Home / Integrations / Chef
Connect Chef infrastructure automation data to Salesforce Agentforce
Chef is the infrastructure automation platform — now part of Progress — that enterprise operations teams use to manage server configuration, compliance scanning, and infrastructure compliance at scale. Chef Infra manages the desired state of infrastructure through cookbooks; Chef InSpec audits compliance against security baselines; Chef Automate provides the dashboard for the compliance and configuration state of the entire managed fleet. For organisations delivering managed services or running customer-attributed infrastructure, Chef's compliance reports and cookbook run history are the operational record of the environment's health and configuration. Salesforce holds the commercial record of the customers those environments serve. When Emerge Digital connects Chef to Agentforce, compliance and configuration context from Chef Automate is available to service and account agents — and Salesforce deal closes coordinate with Chef to bootstrap new customer environments into the managed fleet.
What this unlocks
- Infrastructure compliance scan results during service conversations: when a customer contacts support about security or compliance questions, an agent can read the Chef InSpec compliance profile results for the customer's node group — the controls passed, controls failed, and the latest scan timestamp — and provide an accurate compliance status without the operations team pulling a manual report.
- Closed Won bootstraps new customer environment into Chef management: when a Salesforce opportunity closes for a managed infrastructure service, an agent can bootstrap the customer's nodes with the Chef client and assign the correct cookbook policy group — so the customer's environment is under Chef management from the provisioning step rather than being enrolled manually after onboarding.
- Cookbook run failures create customer-attributed Salesforce cases: when a Chef cookbook run fails on a customer's node group, an agent can create a Salesforce service case with the customer account, the affected node, the failed resource, and the error details — so the operations team has a tracked, customer-attributed service item rather than an untracked Chef Automate alert.
- Compliance drift context for customer security and audit conversations: Chef Automate tracks compliance drift over time — an agent can read the compliance trend for a customer's environment during a security review or an audit conversation, showing whether the environment has been consistently compliant or whether periodic drift has been detected and corrected.
In the customer journey
Customer requests compliance evidence for security audit
A customer contacts their account manager requesting compliance evidence for an internal security audit. They need confirmation that their managed environment meets the CIS benchmark controls. The agent reads the Chef InSpec report for the customer's node group — 94 of 95 CIS controls passed in the most recent scan, with the one exception being a documented exception already logged. The account manager provides the scan timestamp, the control results, and the exception documentation. The audit evidence is available in the call rather than requiring a two-day operations team request.
New managed service customer bootstrapped into Chef from deal close
A Salesforce opportunity closes for a new managed Linux infrastructure customer with a specific security baseline requirement. The agent triggers the Chef bootstrap for the customer's nodes with the correct policy group — applying the security baseline cookbook, the monitoring cookbook, and the backup cookbook from the agreed service tier. The operations team confirms the bootstrap is complete. The customer's environment is managed from provisioning.
Cookbook run failure creates a tracked service case
A Chef cookbook run fails on a customer's database node — the backup configuration resource fails to apply because of a disk space constraint. The agent creates a Salesforce service case for the customer account with the node name, the failed resource, and the error details. The operations team investigates a tracked service item with the customer account context rather than a raw Chef Automate failure notification.
Why not Chef's native monitoring integrations?
Chef Automate integrates with Splunk, Elasticsearch, and some ITSM platforms for compliance reporting and alerting. These are operations-to-operations integrations. What they do not provide is Chef compliance and cookbook run data queryable by a Salesforce Agentforce agent in real time during a customer service conversation: a service agent cannot ask Chef's integrations for the compliance scan results of a specific customer's environment during a support call, bootstrap a new customer's nodes into Chef management when a Salesforce deal closes, or create a Salesforce service case with customer attribution when a cookbook run fails on a managed customer node. Emerge Digital builds the coordination layer that makes Chef infrastructure data available to agents in commercial and service conversations.
Chef's Agentforce integration is most active in the delivery and managed services stages — where infrastructure compliance and cookbook run history are the operational record of the service being delivered, and where compliance events need customer attribution in the Salesforce service record. It is relevant for managed service providers and enterprise IT organisations where Chef manages customer-attributed infrastructure at scale.
How Emerge integrates Chef
Emerge Digital connects Chef to Salesforce Agentforce as a consulting engagement. We map which Chef node groups and policy groups correspond to which Salesforce accounts, configure the deal-close bootstrap triggers that enrol new customer nodes into the managed fleet, build the compliance scan and cookbook run retrieval for service agents, and define the cookbook run failure case creation logic. The integration is designed around your Chef Automate configuration, your cookbook policy structure, and your Salesforce account model.
How we structure an engagementRelated integrations
FAQ
Can the agent modify Chef cookbooks or change the policy group for a customer's nodes?
No. Cookbook editing and policy group changes stay with the operations and DevOps team in Chef's change management workflow. Agents read compliance and run status, and can trigger pre-approved bootstrap actions for new customer environments. They do not modify existing cookbooks or reassign node policy groups.
We use Ansible or Puppet rather than Chef — can you build the same integration?
Yes. Emerge has equivalent integration patterns for Ansible and Puppet. The infrastructure compliance context in service conversations and deal-close environment provisioning use cases apply across configuration management platforms. Emerge builds to the platform your operations team uses.
We use Chef InSpec for compliance scanning independently of Chef Infra — does the integration cover InSpec-only?
Yes. Chef InSpec can be used independently of Chef Infra for compliance scanning. The integration can be scoped to Chef InSpec scan results — relevant for organisations that run InSpec for compliance reporting but use a different tool for configuration management.
How long does a Chef + Agentforce integration take?
A focused engagement typically runs five to seven weeks: mapping node groups to Salesforce accounts, configuring deal-close bootstrap triggers, building compliance scan and run status retrieval for service agents, defining cookbook failure case creation, and testing compliance evidence, new customer bootstrap, and run failure response scenarios.
Ground your agents in Chef.
Tell us what your agents need to read and write in Chef, and we'll design the integration and the governance around it.
Talk to the practicePrefer email? Write to the practice instead.