Salta ai contenuti

AWS

Questi contenuti non sono ancora disponibili nella tua lingua.

The AWS plugin preserves its generic read-only AWS CLI tools and adds deterministic F5 Distributed Cloud Customer Edge administration for Secure Mesh Site v2.

v2.0.0 Development
  • Install a current AWS CLI with STS, EC2 Allowed AMIs, SSM, Service Quotas, Marketplace Agreement Service, ELBv2, and Transit Gateway commands, then authenticate to the intended account and partition. The live read-only verification baseline is AWS CLI 1.46.0; AWS CLI v2 is also supported. Full mutation UAT remains a release gate.
  • Install Platform 5.x and configure F5 Distributed Cloud authentication.
  • Confirm that the target is an authorized lab or demo environment.
  • Subscribe to the F5 Marketplace product in the AWS console. The plugin checks Agreement Service but never automates initial legal acceptance.
ToolPurpose
aws_compute_discoverRetrieve current contract/vendor sources, enumerate every region, pin SSM/AMI versions, and rank agreement, AMI, instance, ENI, AZ, quota, policy, TGW, and brownfield evidence
aws_ce_planCompile schema-v1 intent into a canonical secret-free plan, ownership inventory, rollback state, exact argv arrays, and SHA-256
aws_ce_applyApply or resume only the exact persisted plan after current-source and cloud-state revalidation
aws_ce_statusCorrelate tagged EC2/ENI, NLB/TGW, checkpoint, and F5 evidence
aws_ce_diagnoseRun passive or separately approved active redacted diagnostics
aws_cloud_init_analyzeValidate cloud-init stages and summarize EC2 boot evidence without exposing user data

Natural-language AWS Customer Edge requests first use web research, STS identity, f5xc_ce_v2_capabilities, and aws_compute_discover. Discovery retrieves the dedicated f5xc-ce-automation/v1 contract and current F5/AWS sources, records their normalized SHA-256, enumerates all enabled and opted-out regions, resolves /aws/service/marketplace/prod-wrwzhcymymama/latest regionally, and validates the returned AMI. Planning and apply fail closed for unavailable or changed sources, account/partition substitution, SSM/AMI drift, agreement or quota changes, policy restrictions, route/target/TGW/tag drift, or changed platform capabilities.

  • One-node and three-node topologies support one through eight ordered, symmetric ENIs.
  • Default discovery checks the F5-recommended minimum m5.2xlarge and equivalent current generations for one through four ENIs, plus their 4xlarge variants for five through eight ENIs. The exact regional ENI limits and AZ offerings remain live eligibility gates.
  • direct-eni uses explicit VPC routes to the one-node SLI ENI.
  • nlb-ingress uses three Availability Zones, IP targets, health checks, and explicit cross-zone behavior. The NLB is not a routed VPC/TGW next hop.
  • tgw-static uses appliance-mode attachment, explicit TGW route tables, associations, propagations, routes, and CE ENI routes.
  • Capability-gated tgw-connect uses an appliance transport attachment, one GRE Connect peer per node, six AWS-managed BGP sessions, deterministic inside addressing, and three-zone symmetry.

Plans list all billable resources before approval. Every created resource receives the exact xcsh-managed-by=aws-ce, deployment, plan, and F5 site tags. Routed appliances have EC2 source/destination checks disabled.

Platform returns a session-bound one-use f5xc-ce:// reference. Apply consumes it into a 0600 cloud-init file under a session-owned 0700 directory, passes only the file path to AWS CLI, and deletes it immediately. Plans, command strings, artifacts, diagnostics, and output never contain the token or user data.

Headless mutation requires XCSH_CE_HEADLESS_MUTATIONS=1 and the exact plan hash. Destruction also requires XCSH_CE_ALLOW_DESTROY=1. Initial Marketplace acceptance remains console-only.

Supported operations are deploy, reconcile, start, stop, resize, update-network, replace-node, repair, and teardown. Three-node work advances one node at a time through EC2, registration, F5 health, BGP, NLB/TGW route, and traffic gates. Single-node disruption requires a maintenance window. Teardown restores approved brownfield routing before deleting only exactly owned resources.

Maintainers can run a synthesized prompt trace without cloud mutation:

Terminal window
cd plugins/aws
bun run eval:ce-prompt greenfield-single-node-direct-eni