Docs
Connectors

More connectors

Connectors available today whose live certification is under way, with the settings each one needs.

These connectors are in the product and can be configured in the console today. They pass 3AM's contract tests; their live certification on the real product (as for PagerDuty, Kubernetes and Prometheus) is under way, and each will get a full guide like those when it is certified.

Monitoring

Grafana

Grafana URL and a viewer service-account token. Used for deploy/change annotations and datasource queries.

kind: grafanametrics and queries
SettingWhat to enterRequiredDefault
urlGrafana base URLyes—
datasource_uidDefault datasource UID for queriesno—
bearer_tokensecretBearer token, if requiredno—
usernameBasic-auth user, if requiredno—
passwordsecretBasic-auth passwordno—

Splunk

Management URL (port 8089) and an authentication token with search and alert-read rights.

kind: splunkalerts inmetrics and queries
SettingWhat to enterRequiredDefault
urlManagement API URL, e.g. https://splunk.bank:8089yes—
tokensecretAuthentication tokenyes—
verify_tlsVerify the TLS certificateyestrue
appApp namespace for alertsno"search"
metrics_indexMetrics index used by check packs (mstats)no"*"

Datadog

An API key and an application key (read-only scopes are enough). Pick your Datadog site.

kind: datadogalerts inmetrics and queries
SettingWhat to enterRequiredDefault
siteDatadog site, e.g. datadoghq.com or datadoghq.euyes"datadoghq.com"
api_keysecretAPI keyyes—
app_keysecretApplication keyyes—
api_urlOverride API base URL (proxies, tests)no—

Approvals

Slack

A bot token with chat:write, reactions:read, channels:history and users:read.email. Approvers react ✅ / ❌ or reply.

kind: slackapprovals
SettingWhat to enterRequiredDefault
api_urlWeb API base URLyes"https://slack.com/api"
bot_tokensecretBot token (xoxb-…)yes—
channelChannel ID for approvalsyes—
approversSlack user IDs or e-mails allowed to approveno—

Symphony

Create a bot service account with an RSA key in the Symphony admin portal, then upload its private key here.

kind: symphonyapprovals
SettingWhat to enterRequiredDefault
pod_hostPod host, e.g. bank.symphony.comyes—
agent_hostAgent host (often the same as the pod)no—
key_manager_hostKey manager host (often the same as the pod)no—
bot_usernameBot service account usernameyes—
private_keysecretBot RSA private key (PEM file)yes—
approversE-mail addresses of the people who may approveno—

Phone call (Twilio)

Use a Twilio account with a voice-capable number. 3AM creates and maintains its own Studio flow.

kind: twilio-voiceapprovals
SettingWhat to enterRequiredDefault
account_sidAccount SID (AC…)yes—
auth_tokensecretAuth tokenyes—
from_numberTwilio number calls come from, E.164 (+1…)no—
approversPhone numbers that may approve, E.164no—
pin_sha256secretMap of phone number → SHA-256 of that approver's PIN (enables PIN check)no{}

E-mail

Uses your SMTP relay to send and an IMAP mailbox to read replies. Low assurance: not used for high-risk actions.

kind: emailapprovals
SettingWhat to enterRequiredDefault
smtp_hostSMTP hostyes—
smtp_portSMTP portyes587
smtp_starttlsUse STARTTLSyestrue
imap_hostIMAP hostyes—
imap_portIMAP port (SSL)yes993
imap_sslUse SSL for IMAPyestrue
usernameMailbox user (also the From address)yes—
passwordsecretMailbox passwordyes—
approversAddresses allowed to approveno—

Systems

Database (SQL)

A database account for approved writes. Reads for checks use a separate read-only account (telemetry).

kind: sqlactions
SettingWhat to enterRequiredDefault
engineDatabase engine (mysql, postgres, oracle, mssql)yes—
hostHostyes—
portPortno—
databaseDatabase / service nameyes—
usernameWrite useryes—
passwordsecretPasswordyes—
max_rows_affectedRefuse writes that would change more rows than thisyes1000

Servers (SSH)

Hosts, a key, and the exact command templates 3AM may run, e.g. restart: sudo systemctl restart {service}.

kind: sshactions
SettingWhat to enterRequiredDefault
hostsHost names or IPs 3AM may act onyes—
userSSH useryes—
key_filesecretPrivate key fileyes—
known_hostsknown_hosts file (host keys must be pinned)yes—
commandsCommand templates: {name: {template, params: {param: regex}, risk}}yes—

Webhooks / runbook automation

Requests 3AM may make, e.g. trigger an Ansible Tower job or a Jenkins pipeline: {name: {method, url, body, params, risk, extract}}. risk: "read" marks a request that changes nothing (check packs may use it); extract returns one field of a JSON response.

kind: httpactions
SettingWhat to enterRequiredDefault
requestsRequest templates (JSON)yes—
headerssecretHeaders sent with every request, e.g. an auth headerno{}

Code

GitHub

An organisation (or user) and a read-only token (fine-grained: Contents read, Metadata read).

kind: githubcode
SettingWhat to enterRequiredDefault
ownerOrganisation or useryes—
tokensecretRead-only tokenyes—
api_urlAPI URL (GitHub Enterprise: https://ghe.bank/api/v3)yes"https://api.github.com"
include_archivedInclude archived reposyesfalse

GitLab

GitLab URL, a group (or empty for everything the token sees) and a read_api + read_repository token.

kind: gitlabcode
SettingWhat to enterRequiredDefault
urlGitLab base URLyes"https://gitlab.com"
groupGroup path (empty: all projects the token can read)no""
tokensecretAccess tokenyes—
include_archivedInclude archived projectsyesfalse

Bitbucket Cloud

A workspace and an access token (Repositories: read).

kind: bitbucketcode
SettingWhat to enterRequiredDefault
workspaceWorkspace slugyes—
tokensecretAccess tokenyes—
api_urlAPI URLyes"https://api.bitbucket.org/2.0"

Git server (any)

For servers without a listing API (Gitea, Gerrit, on-prem mirrors): list the repository URLs.

kind: gitcode
SettingWhat to enterRequiredDefault
reposRepository URLs (https or ssh), one per lineyes—
branchBranch to indexyes"main"
auth_headersecretHTTP auth header for https URLs, if neededno—

Tickets and CMDB

Jira

Jira URL, a project key and credentials (Cloud: e-mail + API token; Data Center: a personal access token).

kind: jiratickets
SettingWhat to enterRequiredDefault
urlJira base URLyes—
projectProject key for incident ticketsyes—
issue_typeIssue typeyes"Task"
emailAccount e-mail (Cloud)no—
tokensecretAPI token (Cloud) or personal access token (Data Center)yes—

ServiceNow

Instance URL and an integration user with itil (incidents) and cmdb_read (service catalogue) roles.

kind: servicenowticketsCMDB
SettingWhat to enterRequiredDefault
urlInstance URL, e.g. https://bank.service-now.comyes—
usernameIntegration useryes—
passwordsecretPasswordyes—
assignment_groupAssignment group for incidents (sys_id or name)no—
service_tablesCMDB tables that hold servicesyes["cmdb_ci_service","cmdb_ci_service_discovered"]

On this page