Infrastructure Resources
All commands live under cx infra resources and are read-only. Run
cx infra resources <command> --help for flags.
"Infrastructure monitoring is not enabled for this team" means the team has no infrastructure data. Stop and say so. Do not retry or change filters.
A stderr line starting warning: ... could not verify that infrastructure monitoring is enabled is informational: the enablement check itself failed and
the command still ran.
Resource ids
- Take them from
list(resource_id) and pass them as-is, quoted. health-history,config-changesandconfig-difftake up to 100 ids per call. Pass them all in one call, not one call each. Over 100, the CLI refuses. Split into batches.- An id belongs to one team, so the id commands refuse more than one
-p. Onlytypes,filtersandlistfan out across profiles. From a multi-profilelist, use the row'sprofileto pick the one to query. - Ids mean nothing outside this skill. To reach other skills, use the resource
nameor itsServicevalue.
Finding resources
filtersfirst. Attribute names and values differ per type, so never guess. Per attribute:kind(stringis free text,statusa fixed set),values(the accepted set) andwildcard(whether*works).listwith the filters:- Every
--match-allmust match, at least one--match-anymust match, and the two groups are ANDed.--match-all OS=linux --match-any Health=Critical --match-any Region=eu-west-1meansOS=linux AND (Health=Critical OR Region=eu-west-1). - Commas give one attribute several values. In
--match-anyany one matches. In--match-allall must, which only makes sense for wildcards:--match-all 'Name=*alert*,*processing*'. - Name an attribute once, in one flag. A repeat is refused.
--categoryand--typeare plain filters, not requirements, and are not attributes (no--match-all Category=...). At least one filter or scope flag is required.- Exact values are case-sensitive (
OS=linux, notOS=Linux). Wildcards are not. Quote wildcards so the shell leaves*alone. --name-filterand--scope(service,environment,team) are legacy flags. They need both--categoryand--type, and cannot mix with--match-*.--match-all 'Name=*web*'does what--name-filter webdoes.
- Every
- Zero rows is an answer. Don't retry. A wrong attribute or value is refused with the accepted ones listed.
list -o json is an envelope: {total_count, returned_count, resources}.
The other commands return plain arrays or objects.
- It returns one window, rows 0 to 100 by default (
--start-row, and--end-rowwhich is exclusive). Keep paging whilestart_row + returned_count < total_count. - A window cannot pass row 10,000. For bigger results, narrow the query.
- With several profiles, each one pages against its own
total_count(seecounts_by_profile).
Health
listrows carryhealth_policies: [{id, name, status}]withstatusone ofhealthy,criticalorpending(not evaluated yet). A critical policy says why a resource is critical. No extra call needed.health-historyreturns[{resource_id, health_history: [{timestamp, status}]}]withstatusone ofHealthy,CriticalorUnmonitored. The two sets of statuses have different casing.- Ids that don't parse, and repeats, are dropped. A shorter answer is normal and stderr gives the count. Returned ids are normalized, so they may not string-match the ones sent.
- Infra health is not Service Catalog health. Correlate it with telemetry rather than treating the two as the same.
Raw data
raw-data -o json returns {version_timestamp, raw_data}.
--timestamp(now-7dor ISO-8601) gets the newest version at or before that time.version_timestampsays which version came back, and can be passed back as--timestampto get it again.raw_data: nullmeans no document. That is not an error.version_timestamp: nullwith a document means the document has no version.
Configuration changes
Two steps: find out which resources changed, then see what changed.
config-changeslists only resources that changed. Empty means nothing changed. Don't retry with a wider window.- Rows are per resource and source. A resource with two collectors can give two rows.
- Some cloud and agent types report an update every collection cycle, so
config-changescan flag them when nothing changed. Check withconfig-diffbefore telling the user something changed. config-diffhas no row for a resource with no history in the 14 days before--fromor inside the window. Readoutcomebeforechanges:
beforeandafterare raw JSON.nullmeans the field was added or removed. A new or removed subtree is one entry.- To look at a single change, narrow
--fromand--toaround it.
Related Skills
Bridge with the resource name or its Service value:
cx-telemetry-querying:cx search-fields "<name>" -s valuefinds the log and span fields holding the name.cx logs "filter $l.subsystemname == '<service>'"gets its telemetry.cx-alerts:cx alerts list --name "<name-or-service>".cx-dashboards:cx dashboards search "<name-or-service> ...". Aftersearch-fields -s value,cx dashboards query-search --field <field>finds queries on that field.
