7. Deploying Open Integration using SCM
You can now deploy Open Integration using the infrastructure resources that you created using the configuration files stored in customer Git. This step initiates the deployment of the Open Integration services.
Optionally, you can set up the Coherence server for Open Integration by configuring the
coherence section in the payload. You can deploy a new Coherence
server or use your existing Coherence server during the Open Integration deployment.
In the deployment request, reference the registered git_id, the target
Git branch, the target directory, the uploaded keystore and truststore file paths, and
the required Coherence settings.
You can deploy Open Integration using the /openintegration API
endpoint:
- Method: POST
- Endpoint:
/openintegration - Description: Initiates the deployment of Open Integration using the infrastructure resources and configuration files created in the earlier steps. It creates the Open Integration deployment, generates GitOps resources, creates runtime secrets, runs the image-builder job, and deploys the runtime.
- Sample payload for:
- Deploying Open Integration:
{ "name": "openint1", "infra_id": "7OZMKQ", "openintegration": { "git": { "git_id": "<git_id>", "git_openint_branch": "<customer-branch>", "git_openint_directory": "<customer-openint-directory>" }, "siebel_server_keystore_file_path": "/home/opc/siebel/siebelkeystore.jks", "siebel_client_keystore_file_path": "/home/opc/siebel/siebelkeystore_client.jks", "siebel_truststore_file_path": "/home/opc/siebel/siebeltruststore.jks", "siebel_server_keystore_password": "server", "siebel_truststore_password": "siebel", "siebel_client_keystore_password": "client" } } - Deploying Open Integration with a new Coherence
server:
{ "name": "openint1", "infra_id": "<infra_id>", "openintegration": { "base_url": "<>", "git": { "git_id": "<git_id>", "git_openint_branch": "<customer-branch>", "git_openint_directory": "<customer-openint-directory>" }, "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks", "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks", "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks", "siebel_server_keystore_password": "<server-keystore-password>", "siebel_client_keystore_password": "<client-keystore-password>", "siebel_truststore_password": "<truststore-password>" }, "coherence": { "coherence_cluster_name": "<coherence-cluster-name>", "use_existing": "false", "enable_tls": "true" } } - Deploying Open Integration using an existing Coherence
server:
{ "name": "openint1", "infra_id": "<infra_id>", "openintegration": { "git": { "git_id": "<git_id>", "git_openint_branch": "<customer-branch>", "git_openint_directory": "<customer-openint-directory>" }, "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks", "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks", "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks", "siebel_server_keystore_password": "<server-keystore-password>", "siebel_client_keystore_password": "<client-keystore-password>", "siebel_truststore_password": "<truststore-password>" }, "coherence": { "coherence_cluster_name": "<existing-coherence-cluster-name>", "namespace": "<existing-coherence-namespace>", "use_existing": "true", "wka_endpoint": "<existing-coherence-wka-endpoint>" } } - DeployingOpen Integration using Coherence server with optional EPS keystore
certificates:
{ "name": "openint1", "infra_id": "<infra_id>", "openintegration": { "git": { "git_id": "<git_id>", "git_openint_branch": "<customer-branch>", "git_openint_directory": "<customer-openint-directory>" }, "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks", "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks", "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks", "siebel_server_keystore_password": "<server-keystore-password>", "siebel_client_keystore_password": "<client-keystore-password>", "siebel_truststore_password": "<truststore-password>", "eps": { "ai_egress_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/aiegressserverkeystore.jks", "ai_egress_server_keystore_password": "<ai-egress-password>", "kafka_keystore_file_path": "/home/opc/syncUtility/<sync_id>/kafkakeystore.jks", "kafka_keystore_password": "<kafka-keystore-password>", "kafka_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkatruststore.jks", "kafka_truststore_password": "<kafka-truststore-password>", "kafka_oauth_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkaoauthtruststore.jks", "kafka_oauth_truststore_password": "<kafka-oauth-truststore-password>" } }, "coherence": { "coherence_cluster_name": "<existing-coherence-cluster-name>", "namespace": "<existing-coherence-namespace>", "use_existing": "true", "wka_endpoint": "<existing-coherence-wka-endpoint>" } }
- Deploying Open Integration:
Optional Security Context
You can optionally specify the security_context section at the top
level of the infrastructure provisioning payload when infrastructure resources and
operators must run with custom non-root user ID and group ID. For example:
{
"name": "<openint_name>",
"infra_id": "<infra_id>",
"security_context": {
"run_as_user": <uid>,
"run_as_group": <gid>,
"fs_group": <fs_group_id>
}
}
security_context section.The specified values are applied to the following Open Integration resources:
- Open Integration image builder
- Open Integration application workloads
- Coherence chart resources
If you specify security_context, you must provide all three
parameters:
run_as_userrun_as_groupfs_group
On OpenShift, run_as_user must be within the range specified by the
openshift.io/sa.scc.uid-range namespace annotation. The
fs_group value must be the first ID in the range specified by
the openshift.io/sa.scc.supplemental-groups namespace
annotation.
To determine valid values, inspect the namespace annotations and select a user ID
from the uid-range annotation and the first group ID from the
supplemental-groups annotation.
- Sample API call
request:
POST https://<SCM_instance_IP>:<port_num>/scm/api/v1.0/openintegration Authorization: Basic Auth Content-Type: application/json - Sample response:
{ "data": { "deploy_id": "<deploy_id>", "deploy_status": "creation-in-progress", "infra_id": "<infra_id>", "name": "openint1", "namespace": "openint1", "openintegration": { "git": { "git_id": "<git_id>", "git_openint_branch": "<customer-branch>", "git_openint_directory": "<customer-openint-directory>" }, "siebel_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelserverkeystore.jks", "siebel_client_keystore_file_path": "/home/opc/syncUtility/<sync_id>/siebelclientkeystore.jks", "siebel_truststore_file_path": "/home/opc/syncUtility/<sync_id>/siebeltruststore.jks", "siebel_server_keystore_password": "<server-keystore-password>", "siebel_client_keystore_password": "<client-keystore-password>", "siebel_truststore_password": "<truststore-password>", "eps": { "ai_egress_server_keystore_file_path": "/home/opc/syncUtility/<sync_id>/aiegressserverkeystore.jks", "ai_egress_server_keystore_password": "<ai-egress-password>", "kafka_keystore_file_path": "/home/opc/syncUtility/<sync_id>/kafkakeystore.jks", "kafka_keystore_password": "<kafka-keystore-password>", "kafka_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkatruststore.jks", "kafka_truststore_password": "<kafka-truststore-password>", "kafka_oauth_truststore_file_path": "/home/opc/syncUtility/<sync_id>/kafkaoauthtruststore.jks", "kafka_oauth_truststore_password": "<kafka-oauth-truststore-password>" } }, "stages": [ { "name": "Pre Deploy", "stage_name": "pre_deploy", "status": "" }, { "name": "Prepare GitOps", "stage_name": "prepare_gitops", "status": "" }, { "name": "Flux Setup", "stage_name": "flux_setup", "status": "" } ] }, "message": "success", "status": "success" }
Optional Open Integration Base URL
You can use openintegration.base_url to specify the URL that Open
Integration exposes to its clients. For a NodePort deployment, use an accessible
Kubernetes node host name or IP address and the Open Integration NodePort. For
example:
{
"openintegration": {
"base_url": "https://100.95.243.197:32082/openintegration/v1.0"
}
}
If you omit this field or leave it blank, SCM uses
https://openint-service.<deployment-namespace>.svc.cluster.local:8433.
SCM resolves the value before deployment and writes it to the Open Integration Helm Release as the BASE_URL environment variable.
- EPS JKS file-password pairs are independently optional. When you provide a file path, provide its matching password.
- For an existing Coherence cluster, provide
namespaceandwka_endpoint.
Certificate SAN Requirement
You must ensure that the server certificate includes the Open Integration endpoint used by the integration in its Subject Alternative Name (SAN):
- Service URL:
DNS:openint-service.<namespace>.svc.cluster.local - Node host name URL:
DNS:<node-dns-name> - Node IP URL:
IP:<node-ip-address>
Validation Rules
The following validation rules apply when you deploy Open Integration using SCM:
- The
nameparameter is required in the payload. The value must contain 3 to 12 alphanumeric characters and start with a letter. - The value of the
infra_idparameter must refer to a valid SCM infrastructure record. - The value of
openintegration.git.git_idparameter must be a registered 6-character uppercase alphanumeric Git ID. - The value of
git_openint_branchparameter must be a valid Git branch name. - The value of
git_openint_directoryparameter must be a relative directory inside the customer Git repository. - The
siebel_server_keystore_file_path,siebel_client_keystore_file_path, andsiebel_truststore_file_pathparameters are required in the payload. - The three JKS password parameters are required in the payload.
- If you specify the
security_contextparameter, therun_as_user,run_as_group, andfs_groupvalues are required and must be integers. - The
openintegration.base_urlparameter is optional. If you omit the value or leave it blank, SCM uses the internal Open Integration Service URL. - If you specify the
openintegration.base_urlparameter, the value must be an absolute HTTP or HTTPS URL that contains a host name or IP address. The value must not contain whitespace or embedded credentials. - If the
openintegration.base_urlvalue includes a port, the port must be valid and non-zero. - The
config_json_file_pathandprofile_json_file_pathparameters are not supported in V2.