Splunk AppDynamics Controller Admin Setup

SkillSecurity

"Use when the user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP,

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Splunk AppDynamics Controller Admin Setup skill

What this skill tells your AI

The instructions your AI receives, as published by chambear2809/splunk-cisco-skills in skills/splunk-appdynamics-controller-admin-setup/SKILL.md and read by ahel’s review.

Prerequisites

Tool or accessPurposeVerify
Bash and Python 3Run bundled setup and validation helpersbash --version && python3 --version
Required product/platform accessInspect or configure the selected targetComplete the documented preflight
Credential files for live modesKeep secrets out of chatVerify paths only

Workflow Overview

┌───────────┐   ┌───────────────┐   ┌───────────────┐   ┌─────────────────┐
│ Preflight │ → │ Render/review │ → │ Apply/handoff │ → │ Validate evidence │
└───────────┘   └───────────────┘   └───────────────┘   └─────────────────┘

When to Activate

  • The user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP, user/group/role management, account permissions, licensing, license rules, sensitive data controls, SQL/log masking, environment variable.
  • Preview and review the splunk appdynamics controller admin setup workflow before any live apply phase.
  • Diagnose failed prerequisites, generated assets, configuration, or validation evidence.

Scope

Follow the documented read-only or render-first path whenever it is available. This skill does not imply permission to mutate live systems. Require explicit apply flags, protected credentials, and operator review for state changes.

Examples

Inspect the supported setup modes before selecting one:

bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --help

Expected output: usage, supported modes, and required arguments are displayed without changing the target environment.

Inspect validation modes before running completion checks:

bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh --help

Expected output: offline, live, and completion options are displayed when the skill supports them; help exits without mutation.

Troubleshooting

IssueCauseResolution
Preflight failsA required tool or access path is missingResolve it before rendering or applying
Rendered assets are incompleteRequired non-secret inputs are absentComplete intake and render again
Apply is blockedReview, credentials, or explicit acceptance is missingUse the documented handoff
Validation is incompleteLive evidence is unavailableRecord the gap and keep completion open

Controller administration renders documented API/UI runbooks and read-only probes. This wrapper does not mutate users, groups, roles, API clients, license rules, identity providers, or privacy controls; --apply fails closed. The license-usage reporter is the concrete read-only action path.

bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --render
bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh
bash skills/splunk-appdynamics-controller-admin-setup/scripts/license_usage_report.sh \
  --controller-url "$APPD_CONTROLLER_URL" \
  --account-name "$APPD_ACCOUNT_NAME" \
  --account-id "$APPD_ACCOUNT_ID" \
  --api-client-name "$APPD_API_CLIENT_NAME" \
  --client-secret-file "$APPD_OAUTH_CLIENT_SECRET_FILE" \
  --deep \
  --output-dir ./appd-license-report

Secrets such as OAuth client secrets and passwords must be referenced by chmod-600 files.

The license usage reporter is read-only. It polls documented Controller License API endpoints and writes a customer-facing Markdown consumption report plus complete JSON and CSV exports for timestamp-level analysis.

Live validation notes:

  • APPD_ACCOUNT_ID is the numeric License API account ID, not the account name, tenant key, or GUID-like acctId/tntId claim in an OAuth token.
  • APPD_OAUTH_CLIENT_SECRET_FILE and APPD_OAUTH_TOKEN_FILE must be paths to chmod-600 local files, not inline secret values.
  • API Client role assignments are separate from user role assignments. If license endpoints return 403 for ACCOUNT_LICENSE, LICENSE_USAGE, or LICENSE_RULE, assign and save a role on Administration > API Clients.
  • OAuth JWT role or account-permission claim counts are diagnostic only; some SaaS tokens omit effective API Client permissions even when License API readbacks succeed.
  • AppDynamics SaaS controllers can require the vendor JSON Accept media type; the reporter sends that header for OAuth and License API requests.
  • Deep mode falls back to application inventory when grouped application usage returns an empty items object, and host usage degrades cleanly when no host IDs are available.

Signals

GitHub stars
37
Forks
8
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
splunk-appdynamics-controller-admin-setup
Source
github.com/chambear2809/splunk-cisco-skills