Sign inSign up

skilja/vinna_processeditor

By skilja

•Updated about 1 month ago

Process Editor is a part of the Vinna Platform. It is the frontend for configuring processes.

Image
1

2.7K

skilja/vinna_processeditor repository overview

⁠Quick reference

⁠Supported tags and Versioning

Image tags adhere to <major>.<minor>.<servicepack> format.

<major>.<minor>.<servicepack> points to a specific version. <Major>.<Minor> always points to the latest version. This version is compatible with all previous images of the same <Major>.<Minor> version. <latest> always points to the latest version, but such a version might require service and project database schema updates. To use the latest but compatible version, we recommend to pull a <Major>.<Minor>, e.g. with

docker pull skilja/vinna_processeditor:<Major>.<Minor>

Note: The Vinna Designtime image is only one component of the entire Vinna platform. In order to deploy Vinna you require addtional componens, see below. (Skilja product overview⁠).

The most recent images is:


logo drawing

⁠What is Vinna Process Editor?

Process Editor is a web application that allows setting up the processes for document automation and manage all needed components. You can use this application to set up your processes grouped by clients and units. In addition, you can manage your activities, set up specific roles and maintain your licenses.

⁠How to use this image

Vinna Process Editor cannot be used as a stand-alone container. It is part of the whole Vinna platform, which requires deployments for the following Vinna Services.

skilja/vinna_runtime⁠

skilja/vinna_activitylauncher⁠

skilja/vinna_designtime⁠

skilja/vinna_processmonitor⁠

skilja/vinna_systemmonitor⁠

Note: The following information applies to all Vinna-related images and therefore refers to a complete deployment of all Vinna images. Due to space constraints in this overview section, the instructions provided here are shortened and high-level only.

For detailed guidance, including the complete Docker installation instructions and additional documentation, please visit the Skilja Parter Portal⁠ (Login required)

⁠Overview

drawing

The Vinna Process Management System requires multiple services that work together. A container-based deployment makes it easier to set up multiple services for redundancy and scaling with load balancing. Since the requirements for each system differ, this guide provides a basic environment along with all configuration options that exist for the containers only.

The basic environment consists of:

  • 1 load balancer (traefik)
  • 3 containers for each Process Editor, Process Monitor and System Monitor
  • 1 container for Designtime services
  • 3 containers for Runtime services
  • 1 container for the Activity Server
  • 1 container for Valkey, a key-value store providing a signalR backplane (not required for functioning)
  • A set of containers for metrics and visualization, using Open-Telemetry, Prometheus and Grafana (optional)

The system relies on a relational database and a running Authorization Server⁠. Those components aren't part of this article.

The load balancer provides SSL offloading, as well as routing to the respective services. It must be configured with SSL certificates to provide HTTPS for outside traffic. In our example, all containers use http traffic in the internal docker network. In case self-signed or non-trusted certificates are used for outgoing traffic, e.g. to an Authorization Server, the services have to be configured to trust this specific certificate explicitly via thumbprint.

⁠Sample Docker Compose File

This docker compose sample has to be adjusted. For example, any external hostnames that are not found via docker's DNS must be explicitly added to the docker containers' DNS. Here, we set the Authorization Servers URL auth.contoso.com to the IP 172.22.32.1. The volumes mounts have to be adjusted according to your environment. Finally, all .env files and the config.json files for the websites must be adopted to your environment.

services:
  traefik:
    image: traefik:v3.1
    ports:
      # - "8080:80"
      # - "8081:443"
      - "8100:8100" # the http endpoint
      - "8200:8200" # the https endpoint - that's what the services dt/rt/sysmon use
      - "8080:8080"  # Traefik dashboard
    command:
      - "--configFile=/etc/traefik/traefik.yml" # static config file
    volumes:
      - type: bind
        source: ./traefik.yml
        target: /traefik.yml
      - /var/run/docker.sock:/var/run/docker.sock
      - ./certs:/etc/traefik/certs # ssl certificates
      - ./traefik:/config # dynamic config files

  dt:
    image: skilja/vinna_designtime:4.1
    deploy:
      replicas: 1
    ports:
      # - 8080:8080 # when you have only one dt and want to expose it directly
      - 8080
    labels:
      - traefik.enable=true
      - traefik.http.routers.dt.rule=Host(`dt.docker.localhost`) # routes requests to host dt.docker.localhost to this image
      - traefik.http.routers.dt.tls=true # we want this service only reachable via https (traefik does SSL offloading)
      - traefik.http.routers.dt.entrypoints=websecure # we bind to the websecure port
      - traefik.http.services.dt.loadbalancer.server.port=8080 # this could be omitted if we have only 1 open port
    env_file: ./designtime/designtime.env
    secrets:
      - source: dt_connectionstring
        target: GIULIASECRETS_ConnectionStrings__Designtime
    volumes:
      # - ./certs:/data/certs # only required if SSL certificates must be injected
      - ./data/logs:/data/logs
      - ./data/dt_activities:/App/Activities
      # - ./data/dt_fs_share:/App/FS_SHARE # in case the user wants to store those files not inside the docker container
    extra_hosts:
      - "auth.contoso.com:172.22.32.1"

  pe:
    image: skilja/vinna_processeditor:4.1
    deploy:
      replicas: 1
    ports:
      - 8080
    labels:
      - traefik.enable=true
      - traefik.http.routers.editor.rule=Host(`pe.docker.localhost`)
      - traefik.http.routers.editor.tls=true
      - traefik.http.routers.editor.entrypoints=websecure
      - traefik.http.services.editor.loadbalancer.server.port=8080
    volumes:
      - type: bind
        source: ./processeditor/config.json
        target: /usr/share/nginx/html/assets/config.json

  pm:
    image: skilja/vinna_processmonitor:4.1
    deploy:
      replicas: 1
    ports:
      - 8080
    labels:
      - traefik.enable=true
      - traefik.http.routers.procmon.rule=Host(`pm.docker.localhost`)
      - traefik.http.routers.procmon.tls=true
      - traefik.http.routers.procmon.entrypoints=websecure
      - traefik.http.services.procmon.loadbalancer.server.port=8080
    volumes:
      - type: bind
        source: ./processmonitor/config.json
        target: /usr/share/nginx/html/assets/config.json

  sm:
    image: skilja/vinna_systemmonitor:4.1
    deploy:
      replicas: 1
    ports:
      - 8080
    labels:
      - traefik.enable=true
      - traefik.http.routers.sm.rule=Host(`sm.docker.localhost`)
      - traefik.http.routers.sm.tls=true
      - traefik.http.routers.sm.entrypoints=websecure
      - traefik.http.services.sm.loadbalancer.server.port=8080
    volumes:
      - type: bind
        source: ./systemmonitor/config.json
        target: /usr/share/nginx/html/assets/config.json

  rt:
    image: skilja/vinna_runtime:4.1
    deploy:
      replicas: 3
    ports:
      - 8080
    labels:
      - traefik.enable=true
      - traefik.http.routers.rt.rule=Host(`rt.docker.localhost`)
      - traefik.http.routers.rt.entrypoints=websecure
      - traefik.http.routers.rt.tls=true
      - traefik.http.services.rt.loadbalancer.server.port=8080
    env_file: ./runtime/runtime.env
    secrets:
      - source: rt_connectionstring
        target: GIULIASECRETS_ConnectionStrings__Runtime
    volumes:
      - ./data/logs:/data/logs
    extra_hosts:
      - "auth.contoso.com:172.22.32.1"

  sysmon:
    image: skilja/vinna_runtime:4.1
    ports:
      - 8080
    deploy:
      replicas: 1
    labels:
      - traefik.enable=true
      - traefik.http.routers.sysmon.rule=Host(`sysmon.docker.localhost`)
      - traefik.http.routers.sysmon.entrypoints=websecure
      - traefik.http.routers.sysmon.tls=true
      - traefik.http.services.sysmon.loadbalancer.server.port=8080
    env_file: ./runtime/sysmon.env
    secrets:
      - source: sm_connectionstring
        target: GIULIASECRETS_ConnectionStrings__SystemMonitor
    volumes:
      # - ./certs:/data/certs # only required if SSL certificates must be injected
      - ./data/logs:/data/logs
    extra_hosts:
      - "auth.contoso.com:172.22.32.1"

  launcher:
    image: skilja/vinna_activitylauncher:4.1
    depends_on:
      - rt
      - sysmon
    ports:
      - 8080
    deploy:
      replicas: 1
    labels:
      - traefik.enable=true
      - traefik.http.routers.launcher.rule=Host(`launcher.docker.localhost`)
      - traefik.http.routers.launcher.entrypoints=websecure
      - traefik.http.routers.launcher.tls=true
      - traefik.http.services.launcher.loadbalancer.server.port=8080
    env_file: ./launcher/launcher.env
    volumes:
      # - ./certs:/data/certs # only required if SSL certificates must be injected
      - ./data/logs:/data/logs
      - ./data/launcher_activities:/App/Activities
      - ./data/import:/App/DataImport
    extra_hosts:
      - "auth.contoso.com:172.22.32.1"

  otel-collector:
    image: otel/opentelemetry-collector:latest
    volumes:
      - ./otel-collector/collector-config.yaml:/etc/otelcol/config.yaml
    ports:
      - 1888:1888 # pprof extension
      - 8888:8888 # Prometheus metrics exposed by the Collector
      - 8889:8889 # Prometheus exporter metrics
      - 13133:13133 # health_check extension
      - 4317:4317 # OTLP gRPC receiver
      - 4318:4318 # OTLP http receiver

  prometheus:
    image: prom/prometheus:latest
    volumes: 
      - ./prometheus/prometheus-config.yaml:/etc/prometheus/prometheus.yml
    labels:
      - traefik.enable=true
      - traefik.http.routers.prometheus.rule=Host(`prometheus.docker.localhost`)
      - traefik.http.routers.prometheus.entrypoints=websecure
      - traefik.http.routers.prometheus.tls=true
      - traefik.http.services.prometheus.loadbalancer.server.port=9090
    ports:
      - 9090

  grafana:
    image: grafana/grafana-enterprise
    container_name: grafana
    volumes: 
      - ./grafana/data_sources.yaml:/etc/grafana/provisioning/datasources/data_sources.yml
      - ./grafana/dashboard.yaml:/etc/grafana/provisioning/dashboards/main.yaml
      - ./grafana/dashboards:/var/lib/grafana/dashboards
    labels:
      - traefik.enable=true
      - traefik.http.routers.grafana.rule=Host(`grafana.docker.localhost`)
      - traefik.http.routers.grafana.entrypoints=websecure
      - traefik.http.routers.grafana.tls=true
      - traefik.http.services.grafana.loadbalancer.server.port=3000
    restart: unless-stopped
    ports:
     - 3000

  valkey:
    image: valkey/valkey
    volumes:
      - ./data/valkey:/data
    ports:
      - 6379 

secrets:
    dt_connectionstring:
        file: ./data/secrets/dt_connectionstring.txt
    rt_connectionstring:
        file: ./data/secrets/rt_connectionstring.txt
    sm_connectionstring:
        file: ./data/secrets/sm_connectionstring.txt

⁠Environment Variables and Configuration Files used by the Containers

The containers hosting the services are configured via environment variables. Containers hosting the websites like Process Editor, Process Monitor and System Monitor require a json file that points the URLs to the services.

You need to specify all the parameters via environment variables that are deviating from the defaults. It is recommended to use environment file and pass them as a parameter.

All services support overriding all configuration parameters via environment variables. If an environment variable is present, it replaces an existing value from the configuration file.

The default configuration file, appsettings.json, utilizes a JSON structure for storing settings. For instance, the setting Service:Authority defines the URL for the Authorization Server. To override this value, prefix the environment variable with GIULIA_ and replace all colons (:) with double underscores (__), as colons are not supported in environment variables. This results in the variable being formatted as GIULIA_Service__Authority.

The following list is not complete due to dockerhub size limitations.

⁠General Configuration

All containers require accepting the End User license agreement EULA⁠ of Vinna Process Management System.

⁠Certificates

In case of self-signed certificates, or a root authority that is not trusted by your docker installation, you have to let the service now which certificates they can trust.

  • GIULIA_TRUSTED_CERTIFICATES:
    A comma-separated list of trusted certificate hashes: 1465fa902bd3fc9bc6c33ac091a650470ca4111f,1465fa902bd3fc9bc6c33ac091a650470ca4111d
⁠Service Endpoints

The service endpoints are used in the internal docker network. They allow the service to communicate with each other.

An exception is the Authorization URL, which must be the same URL including schema as any external client or website is using.

  • GIULIA_Service__Authority:
    URL for the authentication server:
    https://auth.contoso.com/auth
  • GIULIA_Service__DesignerServiceEndpoint:
    Endpoint for the designer service, must be provided for the vinna_designtime image:
    http://dt:8080
  • GIULIA_Service__ConfigurationServiceEndpoint:
    Endpoint for the configuration service, must be provided for the vinna_runtime image:
    http://rt:8080
  • GIULIA_Service__ProcessServiceEndpoint:
    Endpoint for the process service, must be provided for the vinna_runtime image:
    http://rt:8080
  • GIULIA_Service__DocumentServiceEndpoint:
    Endpoint for the document service, must be provided for the vinna_runtime image:
    http://rt:8080
  • GIULIA_Service__SystemMonitorServiceEndpoint:
    Endpoint for the system monitor service, must be provided for the vinna_runtime image:
    http://sysmon:8080
  • GIULIA_Service__HostedServices:
    List of hosted services:
    ConfigService,Document,Process or SystemMonitorService
  • GIULIA_Service__SystemMonitor__ActivityLauncherServices:
    A comma-separated list of Activity Server services that are available. Used by the System Monitor service to discover them and query them for current work loads:
    launcher or launcher,launcherOcr,launcherExtraction (if you have different launcher services)
  • GIULIA_Service__PathBase:
    The base path under that a service is exposed in front of the load balancer, e.g. /dt to reach it under https://contoso.com/dt. It must be preceded by a slash.

Containers always host the services on the root path on port 8080. The service name of the container, for example rt defines the URL and is resolved automatically by the container environment: http://rt:8080 The port must not be changed, but either mapped to port on the external network, or reached via load balancer.

⁠Database Connection

Running PlatformConfiguration.exe to set up database, it produces an output file that contains the connection strings to be used. Hint: PlatformConfiguration.exe and the Linux-equivalent are available via the Skilja Partner Portal⁠ From Version 4.2 the services can configure their databases on their own.

  • GIULIA_ConnectionStrings__Designtime:
    Connection string for the runtime database: Data Source=sqlServer,1433;Initial Catalog=40_RuntimeDB;MultipleActiveResultSets=True;User Id=techuser;password=secret;
  • GIULIA_ConnectionStrings__Runtime:
    Connection string for the runtime database: Data Source=sqlServer,1433;Initial Catalog=40_RuntimeDB;MultipleActiveResultSets=True;User Id=techuser;password=secret;
  • GIULIA_ConnectionStrings__SystemMonitor:
    Connection string for the runtime database: Data Source=sqlServer,1433;Initial Catalog=40_RuntimeDB;MultipleActiveResultSets=True;User Id=techuser;password=secret;
  • Giulia_Service__DatabaseProvider:
    Supported database provider:
    Mssql, PostgreSQL
⁠Authentication and Security

The Vinna services are confidential clients and must have the client credentials grant type. The resource services like designtime, runtime and system monitor, must have the additional permission "Resource service". The Activity Server's client must have the additional permission "Activity host". Websites are public clients and are configured in a config.json file that is mounted to /app/html/assets/config.json.

  • Giulia_Service__ClientId:
    Client ID for the service:
    contoso_client
  • Giulia_Service__ClientSecret:
    Client secret for the service:
    contoso_secret
⁠Output Directories

There are three output directory settings that can be specified:

  • Giulia_Service__FileShare__FileOutputPath:
    Base directory for file output, the services will create "FS_SHARE", "Activities", "Config" or other subdirectories inside
    Default value: /var/tmp/Vinna
  • Giulia_Service__FileShare__TempPath:
    Path for storing temporary files
    Default value: /tmp/Vinna
  • Giulia_Service__FileShare__SharedTempPath:
    Path for storing temporary files that need to be shared across multiple service instances (for example, stateful uploads)
    If not specified, same value as in Service:FileShare:TempPath is used
⁠Proxy Configuration

This configuration enables the configuration service endpoint to function as a service discovery endpoint for external clients. Set the endpoints to the URLs that are exposed to the external network. The designer service and System Monitor service do not provide this feature, so they do not need these settings.

  • Giulia_Service__Proxy__Authority:
    URL for the authority - and must be identical to GIULIA_Service__Authority:
    https://auth.contoso.com/auth
  • Giulia_Service__Proxy__ConfigurationServiceEndpoint:
    Proxy endpoint for configuration service:
    https://rt.docker.localhost:8200/
  • Giulia_Service__Proxy__DocumentServiceEndpoint:
    Proxy endpoint for document service:
    https://rt.docker.localhost:8200/
  • Giulia_Service__Proxy__ProcessServiceEndpoint:
    Proxy endpoint for process service:
    https://rt.docker.localhost:8200/
  • Giulia_Service__Proxy__SystemMonitorServiceEndpoint:
    Proxy endpoint for system monitor service:
    https://rt.docker.localhost:8200/
⁠Logging Configuration
  • Giulia_Serilog__LevelSwitches__controlSwitch:
    Default log level:
    Warning
  • GIULIA_Service__Logging__WriteToSystemMonitor:
    Enable logging to system monitor:
    true
  • GIULIA_Service__Logging__ConsoleFormatsCompactJson:
    Use compact JSON format for console logging:
    false
  • GIULIA_Service__Logging__WriteToFile:
    Enable logging to file:
    true
  • GIULIA_Service__Logging__WriteToFilePath:
    Allows to specify a path to the log file:
    /data/logs/runtimeServices.log or /data/logs/runtimeServices.clef (json format)
  • GIULIA_Service__Logging__FileFormatsCompactJson:
    Use compact JSON format for file logging. This is useful if you use other logging providers and feed them with docker's console output:
    false
  • Giulia_Service__Logging__HttpRequestLoggingIncludesQuery:
    Include query parameters in HTTP request logging. Note that this can include sensitive data:
    false
⁠Debugging Options

In case services do not function correctly and you are not certain which configuration they actually use, you can let them log the currently used configuration sources as well as the current settings. Do not use this function if you do not want sensitive data like connection strings to be logged.

  • Giulia_Debug__PrintConfigurations:
    Enable printing of configuration sources:
    true
  • Giulia_Debug__PrintSettings:
    Enable printing of all settings along with their configuration source:
    true
  • Giulia_Debug__TestDatabaseConnection=true:
    Test the database connection string. Defaults to false.
⁠Metrics Configuration

The runtime services support sending metrics to an Open Telemetry⁠ collector. The metrics can then be collected by Prometheus, and displayed with Grafana. Other metrics tools are also available for this - the platform is agnostic to what is being used.

  • Giulia_Metrics__OtlpEndpoint:
    Endpoint for OTLP metrics:
    http://otel-collector:4317
  • Giulia_Metrics__AspNetCoreMetricsEnabled:
    Enable ASP.NET Core metrics:
    true
⁠Activity Server Options

The Activity Server containers have the following configuration options:

  • GIULIA_Service__ActivityServer__DefaultConfiguration:
    Default value: All
    Specifies the default configuration for the Activity Server. The value All corresponds to the "All" configuration that always exists.
  • GIULIA_Service__ActivityServer__DefaultName:
    Default value: ``
    Defines the default name for the Activity Server instance. By default, the hostname is taken.
  • GIULIA_Service__ActivityServer__DefaultDescription:
    Default value: ""
    Provides a default description for the Activity Server. It is empty by default.

Tag summary

Content type

Image

Digest

sha256:7f6aa9cb7…

Size

82.6 MB

Last updated

about 1 month ago

docker pull skilja/vinna_processeditor