Home / Integrations / Puppet
Connect Puppet configuration management data to Salesforce Agentforce
Puppet is the enterprise configuration management platform that operations and DevOps teams use to enforce infrastructure state across large server fleets — ensuring that servers remain in their defined configuration, patches are applied consistently, and software configurations drift back to the desired state automatically. For organisations delivering managed services or running customer-attributed infrastructure, Puppet's compliance reports are the operational record of the environment's health. Salesforce holds the commercial record of the customers whose infrastructure Puppet manages. When a customer's environment falls out of compliance, the operations team needs to know which account is affected. When a new customer is onboarded, Puppet should enforce the correct configuration from day one. When Emerge Digital connects Puppet to Agentforce, configuration compliance context is available to service and account agents — and Salesforce commercial events coordinate with Puppet to onboard new customer environments into the managed configuration fleet.
What this unlocks
- Infrastructure compliance status during service conversations: when a customer contacts support about configuration or environment behaviour, an agent can read the Puppet compliance report for the customer's node group — the last catalog run timestamp, the drift count, and whether the node is in the desired state — and surface this context without the operations team running a manual Puppet query.
- Closed Won triggers Puppet environment classification for new customers: when a Salesforce opportunity closes for a managed service, an agent can classify the new customer's node group in Puppet Enterprise with the correct configuration profiles and policy sets — so the customer's infrastructure is under Puppet management from the provisioning step, not retroactively.
- Compliance drift alerts create customer-attributed Salesforce cases: when Puppet detects persistent configuration drift on a customer's node group — meaning the desired state cannot be enforced — an agent can create a Salesforce service case with the customer account, the affected node count, and the drift details, so the operations team has a tracked service item with customer attribution.
- Patch compliance context for customer security conversations: Puppet enforces OS and application patches across managed fleets — an agent can read the patch compliance status for a customer's node group during a security review conversation, confirming which patches are applied and whether any nodes are non-compliant, rather than asking the operations team to pull a compliance report manually.
In the customer journey
Customer reports environment behaving differently — agent checks compliance
A managed service customer contacts support reporting that their application configuration seems to have changed overnight. The agent reads the Puppet report for the customer's node group — the configuration was enforced last night, reverting a manual change made by a customer-side engineer that had caused drift. The agent confirms the configuration was automatically corrected, provides the drift details, and opens a knowledge-sharing task to inform the customer's team about the managed configuration scope.
New customer onboarded into Puppet management from deal close
A Salesforce opportunity closes for a new managed infrastructure customer with a Linux web tier. The agent classifies the new customer's node group in Puppet Enterprise with the web tier policy — Apache/Nginx configuration, log management, security baseline, and monitoring agent — and confirms the classification to the operations team. The customer's servers are under Puppet management as soon as they are provisioned, rather than being classified manually after onboarding.
Persistent drift creates a tracked service case
Puppet reports persistent drift on four nodes in an enterprise customer's node group — the desired state cannot be enforced due to a conflicting local process. The agent creates a Salesforce service case for the customer account with the node names, the drift type, and the blocking error. The operations team investigates a tracked, customer-attributed service item rather than a raw Puppet alert.
Why not Puppet's native enterprise integrations?
Puppet Enterprise integrates with ServiceNow, Splunk, and some ITSM platforms for compliance reporting and change management workflows. These are operations-to-operations integrations. What they do not provide is Puppet compliance and configuration data queryable by a Salesforce Agentforce agent in real time during a customer service conversation: a service agent cannot ask Puppet's integrations for the current compliance status of a specific customer's node group during a support call, classify a new customer's node group in Puppet Enterprise when a Salesforce deal closes, or create a Salesforce service case with customer attribution when persistent drift is detected on a managed environment. Emerge Digital builds the coordination layer that makes Puppet configuration management context available to agents in commercial and service conversations.
Puppet's Agentforce integration is most active in the delivery and managed services stages — where configuration compliance is the operational state of the service being delivered, and where drift and non-compliance events need customer attribution in the service record. It is relevant for managed service providers and enterprise IT organisations where Puppet manages customer-attributed server fleets.
How Emerge integrates Puppet
Emerge Digital connects Puppet to Salesforce Agentforce as a consulting engagement. We map which Puppet node groups correspond to which Salesforce accounts, configure the Salesforce deal-close triggers that classify new customer environments in Puppet Enterprise, build the compliance report retrieval for service agents, and define the persistent drift case creation logic. The integration is designed around your Puppet Enterprise role and profile structure and your Salesforce account and service model.
How we structure an engagementRelated integrations
FAQ
Can the agent modify Puppet profiles or change the desired state for a customer's node group?
No. Configuration profile management and desired state changes stay with the operations and DevOps team in Puppet Enterprise's change management workflow. Agents read compliance status and can trigger pre-approved classification actions — like applying a standard profile to a new customer node group from a deal close — but do not modify existing Puppet profiles or policies.
We use Chef or Ansible rather than Puppet — can you build the same integration?
Yes. Emerge has equivalent integration patterns for Chef and Ansible. The configuration compliance status in service conversations, deal-close environment classification, and drift alert case creation use cases apply across configuration management platforms. Emerge builds to the platform your operations team uses.
We use Puppet Open Source rather than Puppet Enterprise — does this affect the integration?
Puppet Enterprise has REST APIs and PuppetDB for querying node compliance state programmatically. Puppet Open Source has PuppetDB and report processors that can be used to similar effect, though with more integration design work. Emerge scopes the integration design to your Puppet deployment.
How long does a Puppet + Agentforce integration take?
A focused engagement typically runs five to seven weeks: mapping node groups to Salesforce accounts, configuring deal-close node classification, building compliance status retrieval for service agents, defining drift alert case creation, and testing compliance query, new customer classification, and drift response scenarios.
Ground your agents in Puppet.
Tell us what your agents need to read and write in Puppet, and we'll design the integration and the governance around it.
Talk to the practicePrefer email? Write to the practice instead.