UiPath Documentation
orchestrator
2025.10
true
Orchestrator インストール ガイド
重要 :
このコンテンツの一部は機械翻訳によって処理されており、完全な翻訳を保証するものではありません。 新しいコンテンツの翻訳は、およそ 1 ~ 2 週間で公開されます。

Identity Server のスクリプト

Publish-IdentityServer.ps1 スクリプトを実行して、Identity Server の初期デプロイまたは更新を行います

Identity Server にパブリッシュする

次の表で、Publish-IdentityServer.ps1 スクリプトで使用できるすべてのパラメーターについて説明します。

パラメーター

説明

-action

Mandatory. Indicates the type of scenario you want to start.

次のオプションを使用できます。

  • Deploy - クリーン インストールとして指定します。
  • Update - Identity Server インスタンスを更新中であることを指定します。

-azureAccountApplicationId

Mandatory. The Azure service principal ID.

Please note that the used service principal needs to be assigned the Contributor role to the app service at the subscription scope.

-azureAccountPassword

必須。サービス プリンシパル ID の Azure トークン パスワード。

-azureSubscriptionId

必須。Orchestrator をホストする App Service の Azure サブスクリプション ID。

-azureAccountTenantId

必須。Azure テナント ID。

-orchestratorUrl

必須です。Orchestrator インスタンスの URL です。

-identityServerUrl

必須。Identity Server の URL です。

Important: The URL must contain the Identity Server address + the suffix /identity in lowercase.

例: https://[identity_server]/identity

-resourceCatalogUrl

必須。リソースの URL です。

カタログ。

-orchDetails

このパラメーターは以下の値を含むハッシュ テーブルです。

  • resourceGroupName - 必須です。Orchestrator の App Service を含む Azure リソース グループの名前。
  • appServiceName - 必須です。Orchestrator の Azure App Service の名前。
  • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

-identityServerDetails

このパラメーターは以下の値を含むハッシュ テーブルです。

  • resourceGroupName - 必須です。Identity Server の App Service を含む Azure リソース グループの名前。
  • appServiceName - 必須です。Identity Server の Azure App Service の名前。
  • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

-package

必須。UiPath.IdentityServer.Web.zip アーカイブのフル パスまたは相対パスを指定します。

-cliPackage

必須。UiPath.IdentityServer.Migrator.Cli.zip アーカイブのフル パスまたは相対パスを指定します。

-productionSlotName

任意です。Identity Server の App Service のデプロイ スロットが Azure で設定される既定の運用環境 App Service スロットと異なる場合にのみ使用できます。

-stopApplicationBeforePublish

任意です。存在する場合は、アプリケーションをデプロイ前に停止し、デプロイの完了後に起動します。

-unattended

任意です。存在する場合は、ユーザーの確認なしにデプロイが続行されます。

-tmpDirectory

任意です。必要なファイルをダウンロードおよび解凍するディレクトリの指定を有効化します。

-noAzureAuthentication

Optional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal.

If this parameter is used, the UseServicePrincipal parameter set (which includes items such as the Azure application ID, password, subscription ID, and tenant ID) are no longer necessary.

Publish-IdentityServer.ps1 スクリプトが初期デプロイまたは Identity Server の更新に使用されます。このスクリプトは、Web アプリで既にデータベースの接続文字列 DefaultConnection を設定済みであることを前提としています。

.\Publish-IdentityServer.ps1 `
    -action Deploy `
    -orchestratorUrl "<orchestrator_address>" `
    -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
    -resourceCatalogUrl "<resource_catalog_address>" `
    -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
    -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
    -azureSubscriptionId "<subscription_id>" `
    -azureAccountTenantId "<azure_tenant_id>" `
    -azureAccountApplicationId "<azure_application_id>" `
    -azureAccountPassword "<azure_account_password>" `
    -package "UiPath.IdentityServer.Web.zip" `
    -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
    -stopApplicationBeforePublish `
    -unattended
.\Publish-IdentityServer.ps1 `
    -action Deploy `
    -orchestratorUrl "<orchestrator_address>" `
    -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
    -resourceCatalogUrl "<resource_catalog_address>" `
    -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
    -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
    -azureSubscriptionId "<subscription_id>" `
    -azureAccountTenantId "<azure_tenant_id>" `
    -azureAccountApplicationId "<azure_application_id>" `
    -azureAccountPassword "<azure_account_password>" `
    -package "UiPath.IdentityServer.Web.zip" `
    -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
    -stopApplicationBeforePublish `
    -unattended
重要:

上記スクリプトの実行後、初期デプロイを成功させるために以下の追加手順を実行する必要があります。

Identity Server のパブリッシュ後に次の手順を実行します。

  1. Azure Portal に移動します。
  2. Identity Server の App Service を選択します。
  3. [証明書] メニューの [独自の証明書を利用する] に移動します。
  4. 有効なパスワードを持つ秘密キー証明書の .pfx ファイルをアップロードします。
注:

この証明書はアクセス トークンと ID トークンに署名するために使用されます。

  1. [構成] メニューで、以下のアプリケーションの設定を [アプリケーションの設定] 列に記載されているとおりに追加します。

    アプリケーション設定

    値 (Value)

    説明

    
       AppSettings__IdentityServerAddress
      
    
       AppSettings__IdentityServerAddress
      
    

    https://[identity_server]/identity

    Identity Server のパブリック URL。

    重要: URL には、Identity Server のアドレス + サフィックスが含まれている必要があります
    
      /identity
     
    
      /identity
     
    
    は小文字です。

    
       AppSettings__SigningCredentialSettings__StoreLocation__Location
      
    
       AppSettings__SigningCredentialSettings__StoreLocation__Location
      
    

    CurrentUser

    これは CurrentUser を指し示す必要があります。

    
       AppSettings__SigningCredentialSettings__StoreLocation__Name
      
    
       AppSettings__SigningCredentialSettings__StoreLocation__Name
      
    

    XXXXXXXXXXXXXXXXXXXXXXXXXXXX

    以前にアップロードした証明書の拇印です。

    
       AppSettings__SigningCredentialSettings__StoreLocation__NameType
      
    
       AppSettings__SigningCredentialSettings__StoreLocation__NameType
      
    

    
       Thumbprint
      
    
       Thumbprint
      
    

    Enter
    
      Thumbprint
     
    
      Thumbprint
     
    
    を前のフィールドの型として設定します。

    
       AppSettings__LoadBalancerSettings__RedisConnectionString
      
    
       AppSettings__LoadBalancerSettings__RedisConnectionString
      
    

    
       XXXXXXXXXXXX:XXXX,password=XXXXXX
      
    
       XXXXXXXXXXXX:XXXX,password=XXXXXX
      
    

    The connection string needed to set up your Redis server, which contains the URL of the server, the password, and the port.

    You can also enable SSL encrypted connections between the Orchestrator nodes and the Redis service.

    
          AppSettings__LoadBalancerSettings__SlidingExpirationTimeInSeconds
         
    
          AppSettings__LoadBalancerSettings__SlidingExpirationTimeInSeconds
         
    

    秒数

    The sliding expiration time of an item inside the cache.

    This expiration time applies to both Redis Cache and InMemory Cache.

    
          AppSettings__RedisSettings__UseRedisStoreCache
         
    
          AppSettings__RedisSettings__UseRedisStoreCache
         
    

    
         true
        
    
         true
        
    
    /
    
         false
        
    
         false
        
    
    この値を
    
         true
        
    
         true
        
    
    to enable Redis caching of OAuth client data.

    This helps prevent performance issues when using Interactive Sign In to connect a large number of robots in a short amount of time. This cache uses the same Redis connection string specified in the

    
    AppSettings__LoadBalancerSettings
    
    AppSettings__LoadBalancerSettings
    

    注: 外部アプリケーション 機能を使用している場合、この設定はクライアントをキャッシュし、外部アプリケーションへの更新は反映されないため、これは推奨されません。

    
          AppSettings__RedisSettings__UseRedisStoreClientCache
         
    
          AppSettings__RedisSettings__UseRedisStoreClientCache
         
    

    
         true
        
    
         true
        
    
    /
    
         false
        
    
         false
        
    

    Set its value to true to enable Redis caching for first-party clients (UiPath applications) or third-party clients (external applications).

    If you have a large-scale deployment, it is recommended to enable this flag.

    
          App__Saml2ValidCertificateOnly
         
    
          App__Saml2ValidCertificateOnly
         
    

    
         true
        
    
         true
        
    
    /
    
         false
        
    
         false
        
    
    Azure Web アプリ経由で Orchestrator をデプロイする場合、このパラメーターは
    
         false
        
    
         false
        
    
    .

    This is because SAML2 requires certificates to be added to its trust store, but Azure web apps do not allow this action. Setting the value to

    
    false
    
    false
    
    に設定すると、証明書の確認がバイパスされます。

    
          WEBSITE_LOAD_CERTIFICATES
         
    
          WEBSITE_LOAD_CERTIFICATES
         
    

    XXXXXXXXXXXXXXXXXXXXXXXXXXXX

    以前にアップロードした証明書の拇印の値です。

    
          WEBSITE_LOAD_USER_PROFILE
         
    
          WEBSITE_LOAD_USER_PROFILE
         
    

    1

    ユーザー プロファイル。
    
         -azureUSGovernmentLogin
        
    
         -azureUSGovernmentLogin
        
    
    任意です。このパラメーターは、米国政府機関のデプロイにのみ使用されます。  
    6.

    変更を保存します。

    詳細については、Microsoft Azure ドキュメントをご覧ください。

    秘密キーの証明書を置き換える

    秘密キーの証明書を新しい証明書に置き換える場合は、必ず次の手順に従ってください。

    1. AppSettings__SigningCredentialSettings__StoreLocation__Name パラメーターと WEBSITE_LOAD_CERTIFICATES パラメーターの値を、新しい証明書の拇印に置き換えます。
    2. Identity アプリ サービスを再起動します。
    3. Orchestrator アプリ サービスを再起動します。

    Identity Server へ移行する

    次の表で、MigrateTo-IdentityServer.ps1 で使用できる全パラメーターについて説明します。

    パラメーター

    説明

    -cliPackage

    Mandatory .

    UiPath.IdentityServer.Migrator.Cli.zip アーカイブのフル パスまたは相対パスを指定します。

    -azureDetails

    このパラメーターは以下の値を含むハッシュ テーブルです。

    • azureAccountApplicationId - Mandatory. The Azure service principal ID.

      Please note that the used service principal needs to be assigned the Contributor role to the app service at the subscription scope.

    • azureSubscriptionId - 必須です。Orchestrator をホストする App Service の Azure サブスクリプション ID。
    • azureAccountTenantId - 必須です。Azure テナント ID。
    • azureAccountPassword - 必須です。サービス プリンシパル ID の Azure トークン パスワード。

    -orchDetails

    このパラメーターは以下の値を含むハッシュ テーブルです。

    • resourceGroupName - 必須です。Orchestrator の App Service を含む Azure リソース グループの名前。
    • appServiceName - 必須です。Orchestrator の Azure App Service の名前。
    • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

    -identityServerDetails

    このパラメーターは以下の値を含むハッシュ テーブルです。

    • resourceGroupName - 必須です。Identity Server の App Service を含む Azure リソース グループの名前。
    • appServiceName - 必須です。Identity Server の Azure App Service の名前。
    • targetSlot - 必須です。Azure によって設定された App Service のターゲット スロット。

    -identityServerUrl

    必須。Identity Server のパブリック アドレス。

    Important: The URL must contain the address of Identity Server + the suffix /identity in lowercase.

    例: https://[identity_server]/identity

    -orchestratorUrl

    必須。Orchestrator のパブリック アドレス。

    -tmpDirectory

    任意です。必要なファイルをダウンロードおよび解凍するディレクトリの指定を有効化します。

    -hostAdminPassword

    Mandatory only for fresh deployments, when-action is set to Deploy .

    Specify a custom password for the host administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit.

    -isHostPassOneTime

    Optional. Enables you to enforce a password reset on the first login for the host administrator.

    If this parameter is omitted, the host admin password is not a one-time password.

    -defaultTenantAdminPassword

    Mandatory only for fresh deployments, when-action is set to Deploy .

    Specify a custom password for the default tenant administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit.

    -isDefaultTenantPassOneTime

    Optional. Enables you to enforce a password reset on the first login for the default tenant administrator.

    If this parameter is omitted, the tenant admin password is not a one-time password.

    -noAzureAuthentication

    Optional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal.

    If this parameter is used, the UseServicePrincipal parameter set (which includes items such as the Azure application ID, password, subscription ID, and tenant ID) are no longer necessary.

    MigrateTo-IdentityServer.ps1 スクリプトは、Orchestrator から Identity Server にユーザー データを移行し、その両方の設定を行うために使用します。このスクリプトは Identity Server に対して Orchestrator の ID 権限を設定し、Identity Server 内で Orchestrator のクライアント構成を作成します。

    このスクリプトは、Orchestrator と Identity Server が既にパブリッシュ済みであることを前提としています。

    .\MigrateTo-IdentityServer.ps1 `
        -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
        -azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } `
        -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
        -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
        -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
        -orchestratorUrl "https://<OrchestratorURL>" `
        -hostAdminPassword "12345qwert" `
        -defaultTenantAdminPassword "12345qwert"
    .\MigrateTo-IdentityServer.ps1 `
        -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
        -azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } `
        -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>";  targetSlot = "Production" } `
        -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
        -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
        -orchestratorUrl "https://<OrchestratorURL>" `
        -hostAdminPassword "12345qwert" `
        -defaultTenantAdminPassword "12345qwert"
    
  • Identity Server にパブリッシュする
  • 秘密キーの証明書を置き換える
  • Identity Server へ移行する

このページは役に立ちましたか?

接続

ヘルプ リソース サポート

学習する UiPath アカデミー

質問する UiPath フォーラム

最新情報を取得