Lab Exercise #b
Let's solve some more things to better understand the Camunda 8 platform.
Q. In the camunda installation steps, lets visit
After successfully running the command-set at
If not, can you answer why?
step 5-3.After successfully running the command-set at
step 5-3, and before running the next command step 5-4, would you think camunda app will be accessible via Landing Page? (say Operate or Console)
If not, can you answer why?
Answer:
Hint: Look at step Camunda 5-4 closely. What happens when ingress does not exist?
If you so wish, let's run the helm uninstall camunda app command (as shown below) and see for yourself.
If you so wish, let's run the helm uninstall camunda app command (as shown below) and see for yourself.
# Let's uninstall the camunda app and check it out
helm uninstall {{UNAMESPACE}} --namespace {{UNAMESPACE}}
# Wait until all the camunda app related pods terminate.
# Next, go to step Camunda 5-3 and run the command-set again.
# Wait for all Pods to be in running state.
# Do you notice anything?
Q. Let's fix the issue with the Lead To Opportunity process instance failing to send email notification (Notify via Email).
There are two points here:
There are two points here:
- There are two points of importance here.
- The first is with external SSL certificates and connectors JKS. The certificates associated with external API need to be included into the JKS of connectors pod.
- Next, the process model is invoking a protected API (expects
Bearer token for authentication).
The fix is to send access token from My Keys (in nav panel).
The BPMN process is expecting the token in a k8s secret object. So we'll update the secret and restart the connectors pod.
Let's make these changes and see if it resolves the runtime issue.
Use copy button below to run the command-set
If you see any error, please contact session administrator for assistance.
Use copy button below to run the command-set
If you see any error, please contact session administrator for assistance.
Let's see the solution in action.
Pick an earlier failed process instance via Operator and retry for another attempt.
Or, you may start a new process instance as well via
You may need to wait for a few seconds for the email service to complete successfully. Did you receive an email about
9b-2a. Watch the output of each command below.
If you see any error, please contact session administrator for assistance.
## Fix for Issue #9b-2a: update JKS with the SSL certs from external API endpoint.
export UNAMESPACE={{UNAMESPACE}}
export EXTERNAL_API_URL=cep-api-gw-7k5bxais.an.gateway.dev
# we are creating this public cert file: google-api-gw-cert.pem
openssl s_client -connect $EXTERNAL_API_URL:443 -showcerts < /dev/null 2> /dev/null | sed -n '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/p' > google-api-gw-cert.pem
# Divide the cert into individual parts: google-api-gw-cert.pem
csplit -z -f google-api-gw-cert- -b "%02d.pem" google-api-gw-cert.pem '/-----BEGIN CERTIFICATE-----/' '{*}'
keytool -importcert -alias google-api-gw-cert0 -file google-api-gw-cert-00.pem -keystore ${UNAMESPACE}-zeebe-toolkit.jks -storepass changeit -noprompt
keytool -importcert -alias google-api-gw-cert1 -file google-api-gw-cert-01.pem -keystore ${UNAMESPACE}-zeebe-toolkit.jks -storepass changeit -noprompt
keytool -importcert -alias google-api-gw-cert2 -file google-api-gw-cert-02.pem -keystore ${UNAMESPACE}-zeebe-toolkit.jks -storepass changeit -noprompt
kubectl get secret {{UNAMESPACE}}-zeebe-toolkit-jks -n {{UNAMESPACE}} \
-o jsonpath="{.data.{{UNAMESPACE}}-zeebe-toolkit\.jks}" \
| base64 --decode > {{UNAMESPACE}}-zeebe-toolkit.jks
keytool -importcert -alias ml-google-api-gw -file google-api-gw-cert.pem -keystore ${UNAMESPACE}-zeebe-toolkit.jks -storepass changeit -noprompt
# Upload the new JKS via patch secret
kubectl patch secret {{UNAMESPACE}}-zeebe-toolkit-jks -n {{UNAMESPACE}} \
-p "{\"data\":{\"{{UNAMESPACE}}-zeebe-toolkit.jks\":\"$(base64 -w 0 {{UNAMESPACE}}-zeebe-toolkit.jks)\"}}"
rm -f google-api-gw-cert-00.pem google-api-gw-cert-01.pem google-api-gw-cert-02.pem
echo "Below are the list of certs available in ${UNAMESPACE}-zeebe-toolkit.jks "
keytool -list -storepass changeit -keystore ${UNAMESPACE}-zeebe-toolkit.jks
Use copy button below to run the command-set
9b-2b. Watch the output of each command below.
If you see any error, please contact session administrator for assistance.
## Fix for Issue #9b-2b: update secret with access token (from My Keys in Navigation panel)
# lets run sample process Lead To Opportunity. Refer to step 6-5
export CF_TOKEN=${CF_TOKEN}
kubectl patch secret identity-secret-for-components -n {{UNAMESPACE}} -p "{\"data\":{\"cep-email-access-token\":\"$(echo -n "$CF_TOKEN" | base64 -w 0)\"}}"
# Evict the connectors pod from Project Lens or via kubectl command
export POD_NAME=$(kubectl get pods -n {{UNAMESPACE}} | grep connectors | cut -f 1 -d " ")
# Let it be re-added by the system, this time with new config (JKS and application secret)
kubectl delete pod -n {{UNAMESPACE}} $POD_NAME
Let's see the solution in action.
Pick an earlier failed process instance via Operator and retry for another attempt.
Or, you may start a new process instance as well via
Deploy sample app # 6-5.
You may need to wait for a few seconds for the email service to complete successfully. Did you receive an email about
New Lead To Opportunity - Data Error?
Q. Let's visit Grafana dashboard at
The dashboard includes a statistics panel pertaining to Throughput.
Let's push a dozen messages (run below curl command multiple times).
The below command also includes some extra content to make the payload a bit bulky.
Grafana step 8-3.The dashboard includes a statistics panel pertaining to Throughput.
Let's push a dozen messages (run below curl command multiple times).
The below command also includes some extra content to make the payload a bit bulky.
Answer:
Open Grafana dashboard and keep the Throughput panel visible. The dashboard, by default, has a 5-second auto refresh rate.
You may need to wait for a few seconds for the Grafana dashboard to reflect the new data.
Can you see the panel data change slightly?
# lets run sample process Lead To Opportunity. Refer to step 6-5
export CF_TOKEN=${CF_TOKEN}
curl -v --location --request PUT 'https://{{UNAMESPACE}}.makelabs.in/connectors/inbound/new-lead-record' \
--header 'key: SRM-web-hook-8ui3nm' \
--header 'Content-Type: application/json' \
--data-raw '{
"companyName": "New Vista Travel Corp",
"companyPincode": "600001",
"companyContactPhone": "9836712345",
"companyContactEmail": "c@mail.com",
"agentNotes": "Meets the criteria as outlined in the last month sales manual",
"x-api-key": "SRM-web-hook-8ui3nm",
"auditTrail": {
"privateNotes-a": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. " ,
"privateNotes-b": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-c": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-d": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-e": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-f": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-g": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-h": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-i": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-j": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-k": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-l": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-m": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-n": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. ",
"privateNotes-o": "lets add some text here that is roughly more than 1000 characters. this is to simulate a large payload entering the system. "
}
}'
Run the Lead To Opportunity process instances (above curl command) a handful of times.
Open Grafana dashboard and keep the Throughput panel visible. The dashboard, by default, has a 5-second auto refresh rate.
You may need to wait for a few seconds for the Grafana dashboard to reflect the new data.
Can you see the panel data change slightly?
Next: Lab Exercise #c Operations & Resilience