- 入门指南
- 要求
- 最佳实践
- 安装
- 正在更新
- 身份服务器
- 对启动错误进行故障排除
运行 Publish-IdentityServer.ps1 脚本,以对 Identity Server 进行初始部署或更新。
发布到身份服务器
下表介绍了可与 Publish-IdentityServer.ps1 脚本一起使用的所有参数。
| 参数 | 描述 |
|---|---|
|
| Mandatory. Indicates the type of scenario you want to start. 可用的选项如下:
|
|
| Mandatory. The Azure service principal ID. Please note that the used service principal needs to be assigned the Contributor role to the app service at the subscription scope. |
|
| Mandatory. The Azure token password for the service principal ID. |
|
| Mandatory. The Azure subscription ID for the App Service that hosts Orchestrator. |
|
| Mandatory. The Azure tenant ID. |
|
| 必需。Orchestrator 实例的 URL。 |
|
| 必填。Identity Server 的 URL。 /identity in lowercase.
示例: |
|
| 必填。资源的 URL 目录。 |
|
| 此参数是包含以下值的哈希表:
|
|
| 此参数是包含以下值的哈希表:
|
|
| 必填。指示 UiPath.IdentityServer.Web.zip 存档的完整路径或相对路径。 |
|
| 必填。指示 UiPath.IdentityServer.Migrator.Cli.zip 存档的完整路径或相对路径。 |
|
| 可选。 只有当身份服务器应用程序服务部署槽不同于 Azure 设置的默认生产应用程序服务槽时,才能使用它。 |
|
| 可选。如果存在,它会在部署之前停止应用程序,并在部署完成后启动应用程序。 |
|
| 可选。 如果存在,则部署将继续,无需任何用户确认。 |
|
| 可选。启用下载和解压缩所需文件的目录的规范。 |
|
| Optional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal.
If this parameter is used, the |
Publish-IdentityServer.ps1 脚本用于身份服务器的初始部署或更新。该脚本假定网页应用程序已配置 DefaultConnection 数据库连接字符串。
.\Publish-IdentityServer.ps1 `
-action Deploy `
-orchestratorUrl "<orchestrator_address>" `
-identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
-resourceCatalogUrl "<resource_catalog_address>" `
-orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-azureSubscriptionId "<subscription_id>" `
-azureAccountTenantId "<azure_tenant_id>" `
-azureAccountApplicationId "<azure_application_id>" `
-azureAccountPassword "<azure_account_password>" `
-package "UiPath.IdentityServer.Web.zip" `
-cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
-stopApplicationBeforePublish `
-unattended
.\Publish-IdentityServer.ps1 `
-action Deploy `
-orchestratorUrl "<orchestrator_address>" `
-identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
-resourceCatalogUrl "<resource_catalog_address>" `
-orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-azureSubscriptionId "<subscription_id>" `
-azureAccountTenantId "<azure_tenant_id>" `
-azureAccountApplicationId "<azure_application_id>" `
-azureAccountPassword "<azure_account_password>" `
-package "UiPath.IdentityServer.Web.zip" `
-cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
-stopApplicationBeforePublish `
-unattended
运行上述脚本后,请确保执行下面列出的额外步骤,以成功进行初始部署。
发布身份服务器后,执行以下步骤:
- 转到 Azure 门户。
- 选择您的身份服务器应用程序服务。
- 在“证书”菜单中,转到“自带证书”。
- 上传具备有效密码的
.pfx私钥证书。备注:此证书用于对访问令牌和 ID 令牌进行签名。
- 在“配置”菜单下,按照“应用程序设置”列中写入的内容准确添加以下应用程序设置:
|
应用程序设置 |
值 |
描述 |
|---|---|---|
|
|
https://[identity_server]/identity |
身份服务器的公共 URL。 |
|
|
当前用户 |
这必须指向当前用户。 |
|
|
XXXXXXXXXXXXXXXXXXXXXXXXXXXX |
之前上传的证书的指纹。 |
|
|
|
Enter
|
|
|
|
The connection string needed to set up your Redis server, which contains the URL of the server, the password, and the port. You can also enable SSL encrypted connections between the Orchestrator nodes and the Redis service. |
|
|
秒数 |
The sliding expiration time of an item inside the cache. This expiration time applies to both Redis Cache and InMemory Cache. |
|
|
|
将其值设置为
This helps prevent performance issues when using Interactive Sign In to connect a large number of robots in a short amount of time. This cache uses the same Redis connection string specified in the |
|
|
|
Set its value to true to enable Redis caching for first-party clients (UiPath applications) or third-party clients (external applications). If you have a large-scale deployment, it is recommended to enable this flag. |
|
|
|
对于通过 Azure 网页应用进行的 Orchestrator 部署,此参数必须设置为
This is because SAML2 requires certificates to be added to its trust store, but Azure web apps do not allow this action. Setting the value to |
|
|
XXXXXXXXXXXXXXXXXXXXXXXXXXXX |
之前上传的证书的指纹值。 |
|
|
1 | 用户配置文件。 |
| 可选。此参数仅用于美国政府部署。 |
保存更改。
在 Microsoft Azure 文档中查找更多详细信息。
替换私钥证书
当您将私钥证书替换为新证书时,请确保按照以下步骤操作:
- 将
AppSettings__SigningCredentialSettings__StoreLocation__Name和WEBSITE_LOAD_CERTIFICATES参数的值替换为新证书的指纹。 - 重新启动身份应用程序服务。
- 重新启动 Orchestrator 应用程序服务。
迁移到身份服务器
下表介绍了可与 MigrateTo-IdentityServer.ps1一起使用的所有参数。
| 参数 | 描述 |
|---|---|
|
| Mandatory .
指示 |
|
| 此参数是包含以下值的哈希表:
|
|
| 此参数是包含以下值的哈希表:
|
|
| 此参数是包含以下值的哈希表:
|
|
| 必填。Identity Server 的公共地址。 /identity in lowercase.
示例: |
|
| 必填。Orchestrator 的公共地址。 |
|
| 可选。启用下载和解压缩所需文件的目录的规范。 |
|
| 仅对全新部署为必需,当-action is set to Deploy .
Specify a custom password for the host administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit. |
|
| Optional. Enables you to enforce a password reset on the first login for the host administrator. If this parameter is omitted, the host admin password is not a one-time password. |
|
| 仅对全新部署为必需,当-action is set to Deploy .
Specify a custom password for the default tenant administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit. |
|
| Optional. Enables you to enforce a password reset on the first login for the default tenant administrator. If this parameter is omitted, the tenant admin password is not a one-time password. |
|
| Optional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal.
If this parameter is used, the |
MigrateTo-IdentityServer.ps1 脚本用于将用户数据从 Orchestrator 迁移到 Identity Server,并为两者设置好配置。它将 Orchestrator 的身份授权设置到 Identity Server,并在 Identity Server 中为 Orchestrator 创建客户端配置。
该脚本假定 Orchestrator 和身份服务器已发布。
.\MigrateTo-IdentityServer.ps1 `
-cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
-azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } `
-orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
-orchestratorUrl "https://<OrchestratorURL>" `
-hostAdminPassword "12345qwert" `
-defaultTenantAdminPassword "12345qwert"
.\MigrateTo-IdentityServer.ps1 `
-cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
-azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } `
-orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
-orchestratorUrl "https://<OrchestratorURL>" `
-hostAdminPassword "12345qwert" `
-defaultTenantAdminPassword "12345qwert"