- Inicio
- Marketplace
- Complementos
- AWS
AWS
Esta página aún no está disponible en tu idioma.
The AWS plugin preserves its generic read-only AWS CLI tools and adds deterministic F5 Distributed Cloud Customer Edge administration for Secure Mesh Site v2.
v2.0.0 DevelopmentPrerequisites
Section titled “Prerequisites”- Install a current AWS CLI with STS, EC2 Allowed AMIs, SSM, Service Quotas, Marketplace Agreement Service, ELBv2, and Transit Gateway commands, then authenticate to the intended account and partition. The live read-only verification baseline is AWS CLI 1.46.0; AWS CLI v2 is also supported. Full mutation UAT remains a release gate.
- Install Platform 5.x and configure F5 Distributed Cloud authentication.
- Confirm that the target is an authorized lab or demo environment.
- Subscribe to the F5 Marketplace product in the AWS console. The plugin checks Agreement Service but never automates initial legal acceptance.
Customer Edge tools
Section titled “Customer Edge tools”| Tool | Purpose |
|---|---|
aws_compute_discover | Retrieve current contract/vendor sources, enumerate every region, pin SSM/AMI versions, and rank agreement, AMI, instance, ENI, AZ, quota, policy, TGW, and brownfield evidence |
aws_ce_plan | Compile schema-v1 intent into a canonical secret-free plan, ownership inventory, rollback state, exact argv arrays, and SHA-256 |
aws_ce_apply | Apply or resume only the exact persisted plan after current-source and cloud-state revalidation |
aws_ce_status | Correlate tagged EC2/ENI, NLB/TGW, checkpoint, and F5 evidence |
aws_ce_diagnose | Run passive or separately approved active redacted diagnostics |
aws_cloud_init_analyze | Validate cloud-init stages and summarize EC2 boot evidence without exposing user data |
Mandatory research gate
Section titled “Mandatory research gate”Natural-language AWS Customer Edge requests first use web research, STS identity,
f5xc_ce_v2_capabilities, and aws_compute_discover. Discovery retrieves the dedicated
f5xc-ce-automation/v1 contract and current F5/AWS sources, records their normalized SHA-256,
enumerates all enabled and opted-out regions, resolves
/aws/service/marketplace/prod-wrwzhcymymama/latest regionally, and validates the returned AMI.
Planning and apply fail closed for unavailable or changed sources, account/partition substitution,
SSM/AMI drift, agreement or quota changes, policy restrictions, route/target/TGW/tag drift, or
changed platform capabilities.
Topology and networking
Section titled “Topology and networking”- One-node and three-node topologies support one through eight ordered, symmetric ENIs.
- Default discovery checks the F5-recommended minimum
m5.2xlargeand equivalent current generations for one through four ENIs, plus their4xlargevariants for five through eight ENIs. The exact regional ENI limits and AZ offerings remain live eligibility gates. direct-eniuses explicit VPC routes to the one-node SLI ENI.nlb-ingressuses three Availability Zones, IP targets, health checks, and explicit cross-zone behavior. The NLB is not a routed VPC/TGW next hop.tgw-staticuses appliance-mode attachment, explicit TGW route tables, associations, propagations, routes, and CE ENI routes.- Capability-gated
tgw-connectuses an appliance transport attachment, one GRE Connect peer per node, six AWS-managed BGP sessions, deterministic inside addressing, and three-zone symmetry.
Plans list all billable resources before approval. Every created resource receives the exact
xcsh-managed-by=aws-ce, deployment, plan, and F5 site tags. Routed appliances have EC2
source/destination checks disabled.
Bootstrap and headless controls
Section titled “Bootstrap and headless controls”Platform returns a session-bound one-use f5xc-ce:// reference. Apply consumes it into a 0600
cloud-init file under a session-owned 0700 directory, passes only the file path to AWS CLI, and
deletes it immediately. Plans, command strings, artifacts, diagnostics, and output never contain
the token or user data.
Headless mutation requires XCSH_CE_HEADLESS_MUTATIONS=1 and the exact plan hash. Destruction also
requires XCSH_CE_ALLOW_DESTROY=1. Initial Marketplace acceptance remains console-only.
Lifecycle and verification
Section titled “Lifecycle and verification”Supported operations are deploy, reconcile, start, stop, resize, update-network, replace-node, repair, and teardown. Three-node work advances one node at a time through EC2, registration, F5 health, BGP, NLB/TGW route, and traffic gates. Single-node disruption requires a maintenance window. Teardown restores approved brownfield routing before deleting only exactly owned resources.
Maintainers can run a synthesized prompt trace without cloud mutation:
cd plugins/awsbun run eval:ce-prompt greenfield-single-node-direct-eni