This guide provides detailed information about all features available in the Control-M Extension for Visual Studio Code.
- Overview
- Infrastructure Management
- Workload Management
- Data Services (MFT/MFTE)
- Job Development
- Code Snippets
- Connection Management
- Configuration Options
- Advanced Features
The Control-M Extension brings enterprise workflow automation directly into Visual Studio Code, enabling you to:
- Browse Control-M infrastructure (servers, agents, resources)
- Manage jobs, folders, and configurations
- Develop new jobs using Jobs-as-Code methodology
- Test connection profiles and agents
- Configure MFT/MFTE data transfer services
- Deploy changes to Control-M environments
View all Control-M/Server instances in your environment.
Features:
- List all Control-M/Servers with version information
- View server status and health
- Expand servers to see agents, resources, and run-as credentials
Actions:
- Refresh datacenter list
- Copy server names to clipboard
Manage Control-M Agents across your infrastructure.
Agent Types:
- Managed Agents - Full Control-M Agents with local scheduling
- Agentless Hosts - Remote execution targets without agent installation
Features:
- View agent status (Available, Unavailable, Disabled)
- See agent version and operating system
- View agent directory paths and Java home
- Browse agent parameters
- See host group memberships
- View run-as credentials (local and global)
Available Actions:
-
Ping Agent - Test connectivity to an agent
- Sends a ping command to verify agent is responsive
- Returns success message or error details
- Timeout: 60 seconds with 30-second buffer
-
Get MFT Configuration - Retrieve Managed File Transfer settings
- Shows if MFT is enabled on the agent
- Displays FTS (File Transfer Server) configuration
- Lists available SSL keystores and PGP templates
-
Test Run As User - Verify run-as credentials
- Tests if a specific user account can execute on the agent
- Validates permissions and authentication
- Returns success/failure status
-
Agent Analysis - Comprehensive agent diagnostics
- Detailed analysis of agent configuration
- System resource information
- Installed plugins and versions
- Performance metrics
-
Refresh Agent Data - Reload agent information
View and manage logical groupings of agents.
Features:
- List all host groups with member agents
- View application type and tags
- See agent count per group
Available Actions:
-
Super Dupa Agent Ping Test (All Agents) ⚡
- Tests connectivity to all agents in the host group
- Runs ping tests in parallel for speed
- Provides comprehensive pass/fail summary
- Timeout per agent: 60 seconds
- Great for quick health checks
-
Super Dupa Analysis (All Agents) ⚡
- Runs full diagnostic analysis on all agents in the group
- Parallel execution for fast results
- Comprehensive system and configuration details
- Useful for audits and troubleshooting
Manage agentless remote host definitions.
Features:
- List all defined remote hosts
- View host properties and configuration
- Test connectivity to agentless hosts
Available Actions:
- Ping Remote Host - Verify connectivity to agentless host
Manage centralized connection profiles for various technologies.
Supported Profile Types:
- File Transfer - FTP, SFTP, FTPS, AS2, etc.
- Database - Oracle, SQL Server, PostgreSQL, MySQL, DB2, etc.
- AWS - S3, EC2, ECS, Lambda, etc.
- Azure - Blob Storage, SQL, etc.
- Hadoop - HDFS, Hive, Spark, etc.
- Application Integrator - SAP, PeopleSoft, Informatica, etc.
- And many more...
Features:
- Browse profiles by type and subtype
- View profile details and configuration
- Test connections to verify functionality
Available Actions:
-
Test Connection Profile - Verify profile connectivity
- Requires selecting a server and agent
- Tests actual connection using profile settings
- Returns success message or error details
- Timeout: 90 seconds
-
Super Dupa CCP Test (All Servers & Agents) ⚡
- Comprehensive connection profile testing
- Tests profile across all available servers and agents
- Runs tests in parallel for fast results
- Provides detailed pass/fail summary
- Useful for validating profile configuration across environment
Manage Control-M calendar definitions.
Calendar Types:
- Regular Calendars - Standard date-based calendars
- Periodic Calendars - Interval-based schedules
- Rule-Based Calendars - Complex scheduling rules
Features:
- Browse calendars by type
- View calendar aliases and servers
- Export calendar definitions
Available Actions:
- Get Calendar Details - View complete calendar definition
- Export to JSON file for version control
View active and inactive workload policies.
Features:
- List all workload policies with status
- View policy descriptions and update history
- See policy order numbers
Manage Control-M Site Standards and policies.
Features:
- View all defined site standards
- See business parameters and rule counts
- View associated policies and their scope
- Check which servers and folders are affected
View registered Control-M secrets for secure credential management.
Features:
- List all defined secrets
- Copy secret names for use in job definitions
Monitor Control-M resources (quantitative and semaphore).
Features:
- View available vs. maximum resource counts
- See associated workload policies
- Monitor resource utilization
Browse and manage Control-M folders and jobs.
Features:
- Filter folders using wildcards (e.g.,
PROD*) - Browse folder hierarchy
- View subfolder structure
- See jobs within folders
- Pagination support for large folder lists
Available Actions:
-
Export Folder - Save folder definition to JSON
- Exports complete folder with all jobs
- Saves to local file system
- Ready for version control
-
Refresh Folder - Reload folder contents
- Updates job list
- Refreshes folder metadata
-
Save Job - Export individual job definition
- Saves job as JSON file
- Includes all job properties
-
Save Subfolder - Export subfolder definition
- Saves subfolder with its jobs
-
Save Script - Extract embedded scripts
- For jobs with embedded scripts
- Saves script to separate file
When viewing jobs, you can see:
- Job type and details
- Host/agent assignments (single agent or host group)
- Run-as credentials
- Connection profiles used
- Embedded scripts (if applicable)
For Host Groups in Jobs:
- Expand to see all member agents
- Ping individual agents
- Test agent connectivity
- View MFT configuration per agent
For Connection Profiles in Jobs:
- Test profile connectivity
- View profile configuration
The Data Services view provides comprehensive management of Managed File Transfer capabilities.
Manage agent-level file transfer capabilities.
Features:
- Browse MFT-enabled agents
- View FTS (File Transfer Server) configuration
- Manage SSL keystores
- Handle PGP/GPG key management
SSL Keystore Management:
Available Actions:
-
Get Keystore Details - View SSL certificates
- Lists all certificates in keystore
- Shows certificate validity periods
- Displays certificate subjects and issuers
-
Show Keystore Metadata - View keystore properties
- Keystore type and location
- Last modified date
- Certificate count
GPG/PGP Key Management:
Available Actions:
-
List GPG Keys - View installed PGP keys
- Shows public and private keys
- Displays key IDs and fingerprints
- Lists user IDs associated with keys
-
Import GPG Keys - Add new PGP keys
- Import public keys for encryption
- Import private keys for decryption
- Supports ASCII-armored format
Configuration:
- Set custom run-as users for GPG operations (Linux/Windows)
- Configure GPG command syntax
- Set keystore run-as users
Enterprise-level file transfer hub management.
Site Architecture:
- Hub - Central MFTE server with SSL keystore
- Gateways - Connection points for external transfers
- Processing Rules - Automated file processing workflows
- Users - External user accounts for file transfers
- Groups - User groups for permission management
- Virtual Folders - Logical folder structures
Features:
- View all MFTE site settings
- Export settings to JSON
- Monitor site configuration
Available Actions:
- Save Settings - Export site settings to file
Features:
- View hub configuration and status
- Manage hub SSL keystore
- Monitor hub health
Available Actions:
- Get Keystore Details - View hub certificates
- Show Keystore Metadata - View keystore properties
Automated workflows for incoming/outgoing files.
Features:
- View all processing rules
- See rule status (Enabled/Disabled)
- Browse rule configuration
- View folder variable mappings
Available Actions:
-
Save Rule - Export rule definition
- Saves complete rule to JSON file
-
Enable Rule - Activate a processing rule
- Starts rule processing
-
Disable Rule - Deactivate a processing rule
- Stops rule processing temporarily
-
Copy Variables - Export folder variables
- Generates JSON with variable mappings
- Maps folder variables to MFTE variables (e.g.,
ZZM_FILE_PATH→$$FILE_PATH$$) - Configurable variable prefix (default:
ZZM_)
Features:
- Browse external users
- View user status (Active/Locked)
- See user groups and permissions
- Monitor user access levels
Available Actions:
-
Lock User - Disable user account
- Prevents user from logging in
- Maintains user configuration
-
Unlock User - Re-enable user account
- Restores user access
Features:
- View all user groups
- See group members
- Browse group permissions
Features:
- Browse virtual folder structure
- View folder permissions
- See user/group access levels
Settings:
- Variable Mappings - Define available MFTE variables for auto-mapping
- Variable Prefix - Set prefix for folder variable matching (default:
ZZM_)
Creating MFTE Objects:
The extension provides commands to create MFTE objects from JSON files:
- Create User - Define new external user
- Create Group - Define new user group
- Create Virtual Folder - Define new virtual folder
- Create Rule - Define new processing rule
- Onboard User - Complete user onboarding workflow (see below)
The Onboard User feature provides an automated workflow to set up new MFTE users with all required components in a single operation.
What It Does:
The onboarding process automatically:
- Creates a virtual folder for the user
- Creates the external user account
- Creates or updates a user group
- Assigns appropriate permissions
- Sets up fixed subfolders (incoming/outgoing)
How to Use:
-
Create an onboarding configuration JSON file using the template:
- Template location:
samples/mfte.user.onboarding.template.json - Customize user, virtual folder, and group settings
- Template location:
-
Right-click on the JSON file in VS Code
-
Select
Control-M→Data Services (MFTE)→Onboard User -
Select the MFTE site from the dropdown
-
Confirm the onboarding operation
-
Monitor progress - The extension will:
- Create virtual folder
- Create or check user existence
- Create or update group
- Assign user to virtual folder and group
Onboarding Configuration Template:
{
"user": {
"name": "external_user_01",
"email": "user@company.com",
"company": "CompanyName",
"phoneNumber": "555-1234",
"description": "User onboarded via VS Code extension",
"password": "GENERATE_PASSWORD",
"changePasswordAtNextLogin": true,
"passwordNeverExpires": false
},
"virtualFolder": {
"name": "external_user_01",
"authorizedInternalUsers": ["*"],
"deleteFilesAfterDownload": true,
"deleteFilesAfterDownloadByExternalUsers": true,
"notifyByEmailWhenFileArrive": true,
"accessLevel": "Full control",
"retentionPolicy": 10,
"sizeLimit": 100,
"allowedFilePattern": "",
"blockedFilePattern": "",
"fixedSubFolders": [
{
"name": "incoming",
"accessLevel": "Full control",
"operation": "",
"originalName": ""
},
{
"name": "outgoing",
"accessLevel": "Read only",
"operation": "",
"originalName": ""
}
]
},
"group": {
"name": "CompanyName",
"createIfNotExists": true
},
"accessLevel": "Full control"
}Configuration Fields:
User Section:
name(required) - External user login nameemail- User's email addresscompany- Company name (used for group if not specified)phoneNumber- Contact phone numberdescription- User descriptionpassword- Use "GENERATE_PASSWORD" to auto-generatechangePasswordAtNextLogin- Force password change on first loginpasswordNeverExpires- Disable password expiration
Virtual Folder Section:
name- Virtual folder name (defaults to username if not specified)authorizedInternalUsers- Internal users who can access folderdeleteFilesAfterDownload- Auto-delete after internal users downloaddeleteFilesAfterDownloadByExternalUsers- Auto-delete after external users downloadnotifyByEmailWhenFileArrive- Send email notificationsaccessLevel- Default access levelretentionPolicy- Days to retain filessizeLimit- Max folder size (MB)allowedFilePattern- Regex pattern for allowed filesblockedFilePattern- Regex pattern for blocked filesfixedSubFolders- Predefined subfolders (incoming/outgoing typical)
Group Section:
name- User group name (defaults to company name if not specified)createIfNotExists- Create group if it doesn't exist
Root Level:
accessLevel- Permission level: "Read only", "Read and write", "Full control"
Best Practices:
- Use descriptive user names - Include company prefix or identifier
- Generate passwords - Use "GENERATE_PASSWORD" for security
- Set retention policies - Configure based on data requirements
- Configure fixed subfolders - Separate incoming/outgoing for clarity
- Review permissions - Verify access levels before onboarding
- Test first - Try onboarding in test environment first
Example Workflow:
1. Copy template: samples/mfte.user.onboarding.template.json
2. Create: onboarding-newclient.json
3. Update user information:
- name: "newclient_user01"
- company: "NewClient"
- email: "user01@newclient.com"
4. Right-click file → Control-M → Data Services → Onboard User
5. Select MFTE site
6. Confirm onboarding
7. Verify user, group, and virtual folder created
Notes:
- The onboarding process is transactional - if any step fails, previous steps are not rolled back
- Passwords are automatically generated if "GENERATE_PASSWORD" is specified
- Users are prompted if the user already exists (update or skip)
- Groups are created automatically if they don't exist and
createIfNotExistsis true - Virtual folder structure matches standard MFTE conventions
Validate job definitions before deployment.
Features:
- Syntax validation for JSON job definitions
- Semantic checking for job properties
- Error reporting with line numbers
Usage:
- Open a JSON file with job definitions
- Right-click in editor
- Select Control-M → Build
- View results in output panel
What Gets Validated:
- JSON syntax
- Job type validity
- Required properties
- Property value ranges
- Connection profile references
- Calendar references
Execute jobs directly from VS Code.
Features:
- Run job definitions without deploying
- Track job execution status
- Retrieve job output
Usage:
- Open a JSON file with job definitions
- Right-click in editor
- Select Control-M → Run → Run Folder
- Monitor execution in output panel
Available Actions:
- Run Folder - Execute all jobs in definition
- Get Output - Retrieve job execution logs
Deploy job definitions to Control-M.
Features:
- Deploy jobs to specific Control-M/Server
- Deploy with deployment descriptor for advanced options
- Automatic folder creation
Usage:
- Open a JSON file with job definitions
- Right-click in editor
- Select Control-M → Deploy → Deploy Content
- Confirm deployment
Deploy Options:
- Deploy Content - Standard deployment
- Deploy with Descriptor - Advanced deployment with descriptor file
The extension includes comprehensive code snippets for rapid development.
Type these prefixes in JSON files and press Tab:
Basic Jobs:
ctm-job-simple- Basic command jobctm-job-script- Script job templatectm-job-embedded-script- Job with embedded script
AWS Jobs:
ctm-job-aws-ecs- AWS ECS container jobctm-job-aws-lambda- AWS Lambda function jobctm-job-aws-batch- AWS Batch jobctm-connection-aws- AWS connection profile
Database Jobs:
ctm-job-database- Database job templatectm-connection-oracle- Oracle connection profilectm-connection-sqlserver- SQL Server connection profilectm-connection-postgres- PostgreSQL connection profile
File Transfer:
ctm-connection-sftp- SFTP connection profilectm-connection-ftps- FTPS connection profile
MFTE:
ctm-mfte-rule- MFTE processing rulectm-mfte-user- MFTE external userctm-mfte-group- MFTE user groupctm-mfte-virtualfolder- MFTE virtual folder
Type these prefixes in Python files and press Tab:
Basic Structure:
ctm-python-imports- Import statements for Control-M APIctm-python-connection- Connection setup codectm-python-job-simple- Simple job creation
Job Operations:
ctm-python-job-build- Build job definitionctm-python-job-run- Run jobctm-python-job-deploy- Deploy job
AWS ECS:
ctm-python-aws-ecs- AWS ECS job in Python
Configure your Control-M environment connection.
Settings Location:
- VS Code Settings (
Cmd+,orCtrl+,) - Search for "Control-M"
Required Settings:
- Hostname - Control-M Enterprise Manager hostname
- Port - Automation API port (typically 8443)
- Use HTTPS - Enable secure connections (recommended)
- API Token - Stored securely in VS Code SecretStorage
While the extension connects to one environment at a time, you can:
- Save different workspace settings
- Switch between environments by changing settings
- Use workspace-specific configurations
Security:
- Tokens are stored in VS Code's SecretStorage
- Never stored in plain text
- Automatically used for all API calls
Token Commands:
Control-M: Set API Token- Update tokenControl-M: Test Connection- Verify token validity
Debug Level (control-m.debug.level)
- Options:
off,error,warn,info,debug - Default:
info - Controls log verbosity
Enable Debug Logging (control-m.enableDebugLogging)
- Type: Boolean
- Default:
false - Verbose logging for infrastructure tree creation
Folder Filter (control-m.workload.folderFilter)
- Type: String
- Default:
* - Filter pattern for folder discovery
- Examples:
PROD*,TEST_*,DEV_*
Pagination Page Size (control-m.pagination.pageSize)
- Type: Number
- Default: 25
- Range: 10-100
- Items per page in tree views
MFT Host Group (control-m.mft.hostgroup)
- Type: String
- Default: (empty)
- If specified, only loads agents from this host group
- Improves performance for large environments
GPG Settings:
control-m.mft.gpg.runAs.linux- Run-as user for Linux GPG operationscontrol-m.mft.gpg.runAs.windows- Run-as user for Windows GPG operationscontrol-m.mft.gpg.command- Custom GPG command- Default:
gpg --list-keys --keyid-format LONG
- Default:
Keystore Settings:
control-m.mft.keystore.runAs.linux- Run-as user for Linux keystore operationscontrol-m.mft.keystore.runAs.windows- Run-as user for Windows keystore operations
Variable Mappings (control-m.mfte.variableMappings)
- Type: Array of strings
- Default:
FILE_PATH,FILE_ABS_PATH,FILE_DIR, etc. - Available MFTE variables for auto-mapping
- Add custom variables as needed
Variable Prefix (control-m.mfte.variablePrefix)
- Type: String
- Default:
ZZM_ - Prefix for matching folder variables to MFTE variables
- Example:
ZZM_FILE_PATHmaps to$$FILE_PATH$$
Telemetry Enabled (control-m.telemetry.enabled)
- Type: Boolean
- Default:
true - Respects global VS Code telemetry settings
- Used for product improvement and license compliance
Right-click on items in tree views for context-specific actions:
Infrastructure:
- Copy node IDs to clipboard
- Export infrastructure to JSON
- Test connections and credentials
Workload:
- Export jobs and folders
- Save embedded scripts
- Test associated resources
Data Services:
- Manage users and permissions
- Enable/disable processing rules
- Export configurations
Access all extension commands via Command Palette (Cmd+Shift+P or Ctrl+Shift+P):
Type "Control-M" to see all available commands:
- Configuration commands
- Setup wizard
- View management
- Testing utilities
The extension respects VS Code keyboard shortcuts:
Cmd+Shift+P/Ctrl+Shift+P- Command PaletteCmd+,/Ctrl+,- Settings- Right-click for context menus
View Logs:
- Open Output panel (
Cmd+Shift+UorCtrl+Shift+U) - Select "Control-M" from dropdown
- View extension activity and errors
Enable Detailed Logging:
- Set
control-m.debug.leveltodebug - Enable
control-m.enableDebugLoggingfor tree creation details - Reload VS Code window
For Large Environments:
-
Use Folder Filters
- Set
control-m.workload.folderFilterto limit scope - Example:
PROD_*for production folders only
- Set
-
Configure MFT Host Group
- Set
control-m.mft.hostgroupto specific host group - Reduces agent scanning time
- Set
-
Adjust Pagination
- Increase
control-m.pagination.pageSizefor faster browsing - Decrease for better performance on slower systems
- Increase
-
Lazy Loading
- Agents, host groups, and remote hosts are lazy-loaded
- Expand only needed sections
Version Control Best Practices:
- Store job definitions in Git repositories
- Export folders to JSON files for version control
- Track connection profiles and configurations
- Use branches for different environments
- Review changes before deployment
Recommended Structure:
project/
├── jobs/
│ ├── production/
│ ├── test/
│ └── development/
├── connection-profiles/
├── calendars/
└── site-standards/
CI/CD Integration:
The extension enables modern DevOps practices:
- Develop jobs in VS Code
- Validate with Build service
- Test with Run service
- Commit to Git repository
- Deploy via CI/CD pipeline
- Monitor in Control-M
Example Workflow:
# Validate job definition
code --command control-m.json.build my-job.json
# Deploy to test environment
code --command control-m.json.deploy my-job.json
# Run and verify
code --command control-m.json.run my-job.jsonThe Control-M Extension for VS Code provides comprehensive capabilities for:
- Infrastructure Management - Complete visibility and control
- Job Development - Modern IDE-based workflow creation
- Testing & Validation - Verify before deployment
- Data Services - Advanced file transfer management
- DevOps Integration - Git and CI/CD ready
For additional help, see:
- Getting Started Guide - Initial setup and first steps
- REST API Reference - Technical API documentation
- Production README - Quick reference
Documentation Version 1.0.0