You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于通过Chef Automate API获取所有节点合规报告的技术咨询

Fetching All Nodes' Chef Automate Compliance Reports via API

Great question! You're already set up to pull single-node reports—let's expand that workflow to grab compliance data for all nodes using the Chef Automate API. Here's a practical, step-by-step guide:


1. First: Get a List of All Report IDs (No Node Filter)

The key change here is removing the node_name filter from your initial API call. This will return metadata for every compliance report in your Automate instance, including the report ID, associated node name, and basic status.

Run this curl command (replace your API token and Automate FQDN):

curl -s --insecure -H "api-token: YOUR_API_TOKEN" https://automate.com/api/v0/compliance/reporting/reports -d '{}'

The response will include a reports array with entries like:

{
  "reports": [
    {
      "id": "YYYYYYXXXXXXXXUUUUUUU",
      "node_name": "test.com",
      "status": "passed",
      "updated_at": "2024-05-20T12:34:56Z"
    },
    // More report entries...
  ]
}

2. Handle Pagination (Critical for Large Environments)

Chef Automate uses pagination for large datasets, so you won't get all reports in one call by default. Check the pagination object in the response to see total pages, then loop through each page to collect all report IDs.

For example, to fetch page 2 with 100 reports per page:

curl -s --insecure -H "api-token: YOUR_API_TOKEN" https://automate.com/api/v0/compliance/reporting/reports -d '{
  "pagination": {
    "page": 2,
    "per_page": 100
  }
}'

Pro tip: Set per_page to a higher value (like 100) to minimize the number of API requests needed.


3. Automate Fetching Detailed Reports for All IDs

Once you have all report IDs, you can loop through them to pull the full compliance data (node description, profiles, control pass/fail status). Here's a simple shell script to automate this (requires jq for JSON parsing):

#!/bin/bash

# Replace these values with your own
API_TOKEN="YOUR_API_TOKEN"
AUTOMATE_URL="https://automate.com/api/v0/compliance/reporting/reports"
OUTPUT_DIR="automate_compliance_reports"

# Create output directory if it doesn't exist
mkdir -p $OUTPUT_DIR

# Get total number of pages
TOTAL_PAGES=$(curl -s --insecure -H "api-token: $API_TOKEN" $AUTOMATE_URL -d '{}' | jq '.pagination.total_pages')

# Loop through all pages to collect report IDs
for PAGE in $(seq 1 $TOTAL_PAGES); do
  echo "Fetching page $PAGE of $TOTAL_PAGES..."
  REPORT_IDS=$(curl -s --insecure -H "api-token: $API_TOKEN" $AUTOMATE_URL -d '{
    "pagination": {
      "page": '$PAGE',
      "per_page": 100
    }
  }' | jq -r '.reports[].id')

  # Fetch detailed report for each ID and save to a file
  for ID in $REPORT_IDS; do
    curl -s --insecure -H "api-token: $API_TOKEN" $AUTOMATE_URL/id/$ID -d '{}' > "$OUTPUT_DIR/report_$ID.json"
    echo "Saved report for ID: $ID"
    # Add a small delay to avoid overwhelming the API
    sleep 0.5
  done
done

4. Extract Your Required Fields

Each detailed report JSON contains all the data you need. Use jq to extract node descriptions, profiles, and control statuses into a structured format (like CSV) for analysis:

#!/bin/bash

OUTPUT_DIR="automate_compliance_reports"
CSV_OUTPUT="all_nodes_compliance_summary.csv"

# Write CSV header
echo "Node Name,Node Description,Profile Name,Control Title,Control Status" > $CSV_OUTPUT

# Process each report file
for REPORT_FILE in $OUTPUT_DIR/*.json; do
  jq -r '
    .node.name as $node_name |
    (.node.attributes.description // "No description") as $node_desc |
    .profiles[] as $profile |
    .controls[] as $control |
    [$node_name, $node_desc, $profile.name, $control.title, $control.status] | @csv
  ' $REPORT_FILE >> $CSV_OUTPUT
done

echo "Summary saved to $CSV_OUTPUT"

This will create a CSV with all your required fields for every node and control.


Key Notes

  • Permissions: Ensure your API token has the compliance:read permission to access these endpoints.
  • SSL Security: Instead of --insecure, you can specify your CA certificate with --cacert /path/to/ca.crt for secure connections.
  • Version Compatibility: Field names may vary slightly between Chef Automate versions—adjust the jq queries if needed for your instance.

内容的提问来源于stack exchange,提问作者DevopsDevelop

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 20:53:00