The Skilja Validation Service is a component of Skilja’s document processing solution
2.2K
Maintained by:
Skilja GmbH
Where to get help:
The Skilja Partner Portal or via email [email protected]
Image tags adhere to <major>.<minor>.<servicepack> format.
<major>.<minor>.<servicepack> points to a specific version. <Major>.<Minor> always points to the latest version. This version is compatible with all previous images of the same <Major>.<Minor> version. <latest> always points to the latest version, but such a version might require service and project database schema updates. To use the latest but compatible version, we recommend to pull a <Major>.<Minor>, e.g. with
docker pull skilja/validationservice:<Major>.<Minor>
Note: The Skilja Validation Service image is one of the component of Skilja’s document processing solution. In order to deploy Vinna you require addtional componens, see below. (Skilja product overview).
The most recent images is:
The Skilja Validation Service is a component of Skilja’s document processing solution. It's a web application that allows users to define the layout, validation rules, and the lookups for a document type.
The Skilja Validation Service is not meant to operate as a standalone container. It is specifically designed to work as an additional component within the Vinna Platform.
Skilja/vinna_activitylauncher
For detailed guidance, including the complete Docker installation instructions and additional documentation, please visit the Skilja Parter Portal (Login required)
The image for the Validation Service is based on mcr.microsoft.com/dotnet/aspnet:8.0. You can run the image as a rootless container.
At the end of this topic is a sample docker-compose file to help you set up the service along with an environment file. The system relies on a relational database and a running Authorization Server. Those components aren't part of this article.
The load balancer provides SSL offloading, as well as routing to the respective services. It must be configured with SSL certificates to provide HTTPS for outside traffic. In our example, all containers use http traffic in the internal docker network. In case self-signed or non-trusted certificates are used for outgoing traffic, e.g. to an Authorization Server, the services have to be configured to trust this specific certificate explicitly via thumbprint.
This docker compose sample has to be adjusted. For example, any external hostnames that are not found via docker's DNS must be explicitly added to the docker containers' DNS. Here, we set the Authorization Servers URL auth.contoso.com to the IP 172.22.32.1. The volumes mounts have to be adjusted according to your environment. Finally, all .env files and the config.json files for the websites must be adopted to your environment.
This file composes three instances of the Validation Service behind a load balancer along with a metrics service. The latter is not necessary, but may be interesting in certain use cases.
Note: These are only example configuration files. Please create your own composition based on your specific needs.
services:
validationservice:
build:
image: skilja/validationservice:6.1.1
labels:
- "traefik.enable=true"
- "traefik.http.routers.validationservice.rule=Host(`validationservice.docker.local`)" # routes requests to this url (be aware of certificates and host registration)
- "traefik.http.services.validationservice.loadbalancer.server.port=8080" # we want this service only reachable via https (traefik does SSL offloading)
- "traefik.http.routers.validationservice.entrypoints=websecure" # binding to websecure port
- "traefik.http.routers.validationservice.tls=true"
env_file:
./validationservice.env
extra_hosts:
# Important! The design time host needs to be found from inside the container. If the design time machine has no full qualified name,
# and is only reachable by its host name, the dns of the container only finds it, when it's configured here.
- "platform-server:192.168.xx.xx"
deploy:
replicas: 3 # the number of instances of the validation service
networks:
- web
traefik:
image: traefik:v3.1
command:
- "--configFile=/etc/traefik/traefik.yml" # static config file
ports:
- "8081:8081" # web endpoint
- "8181:8181" # web secure
- "8080:8080" # traefik endpoint
- "8082:8082" # metrics entry point
- "9100:9100" # prometheus endpoint
volumes:
- type: bind
source: ./traefik.yml
target: /etc/traefik/traefik.yml
- "/var/run/docker.sock:/var/run/docker.sock"
- ./certs:/etc/traefik/certs # ssl certificates - with these the load balancer exposes the service endpoints
- ./traefik:/config # dynamic config files
networks:
- web
labels:
- "traefik.http.routers.traefik.rule=Host(`traefik.docker.local`)" # routes requests to this url (be aware of certificates and host registration)
- "traefik.http.services.traefik.loadbalancer.server.port=8080"
# Prometheus is providing a metrics user interface with graphs
# Detailed configuration is done in the prometheus/prometheus.yml
prometheus:
image: prom/prometheus
volumes:
- ./prometheus/prometheus.yml:/etc/prometheus/prometheus.yml
command:
- "--config.file=/etc/prometheus/prometheus.yml"
ports:
- "9090:9090"
networks:
- web
networks:
web:
driver: bridge
This is a sample for an environment file.
# the service endpoint is 8080 by default, you can change it here if necessary
# VCPV_SERVICEENDPOINT=http://+:8047
# The database server configuration - the database types are: SQLServer, PostgreSQL, OracleDB
VCPV_DATABASESERVER=mySqlServer
VCPV_DATABASETYPE=SQLServer
VCPV_DATABASENAME=Validationservice4docker
VCPV_USEINTEGRATEDSECURITY=false
VCPV_SQLUSER=sa
VCPV_SQLPASSWORD=saPassword
VCPV_TRUSTSERVERCERTIFICATE=true
VCPV_USESSL=false
# If the ValidationDesigner requires authentication for review configurations that are not linked to a process.
# The default is true
VCPV_REQUIREAUTHFORDESIGNER=false
# The url of the process designer application, and you can give it a name
VCPV_PLATFORMDESIGNERURL=https://vm-sam1/ProcessEditor
# The client id for the authentication server of the designer
VCPV_CLIENTID=ValidationService
# The name of the log file inside the container stored in the /app/Log folder
VCPV_LOGFILE=_validationService.log
# The available log levels are: Verbose, Debug, Information, Warning, Error
VCPV_LOGLEVEL=Debug
# Use forwarded headers in the ValidationService when it runs behind ssl offloading, the default is false.
VCPV_USEFORWARDEDHEADERS=true
# If you use self signed certificates, e.g. for your ProcessEditor, you need to register the thumbprints of the certificates here.
# To register multiple certificates, you can write them comma-separated.
VCPV_TRUSTEDCERTIFICATES=7e37487bb806a88254a393a1952167b13c86c90f
# By default dataprotection is secured with a default certificate. To use a custom one please give the path to the certificate here.
# Please make sure to use the same certificate for all ValidationServices that run behind the same load balancer or that access the same database.
# Otherwise, authentication will not persist across multiple instances of the service.
# VCPV_DATAPROTECTIONCERTIFICATEPATH=/app/certificates/default-cert.pfx
# VCPV_DATAPROTECTIONCERTIFICATEPASSWORD=
This is a sample for traefik configuration file
entryPoints:
web:
address: ":8081"
websecure:
address: ":8181"
metrics:
address: ":8082"
# Configures the forwarding of the header contents.
# Necessary as ssl offloading changes the schema of the request and calls
# to the oidc auth server can then lead to the wrong return url.
http:
middlewares:
add-headers:
headers:
customRequestHeaders:
X-Forwarded-Proto: "https"
metrics:
prometheus:
entrypoint: "metrics"
api:
dashboard: true
insecure: true
providers:
docker:
exposedByDefault: false
file:
directory: /config # Reference to the dynamic config file
watch: true
## Sample tls configuration file
This is a sample for tls configuration file
```yml
tls:
stores:
default:
defaultCertificate:
certFile: /etc/traefik/certs/traefik.crt
keyFile: /etc/traefik/certs/traefik.key
certificates:
- certFile: /etc/traefik/certs/traefik.crt
keyFile: /etc/traefik/certs/traefik.key
This is a sample for prometheus configuration file
global:
scrape_interval: 15s
scrape_configs:
- job_name: 'traefik'
static_configs:
- targets: ['traefik:8082'] # Target the metrics endpoint defined in Traefik
All the settings you can configure in the configuration tool have equivalents as environment variables. Use them instead of the tool or the resulting configuration file when configuring the service for Docker. A sample environment file is included at the end of this topic.
| Variable | Description |
|---|---|
| VCPV_SERVICEENDPOINT | The service endpoint. The default value is http://+:8080 and the service runs on port 8080, only set this if you are sure you need it. |
| VCPV_DATABASESERVER | Address of the database server. |
| VCPV_DATABASETYPE | Type of the used database. Possible values are SQLServer, PostgreSQL and OracleDB. |
| VCPV_DATABASENAME | Name of the database. |
| VCPV_USEINTEGRATEDSECURITY | true or false - whether the app running user is used for accessing the database. |
| VCPV_SQLUSER | Username of the sql user accessing the database. |
| VCPV_SQLPASSWORD | Password of the sql user. |
| VCPV_TRUSTSERVERCERTIFICATE | true or false - wheter the service always trusts the database certificate. |
| VCPV_USESSL | true or false - wheter the service only has to use ssl for database connection |
| VCPV_REQUIREAUTHFORDESIGNER | true or false - set to false if you want to allow users to access review configurations that are not linked to a process without being authenticated. |
| VCPV_PLATFORMDESIGNERURL | The url of the designer you want to connect to. |
| VCPV_DESIGNERSERVICEENDPOINT | The URL of the Designer Service you want to connect to. Optional, if not set, the service tries to discover it via the Designer URL. |
| VCPV_AUTHNENDPOINT | The URL of the Authorization Server you want to connect to. Optional, if not set, the service tries to discover it via the Designer URL. |
| VCPV_CLIENTID | Set the client ID if you configured a custom one in the Authorization Server |
| VCPV_LOGFILE | Set this if you do not want the default file name fot the lof file. |
| VCPV_LOGLEVEL | Log level. Possible values are Verbose, Debug, Information, Warning and Error. Currently the log is not preserved outside the container, but all log information is written to the container's console output, you can print this instead if you wish. |
| VCPV_USEFORWARDEDHEADERS | true or false - If you are running behind an SSL offloading service such as traefik, which we use in our example, you need to configure Validation Service to use the forwarded headers provided by that service. |
| VCPV_TRUSTEDCERTIFICATES | A comma-separated list of certificate thumbprints Validation Service must trust. Useful and necessary when using self-signed certificates. |
| VCPV_DATAPROTECTIONCERTIFICATEPATH | Validation Service uses a default certificate for data protection purposes. If you want to give a custom certificate for that, define the path to it here. |
| VCPV_DATAPROTECTIONCERTIFICATEPASSWORD | Set the password to the custom certificate here if you configured one. |
| VCPV_SERVICEPATHBASE | Sets the path base of Validation Service. This may be necessary when running behind a reverse proxy or in containerized environments. |
Content type
Image
Digest
sha256:8850b1f9f…
Size
259.1 MB
Last updated
2 months ago
docker pull skilja/validationservice