Using Amazon EventBridge with IBM App Connect Enterprise
Amazon EventBridge is a serverless event bus service that simplifies your application architecture. By using Amazon EventBridge, you can create scalable events from your applications that can integrate with Amazon Web Services (AWS).
About this task
IBM® App Connect Enterprise communicates synchronously with Amazon EventBridge through the Amazon EventBridge Input node and Amazon EventBridge Request node, which is available on Windows, AIX, and Linux® systems.
You can use the Amazon EventBridge Input node in a message flow to accept input from Amazon EventBridge. For example, you can use the Amazon EventBridge Input node to monitor Amazon EventBridge for new AWS events or custom events. When a new AWS event or custom event is created, the Amazon EventBridge Input node generates a message tree that represents the business object with details of the new event. The message tree is propagated to the Out terminal so that the rest of the message flow can use the data to update other systems or to audit the changes. For more information about configuring the Amazon EventBridge Input node, see Amazon EventBridge Input node.
You can use the Amazon EventBridge Request node to connect to Amazon EventBridge and issue requests to perform actions on objects such as events and event buses. For more information, see Amazon EventBridge Request node.
Procedure
The following steps show you how to connect to a Amazon EventBridge account and configure a Amazon EventBridge Request node by using connector discovery. You can follow a similar procedure to configure a Amazon EventBridge Input node to monitor Amazon EventBridge for input, by creating a flow containing a Amazon EventBridge Input node and configuring it through connector discovery.
- In the IBM App Connect Enterprise Toolkit, create a flow that contains an Amazon EventBridge Request node.
- Select the Amazon EventBridge Request node in the flow to show the node properties in the editor.
- On the Basic tab, click Launch Connector
Discovery. A panel is displayed in which you specify the name of the policy project and vault details to be used during connector discovery.
- Specify the details of the policy project and vault to be
used during connector discovery:
- In the Policy Project field, specify the policy project that is
used to store the policies that are created during connector discovery. Alternatively, you can create a new policy project by clicking New and then specifying the name of the new policy project. Then click Finish.
- Specify the vault to be used during connector discovery. By default, credentials that
are used during connector discovery are stored in an external directory vault, which is
an App Connect Enterprise vault that can be used by any integration server.
Alternatively, you can store the credentials in an integration server vault, which is created in the
integration server's work directory and can be used only by that specific integration server. To specify the vault to be used for storing the credentials, complete the steps in the Using the Connector Discovery wizard section of one of the following topics:
- In the Vault key field, enter the vault key that is used to access the credentials stored in the vault. The vault key must be at least 8 characters in length.
- Optional: By default, the specified vault location and vault key are saved as preferences in the Toolkit so that the values are preset when you launch Connector Discovery. If you do not want the preferences to be saved, deselect Save in vault preferences.
- In the Policy Project field, specify the policy project that is
used to store the policies that are created during connector discovery.
- Click Launch Discovery to start the Connector Discovery wizard for
the Amazon EventBridge connector. The Connector Discovery window is displayed. If existing Amazon EventBridge connections (accounts) are available, a list of those connections is displayed. If there are no existing connections, the status of the Amazon EventBridge connector is shown as
Not connected.- If one or more Amazon EventBridge connections
(accounts) are available, complete the following steps:
- Select the connection (account) that you want to use by clicking it.
- Click the required object type and then select the action that you want to perform on the object. For example, to create an event bus in Amazon EventBridge, click Event buses and then Create event bus.
- If there are no existing connections (accounts), complete the following steps:
- Click the required object type and then select the action that you want to perform on that object. For example, to create an event bus in Amazon EventBridge, click Event buses and then Create event bus.
- Click Connect to display a menu from which you must select one of the
following Authorization types:
- Provide credentials for App Connect to use (BASIC)
- Provide credentials for App Connect to use (BASIC OIDC)
- Provide credentials for App Connect to use (AWS PKI)
- If you selected Provide credentials for App Connect to use
(BASIC) as the authorization type, enter the following details:
- Secret access key: The secret access key of your Amazon EventBridge account. Get the secret access key from the Security Credentials page in the AWS Management Console.
- Access key ID: The access key ID of your Amazon EventBridge account. Get the access key ID from the Security Credentials page in the AWS Management Console.
- Region: The region of your Amazon EventBridge instance, for example,
us-east-1. You can find the value for the Region parameter at the end of the URL when you are logged in to the AWS Management Console (for example, https://us-east-2.console.aws.amazon.com/console/home?region=us-east-2#). - Proxy name: Select or specify the name of the proxy that you want App Connect to use to pass the connector calls. This field is only required if calls need to go through a proxy. When using the IBM App Connect Enterprise Toolkit, the proxy name should be specified in the form: {PolicyProjectName}:HTTPProxyPolicyName
- If you selected Provide credentials for App Connect to use (BASIC
OIDC) as the authorization type, enter the following details:
- Region: The region of your Amazon EventBridge instance, for example,
us-east-1. You can find the value for the Region parameter at the end of the URL when you are logged in to the AWS Management Console (for example, https://us-east-2.console.aws.amazon.com/console/home?region=us-east-2#). - Client ID: Specify the unique identifier assigned to an application within an OpenID Connect (OIDC) system
- Client secret: Specify the client secret that is used to authenticate the client application
- ID token: The security token in OpenID Connect (OIDC) that contains claims about the authentication of a user, such as their identity and session validity, typically represented as a JSON Web Token (JWT)
- Refresh token: The refresh token that is generated from the application client ID and client secret
- Role ARN: The Amazon Resource Name (ARN) that specifies an IAM role in AWS, defining the permissions granted to users authenticated via an OpenID Connect-compatible identity provider
- OIDC server URL: Specify the URL of the OpenID Connect (OIDC) server or identity provider that handles authentication and provides tokens for clients
- Proxy name: Select or specify the name of the proxy that you want App Connect to use to pass the connector calls. This field is only required if calls need to go through a proxy. When using the IBM App Connect Enterprise Toolkit, the proxy name should be specified in the form: {PolicyProjectName}:HTTPProxyPolicyName
- Region: The region of your Amazon EventBridge instance, for example,
- If you selected Provide credentials for App Connect to use (AWS PKI) as
the authorization type, enter the following details:
- Region: The region of your Amazon EventBridge instance, for example,
us-east-1. You can find the value for the Region parameter at the end of the URL when you are logged in to the AWS Management Console (for example, https://us-east-2.console.aws.amazon.com/console/home?region=us-east-2#). - Client certificate: The X.509 certificate used to authenticate your workload with IAM Roles Anywhere.
- Client key password: The password for the encrypted Client private key. Required only if the Client private key is protected by a password.
- Client private key: The private key that is associated with the client certificate and used to sign authentication requests.
- Profile ARN: The Amazon Resource Name (ARN) of the IAM Roles Anywhere profile that determines the IAM roles that a workload can assume.
- Role ARN: The Amazon Resource Name (ARN) of the IAM role that defines the permissions that are applied when the role is assumed.
- Trust anchor ARN: The Amazon Resource Name (ARN) of the trust anchor that represents the certificate authority (CA) trusted by IAM Roles Anywhere to validate X.509 client certificates.
- Proxy name: Specify the name of the proxy that you want App Connect to use to pass the connector calls. This field is only required if calls need to go through a proxy. When using the IBM App Connect Enterprise Toolkit, the Proxy name should be specified in the form: {PolicyProjectName}:HTTPProxyPolicyName
- Region: The region of your Amazon EventBridge instance, for example,
- Click Connect.
For more information about identifying these connection details, see How to use IBM App Connect with Amazon EventBridge in the IBM App Connect in containers (Long Term Support Cycle-3) documentation.
- If one or more Amazon EventBridge connections
(accounts) are available, complete the following steps:
- Set the required connector properties in the wizard.
- When you have finished specifying the properties in the Connector Discovery wizard, click
Save. The values of the properties that you set in the wizard are returned to the Amazon EventBridge Request node in the IBM App Connect Enterprise Toolkit.
- When you finish discovery and save the property values, exit the Connector Discovery wizard by clicking the X in the upper-right corner of the window.
- Return to editing the Amazon EventBridge Request
node in the IBM App Connect
Enterprise Toolkit. The connector properties that were set in the Connector Discovery wizard (in step 6) are now visible on the Amazon EventBridge Request node. The Basic tab shows the values of the Action and Object properties that you set in the wizard. For example, if you selected Event buses > Create event bus in the wizard, the following properties are visible on the Basic tab of the node:
- Action -
CREATE - Object -
eventBus
The values of the Action and Object properties are displayed in read-only format. If you want to change these values, you can do so by clicking Launch Connector Discovery again and setting new values in the Connector Discovery wizard. You can modify other properties (if any) by clicking Edit next to the property.
The Schema base name property specifies the base name of the schema files that describe the format of the request and response messages that are sent and received from the Amazon EventBridge connector. The schema base name is set automatically the first time that you run discovery for the node, and it is based on the current flow name and node name. If you set this property manually before you run discovery for the first time, the value that you set will be used. If you rename the schemas after discovery, you must edit this property so that it matches the schema base name that is used by the renamed schemas in the project. If you change this property after discovery, you must either rename the schema names to match or run discovery again.
Depending on the action that was selected during discovery, the Connector Discovery wizard generates either a request schema and a response schema, or a response schema only. A request schema is generated only if the selected action and object require a request message. The generated request schema is used for validation of the request message. If the action was
RETRIEVEorDELETE, only the response schema is returned by the connector.The generated schema files are added to the project and can be used by a Mapping node for transforming input or output data. The full filename of the schema is derived from the schema base name (such as
gen/MyMessageFlow.Amazon_EventBridge_Request), suffixed with either response.schema.json or request.schema.json. You can open the schema by clicking Open request schema or Open response schema. - Action -
- Check that the property settings on the Amazon EventBridge Request node are correct and then save the message flow.
- On the Connection tab of the Amazon EventBridge Request node, select the policy that contains
the details of the security identity to be used for the connection. The policy has a type of
Amazon EventBridge.For more information, see Amazon EventBridge policy. - Optional: Set the Timeout property on the Connection tab to specify the time (in seconds) that the node waits for Amazon EventBridge to process the operation.
- The Filter tab of the Amazon EventBridge Request node contains properties that control
the way in which the message flow selects data. The initial values of these properties are taken
from the property values that were set for the Amazon EventBridge connector in the Connector Discovery
wizard (as described in step 6). If
you subsequently return to the Connector Discovery wizard and change the values of any properties
(by adding new conditions, for example) those updates are reflected in the properties set on the
node.
The Filter Options properties control which objects are to be operated upon when the Amazon EventBridge Request node executes. The Filter Limit properties control the maximum number of items to be retrieved and the action to be taken if the limit is exceeded.
You can modify the values of these properties on the Filter tab of the node, by clicking Edit next to the value that you want to modify in the Filter Options section, and by changing the property values that have been set in the Filter Limit section.
The property values can be either text values or ESQL or XPATH expressions that are resolved from the contents of the message that is passed to the Amazon EventBridge Request node as it executes.
- On the Request tab, set the Data location property to specify the location in the incoming message tree that contains the object data to be created in Amazon EventBridge. This data forms the request that is sent from the Amazon EventBridge Request node to the Amazon EventBridge system.
- On the Result tab, set the Output data location property to specify the location in the output message tree that contains the data of the record that is created in Amazon EventBridge.
- By default, request messages are validated against the request schema that was generated during connector discovery. You can turn off request validation or change the validation settings by using the Validation properties of the Amazon EventBridge Request node.
- Save the message flow.