- 入门指南
- 要求
- 最佳实践
- 安装
- 正在更新
- 身份服务器
- 对启动错误进行故障排除
运行 Publish-IdentityServer.ps1 脚本,以对 Identity Server 进行初始部署或更新
发布到身份服务器
下表介绍了可与 Publish-IdentityServer.ps1 脚本一起使用的所有参数。
| 参数 | 描述 |
|---|---|
|
| Mandatory. Indicates the type of scenario you want to start. 可用的选项如下:
|
|
| Mandatory. The Azure service principal ID. Please note that the used service principal needs to be assigned the Contributor role to the app service at the subscription scope. |
|
| Mandatory. The Azure token password for the service principal ID. |
|
| Mandatory. The Azure subscription ID for the App Service that hosts Orchestrator. |
|
| Mandatory. The Azure tenant ID. |
|
| 必需。Orchestrator 实例的 URL。 |
|
| 必填。Identity Server 的 URL。 /identity in lowercase.
示例: |
|
| 必填。资源的 URL 目录。 |
|
| 此参数是包含以下值的哈希表:
|
|
| 此参数是包含以下值的哈希表:
|
|
| 必填。指示 UiPath.IdentityServer.Web.zip 存档的完整路径或相对路径。 |
|
| 必填。指示 UiPath.IdentityServer.Migrator.Cli.zip 存档的完整路径或相对路径。 |
|
| 可选。 只有当身份服务器应用程序服务部署槽不同于 Azure 设置的默认生产应用程序服务槽时,才能使用它。 |
|
| 可选。如果存在,它会在部署之前停止应用程序,并在部署完成后启动应用程序。 |
|
| 可选。 如果存在,则部署将继续,无需任何用户确认。 |
|
| 可选。启用下载和解压缩所需文件的目录的规范。 |
|
| Optional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal.
If this parameter is used, the |
Publish-IdentityServer.ps1 脚本用于身份服务器的初始部署或更新。该脚本假定网页应用程序已配置 DefaultConnection 数据库连接字符串。
.\Publish-IdentityServer.ps1 `
-action Deploy `
-orchestratorUrl "<orchestrator_address>" `
-identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
-resourceCatalogUrl "<resource_catalog_address>" `
-orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-azureSubscriptionId "<subscription_id>" `
-azureAccountTenantId "<azure_tenant_id>" `
-azureAccountApplicationId "<azure_application_id>" `
-azureAccountPassword "<azure_account_password>" `
-package "UiPath.IdentityServer.Web.zip" `
-cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
-stopApplicationBeforePublish `
-unattended
.\Publish-IdentityServer.ps1 `
-action Deploy `
-orchestratorUrl "<orchestrator_address>" `
-identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase
-resourceCatalogUrl "<resource_catalog_address>" `
-orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } `
-azureSubscriptionId "<subscription_id>" `
-azureAccountTenantId "<azure_tenant_id>" `
-azureAccountApplicationId "<azure_application_id>" `
-azureAccountPassword "<azure_account_password>" `
-package "UiPath.IdentityServer.Web.zip" `
-cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" `
-stopApplicationBeforePublish `
-unattended
运行上述脚本后,请确保执行下面列出的额外步骤,以成功进行初始部署。
发布身份服务器后,执行以下步骤:
- 转到 Azure 门户。
- 选择您的身份服务器应用程序服务。
- 在“证书”菜单中,转到“自带证书”。
- 上传具备有效密码的
.pfx私钥证书。
此证书用于对访问令牌和 ID 令牌进行签名。
-
在“配置”菜单下,按照“应用程序设置”列中写入的内容准确添加以下应用程序设置:
6.应用程序设置
值
描述
AppSettings__IdentityServerAddressAppSettings__IdentityServerAddresshttps://[identity_server]/identity
重要提示:URL 必须包含 Identity Server 的地址 + 后缀身份服务器的公共 URL。
小写。/identity/identityAppSettings__SigningCredentialSettings__StoreLocation__LocationAppSettings__SigningCredentialSettings__StoreLocation__Location当前用户
这必须指向当前用户。
AppSettings__SigningCredentialSettings__StoreLocation__NameAppSettings__SigningCredentialSettings__StoreLocation__NameXXXXXXXXXXXXXXXXXXXXXXXXXXXX
之前上传的证书的指纹。
AppSettings__SigningCredentialSettings__StoreLocation__NameTypeAppSettings__SigningCredentialSettings__StoreLocation__NameTypeThumbprintThumbprintEnter 作为上一字段的类型。ThumbprintThumbprintAppSettings__LoadBalancerSettings__RedisConnectionStringAppSettings__LoadBalancerSettings__RedisConnectionStringXXXXXXXXXXXX:XXXX,password=XXXXXXXXXXXXXXXXXX:XXXX,password=XXXXXXThe connection string needed to set up your Redis server, which contains the URL of the server, the password, and the port.
You can also enable SSL encrypted connections between the Orchestrator nodes and the Redis service.
AppSettings__LoadBalancerSettings__SlidingExpirationTimeInSecondsAppSettings__LoadBalancerSettings__SlidingExpirationTimeInSeconds秒数
The sliding expiration time of an item inside the cache.
This expiration time applies to both Redis Cache and InMemory Cache.
AppSettings__RedisSettings__UseRedisStoreCacheAppSettings__RedisSettings__UseRedisStoreCache/truetruefalsefalse将其值设置为 to enable Redis caching of OAuth client data.truetrueThis helps prevent performance issues when using Interactive Sign In to connect a large number of robots in a short amount of time. This cache uses the same Redis connection string specified in the
注意:如果您使用外部应用程序功能,则不建议这样做,因为此设置将缓存客户端,并且不会反映对外部应用程序的更新。AppSettings__LoadBalancerSettingsAppSettings__LoadBalancerSettingsAppSettings__RedisSettings__UseRedisStoreClientCacheAppSettings__RedisSettings__UseRedisStoreClientCache/truetruefalsefalseSet its value to true to enable Redis caching for first-party clients (UiPath applications) or third-party clients (external applications).
If you have a large-scale deployment, it is recommended to enable this flag.
App__Saml2ValidCertificateOnlyApp__Saml2ValidCertificateOnly/truetruefalsefalse对于通过 Azure 网页应用进行的 Orchestrator 部署,此参数必须设置为 。falsefalseThis is because SAML2 requires certificates to be added to its trust store, but Azure web apps do not allow this action. Setting the value to
意味着绕过证书检查。falsefalseWEBSITE_LOAD_CERTIFICATESWEBSITE_LOAD_CERTIFICATESXXXXXXXXXXXXXXXXXXXXXXXXXXXX
之前上传的证书的指纹值。
WEBSITE_LOAD_USER_PROFILEWEBSITE_LOAD_USER_PROFILE1
用户配置文件。 -azureUSGovernmentLogin-azureUSGovernmentLogin可选。此参数仅用于美国政府部署。 保存更改。
在 Microsoft Azure 文档中查找更多详细信息。
替换私钥证书
当您将私钥证书替换为新证书时,请确保按照以下步骤操作:
- 将
AppSettings__SigningCredentialSettings__StoreLocation__Name和WEBSITE_LOAD_CERTIFICATES参数的值替换为新证书的指纹。 - 重新启动身份应用程序服务。
- 重新启动 Orchestrator 应用程序服务。
迁移到身份服务器
下表介绍了可与
MigrateTo-IdentityServer.ps1一起使用的所有参数。参数
描述
-cliPackageMandatory . 指示
UiPath.IdentityServer.Migrator.Cli.zip存档的完整路径或相对路径。-azureDetails此参数是包含以下值的哈希表:
-
azureAccountApplicationId- Mandatory. The Azure service principal ID.Please note that the used service principal needs to be assigned the Contributor role to the app service at the subscription scope.
-
azureSubscriptionId- 必填。托管 Orchestrator 的应用程序服务的 Azure 订阅 ID。 -
azureAccountTenantId- 必填。Azure 租户 ID。 -
azureAccountPassword- 必填。服务主体 ID 的 Azure 令牌密码。
-orchDetails此参数是包含以下值的哈希表:
-
resourceGroupName- 必填。包含 Orchestrator 应用程序服务的 Azure 资源组名称。 -
appServiceName- 必填。Orchestrator Azure 应用程序服务名称。 -
targetSlot- 必填。Azure 设置的目标应用程序服务槽。
-identityServerDetails此参数是包含以下值的哈希表:
-
resourceGroupName- 必填。包含 Identity Server 应用程序服务的 Azure 资源组名称。 -
appServiceName- 必填。Identity Server Azure 应用程序服务名称。 -
targetSlot- 必填。Azure 设置的目标应用程序服务槽。
-identityServerUrlImportant: The URL must contain the address of Identity Server + the suffix必填。Identity Server 的公共地址。
/identityin lowercase.示例:
https://[identity_server]/identity。-orchestratorUrl必填。Orchestrator 的公共地址。
-tmpDirectory可选。启用下载和解压缩所需文件的目录的规范。
-hostAdminPasswordMandatory only for fresh deployments, when -actionis set toDeploy.Specify a custom password for the host administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit.
-isHostPassOneTimeOptional. Enables you to enforce a password reset on the first login for the host administrator.
If this parameter is omitted, the host admin password is not a one-time password.
-defaultTenantAdminPasswordMandatory only for fresh deployments, when -actionis set toDeploy.Specify a custom password for the default tenant administrator. Please note that passwords have to be least 8 characters long, and must have at least one lowercase character and at least one digit.
-isDefaultTenantPassOneTimeOptional. Enables you to enforce a password reset on the first login for the default tenant administrator.
If this parameter is omitted, the tenant admin password is not a one-time password.
-noAzureAuthenticationOptional. Allows you to publish to the Azure App Service by relying on your own user identity, without having to create a service principal. If this parameter is used, the
UseServicePrincipalparameter set (which includes items such as the Azure application ID, password, subscription ID, and tenant ID) are no longer necessary.MigrateTo-IdentityServer.ps1脚本用于将用户数据从 Orchestrator 迁移到 Identity Server,并为两者设置好配置。它将 Orchestrator 的身份授权设置到 Identity Server,并在 Identity Server 中为 Orchestrator 创建客户端配置。该脚本假定 Orchestrator 和身份服务器已发布。
.\MigrateTo-IdentityServer.ps1 ` -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" ` -azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } ` -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } ` -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } ` -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase -orchestratorUrl "https://<OrchestratorURL>" ` -hostAdminPassword "12345qwert" ` -defaultTenantAdminPassword "12345qwert".\MigrateTo-IdentityServer.ps1 ` -cliPackage "UiPath.IdentityServer.Migrator.Cli.zip" ` -azureDetails @{azureSubscriptionId = "<subscription_id>"; azureAccountTenantId = "<azure_tenant_id>"; azureAccountApplicationId = "<azure_application_id>"; azureAccountPassword = "<azure_account_password>" } ` -orchDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } ` -identityServerDetails @{ resourceGroupName = "<resourcegroup_name>"; appServiceName = "<appservice_name>"; targetSlot = "Production" } ` -identityServerUrl "https://<identity_server_url>/identity" ` // must be in lowercase -orchestratorUrl "https://<OrchestratorURL>" ` -hostAdminPassword "12345qwert" ` -defaultTenantAdminPassword "12345qwert" - 将