More connectors
Connectors available today whose live certification is under way, with the settings each one needs.
These connectors are in the product and can be configured in the console today. They pass 3AM's contract tests; their live certification on the real product (as for PagerDuty, Kubernetes and Prometheus) is under way, and each will get a full guide like those when it is certified.
Monitoring
Grafana
Grafana URL and a viewer service-account token. Used for deploy/change annotations and datasource queries.
kind: grafanametrics and queries| Setting | What to enter | Required | Default |
|---|---|---|---|
url | Grafana base URL | yes | — |
datasource_uid | Default datasource UID for queries | no | — |
bearer_tokensecret | Bearer token, if required | no | — |
username | Basic-auth user, if required | no | — |
passwordsecret | Basic-auth password | no | — |
Splunk
Management URL (port 8089) and an authentication token with search and alert-read rights.
kind: splunkalerts inmetrics and queries| Setting | What to enter | Required | Default |
|---|---|---|---|
url | Management API URL, e.g. https://splunk.bank:8089 | yes | — |
tokensecret | Authentication token | yes | — |
verify_tls | Verify the TLS certificate | yes | true |
app | App namespace for alerts | no | "search" |
metrics_index | Metrics index used by check packs (mstats) | no | "*" |
Datadog
An API key and an application key (read-only scopes are enough). Pick your Datadog site.
kind: datadogalerts inmetrics and queries| Setting | What to enter | Required | Default |
|---|---|---|---|
site | Datadog site, e.g. datadoghq.com or datadoghq.eu | yes | "datadoghq.com" |
api_keysecret | API key | yes | — |
app_keysecret | Application key | yes | — |
api_url | Override API base URL (proxies, tests) | no | — |
Approvals
Slack
A bot token with chat:write, reactions:read, channels:history and users:read.email. Approvers react ✅ / ❌ or reply.
kind: slackapprovals| Setting | What to enter | Required | Default |
|---|---|---|---|
api_url | Web API base URL | yes | "https://slack.com/api" |
bot_tokensecret | Bot token (xoxb-…) | yes | — |
channel | Channel ID for approvals | yes | — |
approvers | Slack user IDs or e-mails allowed to approve | no | — |
Symphony
Create a bot service account with an RSA key in the Symphony admin portal, then upload its private key here.
kind: symphonyapprovals| Setting | What to enter | Required | Default |
|---|---|---|---|
pod_host | Pod host, e.g. bank.symphony.com | yes | — |
agent_host | Agent host (often the same as the pod) | no | — |
key_manager_host | Key manager host (often the same as the pod) | no | — |
bot_username | Bot service account username | yes | — |
private_keysecret | Bot RSA private key (PEM file) | yes | — |
approvers | E-mail addresses of the people who may approve | no | — |
Phone call (Twilio)
Use a Twilio account with a voice-capable number. 3AM creates and maintains its own Studio flow.
kind: twilio-voiceapprovals| Setting | What to enter | Required | Default |
|---|---|---|---|
account_sid | Account SID (AC…) | yes | — |
auth_tokensecret | Auth token | yes | — |
from_number | Twilio number calls come from, E.164 (+1…) | no | — |
approvers | Phone numbers that may approve, E.164 | no | — |
pin_sha256secret | Map of phone number → SHA-256 of that approver's PIN (enables PIN check) | no | {} |
Uses your SMTP relay to send and an IMAP mailbox to read replies. Low assurance: not used for high-risk actions.
kind: emailapprovals| Setting | What to enter | Required | Default |
|---|---|---|---|
smtp_host | SMTP host | yes | — |
smtp_port | SMTP port | yes | 587 |
smtp_starttls | Use STARTTLS | yes | true |
imap_host | IMAP host | yes | — |
imap_port | IMAP port (SSL) | yes | 993 |
imap_ssl | Use SSL for IMAP | yes | true |
username | Mailbox user (also the From address) | yes | — |
passwordsecret | Mailbox password | yes | — |
approvers | Addresses allowed to approve | no | — |
Systems
Database (SQL)
A database account for approved writes. Reads for checks use a separate read-only account (telemetry).
kind: sqlactions| Setting | What to enter | Required | Default |
|---|---|---|---|
engine | Database engine (mysql, postgres, oracle, mssql) | yes | — |
host | Host | yes | — |
port | Port | no | — |
database | Database / service name | yes | — |
username | Write user | yes | — |
passwordsecret | Password | yes | — |
max_rows_affected | Refuse writes that would change more rows than this | yes | 1000 |
Servers (SSH)
Hosts, a key, and the exact command templates 3AM may run, e.g. restart: sudo systemctl restart {service}.
kind: sshactions| Setting | What to enter | Required | Default |
|---|---|---|---|
hosts | Host names or IPs 3AM may act on | yes | — |
user | SSH user | yes | — |
key_filesecret | Private key file | yes | — |
known_hosts | known_hosts file (host keys must be pinned) | yes | — |
commands | Command templates: {name: {template, params: {param: regex}, risk}} | yes | — |
Webhooks / runbook automation
Requests 3AM may make, e.g. trigger an Ansible Tower job or a Jenkins pipeline: {name: {method, url, body, params, risk, extract}}. risk: "read" marks a request that changes nothing (check packs may use it); extract returns one field of a JSON response.
kind: httpactions| Setting | What to enter | Required | Default |
|---|---|---|---|
requests | Request templates (JSON) | yes | — |
headerssecret | Headers sent with every request, e.g. an auth header | no | {} |
Code
GitHub
An organisation (or user) and a read-only token (fine-grained: Contents read, Metadata read).
kind: githubcode| Setting | What to enter | Required | Default |
|---|---|---|---|
owner | Organisation or user | yes | — |
tokensecret | Read-only token | yes | — |
api_url | API URL (GitHub Enterprise: https://ghe.bank/api/v3) | yes | "https://api.github.com" |
include_archived | Include archived repos | yes | false |
GitLab
GitLab URL, a group (or empty for everything the token sees) and a read_api + read_repository token.
kind: gitlabcode| Setting | What to enter | Required | Default |
|---|---|---|---|
url | GitLab base URL | yes | "https://gitlab.com" |
group | Group path (empty: all projects the token can read) | no | "" |
tokensecret | Access token | yes | — |
include_archived | Include archived projects | yes | false |
Bitbucket Cloud
A workspace and an access token (Repositories: read).
kind: bitbucketcode| Setting | What to enter | Required | Default |
|---|---|---|---|
workspace | Workspace slug | yes | — |
tokensecret | Access token | yes | — |
api_url | API URL | yes | "https://api.bitbucket.org/2.0" |
Git server (any)
For servers without a listing API (Gitea, Gerrit, on-prem mirrors): list the repository URLs.
kind: gitcode| Setting | What to enter | Required | Default |
|---|---|---|---|
repos | Repository URLs (https or ssh), one per line | yes | — |
branch | Branch to index | yes | "main" |
auth_headersecret | HTTP auth header for https URLs, if needed | no | — |
Tickets and CMDB
Jira
Jira URL, a project key and credentials (Cloud: e-mail + API token; Data Center: a personal access token).
kind: jiratickets| Setting | What to enter | Required | Default |
|---|---|---|---|
url | Jira base URL | yes | — |
project | Project key for incident tickets | yes | — |
issue_type | Issue type | yes | "Task" |
email | Account e-mail (Cloud) | no | — |
tokensecret | API token (Cloud) or personal access token (Data Center) | yes | — |
ServiceNow
Instance URL and an integration user with itil (incidents) and cmdb_read (service catalogue) roles.
kind: servicenowticketsCMDB| Setting | What to enter | Required | Default |
|---|---|---|---|
url | Instance URL, e.g. https://bank.service-now.com | yes | — |
username | Integration user | yes | — |
passwordsecret | Password | yes | — |
assignment_group | Assignment group for incidents (sys_id or name) | no | — |
service_tables | CMDB tables that hold services | yes | ["cmdb_ci_service","cmdb_ci_service_discovered"] |