logo

NJP

ServiceNow Service Graph Connector Integration for HashiCorp Terraform

Import · Oct 27, 2023 · video

good morning Pina morning Vishnu good morning morning hi welcome everybody see the attendees starting to roll in glad you're here today um we're going to get started um right off the bat with a poll so um we'd like to understand why you're here and uh you know what your interest is we've had one of these presentations from uh hash Corp early this year and really excited about the topic we have today so let me get that going here we go you can answer that as you as you see fit we just want to know a little bit more about um your experience with the the couple of Integrations that um hashicorp has published with service now in our store so far so to get us started now that we're at the top of the hour my name is Aaron Bennett I'm part of our corporate BISD team here at service now and I'm very pleased to um welcome back helina um from hashicorp and um um new new presenter Vishnu uh to join me today and uh deliver this content on this integration from hash Corp one of our U sort of Cornerstone um patterns or Integrations that service now is our service graft connector which populates the cmtb in a sort of a predictable and you know efficient way and um hash corpse is delivered so that's our topic today U Pina if you could go next just want to quickly um point out our Safe Harbor um so webinar may contain some forward-looking statements and you know just take that into account as you you know sort of plan um we recommend um if you want to validate information going forward there will be an opportunity to get a followup from hash Corp towards the end of the webinar or thereabouts so encourage you to um sign on for that if uh if you'd like to get more information after the content today um moving ahead we have other events in are live on service now Community series you're welcome to um check those out just scan the QR code here um or go to the main page on community where you can see what events we have coming up and probably will'll see event from another event from hash Corp in this in the future I'm sure um next one finally just you know to sort of cover what we're going to do today we've got um chat and Q&A available so if you have a question we'll try to address that um in time in the chat the Q&A uh Vish or Pina may decide to try to take that question live if it's in the flow of the content or we'll save it for the end but we will make sure to go back and address all questions at the end whether or not we answered them in chat so that those are here for the benefit of those viewing this recording after the fact um this recording is going to be posted on our service now Community via YouTube channel so that compl content replays can happen there we wouldd love if you'd share that forward and um again just to mention that the sort of the tail end of the of the event will have a survey um that you where you can get an opportunity for feedback there will also be a postevent survey where you can you know comment on the quality of the content what you'd like to see in the future that sort of thing so with that I'm going to turn it over to Pina and Vishnu to introduce themselves and uh take us through their integration today thanks take it away guys oh and by the way let's end the poll so that we can talk about um the sort of the the structure of the audience we have today so we can see that um what 90% of the folks have not yet tried the service craft connector or service catalog so you're in for treat treat people all right go ahead plan all right hi everyone my name is Paula and I'm a senior software engineer at Hashi Corp um I specialize in Cloud infrastructure and integrating terraform with thirdparty platforms such as service now thank you to our service now hosts for inviting us to the community webinar for the second time this year it's a great opportunity and we're very excited to share some new ideas with all of you um from the polling session we can see that most of you have not yet tried um our apps for those of you who are new to our community I encourage you to check out the apps that we've built and if you don't know anything about them yet that's totally fine because in today's session we'll have a demo that will show you exactly how one of the apps works and how you can use it now let me pass it over to vishno to talk about how you can take your infrastructure management cycle to the next level by using both service now and terraform over to you vishu hi everyone I am Vishnu rindra product manager at Ashi Corp from the terraform ecosystem team I see many of you on the call great to see you all thanks for joining in I'm excited to talk about some of the integration what we have built that is the service CRA integration between the service now cmdb and tform Cloud before I start that let me start by giving an overview of what is asharp and the products we offer asharp is as we all know it's a well-known player in the cloud infrastructure automation space we offer multiple tools that help organizations to provision secure connect and run their infrastructure for their applications at the core as you can see in the slide we have eight Key Products each designed to cater specific needs in the cloud infrastucture landscape terraform is one of our most popular offering since it has become a industry standard for infrastructure as code users will be able to use codify their infrastructure and to streamline and automating the provisioning process the terraform is very Cloud agnostic that means it works on variety of cloud platforms we have a terraform registry which has got more than 3,500 providers so that has made its popular as well I and Pina belong to the ecosystem group as she mentioned and our team is responsible for building third-party Integrations to terraform cloud and terraform Enterprise which includes service now as well we have two Integrations for service now as we showed in the poll first one is service catalog and second one is the service graph the service craft integration enables end users to provision Self Serve infrastructure via service now using service catalog service now users can order service items create workspaces perform terraform runs with a ex ing configurations that are hosted in the VCS repositories we had done a re recent webinar a few months back if you have not checked out I strongly encouraged to check that out today we'll be talking about the service graph Integra connector which is the second integration what we have built so what is service graph connector so this is a single source of truth that updates the service now cmdb or the configuration management database with the infrastructure State and the resources provisioned by terraform the the service now cmtv or it is called as configuration management database is a central repository within the service now platform that provides a single source of Truth for an infrastructure and it also offers configurable dashboards for monitoring and Reporting purposes the service craft connector allows you to securely import terraform cloud or Enterprise resources into your service now cmdb so you can maintain a clean complete system of record of your resources and services this is done using the the what we use at in terraform this enables platform teams to give gain a comprehensive view of the resources to support by connecting the terraform to service now you can manage and search for terraform allocated resources alongside the rest of your organization's other resources out of the box we support various resource types which includes some of the providers major Cloud providers which we mentioned AWS Azure Google cloud and V spere but also we have the flexibility create addition to create additional resource mappings that can be done to any of the providers that's the beauty of the service graph with the tform provider because it has got connected to more than 3,500 providers in the regustry uh next we will talk about the benefits of why why it is useful can you go to the next one as we saw service graph connector has many benefits and some of the benefits what we have seen are the the connector updates Whenever there is a cmdb dashboards with res resources deployed inam Cloud this provides enhanced visibility to understand like what has been deployed through the catalog or through any of these terraform Resources by connecting terraform to the service now cmtv platform teams now can manage and search terraform provision resources in the same DV alongside the company's infrastructure as well this is really key for the finance or for Asset Management to track their assets not only the company's assets but also the cloud state of it every time there is a change in terraform it seamlessly and securly reflect in the service of cmtp ensuring all your resources are consistently managed and track uh this is one of the thing which is which is useful for a lot of organization who wants to be compliant for auditing and for security purposes so that when there is a change in the configuration management then they want to consistently manage what is provisioned and what is stored in their uh Truth uh and also the when it comes to the extensibility service admins have the capability to customize mappings as I said previously we provide outof box supports for some of the major Cloud providers but it can be mapped to any of those providers u in the registry if you can search for any providers you pretty much get for most of the third part Integrations now when when we think about how can we import these uh import these resources to the service graph there are two Imports mod methods which we provide push and pull model one thing is user can configure the application to periodically pull all your resources in one batch with schedule poing or you can set up a Web book in your terraform workspaces which will notify your service now instances about the deployments done over there for example this is useful when you're using with the cat loging for example if you're ordering new resources or new items so service graph can pick up from the webbook and store it in the cmdb so it integrates it complements between these two Integrations what we have uh those are the things which I just wanted to highlight about the service graph connector all right thank you vishna for that insightful overview of the product features now let's transition um into the demo portion of our webinar over the next 20 minutes or so I'll walk through the key capabilities um of the app and then um please feel feel free to submit any questions that you might have during the demo and we'll be sure to address them at the end uh to give you the best understanding of what this app can do we'll start the demo by focusing on the core functionality first and once we've covered the basics we'll move on to the setup and customizations options so in this first step I'm creating a new workspace in my terraform Cloud this is the terraform Cloud UI for those of you who are not familiar each workspace represents a single environment workspaces isolate the terraform state for each environment this way you don't have conflicts with State files as you manage in first structure for different environments in parallel I'm going to deploy some infrastructure in this workspace which will be based on the terraform configuration stored in my GitHub repository I've selected a specific repository from the list to serve as a base for my workpace there will be a number of resources built by this terraform configuration we will review them in a moment the goal is to import all those resources into cmdb the configuration management database in service now um as an application developer my job is to provide visibility for my team as to what infrastructure we manage uh how many resources are operational when and by whom they were provisioned and other details like that so the service now service graph connect of a terraform will help us to achieve this once the workspace is created I will also link it to my service now instance by creating a web hook I'll explain the web hook in the later portion of the demo and next I initiated a ter run in my workspace uh as a side note creating workspaces and initiating runs in terraform Cloud can also be done by API calls and by terraform CLI shortly after the run kicks off terraform generates the execution plan which describes the infrastructure changes that will take place to reach the desired State the plan shows U how many resources will be added changed or destroyed in this deployment the total of 37 AWS resources is going to be created the most significant of them which are going to be imported into the service now cmdb are um some networking and security resources we have a VPC Security Group a load balancer we have a bunch of compute type items an ec2 instance and a Lambda function we have some container related resources such as ECS cluster and a kubernetes cluster and of course storage we have a three bucket here in this deployment we have RDS database and cluster Dynamo DB Global table uh you can see some other resources on the list but that's like the core uh that I've mentioned you may have noticed a few deployment errors in the terraform run I intentionally kept them in this speeded up recording to demonstrate that um in the real world mistakes happen errors happen once they are addressed and terraform is Rerun resources can be successfully imported into service now we just need one successful deployment uh to initiate the import um so you can see terraform imply has been finished successfully and once the deployment is done in terraform Cloud we can um head over to the service now instance and open the cmdb workspace by typing cmdb workspace in um in the search menu you can look for a specific resource name for example virtual machine instance uh it will be imported with uh different essential details like unique IDs um names timestamps who created it um each resource also has tags there is a tags tab in this dashboard uh the application will import all of your Cloud TXS uh specified in your terraform configuration as part of the resource definition so it will come from your code and on top of that it will also apply terraform organization and terraform workspace tags to show where exactly in terraform Cloud that resource was provisioned the relationship view in cmdb will uh show you the exact hierarchy of resources in this case like which region the resource belongs to and the AWS account number you can explore the hierarchy by switching to different views and playing around with graphs and dashboards uh creating your own dashboards um customizing them generating reports cmdb is such a powerful tool and you can do so much with it these are some of the resources that we've deployed uh with tarform a couple of minutes ago um once they are important to cmdb you can visualize them in multiple different ways um cmdb acts as a central repository to manage your infrastructure and it gives you a comprehensive insight into the resources you support and the dependencies between them different types of resources will have different data imported into cmdb for example for an ec2 instance will have IP address size number of CPUs uh populated while for other resources like for example um the kubernetes cluster IP address and Port will be displayed um among other details now let's see what happens when the infrastructure is destroyed back to tform Cloud I'm initiating a destroy run in that same workspace now terraform will remove all 37 resources that we've previously built when you run terraform Destroyer terraform looks at the state um to identify all the resources that need to be destroyed as which each resource is destroyed terraform removes it from the state file um this ensures the state accurately reflects the real infrastructure um the state file itself is not deleted after after destroy uh this allows you to keep a history of the infrastructure that existed previously when the service graph connector for Terra form checks the state after a destroy it will detect that some of the resources are missing and it will assume that they've been destroyed it will Mark those resources as non-operational in the cmdb database just like during creation we need the deployment to finish successfully before the import job can be triggered and now we can check same DB the resources are still there they won't be removed completely but uh their operational status changes to non-operational here now that you've seen what the app can do uh let's cover the requirements and go over the basic setup how to achieve exactly what we just saw so what do you need to do in order to install the app the app is available in the service now store uh look for the service graph connector for terraform published by Hashi Corp you can install it to your Enterprise vendor instance for free there is however a license requirement for this app to run in your production instance successfully you will need the itom discovery license uh many customers will already have it in their instances especially if your company already uses cmtb products and other iton products there is a good chance you already have it if you are not sure a good way to check if you have the itom discovery license would be to navigate um to plugins and then type item discovery in the search field and the record should say installed if it doesn't say installed you'll need to activate it first before trying to use the service graph connector for terraform in production uh activating a licensed plug-in for your production vendor instance can be done through the service now support portal I believe it's um support. servicenow.com um an active produ an active um license is required only for production instances there is no entitlement required if you're using uh the plugin for a nonpr instance and the rest of the dependencies will be needed by the app like Discovery and service mapping patterns integration Hub plugins and others will be installed automatically when you download the app uh there is no need to worry about installing them separately once the installation is complete uh refresh your browser and start typing service graph connector for terraform in the search menu the app menu will appear under the service graph connector category if you have other service graph connectors in your instance the terraform one will just be addition to the same family of apps four submenu modules will pop up we have setup that's the place to provide credentials and um go over the basic setup for the app uh next we have data sources it's just one of the apps artifacts storing the import code you won't need to do anything there then we have import schedule it's a place to set um the desired frequency for the import runs and contact support um as the name suggests there is a link to contact the Hashi Corp support team setting up credentials for this app is super easy since the app integrates with both terraform cloud and terraform Enterprise just keep your token ready the app requires only one mandatory token what kind of token it could be either the team token or the organization token team API tokens allow access to the workspaces that the team has access to without being tied to any specific user in your tform Cloud you can set up a team by going into settings and then opening the teams section you can generate um a new token and make sure it has access to manage all workspaces um you will have a bunch of checkboxes um just make sure you give the token the right permissions and in contrast the organization token simply allows access to all workspaces inside that org to J generate an orc token go to settings and then click API tokens and generate a token back to our service now instance click on the setup submenu module and the guided setup form will open up in the first section paste your token whichever token you decide to use the teams one or the org one don't change the name of it just paste the credential into the encrypted field and hit save Mark the section as complete the second section is optional early earlier vishno talked about the two modes of import available through the service graph connector pH terraform um the bulk import going through all of your resources and the web hook import which is more event driven happening per workspace when a successful deployment is finished this section here is meant for your web hook token it's supposed to be a string any kind of string used for the hemac authentication hmac authentication is the way terraform Cloud authenticates Web hook requests with service now in order to securely inform service now that some resources have been successfully deployed and pass the workspace information the service now instance would pick that request and pull terraform State details for the given workspace enter a web hook string here and keep a note of it because you will need it when you set up the actual web hook in terraform Cloud Mark the section is complete and the last field in this section is to set up your terraform connection URL if you use terraform Enterprise you can paste your TF URL into the connection URL field and hit update if you want to use the mid mid server as a proxy for routing requests between your service now instance and terraform Enterprise you can do so by checking the mid server box but if you use terraform Cloud you don't need to update anything in this form because it already points to terraform Cloud by default app. terraform form .io you can just go back and uh mark this section as complete and finally the last portion of the guided setup is for configuring the scheduled import job fill it out only if you plan to use the bulk import option unlike the web hook import discussed earlier the scheduled import will pull all of your resources into cmdb at a scheduled time uh you can set the frequency to for example every hour or once a day keep in mind that this scheduled job will Loop through all of your terraform organizations and it will try to import completely all resources from all of your workspaces it is not recommended for a large scale if you have a lot of workspaces like hundreds and thousands of workspaces the web hook import will perform much better than the bulk one um that's why I'm going to skip the activation here and just exit the section and instead head over to all scheduled Imports and pick service graph terraform scheduled process State this is a different schedule job this job when activated is responsible for periodically checking for new records in the web hook table anytime a new web request comes in from terraform cloud or terraform Enterprise a record gets written to the database and as soon as this schedule job picks it up terraform um service now initiates a request to import terraform resources from the state file if you want to use web hooks you need to activate this job I'm going to set the frequency to every 10 seconds activate it and save this configuration um the history of all your Imports using this method is summarized in this table below so you can go and check um the previous import sets and that concludes the entire setup inside the service now instance the only thing left to do is to configure the web hook in the terraform workspace so let me me show you how to do it once you create a workspace with attached terraform configuration it could be a terraform code stored stored in your Version Control repository like GitHub like here in my case or it could be a module published in your private terraform Cloud registry there are a couple of different ways you can set up workspaces in terraform Cloud um if you want to learn more check out Hashi Corps terraform Cloud tutorials once the workspace is created and you're ready to run terraform in it open the workspace settings and proceed to notifications on the left panel create a new notification of the web hook tabe and fill out the following details enter the name it can be anything I prefer to put service now service graph uh into the title just to remember that this particular notification goes to um service now web hook URL is a fixed endpoint exposed securely in your service now instance through the service graph connector for terraform uh replace the instance ID in the domain name with the ID of your own instance and but the relative part of the URL will be the same for everyone so don't change it and next is the token used to generate the hmac on the notification request it's going to be the same string that we entered in the second step of the guided setup form back and service now it will be used for encoding the request sent to your service now instance and finally we need to specify the trigger when the web hook notification is actually supposed to be triggered uh we don't want any workspace events only specific run events the notification is supposed to be sent only upon a successful completion of the terraform run when all resources are successfully provisioned uncheck everything except completed and click create notification uh if your workb hook notification is set up correctly you should see the green indicator saying status code 100 it means that the connectivity between terraform cloud and service now is successfully established and you can proceed and initiate a terraform run if you have any errors here you will see helpful er error messages you can check the logs in this section it typically takes a couple of minutes to apply terraform and process the request to service now and you can monitor all all of your web hook import sets in the scheduled Imports interface that I showed you previously a successfully completed job has a green indicator and shows a number of successfully processed resources uh it means that they're ready to be viewed in the cmdb dashboard and that concludes um the main portion of our demo we are at almost about half an hour mark uh so probably a good time for our last polling question Erin if you could please put it on the screens excellent demo Pina um as very thorough and complete hopefully we'll have some productive questions I see one or two that have already been answered so perhaps we could read through those while people are um answering the followup question so if we go to the Q&A um just to call it the first one so terraform service now service craft connector supports only terraform Enterprise or does it support terraform Cloud as well so maybe best to just list out the um product that you are supporting at this point in time yes uh the service now service graph connector for terraform successfully integrates with both terraform cloud and terraform Enterprise right and then that's the limit of products that you're supporting at this time correct uh we do not support the terraform um open source Edition uh only only the platform itself cool so that takes care of the second question so [Music] um all attendees um please please please P type any other questions you have in the chat or in the Q&A um we'll take them from either source and uh P Vish would you like to um tell them how they can get more information going forward of course um at the conclusion of the demo we don't want the conversation to end here if you have additional questions thoughts ideas that you would like to explore with us with us further uh we invite you to reach out and connect with us um we are more than happy to engage in deeper discussions and clarify any points from the webinar um don't hesitate to get in touch there are a few ways if you're already an existing user if you installed our apps to your vendor instance um you're welcome to email support hardic corp.com and our support team will take it from there and if you are not a current user yet if you are still deciding whether it's the right tool for the job um maybe you have um just general questions we have a public forum um it's discuss. has.com uh anyone can register there create new topics make sure you label your topic with a service now label so that we could route it correctly and and we would be happy to discuss uh we also invite you to learn more about the service now service graph connector for terraform and give it a try uh we have a couple of resources to support you uh the first link is the Hands-On tutorial that covers U the entire flow step by step it's just what I showed you in the demo from configuring a resource in form creating a workspace in terraform Cloud setting up the service graph and then importing that resource into the service now cmdb um it's easy to follow and especially if you don't have much experience with terraform I would say this is a great place to start and the second link is our official documentation um it covers the requirements it describes the two modes of import that we talked about it provides detailed mapping tables with resource coverage which show exactly how the information from the terraform State object is mapped to the data classes inside the service now cmdb it also covers customizations um customization deserves a few extra comments um as mentioned before the application supports selected resources from four major Cloud providers AWS Google Cloud platform BMW sphere and Azure um you might ask what if I need a different provider or Pro what if for example use AWS but need to import a resource that is currently not supported by the app you can update and customize the default mapping rules offered by the service graph connector for terraform uh it can be done inside the integration Hub ETL interface of your service now instance uh ETL stands for extract extract transform load um the data mapping interface is super intuitive it's very easy to use you can simply drag and drop data pills from sources to targets and create new field mappings of your own without writing any code um that second documentation link that you see on the screen provides instructions on how to do that with examples and screenshots all right what's next uh looking ahead we're committed to maintaining this app and extending it further so there will be definitely new releases and new versions uh please stay connected with us keep an eye out uh for our upcoming events we will have at least one more demo and learning opportunity lined up for you in the near future next time it will likely be hosted by Hashi Corp so I invite you to visit hasic corp.com events and look for service now related webinars in November um the next webinar hasn't been announced yet but it will be shortly all right and this concludes the main segment of our webinar all right we'll pass it around for one more opportunity to ask questions um and another opportunity for attendees to um you know click thanks for those who have clicked for a followup and if any others would like to follow up um please do please indicate so now um we're obviously very available uh for any follow-ups on um you know the discussed channels or the other channels mentioned in the in the content this content will be available posted to the blog on the service now Community after the fact so if you're looking for those links that's where you should go we'll also have the video posted there and um we'd love and encourage if you'd reshare that video so I don't see any other questions posted so I guess we'll um we'll we'll take that as our cue to sign off Pina Vishnu thank you so much again for coming on and presenting for us today um if you have any partying thoughts um I'll let you close us out thank you so much Heron thank you for having us great thanks ad thanks thanks Vishnu um all please have a great week and we'll see you next next time see you next time bye bye

View original source

https://www.youtube.com/watch?v=C-QCn-5hCm4