Downloading and Installing Siebel Cloud Manager
Use this task to create and deploy the SCM stack (that is, to install the SCM instance in a virtual machine instance on OCI).
Before you perform this task, if you want SCM to create the Git repository, install GitLab CE (if it isn't already installed) into the same compartment where you install SCM.
During stack creation, review all default values displayed. Confirm each value or enter a new value as appropriate for your task. Steps for verifying SCM are also included.
To download and install SCM
-
Start the OCI console and log in.
-
Navigate to Marketplace, All applications.
-
Search for Siebel Cloud Manager.
-
Drill down on the Siebel Cloud Manager link.
-
Select the version and compartment (which you created in Creating a Compartment), check review terms and conditions.
-
Click Launch Stack.
-
Navigate to the Stack Variables page.
- Under General, provide the following details:
- Use existing resources: Specify whether you want to use existing
resources (such as Compartment, VCN, mount target, database, and OKE)
for the SCM instance. If you:
- Select "Use existing resources", you can choose your existing resources (such as Compartment, VCN, mount target, database and OKE) for SCM configuration and Siebel environment provisioning.
- Don't select "Use existing resources", SCM creates all the above-mentioned resources.
- Root compartment OCID for your SCM instance (the compartment you created in Step 5)
- SCM public ssh keys for accessing the SCM instance.
- Resource prefix to name the OCI resources (all the resources created through this stack have this prefix added).
- Use existing resources: Specify whether you want to use existing
resources (such as Compartment, VCN, mount target, database, and OKE)
for the SCM instance. If you:
- Under Permissions, specify one of the following
permission types for the SCM instance:
- Instance Principal to provide secure access and permissions to the SCM
instance. When configuring Instance Principal, you have the option to
use existing dynamic group and policy. By default, the "Use Existing
Dynamic Group and Policy" checkbox is unchecked, that is, the system
will automatically:
- Create a new dynamic group.
- Generate an OCI CLI policy.
- Assign the created policy to the SCM instance.
If you select the "Use Existing Dynamic Group and Policy" checkbox then, after the Apply stack job is completed, you must manually:
- Add a new matching rule
"instance.id=<cm_instance_id>"in an existing dynamic group -<dynamic_group_name>. - Add a new policy statement
"Allow dynamic-group <dynamic_group_name> to manage all-resources in compartment id <cm_compartment_ocid>"in an existing policy. This policy allows you to access and perform various CRUD operations in SCM compartment from SCM instance.
- User Principal for user-specific authentication. When you use User
Principal, the SCM instance does not use dynamic groups or automatically
generated policies. The OCI configuration is done manually.
To set up User Principal, you will receive necessary details such as the user's private key, OCI fingerprint, and OCI passphrase. You can generate the private key and obtain the fingerprint from the OCI Console by navigating to Users > Resources > API Keys. All the permissions that apply for this user are available to the SCM instance.
- Instance Principal to provide secure access and permissions to the SCM
instance. When configuring Instance Principal, you have the option to
use existing dynamic group and policy. By default, the "Use Existing
Dynamic Group and Policy" checkbox is unchecked, that is, the system
will automatically:
- Under VCN, specify whether you want to use existing VCN
resource. This option enables you to use your existing network component
resources and allows SCM to create and manage other resources such as mount
target, file system, database, and OKE.
- Network component for SCM Instance: Locate the compartment where the
desired VCN is present for creating the SCM instance and in the
following drop-down field select an existing VCN and a subnet. Note:
- Allow TCP port 22 from your client network to establish SSH connection to the SCM instance.
- Allow TCP port 16690 from your client network to access the SCM application.
- Ensure appropriate egress rules are created for two-way traffic.
- Network component for mount target: Locate the compartment where the
desired VCN is present for creating the mount target and in the
following drop-down field select an existing VCN and a subnet. Note: Allow TCP ports 111, 2048, 2049, 2050 and UDP ports 111, 2048 from the SCM instance subnet.
- "Use existing File system and Mount Target" option is provided to allow
the user to bring existing resources instead of SCM to create the mount
target and file system service. When this option is chosen user has to
provide value for the IP address of the mount target. Note: The existing file system export is to be provided in the subsequent section as below when "Use existing File system and Mount Target" is chosen.
- Network component for SCM Instance: Locate the compartment where the
desired VCN is present for creating the SCM instance and in the
following drop-down field select an existing VCN and a subnet.
-
When the "Use Existing Resources" or "Use existing File System and Mount Target" option is not selected earlier, then under Storage, select the availability domain for storage in which the shared mount target and file storage is created. The options are 1, 2, or 3.
When the "Use Existing Resources" or "Use existing File system and Mount Target" is chosen, provide value of Export path for the desired file storage which will be used as persistence storage for SCM application.
- Under CloudManager Instance Configuration section,
configure the following:
- Select the Cloud Manager Instance Type: Select
the shape for the SCM instance. For example, select
VM.Standard.E5.FlexorVM.Standard.E6.Flex. - No of OCPU's: Enter the number of OCPU cores. For
example, enter
1. This field is available only for SCM instance types that support configurable OCPU values. - Amount of Memory(GB): Enter the memory in
gigabytes. For example, enter
4 GB. This field is available only for SCM instance types that support configurable memory values. - Assign Public IP Address: Select this option to
assign a public IP address to SCM. If you do not select this option, SCM
uses a private IP address.Note: Assigning a public IP address configures SCM for public access. Not assigning a public IP address configures SCM for private access only. Switching between public and private access is not supported.
- Allowed source CIDR for Cloud Manager access:
Enter the IPv4 Classless Inter-Domain Routing (CIDR) block that can
connect to SCM over SSH and the SCM API/UI port. This field is available
and mandatory only when Assign Public IP Address
is selected. You must provide the narrowest CIDR that still allows
administrators to access SCM:
- To allow one specific public IP address, enter the IP address
with
/32. For example, enter203.0.113.10/32when only one administrator machine, VPN egress IP, NAT gateway IP, or corporate proxy egress IP must be allowed. - To allow an entire network range, enter the subnet in CIDR
notation. For example, enter
203.0.113.0/24when administrators connect from a known corporate subnet or controlled network range.
The value must be a valid IPv4 CIDR with prefix length
/1through/32. SCM does not allow the following values:Blocked Value or Range Reason Any /0CIDR, for example0.0.0.0/0or1.1.1.1/0Allows the entire IPv4 internet. 0.x.x.xSpecial-use address range. 127.x.x.xLoopback address range. 224.0.0.0/4through239.255.255.255Multicast range. 240.0.0.0/4through255.255.255.255Reserved or broadcast range. Note: For private SCM deployments, this value is not required because SCM does not expose a public IP address. Private access must come through the customer's VCN, VPN, FastConnect, bastion, or other private access path. - To allow one specific public IP address, enter the IP address
with
- HTTP Proxy: Enter the HTTP proxy server URL for HTTP requests. For example, enter yourhttpproxyserver.com:80.
- HTTPS Proxy: Enter the HTTPS proxy server URL for HTTPS requests. For example, enter yourhttpsproxyserver.com:80.
- URL(s) to bypass proxy: Enter the URLs that must
bypass the proxy server (no_proxy). For example, enter
externalurl1.com,externalurl2.com.Note: You must consider all URLs that might require proxy bypass during SCM and Siebel CRM environment provisioning. The
HTTP_PROXY,HTTPS_PROXY, andNO_PROXYvariables are applied only to the SCM container as environment variables. They are not applied to the container management configuration. - Select security protocol for Siebel Cloud Manager: Optionally, select the security protocol to use: HTTP or HTTPS.
- Enter port number where Siebel Cloud Manager API will be
accessed: Specify the port number to use when accessing
SCM through its APIs. If you select HTTPS, choose whether to provide
your own PEM-format SSL/TLS certificate, such as a CA-signed or
self-signed certificate. If you do not provide a certificate, SCM
provisions and uses a self-signed certificate. You can change the
certificate later.
If you do not select a security protocol, SCM uses HTTPS by default and automatically provisions a self-signed certificate.
Note: The example values specified are indicative only and are not mandatory. Review the vendor documentation to determine the recommended compute shape, CPU, memory, storage, and operating system requirements for your deployment. Select a configuration that meets your workload, performance, and availability requirements. - Select the Cloud Manager Instance Type: Select
the shape for the SCM instance. For example, select
-
Under Network Configuration:
- If "Use Existing Resources" is selected, then you will be prompted to provide existing VCN details, such as the VCN Compartment OCID where VCN resides, and the VCN Name and Subnet where the SCM instance should be created.
- If "Use Existing Resources" is not selected, then you need to specify
whether you want to use Advanced Network Configuration to manage subnet
IP address ranges for the SCM instance and Siebel CRM deployments.
Use this option only to override the default subnet CIDR ranges: /16 for the VCN and /24 for each subnet. If you specify Advanced Network Configuration, then you can modify the default settings of 10.0.0.0/16 for the IP range for the VCN CIDR block, 10.0.0.0/24 for the IP range for the SCM subnet CIDR block, and 10.0.255.0/24 for the IP range for the SCM private subnet CIDR block.
For details, see Using Advanced Network Configuration.
- Under Key Management, choose how you want SCM to use OCI
Vault for key management. The available options depend on whether you selected
Use existing resources:
- If "Use existing resources" is not selected, you can choose one of the
following options:
- Select Create a new OCI Vault to allow SCM to create a new Vault.
- Select Enter OCID of your existing OCI Vault to use an existing OCI Vault.
- Select Do not use Vault to skip Vault usage for key management.
- If "Use existing resources" is selected, you can choose one of the
following options:
- Select Enter OCID of your existing OCI
Vault and provide the OCID of the existing OCI
Vault. You can also enter the OCID of the customer-managed KMS
key. The OCID of the key must start with
ocid1.key. If you omit this value, SCM uses Oracle-managed keys.For more information about the best practices for secrets management, see Using Vault for Managing Secrets.
- Select Do not use Vault to skip Vault usage for key management.
- Select Enter OCID of your existing OCI
Vault and provide the OCID of the existing OCI
Vault. You can also enter the OCID of the customer-managed KMS
key. The OCID of the key must start with
Note: Oracle recommends using OCI Vaults to conform to best practices regarding managing secrets. For more information about the best practices for secrets management, see Using Vault for Managing Secrets. - If "Use existing resources" is not selected, you can choose one of the
following options:
- Under Tags, you can optionally add tags for SCM-created
resources. You can use defined tags and free-form tags to organize the OCI
resources created by the SCM stack.
For defined tags, select the tag namespace and tag key, and enter the tag value. You must ensure the defined tag namespace and key already exist, and that the stack principal has permission to use the selected tag namespace.
If SCM creates file systems and you enter a customer-managed key, you must select at least one defined tag that the dynamic group and policy use to grant OCI File Storage access to the key.
You can use the following matrix to determine when the SCM storage KMS key and tags are required.
Use existing resources Use BYO FSS Customer-managed key provided SCM creates FSS Defined tag required Encryption behavior false false No Yes No Oracle-managed encryption false false Yes Yes Yes, at least one defined tag SCM boot volume and SCM-created FSS false true Yes No Yes, at least one defined tag SCM boot volume only; BYO FSS is not changed true Hidden / N/A Yes No Yes, at least one defined tag SCM boot volume only; existing resources are not changed -
Choose Run Apply and then click Create to create the stack. Terraform scripts run which define the configuration for the new stack.
-
Wait for the completion of the Apply job. If an error such as
authorization failedorrequested resource not foundappears, then choose Run Apply again. -
Make a note of the following URLs provided at the end of the run log:
- CloudManagerApplication. The URL for running SCM, which uses the
public or private IP address and port number of the newly created
instance. You will use this URL to run SCM, as described in Reducing the Ingress Range for Siebel Cloud Manager.
For example:
https://<CM_instance_IP>:<port_num>/- Siebel Lift utility: The Siebel Lift utility is available on My Oracle Support (MOS) as the Siebel CRM 26.8.0.0 Lift Utility (Patch) media file. For more information, see Downloading and Running the Siebel Lift Utility.
- CloudManagerApplication. The URL for running SCM, which uses the
public or private IP address and port number of the newly created
instance. You will use this URL to run SCM, as described in Reducing the Ingress Range for Siebel Cloud Manager.
For example:
-
To verify the running status of the application, run
sshin the SCM VM instance and check thesystemctlstatus for siebel-cloud-manager, as follows:ssh opc@[CM_instance_IP] -
To verify the SCM application is running, run the following commands:
sudo podman ps sudo podman logs -t cloudmanager -f -
To check the response, launch the following URL:
https://<CM_instance_IP>:<port_num>/If you are performing a greenfield deployment, then you are now ready to create an environment using SCM. Otherwise, you must first download and run the Siebel Lift utility, as described in Downloading and Running the Siebel Lift Utility, before you can create an environment using the lifted artifacts in the OCI Object Store.