7. Deploying Open Integration using SCM

You can now deploy Open Integration using the infrastructure resources that you created using the configuration files stored in customer Git. This step initiates the deployment of the Open Integration services.

Optionally, you can set up the Coherence server for Open Integration by configuring the coherence section in the payload. You can deploy a new Coherence server or use your existing Coherence server during the Open Integration deployment.

In the deployment request, reference the registered git_id, the target Git branch, the target directory, the uploaded keystore and truststore file paths, and the required Coherence settings.

You can deploy Open Integration using the /openintegration API endpoint:

  • Method: POST
  • Endpoint: /openintegration
  • Description: Initiates the deployment of Open Integration using the infrastructure resources and configuration files created in the earlier steps. It creates the Open Integration deployment, generates GitOps resources, creates runtime secrets, runs the image-builder job, and deploys the runtime.
  • Sample payload for:
    • Deploying Open Integration:
      {  
         "name": "openint1",
         "infra_id": "7OZMKQ",
         "openintegration": {
            "git": {
               "git_id": "<git_id>",
               "git_openint_branch": "<customer-branch>",
               "git_openint_directory": "<customer-openint-directory>"
            },
            "siebel_server_keystore_file_path": "/home/opc/siebel/siebelkeystore.jks",
            "siebel_client_keystore_file_path": "/home/opc/siebel/siebelkeystore_client.jks",
            "siebel_truststore_file_path": "/home/opc/siebel/siebeltruststore.jks",
            "siebel_server_keystore_password": "server",
            "siebel_truststore_password": "siebel",
            "siebel_client_keystore_password": "client"
         }
      }
    • Deploying Open Integration with a new Coherence server:
      {
         "name": "openint1",
         "infra_id": "<infra_id>",
         "openintegration": {
         "base_url": "<>",
         "git": {
            "git_id": "<git_id>",
            "git_openint_branch": "<customer-branch>",
            "git_openint_directory": "<customer-openint-directory>"
         },
         "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks",
         "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks",
         "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks",
         "siebel_server_keystore_password": "<server-keystore-password>",
         "siebel_client_keystore_password": "<client-keystore-password>",
         "siebel_truststore_password": "<truststore-password>"
         },
         "coherence": {
            "coherence_cluster_name": "<coherence-cluster-name>",
            "use_existing": "false",
            "enable_tls": "true"
         }
      }
    • Deploying Open Integration using an existing Coherence server:
      {
         "name": "openint1",
         "infra_id": "<infra_id>",
         "openintegration": {
         "git": {
            "git_id": "<git_id>",
            "git_openint_branch": "<customer-branch>",
            "git_openint_directory": "<customer-openint-directory>"
         },
         "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks",
         "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks",
         "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks",
         "siebel_server_keystore_password": "<server-keystore-password>",
         "siebel_client_keystore_password": "<client-keystore-password>",
         "siebel_truststore_password": "<truststore-password>"
         },
         "coherence": {
            "coherence_cluster_name": "<existing-coherence-cluster-name>",
            "namespace": "<existing-coherence-namespace>",
            "use_existing": "true",
            "wka_endpoint": "<existing-coherence-wka-endpoint>"
         }
      }
    • DeployingOpen Integration using Coherence server with optional EPS keystore certificates:
      {
         "name": "openint1",
         "infra_id": "<infra_id>",
         "openintegration": {
               "git": {
               "git_id": "<git_id>",
               "git_openint_branch": "<customer-branch>",
               "git_openint_directory": "<customer-openint-directory>"
            },
            "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks",
            "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks",
            "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks",
            "siebel_server_keystore_password": "<server-keystore-password>",
            "siebel_client_keystore_password": "<client-keystore-password>",
            "siebel_truststore_password": "<truststore-password>",
            "eps": {
               "ai_egress_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/aiegressserverkeystore.jks",
               "ai_egress_server_keystore_password": "<ai-egress-password>",
               "kafka_keystore_file_path": "/home/opc/syncUtility/<sync_id>/kafkakeystore.jks",
               "kafka_keystore_password": "<kafka-keystore-password>",
               "kafka_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkatruststore.jks",
               "kafka_truststore_password": "<kafka-truststore-password>",
               "kafka_oauth_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkaoauthtruststore.jks",
               "kafka_oauth_truststore_password": "<kafka-oauth-truststore-password>"
            } 
         },
         "coherence": {
            "coherence_cluster_name": "<existing-coherence-cluster-name>",
            "namespace": "<existing-coherence-namespace>",
            "use_existing": "true",
            "wka_endpoint": "<existing-coherence-wka-endpoint>"
         }
      }

Optional Security Context

You can optionally specify the security_context section at the top level of the infrastructure provisioning payload when infrastructure resources and operators must run with custom non-root user ID and group ID. For example:

{
   "name": "<openint_name>",
   "infra_id": "<infra_id>",
   "security_context": {
      "run_as_user": <uid>,
      "run_as_group": <gid>,
      "fs_group": <fs_group_id>
   }
} 
Note: This is a separate Open Integration configuration. Include it explicitly even if the infrastructure provisioning payload also contains a security_context section.

The specified values are applied to the following Open Integration resources:

  • Open Integration image builder
  • Open Integration application workloads
  • Coherence chart resources

If you specify security_context, you must provide all three parameters:

  • run_as_user
  • run_as_group
  • fs_group

On OpenShift, run_as_user must be within the range specified by the openshift.io/sa.scc.uid-range namespace annotation. The fs_group value must be the first ID in the range specified by the openshift.io/sa.scc.supplemental-groups namespace annotation.

To determine valid values, inspect the namespace annotations and select a user ID from the uid-range annotation and the first group ID from the supplemental-groups annotation.

  • Sample API call request:
    POST https://<SCM_instance_IP>:<port_num>/scm/api/v1.0/openintegration
    	Authorization: Basic Auth
    Content-Type: application/json
  • Sample response:
    {
       "data": {
          "deploy_id": "<deploy_id>",
          "deploy_status": "creation-in-progress",
          "infra_id": "<infra_id>",
          "name": "openint1",
          "namespace": "openint1",
          "openintegration": {
             "git": {
                "git_id": "<git_id>",
                "git_openint_branch": "<customer-branch>",
                "git_openint_directory": "<customer-openint-directory>"
          },
          "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks",
          "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks",
          "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks",
          "siebel_server_keystore_password": "<server-keystore-password>",
          "siebel_client_keystore_password": "<client-keystore-password>",
          "siebel_truststore_password": "<truststore-password>",
          "eps": {
             "ai_egress_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/aiegressserverkeystore.jks",
             "ai_egress_server_keystore_password": "<ai-egress-password>",
             "kafka_keystore_file_path": "/home/opc/syncUtility/<sync_id>/kafkakeystore.jks",
             "kafka_keystore_password": "<kafka-keystore-password>",
             "kafka_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkatruststore.jks",
             "kafka_truststore_password": "<kafka-truststore-password>",
             "kafka_oauth_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkaoauthtruststore.jks",
             "kafka_oauth_truststore_password": "<kafka-oauth-truststore-password>"
          }
       },
       "stages": [
          {
             "name": "Pre Deploy",
             "stage_name": "pre_deploy",
             "status": ""
          },
          {
             "name": "Prepare GitOps",
             "stage_name": "prepare_gitops",
             "status": ""
          },
          {
             "name": "Flux Setup",
             "stage_name": "flux_setup",
             "status": ""
          }
       ]
       },
       "message": "success",
       "status": "success"
    } 

Optional Open Integration Base URL

You can use openintegration.base_url to specify the URL that Open Integration exposes to its clients. For a NodePort deployment, use an accessible Kubernetes node host name or IP address and the Open Integration NodePort. For example:

{
   "openintegration": {
      "base_url": "https://100.95.243.197:32082/openintegration/v1.0"
   }
}

If you omit this field or leave it blank, SCM uses https://openint-service.<deployment-namespace>.svc.cluster.local:8433.

SCM resolves the value before deployment and writes it to the Open Integration Helm Release as the BASE_URL environment variable.

Note:
  • EPS JKS file-password pairs are independently optional. When you provide a file path, provide its matching password.
  • For an existing Coherence cluster, provide namespace and wka_endpoint.

Certificate SAN Requirement

You must ensure that the server certificate includes the Open Integration endpoint used by the integration in its Subject Alternative Name (SAN):

  • Service URL: DNS:openint-service.<namespace>.svc.cluster.local
  • Node host name URL: DNS:<node-dns-name>
  • Node IP URL: IP:<node-ip-address>

Validation Rules

The following validation rules apply when you deploy Open Integration using SCM:

  • The name parameter is required in the payload. The value must contain 3 to 12 alphanumeric characters and start with a letter.
  • The value of the infra_id parameter must refer to a valid SCM infrastructure record.
  • The value of openintegration.git.git_id parameter must be a registered 6-character uppercase alphanumeric Git ID.
  • The value of git_openint_branch parameter must be a valid Git branch name.
  • The value of git_openint_directory parameter must be a relative directory inside the customer Git repository.
  • The siebel_server_keystore_file_path, siebel_client_keystore_file_path, and siebel_truststore_file_path parameters are required in the payload.
  • The three JKS password parameters are required in the payload.
  • If you specify the security_context parameter, the run_as_user, run_as_group, and fs_group values are required and must be integers.
  • The openintegration.base_url parameter is optional. If you omit the value or leave it blank, SCM uses the internal Open Integration Service URL.
  • If you specify the openintegration.base_url parameter, the value must be an absolute HTTP or HTTPS URL that contains a host name or IP address. The value must not contain whitespace or embedded credentials.
  • If the openintegration.base_url value includes a port, the port must be valid and non-zero.
  • The config_json_file_path and profile_json_file_path parameters are not supported in V2.