Document toolboxDocument toolbox

Cluster installation using resources created for Azure externally with Kyvos Native

Applies to: Kyvos Enterprise  Kyvos Cloud (SaaS on AWS) Kyvos AWS Marketplace

Kyvos Azure Marketplace   Kyvos GCP Marketplace Kyvos Single Node Installation (Kyvos SNI)


Once you have created resources from the Azure portal, install Kyvos as explained in this section.

  1. On the Kyvos Installer, select the I have all the resources option.

  2. Click Install Kyvos. The Setup Kyvos Environment dialog is displayed.

  3. Enter details as:

Area

Parameter/Field

Remarks/Description

Area

Parameter/Field

Remarks/Description

 

Cluster Name

Provide a unique cluster name

License

Upload your Kyvos license file, and click UPLOAD

Installation Path

Provide the installation path for Kyvos

Authentication

User Name

Enter your username for authentication.

Authentication Type

  • Private Key: Choose and Upload the Private Key file.

  • Password: Provide your credentials.
    NOTE: To use password authentication for instances while deployment, ensure that the instances have been configured for using Password-based authentication.

Configure Kyvos Services on Cloud

 

 

 

 

 

 

Select Instance by

  • IP Address: Select this option for IP Address-based deployment.

  • Hostname:  Select this option for hostname-based deployment. In this case, you can deploy the cluster using custom hostnames for nodes to be used for Kyvos services. 

    • Click the Use custom hostname for selected nodes link to specify or map a custom hostname for the selected BI Server, Query Engine, and Kyvos Manager/repository node.
      NOTE: Ensure that the instances have been configured for using Custom hostnames.

Deployment

Select None (node mapping manually) option. 

Fetch Resources

Click the link to get a list of externally created resources.

Deploy BI Server, Query Engine, and Web Portal Kyvos Services on <IP address> instance

This checkbox is displayed only when you select the None (node mapping Manually) option from the Deployment list. 

NOTE: By default, this checkbox is disabled. 

Virtual machines for BI Server

Select the VMs to be used for Kyvos BI Server from the drop-down list.

Query Engine Scale Set

Select the scale set to be used for the Kyvos Query Engine scale set from the drop-down list.

Virtual Machines for Query Engine

Select the VMs to be used for the Kyvos Query Engine from the drop-down list.

Virtual machines for Web Portal

Provide a comma-separated list of IP Addresses/Hostnames for the VMs to be used as Web portal instances.

Repository

Shows the IP Address/Hostname of the Kyvos Manager node that will be used as the Repository. 

Repository Password

Provide the Postgres repository password.

Compute Cluster

Compute Cluster Type

Select the Kubernetes or Shared Query Engines option.

NOTE: When you select Kubernetes from the Compute Cluster list, the Kubernetes Details section is displayed.

 

Kubernetes Details

Enter the following Kubernetes details:

  • Kubernetes Cluster Name: Select the Kubernetes cluster name from the list. Click Fetch Details. The Kubernetes cluster details will be fetched.

  • System Node Pool Name: Select the system Node Pool name from the list.

  • User Node Pool Name: Select the User Node Pool name from the list.

  • Validate Kubernetes Cluster Details: Click this link to validate Kubernetes cluster details.

 

Enable Compute Server Scaling

Select this checkbox to enable maximum or minimum compute server for scaling. When you select this checkbox, the following options will be displayed.

  • Minimum Compute Server Count: Select the minimum compute Server count that will be started initially.

  • Maximum Compute Server Count: Select the maximum compute Server count up to which you want to scale.

NOTE: If you do not select this checkbox, the Compute Server Count field is displayed. Compute server scaling will be disabled if this checkbox is not selected.

 

Fetch Parameters

  • Clicking this will open a new dialog box where you need to provide the following details:

    • fs.azure.account.auth.type: The OAuth input is displayed by default.

    • fs.azure.account.oauth.provider.type: The input for this field is displayed by default.

    • fs.azure.account.oauth2clientID: Enter the managed identity client ID.

    • fs.azure.account.oauth2clientID: Enter the tenant ID.

Function

Function Deployment

Optionally, provide the name of the deployment where your Azure Functions are deployed.

  1. Click the Advanced Settings link. The Advanced Settings dialog box is displayed with values populated according to the ones that you defined while creating the stack.

Configuration Type

Parameter/Field

Comments/Description

Configuration Type

Parameter/Field

Comments/Description

Common

Kyvos Setup Package

Select the Kyvos bundle to be installed. Kyvos Manager contains compatible Kyvos bundles. To use any other Kyvos version, click the Upload button.

Semantic Model Local Path

Enter the semantic model local path where cuboids will be copied. For multiple paths, enter a semicolon-separated list.
NOTE: The deployment user must have full permission on the parent of the local semantic model path.

Automatically restart Kyvos services when down

Select this option to enable high availability mode for the Kyvos service. This will ensure Kyvos services are always up and running. The Kyvos Manager will automatically restart the BI server, query engine, repository, and web portal services, in case any of these services go down

BI Server

 

 

Listener Port

Enter the listener port for BI Server.

JMX Port

Enter the JMX port for BI Server health monitoring.

Work Directory

Enter the directory location on HDFS, where BI Server has access permissions.

Maximum Heap Memory

Enter the maximum memory available for BI Server.

Additional Java Options

Use this to define custom Java properties for your BI Server.

Query Engine

 

Thrift Listener Port

Enter the thrift listener port for Query Engine.

JMX Port

Enter the port for Query Engine health monitoring.

Maximum Heap Memory

Enter the maximum memory for Query Engine.

Additional Java Options

Use this to define custom Java properties for your Query Engine.

Web Portal

 

 

 

UI Port

Enter the port on which the Kyvos Web client will run.

JMX Port

Enter the port for Web portal health monitoring.

Shut-down Port

Enter the port to be used for shutting the Tomcat server.

AJP Port

Enter the port on which the AJP connector creates a socket and awaits an incoming connection.

Maximum Heap Memory

Enter the maximum memory for the Web portal.

Additional Java Options

Use this to define custom Java properties for the Web portal.

Network Protocol Configuration

Enable TLS

Select the checkbox to enable TLS for the cluster.
Note: Before enabling TLS, if you are using your own script for resource creation instead of the Kyvos shared scripts, you must rename the OpenSSL configuration file on the Kyvos Manager and the node where the Postgres Service is running. The OpenSSL configuration file is located at /etc/pki/tls/openssl.cnf.

To accomplish this, you will need to have sudo access.

HTTP Protocol Version

Select the HTTP Protocol Version for use with TLS.

Kyvos Web Portal on HTTPS

Select the checkbox to use HTTPS for connecting to Kyvos Web Portal.

TLS Configuration

 

 

 

 

 

 

 

 

 

 

TLS Protocol

Select the version of SSL/TLS protocol to be used. For multiple versions, select the corresponding checkboxes.

TLS Certificate Mode

Select the mode from Use Path or Upload File.

Keystore

Provide the location of the keystore file. This file is used by the server when secure communication is enabled and required by the client when mutual authentication is enabled.
Example: /data/KM_SNI/Certificate/keystore.jks

Keystore Private Key

Enter the keystore password.

Truststore 

Provide the location (path) to read the trust store file. The client requires this file when secure communication is enabled and required by the server when mutual authentication is enabled.
Example: /data/KM_SNI/Certificate/truststore.jks

Truststore Private Key

Enter the truststore password.

Cipher Suite

Enter the encryption algorithm to be used for communication over the TLS layer.

Enable Mutual Authentication

Select to enable mutual authentication. 
NOTE: This option is displayed only if you have installed the Kyvos cluster using the war bundle. For other modes, Mutual authentication is enabled automatically.

Kyvos Web Portal Configuration

Use same certificate as TLS

Select this option to use the same TLS certificate for Kyvos Web Portal.

Use different certificate

  • Certification Mode: Select the Use Path or Upload File option.

  • Keystore: Provide the path or upload the Keystore file for the certificate.

  • Keystore Private Key: Provide the Keystore Private Key for the certificate.

  • Custom Attributes for HTTPS over TLS connector: If needed, provide attributes to be used for the TLS connector.

  • Custom Attributes for Mutual Authentication connector: If needed, provide attributes to be used for the HTTPS connector.

  1. Click Apply.

  2. Click Next. The system validates your settings, and all the configurations done so far are displayed in the Review and Confirm dialog box.

  3. Review the settings, and click BACK to make any changes.

  4. Select the checkboxes to accept the terms and start Kyvos services on installation.

  5. Click Install to complete the installation.

Post-deployment steps

If you have deployed the cluster with externally created Secured Functions, you must perform the following steps after deployment.

  1. Go to the Key Vault created in Azure Deployment.

  2. Navigate to Networking.

  3. Click on Selected Network > Add existing Virtual Networks.

  4. Choose the Virtual network, then select the same Subnet where you have launched your secured Functions.
    You can find the subnet in the inputs of Deployment of Azure Function. Look for the value of the AzureFunctionSubnetName parameter.

  5. Similarly, go to Storage Account associated with Kyvos deployment and perform steps 2 to 5 for the storage account.

Copyright Kyvos, Inc. All rights reserved.