- リリース ノート
- 要件
- インストール
- 基本情報
- プロジェクト
- データセット
- ML パッケージ
- パイプライン
- ML スキル
- ML ログ
- AI Fabric での Document Understanding
- 基本的なトラブルシューティング ガイド
443、8800、31443、31390
Recall from step 1. Provision a Machine, that you also need to allow port 6443 to be accessible from the ip of the cluster itself. Said differently, you can set network configuration rules to constraint IP source address on the rule for port 6443.
AI Fabric テナントをプロビジョニングする
-
Navigate to <linux-machine-ip or domain-name>:31390/ai-app, click on the three-dot menu on the top right, and click on
Log in -
ホスト テナントの管理者資格情報でログインします。ホスト テナントにログインしていることを確認します。既定は
defaultです。 -
ログインすると、アカウントに関連付けられたすべての Orchestrator テナントのリストが表示されます。1 列目は、そのテナントが AI Fabric でもプロビジョニングされているかどうかを示します。初回ログイン時には、すべてのテナントで AI Fabric に
Not Provisionedが表示されます。プロビジョニングするテナントの 3 点リーダー メニューをクリックし、つづいてProvisionをクリックします。数秒後に画面が更新され、テナントの表示が「プロビジョニング済み」になります。
アプリケーション証明書を信頼する
The application certificate needs to be trusted by the Machine where you will be using AI Fabric and the machine that will be using UiPath Robot/Studio. This step can be skipped if you used a trusted domain certificate in Step 5.
Navigate to <machine-ip or domain-name>:31390/ai-app. This step involves adding the application certificate to your trusted certificate store.
-
Google Chome で、アドレス バーにある南京錠アイコンをクリックします (ポート 31443 に対する処理を繰り返すと感嘆符のアイコンになります)。Chrome のバージョンによっては、一部の手順が表示されないことがあります。
-
Show connection details矢印をクリックします。 -
More Informationボタンをクリックします。 -
View CertificateボタンまたはCertificateボタンをクリックします。 -
上部のナビゲーションにある
Detailsタブをクリックします。 -
Copy to Fileボタンをクリックします。 -
[証明書のエクスポート ウィザード] に従って証明書をエクスポートし、後で利用しやすいパスに Base64 エンコード方式で保存します。
-
目的の証明書をダブルクリックし、
Install Certificateをクリックします。 -
証明書のストアの保存場所をローカル マシンに設定し、信頼されたルート証明機関のフォルダーに証明書を置きます。
重要:- 以下の証明書に対して、上記の手順を繰り返します。
- Orchestrator の証明書
- Certificate for <linux-machine-ip or domain-name))))>:31443
注:In this case, there will not be a padlock icon but rather an exclamation icon. The page will say "This XML file does not appear to have any style information associated with it..."
These instructions are from the perspective of a user with a simple networking setup adding certificates to their own local machine's Trusted Root Certificate Authorities. An IT admin can add these certificates to the company's Trusted Store so that users within an organization making use of that trusted store need not go through this process.
アプリケーションのインストールを検証する。
- Navigate to <linux-machine-ip or domain-name>:31390/ai-app, if you are still logged-in on the
hosttenant, use the 3-dot menu on the top-right corner to log out and log in on the tenant you just provisioned in Provisioning an AI Fabric Tenant. - If you see something like
Origin authentication failed, this is due to a rarely occurring problem with permissions. To work-around this, go to Orchestrator and create a new role. Give that role AI Fabric permissions (see About AI Fabric ) and your user to that role. Navigate back to AI Fabric (<linux-machine-ip or domain-name>:31390/ai-app), the issue should be resolved. - Follow the instructions in About Projects to quickly create a project, you can always delete this later.
- Follow the instructions in About Datasets to quickly create a Dataset. Uploading some files to the Dataset allows your to verify that the chain of trust has been established and that there are no issues the the underlying object store. If you have problems this most likely is due to a misconfigured certificate trust chain. Make sure that the three certificates in Trust the Application Certificate are in your trusted store.
- Follow the instructions in Out of the Box Packages to quickly deploy a machine learning model in your tenant. Due to the fact that some of the out-of-the-box packages are quite large and adding them to your account can fail due to connectivity issues, AI Fabric runs a periodic job that will synchronize the out-of-the-box packages of your account. If you do not have all the ones listed here, don't worry. The recurring synchronization job ensures that eventually your account will have all the models. If after a few days you still do not have all the models listed in Out of the Box Packages, contact UiPath Support.
ML スキル アクティビティが AI Fabric と通信可能であることを確認する
- UiPath Studio を使用してオートメーションを構築するマシンで UiPath Studio を開き、UiPath.MLServices.Activities パッケージをまだインストールしていない場合は、ここでインストールします。
- 空の RPA ワークフローを作成し、そこに ML スキル アクティビティを追加します。
- ML スキル アクティビティのドロップダウン矢印をクリックします。エラーが表示される場合は、Studio が AI Fabric バックエンドに安全に接続できないことを意味します。最も一般的なエラーは、
Could not establish trust relationship for the SSL/TLS secure channelです。このエラーの原因は、証明書信頼チェーンの設定の誤りです。「アプリケーション証明書を信頼する」での 3 つの証明書が信頼されたストアにあることを確認してください。
Orchestrator が AI Fabric と通信可能であるかどうかを確認する
このセッションは Orchestrator 20.4 でのみ有効です。20.10 以降のバージョンでは、[ML スキル] ページが Orchestrator から削除されています。
-
Orchestrator に移動します。
-
Click on the
ML Skillstab in the left navigation bar. If there is some misconfiguration, a red-error banner will appear at the top. - If there is an error, it was likely due to a misconfigured trust chain or the fact that Orchestrator cannot communicate with AI Fabric. Verify your network inbound and outbound rules. - If you open the "ML Skills tab" and you see a red banner with the message "An Error has occurred", please openEvent Viewerto see a more detailed message.
そのためには、Event Viewer アプリケーションを開きます。このアプリケーションは、Windows の検索機能で検索できます。
-
Windows logsを展開します。 -
Window LogsでApplicationをクリックします。
エラー: 拇印の値が一致しません
Event Viewer にメッセージ「UiPath.Orchestrator.AiFabric.AiFabricInternalException: AI Fabric への接続に失敗しました。エラー: IDX10638: Cannot create the SignatureProvider, 'key.HasPrivateKey' is false, cannot create signatures. Key: [PII is hidden.」が表示される場合は、以下のトラブルシューティングの手順を実行します。
-
IIS マネージャーに移動し、インストールで使用した Orchestrator 証明書を開きます。
-
Click on
Detailsand verify that the certificate thumbprint value exactly matches the thumprint values written in Orchestrator web.config (in step 3. Configure Orchestrator ).
Web.config の例:
...
<add key="IDP.CurrentTokenThumbprint" value="fb4e45797efd3d21021828617835d05920945091" />
<add key="IDP.PreviousTokenThumbprint" value="fb4e45797efd3d21021828617835d05920945091" />
...
...
<add key="IDP.CurrentTokenThumbprint" value="fb4e45797efd3d21021828617835d05920945091" />
<add key="IDP.PreviousTokenThumbprint" value="fb4e45797efd3d21021828617835d05920945091" />
...
エラー: キーセットが存在しません
Event Viewer にメッセージ「キーセットが存在しない」が表示される場合は、以下のトラブルシューティングの手順を実行します。
-
Orchestrator の Windows Server で
Runに移動し、mmc.exeと入力します。 -
[ファイル] ->
Add/Remove Snap-inをクリックします。 -
表示されるウィザードに
Certificatesを追加し、Okをクリックします。 -
表示されるウィザードでラジオ ボタン
Computer Accountを選択し、Nextをクリックします。 -
ウィザードの最後の画面でラジオ ボタン
Local computerを選択し、[完了] をクリックします。
証明書マネージャーを開きます。
-
Windows のプログラムの検索で、
Manager Computer Certificatesと入力します。 -
PersonalStore で Orchestrator 証明書を右クリックし、All TasksメニューのManage Private Keysをクリックします。 -
[追加] をクリックします。これで、新しいユーザーを権限リストに追加できます。
-
In the wizard that opens, Enter "IIS AppPool<AppPoolName>" replacing
<AppPoolName>with your Application Pool. For example: -
[OK] をクリックし、PowerShell から iisreset を実行します。
すぐに使える ML パッケージを確認する
すぐに使える ML パッケージ (Document Understanding が付属するパッケージ) のダウンロードとインストールに要する時間は、インターネットの帯域幅に応じて 45 分から 3 時間です。これらの ML パッケージをクラスターにアップロードするプロセスは、アプリケーションのインストーラーから独立して実行されます。