F5OS restarting container services through REST API

(The Image is made with ChatGPT AI just to highlight the F5OS kubernetes cluster, for exact list of the kubernetes pods see myF5)

Most of the F5OS services are in docker containers as F5OS is made of kubernetes cluster. If there is a memory or CPU leakage or another issue that needs a container to be restarted then this feature will be helpful. With F5OS 1.8.4 the option to restart those services is available and here is a short demonstration.

Code version:

The code was tested on F5OS 1.8.4 rSeries 5900

CURL example:

(:8888/restconf can be used or /api as I prefer the send one :slightly_smiling_face: )

curl -k -X POST -H’Content-Type: application/yang-data+json’ -u <USERNAME>:<PASSWORD> “https://<MANAGEMENT-IP>:8888/restconf/data/openconfig-system:system/f5-system-diagnostics-qkview:diagnostics/f5-system-diagnostics-docker:os-utils/f5-system-diagnostics-docker:docker/f5-system-diagnostics-docker:restart” -d ‘{ “node” : “platform” , “service” : “snmpd” }’

POSTMAN example:

Ansible Example:

Automating the F5OS token authentication as to not use basic authentication as it is better than sending username and password each time myF5

- name: Resart Service
      ansible.builtin.uri:
              url: "https://10.10.10.12/api/data/openconfig-system:system/f5-system-diagnostics-qkview:diagnostics/f5-system-diagnostics-docker:os-utils/f5-system-diagnostics-docker:docker/f5-system-diagnostics-docker:restart"
              method: POST
              headers:
                Content-Type: application/yang-data+json
                X-Auth-Token: "{{ token }}"
              validate_certs: false
              status_code:
              - 200
              body_format: json
              body:
                node: platform
                service: snmpd
      register: primary_key

Great Ansible F5OS automation article with cool examples:

Five Ways to Automate F5OS with Ansible: A Practical Guide | DevCentral

F5OS API reference:

Github Repo Link:

Summary!

This automation can be used for triggering process/service restart through the API. For example the logs a metrics can be send to a SIEM/SOAR server that then through Automation can trigger the restart.

For more complex tasks needing the Linux access the new superuser role could be used

Securing / Hardening F5OS on rSeries and Automatons like Ansible playbooks that use the native shell module. There could be 2 ansible playbboks as one uploading a script and other executing or scheduling it through cronjob edition.

2 Likes

Thanks for this article.

“https://<MANAGEMENT-IP>:8888/restconf/data/openconfig-system:system/f5-system-diagnostics-qkview:diagnostics/f5-system-diagnostics-docker:os-utils/f5-system-diagnostics-docker:docker/f5-system-diagnostics-docker:restart”

What a wonderful, easy to remember URI :smiley:

I had a short moment of time and was not in the mood to remember this URIs. Restsh has now two more commands for F5OS:

  • f5osa.service.list
  • f5osa.service.restart

1 Like

You work fast @Juergen_Mang   !

1 Like