Installing the capabilities in the OpenShift Console
If you want to select the capabilities to install and use only the default values, then it is easier to do that in the Form View of the IBM® CP4BA FileNet® Content Manager operator.
Before you begin
- Log in to your OCP or ROKS cluster as a cluster administrator.
To allow a nonadministrator user to create the Cloud Pak operators, see Allowing non-cluster administrators to install Operators
. - If you used the
All namespacesoption to install the Cloud Pak operator, switch to the project that you created for your CP4BA FileNet Content Manager deployment. - In the Installed Operators view, verify the status of the IBM CP4BA FileNet Content Manager operator installation reads succeeded, and verify the deployment by checking that all the pods are running.
Procedure
What to do next
- Accessing the capability services
A ConfigMap is created in the namespace to provide the cluster-specific details to access the services and applications. Components that are successfully deployed have URLs in the ConfigMap. If any components failed, the URLs and credentials are not included. The ConfigMap name is prefixed with the deployment name (default is
content). You can find the ConfigMap containing the routes information by clicking and then searching for the string "content-cp4ba-access-info".
The contents of the ConfigMap depends on the components that are included. Each component has one or more URLs, and if needed a username and password.
<component1> URL: <RouteUrlToAccessComponent1> <component1> Credentials: <UserName>/<Password> (optional) <component2> URL: <RouteUrlToAccessComponent2> <component2> Credentials: <UserName>/<Password> (optional)You can also click the YAML tab in the CP4BA deployment (
content) to view the endpointsuriof the installed capabilities.After you have the routes and admin user information, check whether you need to do the following tasks.
Tip: If you want or need to update values in a starter deployment that you made in the Form View, you must edit the deployment in the YAML View. You can edittrueorfalsevalues in the Form View, but the other parameters need to be done in the YAML View. You can access the custom resource from the YAML tab, or by clicking .
- Using the LDAP user registry
- The LDAP server comes with a set of predefined users and groups to use with your starter
environment. Changes to the user repository are not persisted after a pod restart.
- To provide a user for Task Manager, the following LDAP users and groups are created by the deployment.
- In the OCP console, select the project in which you deployed the Cloud Pak, and then click .
- User names:
cp4admin,user1,user2, up to and includinguser10. - Group names:
TaskAdmins,TaskUsers, andTaskAuditors.
The
cp4adminuser is assigned toTaskAdmins. The LDAP usersuser1-user5are assigned toTaskUsers, and the usersuser6-user10are assigned toTaskAuditors. - To modify an existing user's password:Note: Do not change the password of the
cp4adminuser after the Content Platform Engine (CPE) is initialized. Changing the password of the Domain admin user needs extra steps. For more information, see Update System User credentials
.- In the Red Hat® OpenShift console, go to , and
select the
content-openldap-customldifsecret. - Click .
- Change the password for a specified user and click Save.
- Go to , search for the openldap pod.
- In the overflow menu for the pod, click Delete Pod to restart it.
- In the Red Hat® OpenShift console, go to , and
select the
- To add a user:
- In the Red Hat OpenShift console, go to , and
select the
ic-openldap-customldifsecret. - Click .
- Copy and paste the attributes from an existing user, take out the unnecessary attributes, put
the information for the new user, and click Save. The following example is
for the user,
newuser:dn: uid=newuser,dc=example,dc=org uid: newuser cn: newuser sn: newuser userPassword: <password> objectClass: top objectClass: posixAccount objectClass: organizationalPerson objectClass: inetOrgPerson objectClass: person uidNumber: 14583345 gidNumber: 1456456 homeDirectory: /home/newuser/ mail: newuser@example.orgThe
uidNumbermust be a unique and different number from the existing uidNumbers. - Go to , search for the openldap pod.
- In the overflow menu for the pod, click Delete Pod to restart it.
- Sign in to the Common Web UI by following the steps in Accessing your cluster by using the console
. - Follow the steps in Managing console access
to add the user to the Cloud Pak
Platform UI (Zen).
- In the Red Hat OpenShift console, go to , and
select the
- To add a group:
- In the Red Hat OpenShift console, go to , and
select the
icp4adeploy-openldap-customldifsecret. - Click .
- Copy and paste the attributes from an existing group, take out the unnecessary attributes, put
the information for the new group, and click Save.
The following example is for a group name of "
NewGroup".dn: cn=NewGroup,dc=example,dc=org objectClass: groupOfNames objectClass: top cn: NewGroup member: uid=user1,dc=example,dc=org member: uid=user2,dc=example,dc=org member: uid=user3,dc=example,dc=org member: uid=user4,dc=example,dc=org - Go to , and search for the openldap pod.
- In the overflow menu for the pod, click Delete Pod to restart it.
- Sign in to the Common Web UI by following the steps in Accessing your cluster by using the console
. - Follow the steps in Managing user groups
to add the group to the Cloud Pak
Platform UI (Zen).
- In the Red Hat OpenShift console, go to , and
select the
- To provide a user for Task Manager, the following LDAP users and groups are created by the deployment.
- Creating storage policy and associate the Advanced Storage Area that was created during the deployment
-
- Create a storage policy and associate the storage policy with the existing advanced storage
area. See Storage policies
for more information. - Assign the newly created storage policy to existing document class.
- Create a storage policy and associate the storage policy with the existing advanced storage
area. See Storage policies
- Enabling GraphQL integrated development environments for FileNet Content Manager
- The GraphQL integrated development environment (IDE) is not enabled by default because of a
security risk. If you want to include this capability in your starter environment, add the parameter
to enable the IDE.
- Click , then click YAML to go into the YAML view.
- Add the following parameter to the
file:
graphql: graphql_production_setting: enable_graph_iql: true - Apply the updated custom resource YAML file.
In the next reconciliation loop, the operator picks up the change and includes GraphQL with your deployment.
- Importing sample data for IBM Business Automation Insights
- If you selected Business Automation Insights as an optional
component, you can test and explore the component by importing sample data. For more information,
see https://github.com/icp4a/bai-data-samples

- Enabling Business Automation Insights for FileNet Content Manager
- If you selected Business Automation Insights as an optional
component and included the Content event emitter in your deployment, you must update the deployment
to add the Kafka certificate to the trusted certificate list.
- Create a secret with your Kafka certificate, for
example:
oc create secret generic eventstreamsecret --from-file=tls.crt=eventstream.crt - Update the
trusted_certificate_listparameter to the YAML View in the OCP console to include the secret that you created.shared_configuration: trusted_certificate_list: ['eventstreamsecret']If other certificates are in the list, use a comma to separate your new entry.
- Apply the updated custom resource YAML file.
- Create a secret with your Kafka certificate, for
example:
- Verifying the creation of the CDD repository for Content Designer
- If you installed IBM FileNet Content
Manager, use the Gitea pod terminal from the Red Hat OpenShift console to run the following command:
/ # ls -l /data/git/repositories/content-designer/- If the output shows cdd.git, then the content-designer
directory exists and the Git repository is created
successfully.
drwxr-xr-x 7 git git 147 May 5 15:58 cdd.git - If the output does not show the CDD repository, go to the operator logs to understand why the deployment failed.
- If the output shows cdd.git, then the content-designer
directory exists and the Git repository is created
successfully.