UiPath Documentation
orchestrator
2023.10
false
Orchestrator インストール ガイド
重要 :
このコンテンツの一部は機械翻訳によって処理されており、完全な翻訳を保証するものではありません。 新しいコンテンツの翻訳は、およそ 1 ~ 2 週間で公開されます。

Identity Server のスクリプト

Publish-IdentityServer.ps1 スクリプトを実行して、Identity Server の初期デプロイまたは更新を行います。

Identity Server にパブリッシュする

次の表で、Publish-IdentityServer.ps1 スクリプトで使用できるすべてのパラメーターについて説明します。

パラメーター

説明

-action

Mandatory. Indicates the type of scenario you want to start.

次のオプションを使用できます。

  • Deploy - クリーン インストールとして指定します。
  • Update - Identity Server インスタンスを更新中であることを指定します。

-azureAccountApplicationId

Mandatory. The Azure service principal ID.

Please note that the used service principal needs to be assigned the Contributor role to the app service at the subscription scope.

-azureAccountPassword

必須。サービス プリンシパル ID の Azure トークン パスワード。

-azureSubscriptionId

必須。Orchestrator をホストする App Service の Azure サブスクリプション ID。

-azureAccountTenantId

必須。Azure テナント ID。

-orchestratorUrl

必須です。Orchestrator インスタンスの URL です。

-identityServerUrl

必須。Identity Server の URL です。

Important: The URL must contain the Identity Server address + the suffix /identity in lowercase.

例: https://[identity_server]/identity

-resourceCatalogUrl

必須。リソースの URL です。

カタログ。

-orchDetails

このパラメーターは以下の値を含むハッシュ テーブルです。

  • resourceGroupName - 必須です。Orchestrator の App Service を含む Azure リソース グループの名前。
  • appServiceName - 必須です。Orchestrator の Azure App Service の名前。
  • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

-identityServerDetails

このパラメーターは以下の値を含むハッシュ テーブルです。

  • resourceGroupName - 必須です。Identity Server の App Service を含む Azure リソース グループの名前。
  • appServiceName - 必須です。Identity Server の Azure App Service の名前。
  • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

-package

必須。UiPath.IdentityServer.Web.zip アーカイブのフル パスまたは相対パスを指定します。

-cliPackage

必須。UiPath.IdentityServer.Migrator.Cli.zip アーカイブのフル パスまたは相対パスを指定します。

-productionSlotName

任意です。Identity Server の App Service のデプロイ スロットが Azure で設定される既定の運用環境 App Service スロットと異なる場合にのみ使用できます。

-stopApplicationBeforePublish

任意です。存在する場合は、アプリケーションをデプロイ前に停止し、デプロイの完了後に起動します。

-unattended

任意です。存在する場合は、ユーザーの確認なしにデプロイが続行されます。

-tmpDirectory

任意です。必要なファイルをダウンロードおよび解凍するディレクトリの指定を有効化します。

-noAzureAuthentication

Optional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal.

If this parameter is used, the UseServicePrincipal parameter set (which includes items such as the Azure application ID, password, subscription ID, and tenant ID) are no longer necessary.

Publish-IdentityServer.ps1 スクリプトが初期デプロイまたは Identity Server の更新に使用されます。このスクリプトは、Web アプリで既にデータベースの接続文字列 DefaultConnection を設定済みであることを前提としています。

.\Publish-IdentityServer.ps1 `
    -action Deploy `
    -orchestratorUrl "<orchestrator_address>" `
    -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
    -resourceCatalogUrl "<resource_catalog_address>" `
    -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
    -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
    -azureSubscriptionId "<subscription_id>" `
    -azureAccountTenantId "<azure_tenant_id>" `
    -azureAccountApplicationId "<azure_application_id>" `
    -azureAccountPassword "<azure_account_password>" `
    -package "UiPath.IdentityServer.Web.zip" `
    -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
    -stopApplicationBeforePublish `
    -unattended
.\Publish-IdentityServer.ps1 `
    -action Deploy `
    -orchestratorUrl "<orchestrator_address>" `
    -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
    -resourceCatalogUrl "<resource_catalog_address>" `
    -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
    -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
    -azureSubscriptionId "<subscription_id>" `
    -azureAccountTenantId "<azure_tenant_id>" `
    -azureAccountApplicationId "<azure_application_id>" `
    -azureAccountPassword "<azure_account_password>" `
    -package "UiPath.IdentityServer.Web.zip" `
    -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
    -stopApplicationBeforePublish `
    -unattended
重要:

上記スクリプトの実行後、初期デプロイを成功させるために以下の追加手順を実行する必要があります。

Identity Server のパブリッシュ後に次の手順を実行します。

  1. Azure Portal に移動します。
  2. Identity Server の App Service を選択します。
  3. [証明書] メニューの [独自の証明書を利用する] に移動します。
  4. 有効なパスワードを持つ秘密キー証明書の .pfx ファイルをアップロードします。
    注:

    この証明書はアクセス トークンと ID トークンに署名するために使用されます。

  5. [構成] メニューで、以下のアプリケーションの設定を [アプリケーションの設定] 列に記載されているとおりに追加します。

アプリケーション設定

値 (Value)

説明


      AppSettings__IdentityServerAddress
     

      AppSettings__IdentityServerAddress
     

https://[identity_server]/identity

Identity Server のパブリック URL。

重要: URL には、Identity Server のアドレス + サフィックスが含まれている必要があります

     /identity
    

     /identity
    
は小文字です。


      AppSettings__SigningCredentialSettings__StoreLocation__Location
     

      AppSettings__SigningCredentialSettings__StoreLocation__Location
     

CurrentUser

これは CurrentUser を指し示す必要があります。


      AppSettings__SigningCredentialSettings__StoreLocation__Name
     

      AppSettings__SigningCredentialSettings__StoreLocation__Name
     

XXXXXXXXXXXXXXXXXXXXXXXXXXXX

以前にアップロードした証明書の拇印です。


      AppSettings__SigningCredentialSettings__StoreLocation__NameType
     

      AppSettings__SigningCredentialSettings__StoreLocation__NameType
     


      Thumbprint
     

      Thumbprint
     

Enter

     Thumbprint
    

     Thumbprint
    
を前のフィールドの型として設定します。


      AppSettings__LoadBalancerSettings__RedisConnectionString
     

      AppSettings__LoadBalancerSettings__RedisConnectionString
     


      XXXXXXXXXXXX:XXXX,password=XXXXXX
     

      XXXXXXXXXXXX:XXXX,password=XXXXXX
     

The connection string needed to set up your Redis server, which contains the URL of the server, the password, and the port.

You can also enable SSL encrypted connections between the Orchestrator nodes and the Redis service.


      AppSettings__LoadBalancerSettings__SlidingExpirationTimeInSeconds
     

      AppSettings__LoadBalancerSettings__SlidingExpirationTimeInSeconds
     

秒数

The sliding expiration time of an item inside the cache.

This expiration time applies to both Redis Cache and InMemory Cache.


      AppSettings__RedisSettings__UseRedisStoreCache
     

      AppSettings__RedisSettings__UseRedisStoreCache
     


     true
    

     true
    
/

     false
    

     false
    
この値を

     true
    

     true
    
to enable Redis caching of OAuth client data.

This helps prevent performance issues when using Interactive Sign In to connect a large number of robots in a short amount of time. This cache uses the same Redis connection string specified in the


AppSettings__LoadBalancerSettings

AppSettings__LoadBalancerSettings
注: 外部アプリケーション 機能を使用している場合、この設定はクライアントをキャッシュし、外部アプリケーションへの更新は反映されないため、これは推奨されません。


      AppSettings__RedisSettings__UseRedisStoreClientCache
     

      AppSettings__RedisSettings__UseRedisStoreClientCache
     


     true
    

     true
    
/

     false
    

     false
    

Set its value to true to enable Redis caching for first-party clients (UiPath applications) or third-party clients (external applications).

If you have a large-scale deployment, it is recommended to enable this flag.


      App__Saml2ValidCertificateOnly
     

      App__Saml2ValidCertificateOnly
     


     true
    

     true
    
/

     false
    

     false
    
Azure Web アプリ経由で Orchestrator をデプロイする場合、このパラメーターは

     false
    

     false
    
.

This is because SAML2 requires certificates to be added to its trust store, but Azure web apps do not allow this action. Setting the value to


false

false
に設定すると、証明書の確認がバイパスされます。


      WEBSITE_LOAD_CERTIFICATES
     

      WEBSITE_LOAD_CERTIFICATES
     

XXXXXXXXXXXXXXXXXXXXXXXXXXXX

以前にアップロードした証明書の拇印の値です。


      WEBSITE_LOAD_USER_PROFILE
     

      WEBSITE_LOAD_USER_PROFILE
     

1

ユーザー プロファイル。

     -azureUSGovernmentLogin
    

     -azureUSGovernmentLogin
    
任意です。このパラメーターは、米国政府機関のデプロイにのみ使用されます。  
6.

変更を保存します。

詳細については、Microsoft Azure ドキュメントをご覧ください。

秘密キーの証明書を置き換える

秘密キーの証明書を新しい証明書に置き換える場合は、必ず次の手順に従ってください。

  1. AppSettings__SigningCredentialSettings__StoreLocation__Name パラメーターと WEBSITE_LOAD_CERTIFICATES パラメーターの値を、新しい証明書の拇印に置き換えます。
  2. Identity アプリ サービスを再起動します。
  3. Orchestrator アプリ サービスを再起動します。

Identity Server へ移行する

次の表で、MigrateTo-IdentityServer.ps1 で使用できる全パラメーターについて説明します。

パラメーター

説明

-cliPackage

Mandatory .

UiPath.IdentityServer.Migrator.Cli.zip アーカイブのフル パスまたは相対パスを指定します。

-azureDetails

このパラメーターは以下の値を含むハッシュ テーブルです。

  • azureAccountApplicationId - Mandatory. The Azure service principal ID.

    Please note that the used service principal needs to be assigned the Contributor role to the app service at the subscription scope.

  • azureSubscriptionId - 必須です。Orchestrator をホストする App Service の Azure サブスクリプション ID。
  • azureAccountTenantId - 必須です。Azure テナント ID。
  • azureAccountPassword - 必須です。サービス プリンシパル ID の Azure トークン パスワード。

-orchDetails

このパラメーターは以下の値を含むハッシュ テーブルです。

  • resourceGroupName - 必須です。Orchestrator の App Service を含む Azure リソース グループの名前。
  • appServiceName - 必須です。Orchestrator の Azure App Service の名前。
  • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

-identityServerDetails

このパラメーターは以下の値を含むハッシュ テーブルです。

  • resourceGroupName - 必須です。Identity Server の App Service を含む Azure リソース グループの名前。
  • appServiceName - 必須です。Identity Server の Azure App Service の名前。
  • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

-identityServerUrl

必須。Identity Server のパブリック アドレス。

Important: The URL must contain the address of Identity Server + the suffix /identity in lowercase.

例: https://[identity_server]/identity

-orchestratorUrl

必須。Orchestrator のパブリック アドレス。

-tmpDirectory

任意です。必要なファイルをダウンロードおよび解凍するディレクトリの指定を有効化します。

-hostAdminPassword

新規デプロイの場合のみ必須。-action is set to Deploy .

Specify a custom password for the host administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit.

-isHostPassOneTime

Optional. Enables you to enforce a password reset on the first login for the host administrator.

If this parameter is omitted, the host admin password is not a one-time password.

-defaultTenantAdminPassword

新規デプロイの場合のみ必須。-action is set to Deploy .

Specify a custom password for the default tenant administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit.

-isDefaultTenantPassOneTime

Optional. Enables you to enforce a password reset on the first login for the default tenant administrator.

If this parameter is omitted, the tenant admin password is not a one-time password.

-noAzureAuthentication

Optional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal.

If this parameter is used, the UseServicePrincipal parameter set (which includes items such as the Azure application ID, password, subscription ID, and tenant ID) are no longer necessary.

MigrateTo-IdentityServer.ps1 スクリプトは、Orchestrator から Identity Server にユーザー データを移行し、その両方の設定を行うために使用します。このスクリプトは Identity Server に対して Orchestrator の ID 権限を設定し、Identity Server 内で Orchestrator のクライアント構成を作成します。

このスクリプトは、Orchestrator と Identity Server が既にパブリッシュ済みであることを前提としています。

.\MigrateTo-IdentityServer.ps1 `
    -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
    -azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } `
    -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
    -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
    -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
    -orchestratorUrl "https://<OrchestratorURL>" `
    -hostAdminPassword "12345qwert" `
    -defaultTenantAdminPassword "12345qwert"
.\MigrateTo-IdentityServer.ps1 `
    -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
    -azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } `
    -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
    -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
    -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
    -orchestratorUrl "https://<OrchestratorURL>" `
    -hostAdminPassword "12345qwert" `
    -defaultTenantAdminPassword "12345qwert"
  • Identity Server にパブリッシュする
  • 秘密キーの証明書を置き換える
  • Identity Server へ移行する

このページは役に立ちましたか?

接続

ヘルプ リソース サポート

学習する UiPath アカデミー

質問する UiPath フォーラム

最新情報を取得