Start a conversation

Why are Previously Approved Templates Asking for Approval Again?

Overview

You previously generated runbooks for a Fixer — the GENERATE RUNBOOK(S) button on the Generate Runbooks tab had turned into a checkmark, and its recommendations were selectable on Available to Execute. Now, for that same Fixer and account, you notice the checkmark is gone, GENERATE RUNBOOK(S) is back, and the recommendations show status Pending Approval again — even though nothing changed on your end.

Solution

This is expected behavior. It happens when CloudFix ships an updated version of the runbook (the SSM Automation document) for that Fixer. CloudFix tracks each deployed runbook by a content hash; when the hash of the version in your account no longer matches the current one in CloudFix's catalog, that runbook is treated as out of date until it is refreshed.

Pending Approval is legacy status text — nothing is waiting on a human approver. It means the currently deployed runbook for that Fixer is stale or missing in your account. There is no separate "approve" action anymore; the runbook simply needs to be redeployed.

To refresh it, go to the Generate Runbooks tab and click GENERATE RUNBOOK(S) again for that Fixer. This redeploys the current runbook to your management account and re-shares it with every account that has a recommendation for that Fixer — you don't need to repeat it per account.

While the recommendation shows Pending Approval, it isn't selectable for EXECUTE on Available to Execute — the button stays disabled for that row until the runbook is redeployed. Clicking GENERATE RUNBOOK(S) is what unblocks it: once the redeploy finishes, the row's status returns to Ready and you can select it and execute as usual.

There's no setting that prevents this refresh cycle — it's driven by CloudFix shipping new runbook versions, not by anything configurable per tenant. In particular, the AUTO APPROVE TEMPLATES checkbox in Settings > Finders & Fixers does not skip or suppress it: that setting only controls whether the approver role in your CloudFix stack trusts CloudFix, and it has no effect on when a Fixer's runbook needs to be redeployed. If you want new recommendations for a Fixer to execute automatically without you clicking anything, that's what ALWAYS EXECUTE FIXER (also in Settings > Finders & Fixers) is for — and even on that automatic path, CloudFix still refreshes a stale runbook by itself before running the fix.

Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted
  3. Updated

Comments