories navigate to VCS repositories and create a new record you can have multiple repos listed here let's say I have a GitHub repository that builds a very simple virtual machine in AWS using terraform it can be anything a kubernetes cluster a database a storage bucket anything that can be built with terraform can also be exposed as a catalog item in servicenow I'll name it AWS VM identifier is your GitHub username slash the name of the Repository make sure there are no spaces here and the oauth token ID comes from connecting your version control system to terraform cloud terraform Cloud uses the oauth protocol to authenticate with VCS providers in your terraform Cloud that would be under Version Control providers once you go through the entire authentication flow the oauth will be available in the terraform Cloud UI copy the token and paste it back in the servicenow form the rest of the fields are optional hit submit finally we can proceed to the catalog in the main search menu type catalogs make sure it's the one under the service catalog and not under system mobile I already have terraform catalog configured in my instance but if you're going through the installation in configuration process for the very first time click on the plus button in the top right corner and add terraform catalog with title and image to the UI the app incorporates 15 default catalog items that enable users to create workspaces with variables trigger terraform runs apply the runs and delete workspaces they all can be used as is or customized and extended further create workspace for example just creates a single workspace in terraform cloud or Enterprise terraform Cloud manages infrastructure collections with workspaces instead of directories a workspace contains everything terraform needs to manage a given collection of infrastructure and separate workspaces function like completely separate working directories other catalog items like create run or apply run can be used to trigger and apply terraform runs in that previously built workspace but I think the most popular default catalog item is provision Resources with variables which creates a new workspace with a required set of variables initiates a running that workspace and approves it by doing terraform apply you can provision the infrastructure fully by using that single catalog item there is also delete workspace for cleanup purposes delete workspace would first trigger terraform destroy on your terraform workspace remove your infrastructure completely and then delete that workspace from your terraform cloud or Enterprise one of the big advantages of this app is high extensibility servicenow admins have the flexibility to customize the terraform catalog utilizing the default items as foundational building blocks to create their own workflows admins have access to the entire code base of the app you can open it in the studio interface see all the scripts and play around with them one of the most popular customizations that users undertake is attaching their own variable sets let me give you an example as an admin I plan to give my users an opportunity to order a virtual machine in AWS which means I would need to attach my own custom variable set to the catalog item because the default variable said that the app comes with won't work in this case a new custom variable set needs to be declared and attached to this catalog item our documentation covers the steps you'll need to take in order to create and pass new variables in this particular case I want users to be able to pick the size of the instance and what about AWS credentials there are a couple of ways you can pass your cloud provider credentials to the catalog item you can either attach them here in servicenow or you can create a global variable set in your terraform cloud that would be in your project under settings go to variable sets this is a global variable set that will apply to all workspaces in this particular project it is very convenient and you don't need to store sensitive data in your servicenow instance and that's what I'm going to do here so far we've been exploring the terraform catalog configuration from the servicenow admin perspective what the end users experience will be different as they will need to interact only with the service portal interface once the admin work is finished pin your catalog items to the service catalog so that they are visible in the service portal you decide which items you want to expose to your end users in the search menu navigate to service portal home in the catalog look for provision resources for the variables this is one of our recent items let's take a look at the form you can of course rename this catalog item as an admin one thing I should say about customizations is that it's better not to edit the default catalog it is recommended that you create a copy of an item and then modify it and that will minimize the risk of overrides when you upgrade the terraform plugin to newer versions first pick the repository as you can see I have other AWS items configured here not just the virtual machine you could have multiple repositories building different resources for different Cloud providers foreign next terraform project name this is new this field will be available in version 2.2.1 which will be released by the end of July 2023. if you have multiple projects in your terraform cloud or Enterprise you can pick in which project you want to build this particular resource default project is the default value I'm going to use service catalog demo which I've already created in my terraform cloud description is optional next is the execution mode version 2.2 introduces a new feature to the service catalog for terraform that allows you to set the execution mode for your terraform workspaces there are several modes to choose from the default value is remote which executes in terraform Cloud's infrastructure using a consistent and reliable pool of disposable agents another option we've added is Agent agent allows you to run terraform operations on isolated private or on-premises infrastructure this option requires you to create an agent pool in your organization beforehand and then provide that agents pool pools ID when you order a new workspace through the service catalog uh by the way terraform Cloud free edition now includes One self-hosted agent but if you need more than one agent then free edition won't cover that and you will need a higher tier I'll go with a remote and I'll go with the smallest instance size next I'm clicking order now and the provisioning process begins let me switch to terraform Cloud to see the effect thank you end users typically won't have access to terraform Cloud but everything that happens to their deployment is reported back to the servicenow ticket as you can see all workspaces will be named after terraform ticket IDs this is a default Behavior switching back to our ticket version 2.2 of the service catalog for terraform contains performance improvements among the most frequently requested updates was reducing the number of API calls between servicenow and terraform cloud to achieve this we've introduced additional conditions to the pollen mechanism and limited it to Shorter intervals now an average terraform run with a default on-demand polling setup incurs only approximately 5 API calls per workspace compared to the previous 30. several enhancements have been made to the servicenow ticket comments with the latest update you can now monitor all of your terraform run stages and their corresponding timestamps within the servicenow ticket interface and repetitive comments are no longer a concern with the application once the deployment job is finished the final comment in the servicenow ticket usually lists the outputs outputs come from your terraform configuration anything you want to communicate to your servicenow users you can Define as outputs usually it's a separate outputs.tf file in your terraform configuration in case of virtual machine deployment it makes sense to Output such details as IPS DNS and your users will have access to this data in the ticket Commons looking back at all the comments in the ticket perhaps it might seem like there are too many messages you can regulate the frequency of communication between your servicenow instance and terraform cloud or Enterprise by modifying the polling schedules there are several places where you can tweak those settings the first one is workflow schedules pick the ones that belong to the terraform application this should be three records let's open the Run state which is the most crucial one the default value is on demand however you can change it to run periodically at a short regular interval if you want the servicenow instance to follow each terraform deployment closely and get that feedback in almost real time this is the place to set it up and this is what I had for the demo if your preference is to reduce the amount of calls between servicenow and terraform you can leave the scheduler to be on demand another place to tweak polling schedules is the flow designer and admins will use the flow designer interface for any customizations this is where the basic flows of the terraform app are defined the default value is five minutes you can make the interval shorter or longer depending on your preference and the needs of your organization finally to destroy the infrastructure order delete workspace from the catalog pick your workspace ID which corresponds to the servicenow ticket and hit order now it triggers terraform destroy entire form cloud here the destroy run has begun after the run is successfully finished the workspace will be completely removed from terraform cloud or Enterprise you can track the history of your terraform catalog orders by navigating to terraform resources the table Lets All attempts including errored and deleted items and that concludes today's demo all right that is it for the demo and we are at almost 30 minute mark so Aaron back to you for the polling question yeah no this is a good time to change gears and talk about um any any Deep dive questions anyone has um in the chat so before anyone takes off to your next meeting today like to um offer you the chance to get in touch with fashion Corp directly afterwards so if you answer yes to this poll um any question you have whether it be you know hey I want a demo I want to you know entitle this on a on a specific instance I want to understand what the licensing implications are if I'm already a user um any any kind of request um will be um you know we'll be able to help you with that through this uh contact form so please answer yes if you're interested and we'll certainly make sure that we get that information to Paulina and the team um to get in touch as you can tell Paulina built the app she's very technically familiar with it so you're getting access to someone directly who has intimate knowledge and how the integration Works uh you get the you'll get a lot out of that contract so that's the opportunity you get by attending the live webinar today um so please let's yeah we'll give this a few minutes to soak and see if there's anyone else um currently attending live who wants to answer yes to that question and uh we'll go through some of the questions that we got in chat so if you do have other questions please let us know um and uh we can we can you know go back through some of the content um step into an instance whatever whatever plan that you think uh would make the most sense so really quick well the first question was uh just a housekeeping question about whether the recording and PowerPoint will be shared uh yes there's a the registration page for the webinar um all that content will be posted afterwards it'll also be available on our YouTube uh Community page for servicenow so um either or if you want the sharing link that'll be a YouTube link that's embedded in that blog and that'll be up um hopefully today or at least by the end of this week um at the very latest it comes up pretty quickly now the second question was can this uh plug in this new this new app on the store be enabled on a personal developer instance a PDI and yes it can but you have to actually contact Patrick work about him doing that entitlement so that can't be requested through the store it has to be requested directly from uh hashcorp and there's a couple of entitlements available for pdis and um if you're working with them they can they can do that for you and then Plano turn this question over to you on the servicenow side um any additional licenses needed on the service now with the app downloaded from the store I believe this is um available to all itsm customers so if you're a platform customer with access to service catalog you should be able to use the app please how about on the terraform side on the terraform side you will need terraform cloud or terraform Enterprise because as you've seen in the demo one of the first steps in configuring the app is providing the API token to your servicenow instance that's how you make it communicate to terraform and back so that's a big requirement and uh the demo also covered a couple of underlying plugins that the app uses under the hood flow designer is one of the most important ones so access to the Flow Design is definitely needed but as far as I'm aware it it it's not a special license or anything like that and all dependencies are being installed automatically when you download the app from the servicenow store yeah that's a good point on Flow designer it there is a base tier of flow designer that's available to all platform customers which I believe is what Plano you you made a dependency in your app so that is something that is not you know uh an additional subscription but you would have to have your admin admin install that for you if it's not installed already on your platform um so another question I think more of a technical question is from Shiva how you've got the um VCS repositories in the app if I understand correctly uh the question is about whether you can use attach VCS repositories and use them with this integration that's actually the only way uh you can make your repositories work um with the app all the workspaces provision through the app are of VCS type um so definitely if you have multiple um Version Control repositories where your terraform configuration is defined where you build various resources for multiple different Cloud providers you can all you can connect them all to your servicenow instance you can attach them to your terraform Cloud organizations and then you can expose all that work as a catalog item in the servicenow for your end users and they can just order those items in a user-friendly interface that the service portal provides uh any other questions on the demo content any Curiosities on like uh what can be what can be done with uh you know any other use cases with terraform that other than what you saw today we'll check the questions you don't see anything in the Q a so Paulina is there any other content or um you know what's next for Azure Corp that you'd like to cover real quick before we close out yeah absolutely uh first of all um at the conclusion of today's demo we absolutely don't want the conversation to end here if you have additional questions thoughts ideas after the webinar that you would like to explore further we invite you to reach out and connect with us our team is more than happy to engage in deeper discussions clarify any points from the webinar um or simply chat about you know broader concepts related to the topic don't hesitate to get in touch there are few ways if you are an existing service catalog customer you can always email support.com and um for everyone else if you are not a an app user just yet maybe you're on the fence maybe you're just considering different options um please feel free to post your questions on our Forum it's a public forum at discuss dot hashcorp.com please make sure you tag your topics with servicenow tag that will help us route your question to the Right audience all right what's next um looking ahead the Futures field with exciting opportunities and developments first of all we do plan to update the service catalog for terraform plugin with new features we are committed to maintaining the app and extending it further so there will definitely be new releases and we've also been working on another application the ga of which is planned for the end of July it is called the servicenow service graph connector for terraform as the name suggests it's one of the apps in the service graph connector family but designed specifically for terraform just like the service catalog application we discussed today the second plugin also connects your servicenow instance to terraform cloud or terraform Enterprise and while the catalog application is designed to provision infrastructure the service graph connector for terraform pulls resources from terraform cloud or Enterprise and imports them into the servicenow cmdb cmdb is configuration management database in servicenow if you haven't worked with cmdb before it's a central repository with that within the servicenow platform which provides a single source of Truth for your infrastructure and it offers configurable dashboards for monitoring and Reporting so this new app will help you manage and search for your terraform provisioned resources and give you a comprehensive view of the resources and infrastructure that your team supports the app uses terraform State file as a primary source of data so it won't make any requests to your cloud provider and the entire communication is between your servicenow instance and terraform cloud or Enterprise that makes this app different from some of the existing Solutions on the market you can configure the app in such a way that as soon as your deployment finishes in terraform Cloud an import gets triggered and your resources will be populated in cmdb dashboards um the app supports selected resources from four major Cloud providers we support AWS Google Cloud platform Azure and VMware VMware Ruby sphere and we've included some of the most popular resources from various categories such as the compute like your ec2 instances networking Security Storage like buckets databases of various kinds from various Cloud providers you can use both apps side by side I like to think about the service catalog for terraform as a write operation so it's creating provisioning your infrastructure while the service graph connector for terraform would be a read operation importing your infrastructure in into servicenow cmdb for monitoring and Reporting you can use the app separately of course it all depends on your business needs take special note of the dates because um there will be updates coming there will be a release um for that um service graph app for cmdb and we'll do another one of these events so um please check back on live on servicenow for uh more hashicorp content um that's upcoming and uh we're excited to bring you that um bring back Polina again for another um for another demo and uh and show you that uh that application when it's finished that's right we will have at least one more demo and uh in learning opportunity lined up uh for you in the near future so we encourage you to stay connected with us and please keep an eye out uh for our upcoming events and I don't see any additional questions in the chat so we both like to thank you so much for tuning today um yes please again check back in the blog for the updated content please share that with anyone you think would be interested please get in contact with Paulina if you're interested in deploying the app the objective of these sessions is to um you know show you solutions that you may not have known existed between our two technologies and um the the ideal outcome there is that we deploy this app and environment and make it successful so again thanks very much for attending today uh Paulina let's uh let's sign off thank you so much all right bye everybody
https://www.youtube.com/watch?v=5_eFotTfIFQ