The Skilja Lookup Service supports applications to access customer data.
2.5K
Maintained by:
Skilja GmbHā
Where to get help:
The Skilja Partner Portalā or via email [email protected]ā ā
Image tags adhere to <major>.<minor>.<servicepack> format.
<major>.<minor>.<servicepack> points to a specific version. <Major>.<Minor> always points to the latest version. This version is compatible with all previous images of the same <Major>.<Minor> version. <latest> always points to the latest version, but such a version might require service and project database schema updates. To use the latest but compatible version, we recommend to pull a <Major>.<Minor>, e.g. with
docker pull skilja/lookupservice:<Major>.<Minor>
Note: The Vinna Lookup Service image is one of the component of Skilja's document processing solution. In order to deploy Vinna you require addtional componens, see below. (Skilja product overviewā ).
The most recent images is:
Warning : Breaking Changes with 6.2
The Skilja Lookup Service is a component that can be installed as part of the Vinna Platform. The Skilja Lookup Service provides an abstraction layer for applications that need to get customer data or other information stored in a database.
The Vinna Lookup Service cannot be used as a stand-alone container. It is an optional part of the whole Vinna platform, which requires deployments for the following Vinna Services.
Skilja/vinna_activitylauncherā
For detailed guidance, including the complete Docker installation instructions and additional documentation, please visit the Skilja Parter Portalā (Login required)
The image for the Lookup Service is based on mcr.microsoft.com/dotnet/aspnet:10.0. You can run the image as a rootless container.
At the end of this topic is a sample docker-compose file to help you set up the service along with an environment file. The system relies on a relational database and a running Authorization Serverā . Those components aren't part of this article.
The load balancer provides SSL offloading, as well as routing to the respective services. It must be configured with SSL certificates to provide HTTPS for outside traffic. In our example, all containers use http traffic in the internal docker network. In case self-signed or non-trusted certificates are used for outgoing traffic, e.g. to an Authorization Server, the services have to be configured to trust this specific certificate explicitly via thumbprint.
This docker compose sample has to be adjusted. For example, any external hostnames that are not found via docker's DNS must be explicitly added to the docker containers' DNS. Here, we set the Authorization Servers URL auth.contoso.com to the IP 172.22.32.1. The volumes mounts have to be adjusted according to your environment. Finally, all .env files and the config.json files for the websites must be adopted to your environment.
This file composes three instances of the lookup Service behind a load balancer along with a metrics service. The latter is not necessary, but may be interesting in certain use cases.
Note: These are only example configuration files. Please create your own composition based on your specific needs.
services:
lookupservice:
build:
image: skilja/lookupservice:6.2.0
labels:
- "traefik.enable=true"
- "traefik.http.routers.lookupservice.rule=Host(`lookupservice.docker.local`)" # routes requests to this url (be aware of certificates and host registration)
- "traefik.http.services.lookupservice.loadbalancer.server.port=8080" # we want this service only reachable via https (traefik does SSL offloading)
- "traefik.http.routers.lookupservice.entrypoints=websecure" # binding to websecure port
- "traefik.http.routers.lookupservice.tls=true"
env_file:
./lookupservice.env
extra_hosts:
# Important! The design time host needs to be found from inside the container. If the design time machine has no full qualified name,
# and is only reachable by its host name, the dns of the container only finds it, when it's configured here.
- "platform-server:192.168.xx.xx"
volumes:
# Mount folders if you want to share are preserver data
# in this case all instances of the service share the same ProgramData folder, e.g. for SQLite based settings
- /c/Temp/ls_data:/app/ProgramData
deploy:
replicas: 3 # the number of instances of the lookup service
networks:
- web
traefik:
image: traefik:v3.1
command:
- "--configFile=/etc/traefik/traefik.yml" # static config file
ports:
- "8081:8081" # web endpoint
- "8181:8181" # web secure
- "8080:8080" # traefik endpoint
- "8082:8082" # metrics entry point
- "9100:9100" # prometheus endpoint
volumes:
- type: bind
source: ./traefik.yml
target: /etc/traefik/traefik.yml
- "/var/run/docker.sock:/var/run/docker.sock"
- ./certs:/etc/traefik/certs # ssl certificates - with these the load balancer exposes the service endpoints
- ./traefik:/config # dynamic config files
networks:
- web
labels:
- "traefik.http.routers.traefik.rule=Host(`traefik.docker.local`)" # routes requests to this url (be aware of certificates and host registration)
- "traefik.http.services.traefik.loadbalancer.server.port=8080"
# Prometheus is providing a metrics user interface with graphs
# Detailed configuration is done in the prometheus/prometheus.yml
prometheus:
image: prom/prometheus
volumes:
- ./prometheus/prometheus.yml:/etc/prometheus/prometheus.yml
command:
- "--config.file=/etc/prometheus/prometheus.yml"
ports:
- "9090:9090"
networks:
- web
networks:
web:
driver: bridge
This is a sample for an environment file.
# the service endpoint is 8080 by default, you can change it here if necessary
# LS_ServiceEndpoint=http://+:8080
LS_ConfigurationService=https://platform-server/api/configurationservice/
LS_loglevel=Verbose
LS_UseForwardedHeaders=true
LS_TrustedCertificates=7e37487bb806a88254a393a1952167b13c86c90f
LS_ProgramDataPath=/app/ProgramData
This is a sample for traefik configuration file
entryPoints:
web:
address: ":8081"
websecure:
address: ":8181"
metrics:
address: ":8082"
# Configures the forwarding of the header contents.
# Necessary as ssl offloading changes the schema of the request and calls
# to the oidc auth server can then lead to the wrong return url.
http:
middlewares:
add-headers:
headers:
customRequestHeaders:
X-Forwarded-Proto: "https"
metrics:
prometheus:
entrypoint: "metrics"
api:
dashboard: true
insecure: true
providers:
docker:
exposedByDefault: false
file:
directory: /config # Reference to the dynamic config file
watch: true
This is a sample for tls configuration file
tls:
stores:
default:
defaultCertificate:
certFile: /etc/traefik/certs/traefik.crt
keyFile: /etc/traefik/certs/traefik.key
certificates:
- certFile: /etc/traefik/certs/traefik.crt
keyFile: /etc/traefik/certs/traefik.key
This is a sample for prometheus configuration file
global:
scrape_interval: 15s
scrape_configs:
- job_name: 'traefik'
static_configs:
- targets: ['traefik:8082'] # Target the metrics endpoint defined in Traefik
Beginning with version 6.2 the used service user is changed to be uniform across all Skilja containers. For .Net based containers like this one, the UID/GID 1654 is now used. This is a non root user called 'app'. This becomes important when working with Volume Mounts.
All settings provided in the settings keys topic can be defined as environment variables. Just add a LS_ prefix to them. For example, LS_ConfigurationService is the key to the environment file for configuring the connected platform's configuration service.
| Variable | Description |
|---|---|
| LS_ServiceEndpoint | By default, Lookup Service runs on port 8080. Only set this if you are sure you need it. |
| LS_loglevel | The log file is stored in a subfolder Log in the application data folder. Currently, the log is not preserved outside the container, but all log information is written to the container's console output. You can print this instead if you wish. |
| LS_UseForwardedHeaders | If you are running behind an SSL offloading service such as traefik, which we use in our example, you need to configure Lookup Service to use the forwarded headers provided by that service. |
| LS_ProgramDataPath | The program data path configured here can be a mounted folder. This allows multiple instances of Lookup Service to share settings via a file-based SQLite database. |
| LS_ConfigurationService | Please ensure that the host specified here can be found from within the running Docker container. |
| LS_TrustedCertificates | A comma-separated list of certificate thumbprints Lookup Service must trust. Useful and necessary when using self-signed certificates. |
| LS_DatabaseProvider | When running in Docker, we recommend using a dedicated database server to share settings between multiple instances. Please configure this and the associated database settings accordingly (see settings keys and settings database). |
Content type
Image
Digest
sha256:1a0542df2ā¦
Size
172 MB
Last updated
24 days ago
docker pull skilja/lookupservice