weave
module · Networking

Cisco Umbrella

Cisco Umbrella — DNS policies, destinations, identities, activity

Namespace: weave cisco_umbrella Env: UMBRELLA_API_KEY
5
Commands
1
State kinds
Networking
Category
1
API docs

Setup

Configure credentials via environment variables. We recommend sourcing them through 1Password or your secrets manager rather than committing them to the shell rc.

Official API reference

weave commands for this module are checked against the vendor's published API.

Variable Description Status
UMBRELLA_API_KEYRequired for authentication.required
UMBRELLA_API_SECRETRequired for authentication.required

Sanity-check the wiring:

weave secrets check
weave cisco_umbrella --help
weave doctor   # reports UMBRELLA_API_KEY status

Capabilities

What this module can do, by entity and verb. means a working CLI surface; · means not (yet) wired.

Entity findlistshowdosnapshotdiffapply
destination······
domain·····
identity······
policies····
policy······

Commands

Every registered CLI command, grouped by verb. Each example uses placeholder arguments — substitute real values for your environment.

find (1)

find domain

read

Look up domain category (Investigate-style).

weave cisco_umbrella find domain <domain>

list (3)

list destinations

read

List policy destinations.

weave cisco_umbrella list destinations <arg>

list identities

read

List identities.

weave cisco_umbrella list identities <arg>

list policies

read

List DNS policies.

weave cisco_umbrella list policies <arg>

show (1)

show domain

read

Show domain risk details.

weave cisco_umbrella show domain <domain>
snapshot / diff / apply are generated automatically from the State Kinds declared on this module — see the State kinds section below for per-kind details. Workflow: snapshot → edit YAML → diffapply --yes (or confirm interactively; apply --dry-run previews the same diff).

State kinds

Resources this module can snapshot and diff; apply where the kind supports live writes (see Round-trip per kind). Always run diff before apply; use --yes in automation after review. Files live under .weave-state/cisco_umbrella/.

This module is on the thinner integration path — use snapshot / diff for audit; confirm apply per kind below before relying on writes.

policies

snapshot diff apply

Umbrella DNS policies — metadata via PATCH /policies/v2/:id.

Scope
Round-trip
Full round-trip — snapshot, diff, apply.

State file skeleton

module: cisco_umbrella
kind: policies
items:
  - # <fields specific to this kind — see snapshot output>

Workflows

End-to-end recipes from operators who already run this module in production. Copy, adapt, and put under change-control.

DNS policy audit

weave cisco_umbrella snapshot policies
weave cisco_umbrella diff policies
weave cisco_umbrella apply policies

List policies

weave cisco_umbrella list policies

Terraform parity

For each Terraform resource in the canonical provider, here's the equivalent live-API verb in weave. Use this as a migration cheat-sheet, not a 1:1 contract — weave deliberately stays in the live-state lane, not the desired-state lane.

Terraform resource weave equivalent
umbrella_policyweave cisco_umbrella snapshot/diff/apply policies

Troubleshooting & source

Missing credentials

Run weave doctor — it reports which env vars (including UMBRELLA_API_KEY) are set and which are blank.

Unexpected behaviour from a state apply

Re-run weave cisco_umbrella diff <kind> to confirm the controller's current state, then re-snapshot before the next apply. The driver always re-snapshots before diffing.