The runtime is a part of the Vinna Platform, used to automate document-driven business tasks.
2.7K
Maintained by:
Skilja GmbHā
Where to get help:
The Skilja Partner Portalā or via email [email protected]ā ā
Image tags adhere to <major>.<minor>.<servicepack> format.
<major>.<minor>.<servicepack> points to a specific version. <Major>.<Minor> always points to the latest stable version / service pack. This version is compatible with all previous images of the same <Major>.<Minor> version. <latest> always points to the latest version, but such a version might require service and project database schema updates. To use the latest but compatible version, we recommend to pull a <Major>.<Minor>, e.g. with
docker pull skilja/vinna_runtime:<Major>.<Minor>
Note: The Vinna Runtime image is only one component of the entire Vinna platform. In order to deploy Vinna you require additional components, see below. (Skilja product overviewā ).
The most recent images is:
The runtime is a part of the Vinna Platform, used to automate document-driven business tasks and workflows. Runtime hosts the configuration, process and document services.
At runtime, you process documents by executing activities defined in a Process at
DesignTime Environmentā with
Process Editorā .
That means, you create, modify, and delete document data, respectively, work items, within a defined process.
A work item is a data structure that contains references to documents and additional meta data.
The Vinna Runtime cannot be used as a stand-alone container. It is part of the whole Vinna platform, which requires deployments for the following Vinna Services.
skilja/vinna_activitylauncherā
Note: The following information applies to all Vinna-related images and therefore refers to a complete deployment of all Vinna images. Due to space constraints in this overview, the instructions provided here are shortened and high-level only.
For detailed guidance, including the complete Docker installation instructions and additional documentation, please visit the Skilja Parter Portalā (Login required)
The Vinna Process Management System requires multiple services that work together. A container-based deployment makes it easier to set up multiple services for redundancy and scaling with load balancing. Since the requirements for each system differ, this guide provides a basic environment along with all configuration options that exist for the containers only.
The basic environment consists of:
The system relies on a relational database and a running Authorization Serverā . Those components aren't part of this article.
The load balancer provides SSL offloading, as well as routing to the respective services. It must be configured with SSL certificates to provide HTTPS for outside traffic. In our example, all containers use http traffic in the internal docker network. In case self-signed or non-trusted certificates are used for outgoing traffic, e.g. to an Authorization Server, the services have to be configured to trust this specific certificate explicitly via thumbprint.
This docker compose sample has to be adjusted. For example, any external hostnames that are not found via docker's DNS must be explicitly added to the docker containers' DNS. Here, we set the Authorization Servers URL auth.contoso.com to the IP 172.22.32.1. The volumes mounts have to be adjusted according to your environment. Finally, all .env files and the config.json files for the websites must be adopted to your environment.
services:
traefik:
image: traefik:v3.1
ports:
# - "8080:80"
# - "8081:443"
- "8100:8100" # the http endpoint
- "8200:8200" # the https endpoint - that's what the services dt/rt/sysmon use
- "8080:8080" # Traefik dashboard
command:
- "--configFile=/etc/traefik/traefik.yml" # static config file
volumes:
- type: bind
source: ./traefik.yml
target: /traefik.yml
- /var/run/docker.sock:/var/run/docker.sock
- ./certs:/etc/traefik/certs # ssl certificates
- ./traefik:/config # dynamic config files
dt:
image: skilja/vinna_designtime:4.1
deploy:
replicas: 1
ports:
# - 8080:8080 # when you have only one dt and want to expose it directly
- 8080
labels:
- traefik.enable=true
- traefik.http.routers.dt.rule=Host(`dt.docker.localhost`) # routes requests to host dt.docker.localhost to this image
- traefik.http.routers.dt.tls=true # we want this service only reachable via https (traefik does SSL offloading)
- traefik.http.routers.dt.entrypoints=websecure # we bind to the websecure port
- traefik.http.services.dt.loadbalancer.server.port=8080 # this could be omitted if we have only 1 open port
env_file: ./designtime/designtime.env
secrets:
- source: dt_connectionstring
target: GIULIASECRETS_ConnectionStrings__Designtime
volumes:
# - ./certs:/data/certs # only required if SSL certificates must be injected
- ./data/logs:/data/logs
- ./data/dt_activities:/app/Activities
# - ./data/dt_fs_share:/app/FS_SHARE # in case the user wants to store those files not inside the docker container
extra_hosts:
- "auth.contoso.com:172.22.32.1"
pe:
image: skilja/vinna_processeditor:4.1
deploy:
replicas: 1
ports:
- 8080
labels:
- traefik.enable=true
- traefik.http.routers.editor.rule=Host(`pe.docker.localhost`)
- traefik.http.routers.editor.tls=true
- traefik.http.routers.editor.entrypoints=websecure
- traefik.http.services.editor.loadbalancer.server.port=8080
volumes:
- type: bind
source: ./processeditor/config.json
target: /usr/share/nginx/html/assets/config.json
pm:
image: skilja/vinna_processmonitor:4.1
deploy:
replicas: 1
ports:
- 8080
labels:
- traefik.enable=true
- traefik.http.routers.procmon.rule=Host(`pm.docker.localhost`)
- traefik.http.routers.procmon.tls=true
- traefik.http.routers.procmon.entrypoints=websecure
- traefik.http.services.procmon.loadbalancer.server.port=8080
volumes:
- type: bind
source: ./processmonitor/config.json
target: /usr/share/nginx/html/assets/config.json
sm:
image: skilja/vinna_systemmonitor:4.1
deploy:
replicas: 1
ports:
- 8080
labels:
- traefik.enable=true
- traefik.http.routers.sm.rule=Host(`sm.docker.localhost`)
- traefik.http.routers.sm.tls=true
- traefik.http.routers.sm.entrypoints=websecure
- traefik.http.services.sm.loadbalancer.server.port=8080
volumes:
- type: bind
source: ./systemmonitor/config.json
target: /usr/share/nginx/html/assets/config.json
rt:
image: skilja/vinna_runtime:4.1
deploy:
replicas: 3
ports:
- 8080
labels:
- traefik.enable=true
- traefik.http.routers.rt.rule=Host(`rt.docker.localhost`)
- traefik.http.routers.rt.entrypoints=websecure
- traefik.http.routers.rt.tls=true
- traefik.http.services.rt.loadbalancer.server.port=8080
env_file: ./runtime/runtime.env
secrets:
- source: rt_connectionstring
target: GIULIASECRETS_ConnectionStrings__Runtime
volumes:
- ./data/logs:/data/logs
extra_hosts:
- "auth.contoso.com:172.22.32.1"
sysmon:
image: skilja/vinna_runtime:4.1
ports:
- 8080
deploy:
replicas: 1
labels:
- traefik.enable=true
- traefik.http.routers.sysmon.rule=Host(`sysmon.docker.localhost`)
- traefik.http.routers.sysmon.entrypoints=websecure
- traefik.http.routers.sysmon.tls=true
- traefik.http.services.sysmon.loadbalancer.server.port=8080
env_file: ./runtime/sysmon.env
secrets:
- source: sm_connectionstring
target: GIULIASECRETS_ConnectionStrings__SystemMonitor
volumes:
# - ./certs:/data/certs # only required if SSL certificates must be injected
- ./data/logs:/data/logs
extra_hosts:
- "auth.contoso.com:172.22.32.1"
launcher:
image: skilja/vinna_activitylauncher:4.1
depends_on:
- rt
- sysmon
ports:
- 8080
deploy:
replicas: 1
labels:
- traefik.enable=true
- traefik.http.routers.launcher.rule=Host(`launcher.docker.localhost`)
- traefik.http.routers.launcher.entrypoints=websecure
- traefik.http.routers.launcher.tls=true
- traefik.http.services.launcher.loadbalancer.server.port=8080
env_file: ./launcher/launcher.env
volumes:
# - ./certs:/data/certs # only required if SSL certificates must be injected
- ./data/logs:/data/logs
- ./data/launcher_activities:/app/Activities
- ./data/import:/data/import
extra_hosts:
- "auth.contoso.com:172.22.32.1"
otel-collector:
image: otel/opentelemetry-collector:latest
volumes:
- ./otel-collector/collector-config.yaml:/etc/otelcol/config.yaml
ports:
- 1888:1888 # pprof extension
- 8888:8888 # Prometheus metrics exposed by the Collector
- 8889:8889 # Prometheus exporter metrics
- 13133:13133 # health_check extension
- 4317:4317 # OTLP gRPC receiver
- 4318:4318 # OTLP http receiver
prometheus:
image: prom/prometheus:latest
volumes:
- ./prometheus/prometheus-config.yaml:/etc/prometheus/prometheus.yml
labels:
- traefik.enable=true
- traefik.http.routers.prometheus.rule=Host(`prometheus.docker.localhost`)
- traefik.http.routers.prometheus.entrypoints=websecure
- traefik.http.routers.prometheus.tls=true
- traefik.http.services.prometheus.loadbalancer.server.port=9090
ports:
- 9090
grafana:
image: grafana/grafana-enterprise
container_name: grafana
volumes:
- ./grafana/data_sources.yaml:/etc/grafana/provisioning/datasources/data_sources.yml
- ./grafana/dashboard.yaml:/etc/grafana/provisioning/dashboards/main.yaml
- ./grafana/dashboards:/var/lib/grafana/dashboards
labels:
- traefik.enable=true
- traefik.http.routers.grafana.rule=Host(`grafana.docker.localhost`)
- traefik.http.routers.grafana.entrypoints=websecure
- traefik.http.routers.grafana.tls=true
- traefik.http.services.grafana.loadbalancer.server.port=3000
restart: unless-stopped
ports:
- 3000
valkey:
image: valkey/valkey
volumes:
- ./data/valkey:/data
ports:
- 6379
secrets:
dt_connectionstring:
file: ./data/secrets/dt_connectionstring.txt
rt_connectionstring:
file: ./data/secrets/rt_connectionstring.txt
sm_connectionstring:
file: ./data/secrets/sm_connectionstring.txt
The containers hosting the services are configured via environment variables. Containers hosting the websites like Process Editor, Process Monitor and System Monitor require a json file that points the URLs to the services.
You need to specify all the parameters via environment variables that are deviating from the defaults. It is recommended to use environment file and pass them as a parameter.
All services support overriding all configuration parameters via environment variables. If an environment variable is present, it replaces an existing value from the configuration file.
The default configuration file, appsettings.json, utilizes a JSON structure for storing settings.
For instance, the setting Service:Authority defines the URL for the Authorization Server.
To override this value, prefix the environment variable with GIULIA_ and replace all colons (:) with double underscores (__),
as colons are not supported in environment variables.
This results in the variable being formatted as GIULIA_Service__Authority.
The following list is not complete due to dockerhub size limitations.
All containers require accepting the End User license agreement EULAā of Vinna Process Management System.
ACCEPT_EULA:y to accept the End User License Agreementā .In case of self-signed certificates, or a root authority that is not trusted by your docker installation, you have to define trusted certificates.
GIULIA_TRUSTED_CERTIFICATES:The service endpoints are used in the internal docker network. They allow the service to communicate with each other.
An exception is the Authorization URL, which must be the same URL including schema as any external client or website is using.
GIULIA_Service__Authority:https://auth.contoso.com/authGIULIA_Service__DesignerServiceEndpoint:http://dt:8080GIULIA_Service__ConfigurationServiceEndpoint:http://rt:8080GIULIA_Service__ProcessServiceEndpoint:http://rt:8080GIULIA_Service__DocumentServiceEndpoint:http://rt:8080GIULIA_Service__SystemMonitorServiceEndpoint:http://sysmon:8080GIULIA_Service__HostedServices:ConfigService,Document,Process or SystemMonitorServiceGIULIA_Service__SystemMonitor__ActivityLauncherServices:launcher or launcher,launcherOcr,launcherExtraction (if you have different launcher services)GIULIA_Service__PathBase:/dt to reach it under https://contoso.com/dt.
It must be preceded by a slash.Containers always host the services on the root path on port
8080. The service name of the container, for examplertdefines the URL and is resolved automatically by the container environment:http://rt:8080The port must not be changed, but either mapped to port on the external network, or reached via load balancer.
Running PlatformConfiguration.exe to set up database, it produces an output file that contains the connection strings to be used.
Hint: PlatformConfiguration.exe and the Linux-equivalent are available via the Skilja Partner Portalā
From Version 4.2 the services can configure their databases on their own.
GIULIA_ConnectionStrings__Designtime:Data Source=sqlServer,1433;Initial Catalog=40_RuntimeDB;MultipleActiveResultSets=True;User Id=techuser;password=secret;GIULIA_ConnectionStrings__Runtime:Data Source=sqlServer,1433;Initial Catalog=40_RuntimeDB;MultipleActiveResultSets=True;User Id=techuser;password=secret;GIULIA_ConnectionStrings__SystemMonitor:Data Source=sqlServer,1433;Initial Catalog=40_RuntimeDB;MultipleActiveResultSets=True;User Id=techuser;password=secret;Giulia_Service__DatabaseProvider:Mssql, PostgreSQLThe Vinna services are confidential clients and must have the client credentials grant type.
The resource services like designtime, runtime and system monitor, must have the additional permission "Resource service".
The Activity Server's client must have the additional permission "Activity host".
Websites are public clients and are configured in a config.json file that is mounted to /app/html/assets/config.json.
Giulia_Service__ClientId:contoso_clientGiulia_Service__ClientSecret:contoso_secretThere are three output directory settings that can be specified:
Giulia_Service__FileShare__FileOutputPath:/var/tmp/VinnaGiulia_Service__FileShare__TempPath:/tmp/VinnaGiulia_Service__FileShare__SharedTempPath:Service:FileShare:TempPath is usedThis configuration enables the configuration service endpoint to function as a service discovery endpoint for external clients. Set the endpoints to the URLs that are exposed to the external network. The designer service and System Monitor service do not provide this feature, so they do not need these settings.
Giulia_Service__Proxy__Authority:GIULIA_Service__Authority:https://auth.contoso.com/authGiulia_Service__Proxy__ConfigurationServiceEndpoint:https://rt.docker.localhost:8200/Giulia_Service__Proxy__DocumentServiceEndpoint:https://rt.docker.localhost:8200/Giulia_Service__Proxy__ProcessServiceEndpoint:https://rt.docker.localhost:8200/Giulia_Service__Proxy__SystemMonitorServiceEndpoint:https://rt.docker.localhost:8200/Giulia_Serilog__LevelSwitches__controlSwitch:WarningGIULIA_Service__Logging__WriteToSystemMonitor:trueGIULIA_Service__Logging__ConsoleFormatsCompactJson:falseGIULIA_Service__Logging__WriteToFile:trueGIULIA_Service__Logging__WriteToFilePath:/data/logs/runtimeServices.log or /data/logs/runtimeServices.clef (json format)GIULIA_Service__Logging__FileFormatsCompactJson:falseGiulia_Service__Logging__HttpRequestLoggingIncludesQuery:falseIn case services do not function correctly and you are not certain which configuration they actually use, you can let them log the currently used configuration sources as well as the current settings. Do not use this function if you do not want sensitive data like connection strings to be logged.
Giulia_Debug__PrintConfigurations:trueGiulia_Debug__PrintSettings:trueGiulia_Debug__TestDatabaseConnection=true:The runtime services support sending metrics to an Open Telemetryā collector. The metrics can then be collected by Prometheus, and displayed with Grafana. Other metrics tools are also available for this - the platform is agnostic to what is being used.
Giulia_Metrics__OtlpEndpoint:http://otel-collector:4317Giulia_Metrics__AspNetCoreMetricsEnabled:trueThe Activity Server containers have the following configuration options:
GIULIA_Service__ActivityServer__DefaultConfiguration:AllAll corresponds to the "All" configuration that always exists.GIULIA_Service__ActivityServer__DefaultName:GIULIA_Service__ActivityServer__DefaultDescription:""Content type
Image
Digest
sha256:3c81e504aā¦
Size
119.2 MB
Last updated
about 1 month ago
docker pull skilja/vinna_runtime