Keys¶
The key value store of Consul administrates environment variables for the DPF server configuration.
The keys are commonly set during the installation or configuration of the DPF system.
Hint - usage in Working Units
Use the environment variables in the working unit scripts in order to avoid absolute paths.
Units¶
Values with time specifications are specified in the following time units:
-
seconds(s,sec) -
minutes(m,min) -
hours(h,hr) -
days(d) -
weeks(w,wk) -
months -
years(y,yr)
Example - with time units
<time_interval>=2h30m<time_interval>=4m2s
ALLOWED_OIDC_CLIENTS¶
ALLOWED_OIDC_CLIENTS specifies the allowed OIDC clients and roles to get access to the jobclient API.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/ALLOWED_OIDC_CLIENTS
Available values: JSON string format
Default: none
Example - configuration giving access to clients client-a and client-b for users with the corresponding roles
{
"client-a": {
"roles": {
"role-1": {},
"role-2": {}
}
},
"client-b": {
"roles": {
"role-3": {}
}
}
}
AUTH_ADDITIONAL_SCOPES¶
AUTH_ADDITIONAL_SCOPES specifies additional scopes for OAuth 2 (required for Azure AD for example). Multiple scopes are separated by a blank.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/AUTH_ADDITIONAL_SCOPES
Available values: String
<scope_1> <scope_2> ... <scope_n>
Default: none
AUTH_CLIENT_ID¶
AUTH_CLIENT_ID specifies the client name configured in the OIDC identity provider for retrieving the access token.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/AUTH_CLIENT_ID
Available values: String
<client_id>
Default:
-
seal-plossyscliservice:seal-plossyscli -
seal-plossysadminservice:seal-plossysadmin
AUTH_CLIENT_SECRET¶
AUTH_CLIENT_SECRET specifies the client secret for retrieving the OIDC identity provider's access token.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/AUTH_CLIENT_SECRET
Available values: String
<client_secret>
Default: not revealed
AUTH_ISSUER_URL¶
AUTH_ISSUER_URL specifies the OIDC issuer URL. This URL is configured in Keycloak for example. For more information about Keycloak used with SEAL Systems products, refer to the SEAL Interfaces for OIDC documentation.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/AUTH_ISSUER_URL
Available values: String
<oidc_issuer_url>
Default: none
AUTH_PROXY¶
AUTH_PROXY specifies a proxy URL to access the OIDC provider.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/ipp/AUTH_PROXY
Available values: String
<oidc_proxy_url>
Default: none
AUTH_TOKEN_ENDPOINT¶
AUTH_TOKEN_ENDPOINT specifies the URL of the token endpoint.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not exist yet, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/AUTH_TOKEN_ENDPOINT
Available values: String
<auth_token_endpoint>
Default: The default is retrieved automatically from the OIDC service.
AUTH_TYPE¶
AUTH_TYPE specifies the mode of the client authentication.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/AUTH_TYPE
Available values: String
-
oidcIn the request the service expects a JSON Web token (JWT) which is received from an authentication via OpenID server connect.
-
noneNo authentication required
Default: none
BROKER_FORCE_TLS¶
BROKER_FORCE_TLS specifies if the SEAL NATS message broker uses TLS.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/BROKER_FORCE_TLS
Available values: Boolean
false-
N -
true Y
Default: false
BROKER_SERVERS¶
BROKER_SERVERS specifies the message broker server hosts and ports. Multiple server and port items are separated by commas.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/BROKER_SERVERS
Available values: String
nats1:4222,nats2:4222,nats3:4222
Default: localhost:4222
BROKER_REJECT_UNAUTHORIZED¶
BROKER_REJECT_UNAUTHORIZED specifies if self-signed TLS certificates from the message broker will be rejected. Only used if BROKER_FORCE_TLS is enabled.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/BROKER_REJECT_UNAUTHORIZED
Available values: Boolean
true-
Y -
false N
Default: true
BROKER_TOKEN¶
BROKER_TOKEN specifies the message broker access token.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/BROKER_TOKEN
Available values: String
Default: none
CONSUL_TOKEN¶
CONSUL_TOKEN specifies the ACL token with which the DPF services authenticate themselves to Consul.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/CONSUL_TOKEN
Available values: String
<token>
Default: INSECURE_ACL_MASTER_TOKEN
Literature - configure Consul ACL
Refer to Configure ACL for on-premise Windows or Configure ACL for on-premise Linux.
CONSUL_URL¶
CONSUL_URL specifies the URL of the Consul server to which the DPF services log on.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/CONSUL_URL
Available values: String
<consul_url>
Default: https://localhost:8500
DPFBIN¶
DPFBIN specifies the directory containing the binaries of the DPF system.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/DPFBIN
Available values: String
<directory>
Default:
- Windows:
server\dpf\bin_<PLS_OSFULLNAME> - Linux:
/opt/seal
Literature
See also PLS_OSFULLNAME.
Do not change
The value is set during the installation process. It may not be changed afterwards.
DPFDATA¶
DPFDATA specifies the directory containing the DPF data and the job directories.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/DPFDATA
Available values: String
<directory>
Default: data\dpf
Do not change
The value is set during the installation process. It may not be changed afterwards.
DPFROOT¶
DPFROOT specifies the installation directory of the DPF system.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/DPFROOT
Available values: String
<directory>
Default:
- Windows:
C:\SEAL\applications\ - Linux:
/opt/seal
Do not change
The value is set during the installation process. It may not be changed afterwards.
DPFSRV¶
DPFSRV specifies the directory of the server components of the DPF system.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/DPFSRV
Available values: String
<directory>
Default: server\dpf
Do not change
The value is set during the installation process. It may not be changed afterwards.
ID_PROVIDER_CERT¶
ID_PROVIDER_CERT specifies the path and the file name of the certificate generated by the OIDC identity provider.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/ID_PROVIDER_CERT
Available values: String
<path_name>
Default: none
ID_PROVIDER_NAME¶
ID_PROVIDER_NAME specifies the name of the OIDC identity provider. When using more than one OIDC identity provider, separate their names by blanks.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/ID_PROVIDER_NAME
The key is mandatory.
Available values: String
-
<id_provider_name>(For example, with Keycloak, it is a complete URL:https://<hostname>:32769/realms/SEAL) -
<id_provider_name_1> <id_provider_name_2>(For example, with Keycloak, they are complete URLs:https://<cluster internal hostname>:32769/realms/SEAL https://<cluster external hostname>:32769/realms/SEAL)
Default: none
JWT_LOG_TOKEN¶
Logs the JSON web token payload in info level if set. If log level lower than info nothing is logged.
The key is available for the seal-dpf-jobclient-api service
In Consul, the key is specified here. If the key does not exist yet, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/JWT_LOG_TOKEN
Available values: Boolean
-
YThe token payload is logged.
-
NThe token payload is not logged.
Default: N
JWT_ROLES¶
JWT_ROLES specifies the property name set in the JSON Web Token (JWT) for accessing the user roles.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here:
dc/home/env/service/dpf-jobclient-api/tag/any/JWT_ROLES
Available values: String
<property_name>
Default: none
LOG_LEVEL¶
LOG_LEVEL specifies the log level for the correspondent service. Messages that correspond to this log level or a higher one are written to the log file.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
-
dc/home/env/service/any/tag/any/LOG_LEVELfor all services -
dc/home/env/service/<service>/tag/any/LOG_LEVELfor the specific<service>service
Available values: String
-
debugDebug messages and higher are written to the log file of the service.
-
infoInformation messages and higher are written to the log file of the service.
-
warnWarning messages and higher are written to the log file of the service.
-
errorError messages and higher are written to the log file of the service.
-
fatalSerious error messages are written to the log file of the service.
Default: info
Hint - job logs
To specify the log level for jobs, refer to LogLevel.
Hint - microservice environment
When the LOG_LEVEL for dpf-process-manager service is set to info, the first line of job.log states if the new microservice environment was used for the job.
MAX_INSTANCES¶
MAX_INSTANCES specifies the service wide maximum number of parallel job executions.
The key is available for the seal-dpf-wusystemcall, seal-dpf-wujavacall4, seal-dpf-wu-manager-rest, seal-dpf-wusendback and seal-dpf-wustandard services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
-
dc/home/env/service/dpf-wusystemcall/tag/any/MAX_INSTANCES -
dc/home/env/service/dpf-wujavacall4/tag/any/MAX_INSTANCES -
dc/home/env/service/dpf-wu-manager-rest/tag/any/MAX_INSTANCES -
dc/home/env/service/dpf-wusendback/tag/any/MAX_INSTANCES -
dc/home/env/service/dpf-wustandard/tag/any/MAX_INSTANCES
Available values: Integer
<max_instances>
Default: 10
MONGO_CONNECT_RETRIES¶
MONGO_CONNECT_RETRIES specifies the number of attempts of a service to connect to the database.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/MONGO_CONNECT_RETRIES
Available values: Integer
<number_retries>
Default: 10
MONGO_DPF_URL¶
MONGO_JOBS_URL specifies the URL of the database where the DPF jobs are storaged.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/MONGO_DPF_URL
Available values: String
-
mongodb://<server>:<port>/dpffor a single MongoDB server -
mongodb://<server1>,<server2,<server3>/dpf?replicaSet=<replica_set>for MongoDB in the cluster mode
Default: mongodb://localhost:27017/dpf
MONGO_LOCKS_AGE¶
MONGO_LOCKS_AGE specifies the time interval after which a lock is regarded as outdated and deleted from the database. A quarter of MONGO_LOCKS_AGE is used as lock-update interval by all services. The time interval has to be specified including the unit. For the available units, refer to Units at the top of the page.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/MONGO_LOCKS_AGE
Available values: String
<time_interval_and_unit>
Default: 1m
MONGO_LOCKS_INTERVAL¶
MONGO_LOCKS_INTERVAL specifies the time interval after which the ages of the locks are checked. The time interval has to be specified including the unit. For the available units, refer to Units at the top of the page.
The key is available for the seal-dpf-process-manager and seal-dpf-jobcleaner services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
-
dc/home/env/service/dpf-process-manager/tag/any/MONGO_LOCKS_INTERVAL -
dc/home/env/service/dpf-jobcleaner/tag/any/MONGO_LOCKS_INTERVAL
Available values: String
<time_interval_and_unit>
Default: 5s
PERLLIB¶
PERLLIB specifies the directory of the Perl library.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/PERLLIB
Available values: String
<directory>
Default: none
PLS_OSFULLNAME¶
PLS_OSFULLNAME specifies the name of the operating system used for accessing the platform-specific files.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/PLS_OSFULLNAME
Available values: String
-
winnt5Windows Server
-
linux223Linux Server
-
<operating system>
Default: none
Do not change
The value is set during the installation process. It may not be changed afterwards.
PLSROOT¶
PLSROOT specifies the installation directory.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/PLSROOT
Available values: String
<directory>
Default:
- Windows:
C:\SEAL\applications\ - Linux:
/opt/seal/
Do not change
The value is set during the installation process. It may not be changed afterwards.
PLSDATA¶
PLSDATA specifies the directory of the data area.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/PLSDATA
Available values: String
<directory>
Default: data
Do not change
The value is set during the installation process. It may not be changed afterwards.
PLSTBIN¶
PLSTBIN specifies the directory containing the binaries of the tools.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/PLSTBIN
Available values: String
<directory>
Default: tools\bin_<PLS_OSFULLNAME>
Literature
See also PLS_OSFULLNAME.
Do not change
The value is set during the installation process. It may not be changed afterwards.
RESTWU_URL_ORIGIN¶
RESTWU_URL_ORIGIN specifies the base URL for the REST working unit service connection.
The key is available for the any service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/RESTWU_URL_ORIGIN
Available values: String
<restwu_url>
Default: https://localhost:9126
S3_ACCESS_KEY_ID¶
S3_ACCESS_KEY_ID specifies the access key ID for uploading files to S3. The value can be overwritten by the accessKeyId input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_ACCESS_KEY_ID
Available values: String
<accessKeyId>
Default: none
S3_BASE_DIR_TEMPLATE¶
S3_BASE_DIR_TEMPLATE specifies a template for the job directory name on S3, with placeholders for RLI parameters. The value can be overwritten by the baseDirTemplate input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_BASE_DIR_TEMPLATE
Available values: String
<baseDirTemplate>
Default: original job directory
S3_BUCKET¶
S3_BUCKET specifies the S3 bucket for uploading files. The value can be overwritten by the bucket input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_BUCKET
Available values: String
<bucket>
Default: none
S3_ENDPOINT¶
S3_ENDPOINT specifies the URL of the S3 endpoint. Only needed for an S3-compatible service that is not accessible via AWS's default per-region endpoints, for example MinIO. The value can be overwritten by the endpoint input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_ENDPOINT
Available values: String
<endpoint>
Default: none
S3_FILE_NAME_TEMPLATE¶
S3_FILE_NAME_TEMPLATE specifies a template for target file names on S3, with placeholders for RLI item parameters. The value can be overwritten by the fileNameTemplate input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_FILE_NAME_TEMPLATE
Available values: String
<fileNameTemplate>
Default: original file names
S3_METADATA_KEYS¶
S3_METADATA_KEYS specifies RLI item metadata keys, separated with commas, for filtering S3 object metadata. S3 has a fixed limit of 2 KB metadata for each uploaded file. By default, every metadata key of an RLI item is uploaded as S3 object metadata; if this exceeds the size limit, only the specified keys are uploaded, reducing them further if still necessary. The value can be overwritten by the metadataKeys input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_METADATA_KEYS
Available values: String
<metadataKeys>
Default: none
S3_REGION¶
S3_REGION specifies the S3 region for uploading files. The value can be overwritten by the region input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_REGION
Available values: String
<region>
Default: eu-central-1
S3_SECRET_ACCESS_KEY¶
S3_SECRET_ACCESS_KEY specifies the secret access key for uploading files to S3. The value can be overwritten by the secretAccessKey input parameter of the s3.copyFromRli working unit. This key is only used by Output Files to an S3 Bucket.
The key is available for the seal-dpf-wustandard service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-wustandard/tag/any/S3_SECRET_ACCESS_KEY
Available values: String
<secretAccessKey>
Default: none
SAPNWRFCINI_PATH¶
SAPNWRFCINI_PATH specifies the directory where the SAP configuration file sapnwrfc.ini is stored. The key has to be set if notifications are to be returned to the requesting SAP Systems.
The key is available for the seal-dpf-sap-connect service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-sap-connect/tag/any/SAPNWRFCINI_PATH
Available values: String
<path>
Default:
-
Windows:
C:/ProgramData/SEAL Systems/PLOSSYS/config -
Linux:
/opt/seal/etc
SAP_SYSTEMS¶
SAP_SYSTEMS specifies a list of SAP communication arrangements (CA) for accesing the SAP oData Print API. The communication arrangements may either be specified in JSON or YAML format.
The key is available for the following services:
-
seal-dpf-workingunit-hdm-checkin -
seal-dpf-sap-connect
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
-
dc/home/env/service/dpf-workingunit-hdm-checkin/tag/any/SAP_SYSTEMS -
dc/home/env/service/dpf-sap-connect/tag/any/SAP_SYSTEMS
Instead of setting the key for each service, it can also be specified here once and for all:
dc/home/env/service/any/tag/any/SAP_SYSTEMS
Available values: String
<List of Systems>
Default: none
Example of SAP_SYSTEMS in YAML format
SAP_SYSTEMS: |
- systemId: ID1
user: 'UserForCheckin'
password: 'encryptedPW'
srvHostPort: 'SapUrl:PortOfHDMinterface'
- systemId: ID2
user: 'UserForCheckin'
password: 'encryptedPW'
srvHostPort: 'SapUrl:PortOfHDMinterface'
-
systemId: mandatory, 3 characters SAP system id, used for logging and communication scenario467. -
systemName: optional, description of the SAP system, replacessystemIdfor logging. -
loginMethod: optional, method to use for login, possible values arebasic,csrf,oauth, default iscsrf. -
user: mandatory forbasic,csrfSAP technical user name. -
password: mandatory forbasic,csrfSAP technical user password. -
srvHostPort: optional, host and port of SAP service in URL format, default ishttps://localhost:50001. -
srvPath: optional, path to SAP Cloud Print service, default is/sap/opu/odata/sap/API_CLOUD_PRINT_PULL_SRV. -
icmInterval: optional, interval for polling SAP ICM cache, default is5s. -
maxItems: optional, maximum number of items to fetch from SAP when transfer type ismulti, default is150. -
waitAfterFetchError: optional, time to wait after fetch error, default is5s. -
authClientId: mandatory foroauth, OAuth client id. -
authClientSecret: mandatory foroauth, OAuth client secret. -
authIssuerUrl: optional, URL to OAuth service, default is${srvHostPort}/oauth/token. -
itemTransfer: optional, method for transfering document items, possible valuessingleandmulti. Default ismulti. -
saveJSON: optional, iftruesave original JSON document object from SAP as temporary file in the database for debugging purposes. Default isfalse. -
notifyTransfer: optional, method for transfering document status notifications, possible valuessingleandmulti. Default is the value fromitemTransfer. -
mappings: optional, list of mappings for SAP printer names to OMS printer names. Every entry consists of an object with two properties:-
sap: mandatory, SAP printer name. -
pls: mandatory, OMS printer name.
-
SEAL_CUSTOMDIR¶
SEAL_CUSTOMDIR specifies the directory containing the customer specific files for the products from SEAL Systems.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/any/tag/any/SEAL_CUSTOMDIR
Available values: String
<directory>
Default:
-
none
No customer specific files are searched or evaluated.
Do not change
The value is set during the installation process. It may not be changed afterwards.
SECRET¶
SECRET specifies the secret used to decrypt the passwords for all SAP communication arrangements. The key can be created using the createPwdSecret command of DPF CLI.
If neither SECRET nor SECRET_FILE is set, the passwords are assumed to be stored in plain text.
The key is available for the following services:
-
seal-dpf-workingunit-hdm-checkin -
seal-dpf-workingunit-odata-notify
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
-
dc/home/env/service/dpf-workingunit-hdm-checkin/tag/any/SECRET -
dc/home/env/service/dpf-workingunit-odata-notify/tag/any/SECRET
Instead of setting the key for each service, it can also be specified here once and for all:
dc/home/env/service/any/tag/any/SECRET
Available values: String
Default: none
SECRET_FILE¶
SECRET_FILE specifies the path and name of a JSON formatted file containing the secret used to decrypt the passwords for all SAP communication arrangements. The file must contain a JSON object with a single property named pwdSecret with the secret as value. The key can be created using the createPwdSecret command of DPF CLI.
If neither SECRET nor SECRET_FILE is set, the passwords are assumed to be stored in plain text.
Example:
{
"pwdSecret": "bbb863a84c5a436ba8398216994ddcb6"
}
The key is available for the following services:
-
seal-dpf-workingunit-hdm-checkin -
seal-dpf-workingunit-odata-notify
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
-
dc/home/env/service/dpf-workingunit-hdm-checkin/tag/any/SECRET_FILE -
dc/home/env/service/dpf-workingunit-odata-notify/tag/any/SECRET_FILE
Instead of setting the key for each service, it can also be specified here once and for all:
dc/home/env/service/any/tag/any/SECRET_FILE
Available values: String
Default: none
SERVICE_URL¶
SERVICE_URL specifies how a service can be accessed.
The key is available for all services.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/<service>/tag/any/SERVICE_URL
Available values: String
<service_url>
Default: The server name is determined when a service is started and the default port is used. The correspondent assignment is described in Used Ports.
TRACKER_URL¶
TRACKER_URL specifies a URL through which the DPF tracker UI can be reached by a client.
The key is available for the seal-dpf-jobclient-api service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-jobclient-api/tag/any/TRACKER_URL
Available values: String
<tracker_url>
Default: http://localhost:4343
USE_ACCOUNTING_SERVICE¶
USE_ACCOUNTING_SERVICE specifies if the accounting log files are to be written by seal-dpf-process-manager or seal-dpf-accounting service. In cluster mode, you have to set it to true.
The key is available for the seal-dpf-process-manager service.
In Consul, the key is specified here. If the key does not yet exist, you have to create it:
dc/home/env/service/dpf-process-manager/tag/any/USE_ACCOUNTING_SERVICE
Available values: Boolean
-
falseseal-dpf-process-managerservice is writing theaccounting.logas known for DPF 3.x.x. -
trueseal-dpf-accountingservice is writing cluster compliant service log files namedseal-dpf-accounting.log.
Default: false