Installing

The following sections outlines the steps to set up IBM Connect Direct Web Services. This workflow also describes how to plan, configure, uninstall, and troubleshoot the IBM® Connect:Direct® Web Service.

The table lists the necessary installation and configuration tasks that you must perform to complete the installation.

Task For more information, see the following sections in this guide
Installing IBM Connect:Direct Web Service

Installing on UNIX

Installing on Windows

Installing on AIX

Configuring a secure connection between IBM Connect:Direct Web Console and a IBM Connect:Direct server Establishing a Secure Connection between IBM Connect:Direct and IBM Connect:Direct Web Service

Configuring the property files that control system-wide IBM Connect:Direct Web Console properties.

Configuring application.properties

Configuring Web Services Logs

Connect:Direct Web Services Logs
Configuring Control Center integration Connect:Direct Web Services and Control Center Integration

Installing on UNIX

Before you begin

  • Review the system requirements. For more information, see Minimum Hardware and Software Requirements.
  • Make sure you have added firewall rules for inbound and outbound connections between Web Services and Connect Direct Server. Firewall rules must allow inbound connections to the specified Web Services port. Connect Direct server must also have its API port open for web service.

Procedure

To install the Connect:Direct Web Services from command line on a UNIX Operating System follow the steps given below.

Note:
  • If you are installing as a root user, the product will be installed across system and therefore, it is recommended not to install as a root user. You should install it in a shared area with limited access so as not to disrupt any permission changes on the /root directory.
  • Ensure that you login to the same functional account to upgrade Connect:Direct Web Services.

  1. If you have downloaded the software from IBM Passport Advantage go to the download folder.
    Note: Passport Advantage provides access to your IBM software purchases, so you can download products directly to the computers where you want to install them. For information on the how to download software using Passport Advantage see, Passport Advantage.
  2. Untar the installer .tar.gz file and refer cdws_install_cdws_overview.html table.
    % tar -zxvf $INSTALLER_FILENAME
  3. Run the remove/MFTWebServicesInstall.sh script. To check privileges, run the following command.
    [user@xxd]# ls -l MFTWebServicesInstall.sh
    -r-xr-x---. 1 <user> <user> <filesize> <date> MFTWebServicesInstall.sh
    
  4. The installation menu appears.

    Preparing to install

    Extracting the JRE from the installer archive...

    Unpacking the JRE...

    Extracting the installation resources from the installer archive...

    Configuring the installer for this system's environment...

    Launching installer...

    ===============================================================================

    MFTWebServices (created with InstallAnywhere)

    -------------------------------------------------------------------------------

    Preparing CONSOLE Mode Installation...

    ===============================================================================

    Introduction

    ------------

    Welcome to the installation wizard for MFTWebServices.

    This wizard guides you through the installation of MFTWebServices.

    You are strongly recommended to quit all programs before continuing with this

    installation.

    Respond to each prompt to proceed to the next step in the installation.

    You may cancel this installation at any time by typing 'quit'.

    Licensed Materials - Property of IBM Corp. © IBM Corporation and other(s).

    2023.

    PRESS <ENTER> TO CONTINUE:

  5. Enter the absolute installation path and press ENTER to confirm the location.
    Choose Install Folder

    ----------------------------

    Where would you like to install?

    Default Install Folder: $HOME/MFTWebServices

    ENTER AN ABSOLUTE PATH, OR PRESS <ENTER> TO ACCEPT THE DEFAULT

  6. Enter Secure port number details that Connect:Direct Web Server uses to connect to the Web Service and press ENTER to continue.
    Port for Web Server

    --------------------------

    Enter the ConnectDirectWebServices secure sever port.

    eg. https://<hostname:port>/cdws-doc/signOn.html

    https://<hostname:port>/cdws-ui/index.html

    Secure Port (Default: 9443):

  7. Pre-Installation summary appears.
    Press ENTER to continue.

    Pre-Installation summary appears.

    ===============================================================================

    Pre-Installation Summary

    ------------------------

    Review the following information before you continue the installation:

    Product Name:

    MFTWebServices

    Install Folder:

    /root/MFTWebServices

    Web Server Port

    9443

    Version

    6.3.0

    Disk Space Information (for Installation Target):

    Required: 1,120.46 MegaBytes

    Available: 31,809.7 MegaBytes

    PRESS <ENTER> TO CONTINUE:

  8. User is prompted to set the Keystore password.

    Keystore Password

    ------------------------

    Enter a password for Connect:Direct Web Service's keystore. (Please retain this password as it will be required in the future.)

    Please Enter the Password:

    Note: Keystore password must be 6 ore more characters. Keystore password should not include any of these special characters, o "%^{}|<>~'`.
  9. Enter the Keystore password again to confirm the user input in the previous step.
    Confirm Password

    ----------------------------

    Please Enter the Password again:

    Note:

    Keystore password must be 6 or more characters.

    Keystore password should not include any of these special characters, o "%^{}|<>~'`.

  10. User is prompted to set the truststore password.

    Truststore Password

    -------------------

    Enter a password for Connect:Direct Web Service's truststore. (Please retain this password as it will be required in the future.)

    Please Enter the Password:

  11. Enter the Truststore password again to confirm the user input in the previous step.

    ===============================================================================

    Confirm Truststore Password

    ---------------------------

    Please Enter the Password again:

    ===============================================================================

    Note:

    Truststore password must be 6 or more characters.

    Truststore password should not include any of these special characters, o "%^{}|<>~'`.

  12. Configure Cerificate information screen appears. Enter the Certificate option serial number for the certificate type that you would like to configure a Self Signed certificate and CA Signed certificate.
    Note: When installation is completed, users can add a CA Signed certificate or any other certificate in existing Keystore/Truststore. Users can also add a new Keystore/Truststore. For more information, see Configuring Keystore/Truststore.

    Configure Certificate

    ---------------------------

    1. Self Signed Certificate: A certificate is automatically generated from input provided by you.

    2. CA Signed Certificate: Import a CA Signed certificate, its private key, and the CA and intermediate certificates.

    Please note that certificate configuration can be updated after installation.

    Please refer IBM CDWS 6.3 documentation for more details.

    Enter Your Choice:

    1. Generate Self Signed Certificate

    2. Import CA Signed Certificate

    (Default: 1):

  13. If enter[1], answer the following prompts related to Self Signed Certificate details.

    Certificate Label

    -----------------

    Enter Certificate Label (Default: mftwebservices):

    ========================================

    Certificate Expiry Time

    -----------------------

    Enter Certificate expiry time(MAX value: 3649 days) (Default: 365):

    ========================================

    Common Name(CN)

    ---------------

    Enter Common Name(CN) (Default: <hostname>):

    ========================================

    Organization Name

    -----------------

    Enter name of the organization (Default: OrganizationName):

    ========================================

    Locality Name

    -------------

    Enter name of the locality (Default: Irving):

    ========================================

    State Name

    ----------

    Enter name of the State (Default: Texas):

    ========================================

    Country Name

    ------------

    Enter Country Name (Default: US):

    ========================================

    Enter E-mail Address

    --------------------

    Enter E-mail Address (Default: noreply@noreply.com):

    ========================================

    Enter DNS Name

    --------------

    Enter DNS Name (Default: <hostname>):

    ========================================

    Enter IP Address

    ----------------

    Enter IP Address (Default: <IPv4 address>):

    Table below describes Self Signed certificate field, descriptions, example, and default values.

    Table 1. Self Signed Certificate generation entries and descriptions
    Entry Description Example value Default Value
    Certificate label Any descriptive name to identify the certificate. mycertificatename mftwebservices
    Certificate Expiry Time Enter the certificate expiration time in days 278 days 365 days

    Max value: 3649 days

    Common Name (CN) Identifies the host name associated with the certificate yourdomain <hostname>
    Organization

    The legal name of your organization. This should not be abbreviated and should include suffixes such as Inc, Corp, or LLC.

    Note: Do not abbreviate or use any of these symbols: ! @ # $ % ^ * ( ) ~ ? > < / \.
    MyOrganizationName Inc. organizationname
    Locality

    The city where your organization is located.

    Irving Irving
    State The state/region where your organization is located.
    Note: Do not use abbreviations.
    Texas Texas
    Country

    The two-letter ISO code for the country where your organization is location.

    US US
    E-mail ID An email address used to contact your organization. support@mydomain.com noreply@noreply.com
    DNS Name Identifies the domain name associated with the certificate. localhost <hostname>
    IP Address Identifies the IP Address associated with the certificate 127.0.0.1 <IPv4 address>
  14. Self Signed certificate details display. Press ENTER to continue.
    The certificate will be generated with following details:

    EYSTORE NAME: ssl-server.jks

    KEYSIZE: 2048

    CERTIFICATE LABEL:"mftwebservices"

    CERTIFICATE EXPIRY TIME: "365"

    CN: <hostname>

    ORGANIZATION: "OrganizationName"

    LOCALITY: "Irving"

    STATE: "Texas"

    COUNTRY: "US"

    EMAIL ID: "noreply@noreply.com"

    ALGORITHM: SHA256withRSA

    FQDN: <hostname>

    IP ADDRESS: <IPv4 Address>

    PRESS <ENTER> TO CONTINUE:

  15. Self Signed certificate is generated successfully.
    Certificate Generated Successfully.

    Keystore NAME: ssl-server.jks

    CERTIFICATE LABEL: mftwebservices

    PATH: /$HOME/MFTWebServicesDoc/mftws/BOOT-INF/classes/ssl-server.jks

    ALGORITHM: SHA256withRSA

    PRESS <ENTER> TO CONTINUE:

  16. Enter the absolute location path to export the self signed public certificate and press ENTER to continue.
    Note: If set EMPTY, export will be skipped.

    Export Self Signed Public Certificate

    -------------------------------------

    Note: This public certificate can be imported to truststore of the server to

    make secure connection.

    Please input a full path to save exported self signed public certificate.

    Ex. /root/MFTWebServices

    If set empty, then export will be skipped during installation, and you can

    export certificate later via CDWS Admin UI.

    :

  17. If enter [2], user is prompted to set CA Signed certificate details

    CA Signed Certificate File

    --------------------------

    Please input a certificate file in PEM or PKCS12 format with full path.

    Note : The file must contain the private key, the CA Signed certificate, the

    CA certificate and all intermediate certificates.

    Ex. /root/certificates/caCert.pem

    :

    Then ask for the password as below:

    Enter CA Signed Certificate private key password

    ------------------------------------------------

    Importing CA Signed Certificate requires private key password.

    Please Enter the Password:

    After entering the password, certificate details window prompt as below:

    Certificate Details

    -------------------

    The certificate will be added of the following details:

    ________________________________________________________

    KEYSTORE NAME: ssl-server.jks

    KEYSIZE: 2048

    CERTIFICATE LABEL: mftwebservices

    PRESS <ENTER> TO CONTINUE:

  18. After configuring the certificate, user is prompted to set Trusted Certificate details.
    Note: If set EMPTY, import will be skipped.

    Import Trusted Certificate

    --------------------------

    This trusted certificate will be added in truststore of the CDWS to make

    secure connection with the connect direct node.

    Please input a certificate file in base64 encoded PEM format Certificate file.

    Ex. /root/certificates/trustCert.pem

    If set empty, then import will be skipped during installation, and you can

    import certificate later into trusted store via CDWS Admin UI.

    :

  19. Installation completed message appears and press ENTER to exit the installation screen
    Installation completed message as below:

    Installation Completed

    ------------------------------------------------------------

    Installation and Certificate configuration is completed.

    ConnectDirectWebServices-<$VERSION> has been successfully installed to:

    /$HOME/MFTWebServices

    MFTWebServices User Interface is available at :

    https://<hostname:port>/cdws-ui/index.html

    MFTWebServices API reference is available at :

    https://<hostname:port>/cdws-doc/signOn.html

    PRESS <ENTER> TO EXIT THE INSTALLER

What to do next

  1. Configuration settings for IBM Connect:Direct Web Service
  2. Logging in

Directory Structure

The following figure illustrates IBM Connect:Direct Web Service directory structure after a successful installation:


| --- bin

| --- jre

| --- JSONFileSystem

| --- license

| --- logs

| --- mftws

| --- README.txt

| --- RestLogs

| --- sampleRESTClientScripts

| --- UninstallerData

Installing on Windows

Before you begin

Before you begin, see Minimum Hardware and Software Requirements.

Make sure you have added firewall rules for inbound and outbound connections between Web Services and Connect Direct Server. Firewall rules must allow inbound connections to the specified Web Services port. Connect Direct server must also have its API port open for web service.

Procedure

To install IBM Connect:Direct Web Service on a Windows platform follow the steps given below.

  1. If you downloaded the software from IBM Passport Advantage, unzip the Installer zip file and double click on MFTWebServices.exe file.
    Note: For information on the how to download software using Passport Advantage see, Passport Advantage.
    InstallAnywhere window appears containing a progress bar and Cancel button. Wait for the progress bar to complete to 100%.
  2. Installation Folder window appears. This window serves as a welcome screen with a Guided Setup on the left. The Guided Step up is an installation status panel. As you complete each task, the status panel is updated. Click Next. In the Installation Folder window, use the default location or click Choose and specify a different location. Click Restore Default Folder to choose the default location.
  3. Click Next to continue.
  4. The Ports window appears. Enter the following:
    • Secure Port that the Web Services uses to connect to the Web Server. For example,
      https://<hostname:port>/cdws-doc/signOn.html
      https://<hostname:port>/cdws-ui/index.html
         
      Default: 9443
  5. Click Next to continue.
  6. In the Pre-Installation Summary window, review the information, and then click Install.
  7. The Enter Keystore Password screen appears.
  8. Enter the Keystore password again to confirm the user input. Click Next.
    Note:

    Keystore password must be 6 or more characters.

    Keystore password should not include any of these special characters, o "%^{}|<>~'`.

  9. The Enter Truststore Password screen appears.
  10. Enter the Truststore password again to confirm the user input. Click Next.
    Note:

    Truststore password must be 6 or more characters.

    Truststore password should not include any of these special characters, o "%^{}|<>~'`.

  11. Configure Certificate window appears.
    This window provides users two options that can be used to configure a certificate:
    1. Generate Self Signed Certificate
    2. Import CA Signed Certificate
    Note: When installation is complete, users can add a CA Signed certificate or any other certificate in the existing Keystore/Truststore. User can also add a new Keystore/Truststore. For more information, see Configuring Keystore/Truststore.
  12. Select Generate Self Signed Certificate option to generate a User-Defined certificate.
  13. The Self Signed Certificate screen appears. Enter certificate details in the fields, as applicable. To generate a Self Signed certificate click Next.

    Table below describes Self Signed certificate field, descriptions, example, and default values.

    Table 2. Self Signed Certificate generation field descriptions
    Fields Description Example value Default Value
    Certificate label Any descriptive name to identify the certificate. mycertificatename mftwebservices
    Certificate Expiry Time Enter the certificate expiration date in days 278 days 365 days

    Max value: 3649 days

    Common Name (CN) Identifies the host name associated with the certificate yourdomain <hostname>
    Organization

    The legal name of your organization. This should not be abbreviated and should include suffixes such as Inc, Corp, or LLC.

    Note: Do not abbreviate or use any of these symbols: ! @ # $ % ^ * ( ) ~ ? > < / \.
    MyOrganizationName Inc. organizationname
    Locality

    The city where your organization is located.

    Irving Irving
    State The state/region where your organization is located.
    Note: Do not use abbreviations.
    Texas Texas
    Country

    The two-letter ISO code for the country where your organization is location.

    US US
    E-mail ID An email address used to contact your organization. support@mydomain.com noreply@noreply.com
    DNS Name Identifies the domain name associated with the certificate. localhost <hostname>
    IP Address Identifies the IP Address associated with the certificate. 127.0.0.1 <IPv4 address>
  14. Self Signed certificate details summary window appears. Click Next to continue.
  15. Self Signed certificate is generated and Click Next to continue.
  16. Export Self Signed Public Certificate screen appears, user must select a valid path to save the certificate. This public certificate can be imported into the server's truststore to establish a secure connection.
    Note: If left empty, the export process will be skipped.
  17. Alternatively, users can select Import CA Signed Certificate option to configure a CA Signed certificate in keystore.
  18. In the Select CA Signed certificate screen, user has to choose a valid path to the CA signed certificate to be imported.
    Note: Certificate file must be either in PEM or PCKS12 format and it must contain the private key, the CA signed certificate, the CA certificate and all intermediate certificates.
  19. Enter the Private key password of the certificate. Click Next to import the certificate.
  20. The certificate will get imported successfully. Click Next to continue.
  21. Import Trusted Certificate screen appears, user has to choose valid path to the trusted certificate to configure in the truststore of the IBM Connect:Direct Web Service to make secure connection with the Connect:Direct node
  22. Installation Completed screen appears. Click Done.

What to do next

  1. Configuration settings for IBM Connect:Direct Web Service
  2. Logging in

Directory Structure

The following figure illustrates IBM Connect:Direct Web Service directory structure after a successful installation on a Windows Operating System:

| --- jre

| --- mftws

| --- license

| --- sampleRESTClientScripts

| --- Encryption

| --- README.txtc

| --- bin

| --- RestLogs

| --- JSONFileSystem

| --- Uninstall_MFTWebServices

| --- logs

| --- clear-syslog.bat
      

Installing on AIX

Before you begin

Connect:Direct Web Services on AIX requires the following system libraries to be installed:
  • libatomic.a
  • libgcc_s.a
  • libc++.a
  • libunwind.a
  • libatomic.a
  • libc++abi.a

Make sure you add firewall rules for inbound and outbound connections between Web Services and Connect Direct Server. Firewall rules must allow inbound connections to the specified Web Services port. Connect Direct server must also have its API port open for web service.

Note: Ensure that you install using Root Privilege.

About this task

Follow the procedure given below to prepare and complete installation on AIX.

Procedure

  1. Download the appropriate libgcc RPM from https://www.ibm.com/support/pages/aix-toolbox-open-source-software-downloads-alpha.
    1. For AIX 7.1, download the following RPM:
      libgcc-6.3.0-2.aix7.1.ppc.rpm
    2. For AIX 7.2, download the following RPM:
      libgcc-8.1.0-2.aix7.2.ppc.rpm
  2. To use Java 17 runtime, you need the XL C++ runtime 16.1.0.7 or later. For more details,refer to the https://www.ibm.com/support/pages/fix-list-xl-cc-runtime-aix#161X.
  3. When the libgcc RPM is installed, copy the libatomic.a and libgcc_s.a libraries to /usr/lib directory.
    1. For AIX 7.1 copy from
      /opt/freeware/lib/gcc/powerpc-ibm-aix7.1.0.0/6.3.0/ppc64/
    2. For AIX 7.2 copy from
      /opt/freeware/lib/gcc/powerpc-ibm-aix7.2.0.0/8.1.0/ppc64/
  4. If you have downloaded the Web Services for AIX installation software from Fix Central or Passport Advantage go to the download folder.
  5. Refer cdws_install_cdws_overview.html table. To continue installing follow the steps described in Installing on UNIX

Installing on zLinux

Before you begin

Connect:Direct Web Services on zLinux requires the following system libraries to be installed:
Note: Ensure that you install using Root Privilege.

Make sure you add firewall rules for inbound and outbound connections between Web Services and Connect Direct Server. Firewall rules must allow inbound connections to the specified Web Services port. Connect Direct server must also have its API port open for web service.

About this task

Follow the procedure given below to prepare and complete installation on zLinux.

Procedure

  1. If you have downloaded the Web Services for zLinux installation software from Fix Central or Passport Advantage go to the download folder.
  2. Refer cdws_install_cdws_overview.html table. To continue installing follow the steps described in, Installing on UNIX

Installing IBM Connect:Direct Web Service using an IBM Certified Container Software

IBM Certified Container Software (CCS) can be installed on the Kubernetes based cluster.

Kubernetes is an open-source container orchestration engine to automate the deployment, scaling and management of containerized applications. This application release has been qualified and certified on an on-premise Red Hat® OpenShift® Container Platform (OCP) which is an enterprise-ready Kubernetes container platform with full-stack automated operations to manage the deployment life-cycle.

IBM CCS offers a container image and a helm chart. It meets the standard criteria for the packaging and deployment of containerized software. In addition, the container image is IBM certified.

For more details, refer to the below links:

Pre-installation Tasks

Before you install IBM Certified Container Software for Connect:Direct Web Services, complete the following tasks:
  1. Setting up Your Registry Server: Ensure you have a registry server in place to host the image required for installation.
  2. Setting up Namespace or Project: Ensure that you have an existing namespace/project or create a new one if necessary.
  3. Installing and configuring IBM Licensing and Metering service: Ensure that this service is installed on your cluster.
  4. Downloading the Certified Container Software: Ensure that the installation files are available on your client system.
  5. Creating the Security Context Constraints for OpenShift Cluster: Make sure you have generated the necessary SCC using the provided scripts.
  6. Creating storage for data persistence: Ensure you have required storage option ready to be used.
  7. Creating secret: Ensure you have secrets needed for Connect:Direct Web Services configuration and pull secret (if required).
  8. Configuring the Deployment: Review the various parameters in the values.yaml file along with their default values. Update any default values as necessary and as supported by IBM Certified Container Software for Connect:Direct for Web Services.

Post-installation tasks

The post deployment configuration steps can be performed via:

• Accessing Connect Direct Web Services

  • Access Connect Direct Web Services using the Load Balancer or External IP address and the port to which container server port (9443) is mapped. For more information, refer to Exposed Services.
  • Issue the following command to get the external IP address
    kubectl get svc

• Attaching to the container

Follow the steps given below:
  • Issue the following command to get the pod name
    kubectl get pods -n <namespace>
  • Issue the following command to attach to the container
    kubectl exec -it <pod name> bash

• Restarting Connect:Direct Web Services inside container

  • Sometime, few configurations of IBM Connect:Direct Web Services needs its services to be restarted. To restart the Connect:Direct Web Services in container, delete the existing pod. Run below command to delete the pod:
    kubectl delete pod <pod name> -n <namespace>

Known Limitations

  • High availability and scalability are supported in traditional way of Connect:Direct Web Services deployment using Kubernetes load balancer service.
  • IBM Connect:Direct Web Services chart supports only the x64 architecture.

Configure AWS CloudWatch for Rendering Container Logs (EKS)

Configure Amazon CloudWatch Observability for Amazon EKS to collect, store, monitor, and analyze container logs and metrics from rendering workloads.

Prerequisites

Ensure the following prerequisites are in place:
  • An existing Amazon EKS cluster
  • EKS cluster version 1.23 or later
  • AWS CLI version 2 installed and configured
  • kubectl installed and configured for cluster access

Required IAM Permissions

Verify that the user or role performing this procedure has the following permissions:
  • Amazon EKS
  • AWS IAM
  • Amazon CloudWatch

Configure IAM for Worker Nodes

Configure IAM permissions for EKS worker nodes so that CloudWatch can collect and store container logs.

Complete the following steps to configure the required IAM role permissions:
  1. Open the AWS Management Console.
  2. Go to IAM > Roles.
  3. Locate the IAM role used by the EKS worker nodes.
  4. Attach one of the following policies to allow worker nodes to publish logs to CloudWatch:
    Option 1: AWS Managed Policy (Simpler) - CloudWatchLogsFullAccess
    Option 2: Custom Policy (Least Privilege - Recommended)
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "logs:CreateLogGroup",
            "logs:CreateLogStream",
            "logs:PutLogEvents",
            "logs:DescribeLogStreams"
          ],
          "Resource": "*"
        }
      ]
    }                
Step 1: Install the Amazon CloudWatch Observability Add-on
Install the Amazon CloudWatch Observability add-on to enable log collection, metrics monitoring, and observability features for the EKS cluster.
  1. Open the Amazon EKS console.
  2. Select the EKS cluster.
  3. Go to Add-ons.
  4. Select Get more add-ons.
  5. Search for Amazon CloudWatch Observability.
  6. Select Install.
Configuration options
Review and configure the add-on access and namespace settings before completing the installation.
  • Add-on access: Select EKS Pod Identity (Alternatively, IAM Roles for Service Accounts (IRSA) can be used.)
  • Namespace: Use the default namespace (amazon-cloudwatch) or provide a custom namespace.
  • Select Install or Create.
  • Wait for the installation to complete.
Step 2: Verify Add-on Status
Verify that the CloudWatch Observability add-on and its required components are running successfully in the cluster.
  1. In the EKS console, open Add-ons.
  2. Confirm that the Amazon CloudWatch Observability add-on status is Active.
  3. Select the add-on name to view detailed information.
  4. Optional: Verify pods by running:
    kubectl get pods -n amazon-cloudwatch
    Confirm that the following exported components are deployed and running after installation:
    • cloudwatch-agent
    • fluent-bit
Step 3: View Logs in CloudWatch
Access CloudWatch Logs to verify that container node, and cluster logs are being collected and stored successfully.
  1. Open the Amazon CloudWatch console.
  2. Go to Logs > Log groups.

    CloudWatch automatically creates the following log groups:

    /aws/containerinsights/<cluster-name>/application
    /aws/containerinsights/<cluster-name>/performance
    /aws/containerinsights/<cluster-name>/host
    Log group details
    • application: Application and container logs
    • performance: Cluster and workload performance metrics
    • host: Node-level logs and metrics

    Logs are automatically created and stored using this naming convention.

Optional: Enable CloudWatch Application Signals

CloudWatch Application Signals collects application-level metrics and traces such as latency and availability without requiring code changes.

Complete the following steps to enable Application Signals for the EKS cluster.

Steps to enable
  1. Open Amazon CloudWatch Observability.
  2. Select Enable CloudWatch Application Signals.
  3. Under Platform, select EKS.
  4. Choose the EKS cluster.
  5. Select a setup method:
    • Console (recommended)
    • Manifest (YAML)
  6. Complete the configuration and select Enable.

(Optional) Customize Log Collection

Customize CloudWatch log collection settings to align with operational, monitoring, and compliance requirements.

Advanced users only:
  1. Open the Amazon CloudWatch console.
  2. Navigate to Logs > Log groups.
  3. Adjust log retention policies as needed.
Note: This configuration changes are intended for users who require customized log retention or log management settings.

Upgrade or Remove the Add-on (UI)

Manage the CloudWatch Observability add-on throughout its lifecycle by upgrading to a newer version or removing it from the cluster.

Upgrade the Add-on
Upgrade the add-on to access the latest features, performance improvements, security updates, and bug fixes.
  1. Open the Amazon EKS console.
  2. Select the EKS cluster.
  3. Navigate to Add-ons.
  4. Select Amazon CloudWatch Observability.
  5. Click Update.
  6. Choose the latest available version.
Remove the Add-on
Remove the add-on when CloudWatch observability features are no longer required for the cluster.
  1. Select the add-on.
  2. Select Remove.
  3. Confirm deletion.

Log Analysis in CloudWatch

Use CloudWatch log analysis tools to search, filter, troubleshoot, and gain operational insights from collected container logs.

For log analysis, the following CloudWatch tools are commonly used:
  • Log Tail - Used to view live logs in near real-time.
  • Logs Insights - Used for querying, filtering, and analyzing logs.

Common Logs Insights Query Commands

The following commands are commonly used when building CloudWatch Logs Insights queries for filtering, aggregating, and analyzing log data.
  • fields
  • filter
  • filterIndex (new)
  • stats
  • sort
  • limit
  • parse
  • dedup
  • pattern
  • diff
  • unnest (new)

For more information about Logs Insights query commands and syntax, see CloudWatch Logs Insights query syntax.

Sample CloudWatch Logs Insights Queries

Use the following example queries as a starting point for monitoring application behavior, troubleshooting issues, and analyzing log data.
  1. View Recent Application Logs: Use this query to display the most recent application log entries.
    fields @timestamp, @message
    sort @timestamp desc
    limit 50 
  2. Filter Logs for a Specific Namespace: Use this query to retrieve logs generated by workloads running in a specific Kubernetes namespace.
    fields @timestamp, kubernetes.namespace_name, @message
    filter kubernetes.namespace_name = "default"
    sort @timestamp desc
    limit 50
  3. Filter Logs for a Specific Pod: Use this query to view log entries generated by a specific Kubernetes pod.
    fields @timestamp, kubernetes.pod_name, @message
    filter kubernetes.pod_name like /my-app/
    sort @timestamp desc
  4. Search for Error Messages: Use this query to identify log entries that contain error messages.
    fields @timestamp, @message
    filter @message like /error/i
    sort @timestamp desc
    limit 100
  5. Count Errors Over Time: Use this query to analyze error occurrence trends over a specified time interval.
    filter @message like /error/i
    stats count() as error_count by bin(5m)
  6. View Logs by Container Name: Use this query to display log entries generated by a specific container.
    fields @timestamp, kubernetes.container_name, @message
    filter kubernetes.container_name = "app-container"
    sort @timestamp desc
  7. Duplicate Repeated Log Messages: Use this query to remove duplicate log messages and focus on unique events during log analysis.
    fields @message
    dedup @message
    limit 20

Migrating to Connect:Direct Web Services using Certified Container Software

Follow the steps given below to create a backup and restore IBM Connect:Direct Web Services using Certified Container Software:
  1. Create a backup
    To create a backup of configuration data and other information such as logs and configuration files, present in the persistent volume, follow the steps given below:
    1. Go to mount path of Persistent Volume.
    2. Make copy of the following directories and store them at a secured location:
      • json
      • restlogs
      • configFiles
        Note:
        • Update the path in .hiddenFile for the CDWS keystore and truststore. The installation path is /opt/MFTWebServices/.
        • If Connect:Direct Web Services is installed in a conventional mode, create a backup of the following directories:
          • INSTALLATION_DIR/JSONFileSystem
          • INSTALLATION_DIR/RestLogs
          • INSTALLATION_DIR/mftws/BOOT-INF/classes

        From the classes directory, only following files are required: application.properties, .hiddenFile, ssl-server.jks, trustedkeystore.jks, log4j2.yaml. These files will be placed in configFiles directory on persistent volume.

  2. Restore the data in a new deployment
    To restore data in a new deployment, follow the steps given below:
    1. Create a Persistent Volume.
    2. Copy all the backed-up directories to the mount path of Persistent Volume.
  3. For other prerequisites such as secrets see, Pre-installation Tasks.
  4. Upgrade to Certified Container Software
    Create a new instance of chart using the following helm CLI command:
    helm install <release-name> --set license=true,image.repository=<reponame>,image.tag=<image tag>,image.imageSecrets=<image pull secret>,secret.secretName=<CDWS secret name> ibm-cdws-1.0.x.tgz

Silent Install and Silent Upgrade for Connect:Direct Web Services

Connect:Direct Web Services administrators can use procedures defined in the following sections to run an unattended install with minimal user interaction. Silent installs can be used for repetitive installs in your deployment.

Installation and Upgrade Considerations

  • Ensure that the installation executable file, script, and silentInstall.properties file are placed in the same directory. Also, do not rename these files.

  • The same silentInstall.properties file that was used to perform silent installation must be used to upgrade Connect:Direct Web Services to a different version.
  • When you upgrade from version < 6.0.0.5 the user must update database properties that is, Redis properties (REDIS_PORT) must be replaced with changed PostgreSQL properties (POSTGRES_PORT and POSTGRESQL_PASSWORD) in the silentInstall.properties file.

    Attention: CDWS 6.2.0.10 onwards steps related to Postgres are not applicable
A Silent install is implemented in two steps:
  1. Supply values in the silentInstall.properties file included in software package, Fix Pack 3 (v6.0.0.3) and above.

    silentInstall.properties file defines the installation configuration that you would normally enter during an interactive installation process (console-mode installation). The silentInstall.properties file is subsequently used to silently install Connect:Direct Web Services.

    Before you begin

    The following Connect:Direct Web Services minimum version levels are required to perform silent installation:

    Table 3.
    Product Minimum Version
    IBM Connect:Direct Web Services Fix Pack 3 (v6.0.0.3)
    The following table lists script files to be used by Operating Systems to perform unattended installation.
    Table 4. Silent Installer script name by OS
    Operating System Silent installation script name
    Windows MFTWebServicesInstall.bat
    UNIX MFTWebServicesInstall.sh
  2. To perform silent installation see the following examples:

    UNIX environment (RHEL)

    When executing the MFTWebServicesInstall.sh, pass the argument silent to the script.

    [user@SolQA-02 CDWS_6.1.0.1]$ ./MFTWebServicesInstall.sh silent
    Installing Webservices...
    Installer installed/upgraded correctly.
    Please refer INSTALLATION_DIRECTORY/README.txt for getting started with MFTWebservices.
    Press any key to continue.....

    WINDOWS environment

    To install in a Windows environment, execute the MFTWebservicesInstall.bat file available in the download folder.
    C:\Users\Administrator\Desktop\CDWS_Installer\CDWS_6.1.0.0_01_05_2020>MFTWebservicesInstall.bat 
    Installing Webservices...
    "Exit Code: 0"
    Installer installed/upgraded correctly.
    Please refer INSTALLTION_DIRECTORY/README.txt for getting started with MFTWebservices.
    Press any key to continue . . .

    Error Handling during Silent Install

    • If you encounter problems when performing a silent installation review the log file, failure.txt, available inside the logs directory at the same location where you have installed Connect:Direct Web Services.
    • If silent installation does not begin:
      • Cleanup the registry settings in the .com.zero.registry.xml

        In UNIX environment, this file is located in /var for Root users and $HOME/for non-root users. In Windows, this file is located in C:\Program Files\Zero G Registry.

      • Edit the Zero G registry file to remove entries that begin with MFTWebServices and delete any entries beginning with the following tag:
        <product name="MFTWebServices">...</product>
      • Attempt silent installation again.

Connect:Direct Web Services Silent Install and Silent Upgrade Example

Procedure
  1. Download the installation package from Fix Central and navigate to the directory where the installation package is downloaded.

    The following files will be used to perform Silent Installation:

    • silentInstall.properties
    • MFTWebservices.exe

    • MFTWebservicesInstall.bat (for Windows)
    • MFTWebServicesInstall.sh (for UNIX)
  2. Modify the silentInstall.properties file based on your requirements.
Table 5. Common Parameters for Window/Unix-based Silent installation
Parameters Mandatory/Optional Description
Read-Only parameters
INSTALLER_UI Use default value Do not modify this attribute.
CHOSEN_INSTALL_SET Use default value Do not modify this attribute.
Editable Parameters
USER_INSTALL_DIR M The directory where the installer will get installed.

For Unix, example: /root/MFTWebServices

For Windows, directories should be separated with double backslash. (\\)

Example: C:\\Program Files\\MFTWebservices

SSL_PORT M Port number used to communicate with the Jetty server.
KEYSTORE_PASS M This attribute can contain either clear text or base64 encoded password for the Keystore where the certificate will be placed. When a clear text password is provided, the value will be encrypted and updated in the silentInstall.properties file. The Keystore password must be 6 or more characters.
CONFIRM_PASS M This attribute should store the same value as KEYSTORE_PASS attribute.
TRUSTSTORE_PASS M This attribute can contain either clear text or base64 encoded password for the Truststore where the certificate will be placed. When a clear text password is provided, the value will be encrypted and updated in the silentInstall.properties file. The Truststore password must be 6 or more characters.
CONFIRM_TRUSTSTORE_PASS M This attribute should store the same value as TRUSTSTORE_PASS attribute.
CERTIFICATE_TYPE M

This attribute stores value for certificate type to be used for secured communication

Possible values:
  1. Generate Self Signed certificate
  2. Import CA Signed certificate

Default value: 1

TRUST_CERTIFICATE_FILE O

This attribute should contain the full path of the file with the file name. It only considers PEM format extension certificate.

For Unix, example: /root/Certificates/trustCert.pem

For Windows, directories should be separated with double backslash. (\\)

Example: C:\\Certificates\\trustCert.pem

Note: If set empty, then import will be skipped.
BACKUP_CONFIG_DATA O

This attribute decides whether to backup the data during uninstallation of the product.

Valid Values are:
  • yes to save the data after uninstallation (Default Value)
  • no to not save the data after uninstallation
Note: If yes is mentioned it will backup configuration data at $INSTALLATION_DIRECTORY/backup Files location.
Table 6. Common parameters based on certificate type
Parameters Mandatory/Optional Description
If certificate type is Self Signed certificate
CERTIFICATE_LABEL M This attribute should store the certificate label or alias of the certificate entered in lower case.
CERTIFICATE_EXPIRY_TIME M This attribute should store the expiry time in days.

Value entered should be greater than 0.

COMMON_NAME M

This attribute should store the Common Name of the certificate.

Values not allowed:
  • Special characters
  • IP addresses, Port numbers
  • "http:// or https://"
ORGANISATION M This attribute should store an Organization Name that must be registered with some authority at the national, state, or city level.

Use the legal name under which your organization is registered. Do not use an abbreviated form or use any of these symbols: ! @ # $ % ^ * ( ) ~ ? > < / \.

LOCALITY M This attribute should store the name of locality/city where the organization is located.
STATE M This attribute should store the name of state where the organization is located.
COUNTRY M This attribute should store country code in the standard format where the organization is located.
EMAIL_ID M This attribute should store e-mail ID for the support group.
DNS_NAME M This attribute should store the domain name secured by the certificate.
IP_ADDR M This attribute should store the IP address secured by the certificate.
EXPORT_CERTIFICATE_LOC O

This attribute should contain the valid absolute path to save the self signed public certificate.

For Unix, example : /root/MFTWebservices

For Windows, directories should be separated with double backslash. (\\)

Example : C:\\Program Files\\MFTWebservices

Note: If set empty, export will be skipped.
If certificate type is CA Signed certificate
CA_CERTIFICATE_FILE M This attribute should contain the full path of the file with the file name. It only considers PEM or PKCS12 format extension certificate. The file must contain the private key, the CA-signed certificate, the CA certificate and all intermediate certificates.

For Unix, example: /root/Certificates/certFile.pem

For Windows, directories should be separated with double backslash. (\\)

Example: C:\\Certificates\\certFile.pem

CA_CERTIFICATE_PASSWORD M This attribute should contain the private key password of the CA Signed certificate. The password would be the Base64 password.
CERTIFICATE_LABEL M This attribute should store the certificate label or alias of the certificate entered in lower case.