如何跨组织获取所有运行中应用?如何访问Cloud Foundry的Doppler URL?
Great questions! Let's break this down step by step for both manual CLI usage and API access, plus how to leverage Doppler for real-time staging event monitoring.
If you need to gather this data manually without scripting, follow these steps:
- First, log in without specifying an organization or space—this lets you access all orgs you have permissions for:
cf login --skip-ssl-validation -a <CF_API_URL> -u <USERNAME> -p <PASSWORD> - List all organizations:
cf orgs - For each organization, switch your target org, list its spaces, then switch to each space to view running apps:
# Example workflow for a single org/space cf target -o <ORG_NAME> cf spaces cf target -s <SPACE_NAME> # Filter to only show running apps cf apps | grep "started" # Get full details for a specific app cf app <APP_NAME>
To avoid repetitive manual work, use a simple bash script to automate the full traversal:
#!/bin/bash # Fetch all orgs (trim header/footer from cf orgs output) ORGS=$(cf orgs | tail -n +4 | head -n -1) for ORG in $ORGS; do echo "=== Scanning Organization: $ORG ===" cf target -o "$ORG" # Fetch all spaces in the org SPACES=$(cf spaces | tail -n +4 | head -n -1) for SPACE in $SPACES; do echo "--- Scanning Space: $SPACE ---" cf target -s "$SPACE" # List running apps with basic info cf apps | grep "started" # Uncomment below to get full details for each running app # APP_NAMES=$(cf apps | grep "started" | awk '{print $1}') # for APP in $APP_NAMES; do # echo "===== App Details: $APP =====" # cf app "$APP" # done done done
Cloud Foundry provides a robust REST API for programmatic access, which is far more scalable as organizations/spaces change. Here's the workflow:
- Step 1: Retrieve an access token
Authenticate to get a bearer token for API requests:
Extract thecurl -k -X POST "<CF_API_URL>/oauth/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=password&username=<USERNAME>&password=<PASSWORD>&client_id=cf"access_tokenfield from the JSON response. - Step 2: Fetch all organizations
Note thecurl -k -H "Authorization: Bearer <ACCESS_TOKEN>" "<CF_API_URL>/v2/organizations"metadata.guidfor each organization—this is needed to fetch its spaces. - Step 3: Fetch spaces for each organization
For each org GUID, get its associated spaces:curl -k -H "Authorization: Bearer <ACCESS_TOKEN>" "<CF_API_URL>/v2/organizations/<ORG_GUID>/spaces" - Step 4: Fetch running apps for each space
Filter apps to only include those in aSTARTEDstate:
The response includes full app details like memory limits, routes, buildpack info, and metadata. You can also use the v3 API (curl -k -H "Authorization: Bearer <ACCESS_TOKEN>" "<CF_API_URL>/v2/spaces/<SPACE_GUID>/apps?q=state:STARTED"/v3/apps) for newer features, but v2 is widely supported for basic app queries.
Doppler is Cloud Foundry's component for streaming logs and real-time events. You'll use WSS (WebSocket Secure) (not HTTPS) to maintain a persistent connection for live updates. Here's how to set this up:
- Step 1: Get the Doppler endpoint
Retrieve the Doppler URL from the CF API info endpoint:
Look for thecurl -k "<CF_API_URL>/v2/info"doppler_logging_endpointfield—it will look likewss://doppler.your-cf-domain.com:443. - Step 2: Connect to the Doppler Firehose
To monitor global staging events, subscribe to the Firehose (requires admin-level permissions likefirehose.adminorcloud_controller.admin). Use a WebSocket client likewscat(install vianpm install -g wscat) to connect:wscat -k "Authorization: Bearer <ACCESS_TOKEN>" -c "wss://doppler.your-cf-domain.com:443/firehose?subscription_id=my-staging-monitor" - Step 3: Filter for Staging Completed Events
The Firehose streams all platform events. Look for messages where theevent_typeisStagingCompleted—these contain details about newly staged apps, including app GUID, organization/space metadata, staging status, and buildpack results. You can parse these messages programmatically (e.g., with a Node.js or Python WebSocket client) to automatically fetch new app details whenever staging finishes.
Key Notes:
- Ensure your user account has the necessary permissions to access all organizations/spaces and the Firehose.
- For production use, implement reconnection logic for the Doppler WebSocket connection (since connections can drop unexpectedly).
- The
cf logscommand is for individual app logs—use the Firehose for global event monitoring.
内容的提问来源于stack exchange,提问作者overexchange

