Accéder au contenu principal
Version: 21.0

Prepare the Database User Credentials

ADOIT communicates with the database using a dedicated database user. This can be the default database user ADOxx or an individual database user.

In earlier versions of ADOIT, the database user ADOxx could use a predefined default password. Starting with ADOIT 21.0, this predefined password is no longer permitted for security reasons. If you are using an existing ADOIT database with the ADOxx user and the predefined password, you must change the password in the database.

The database user credentials must then be made available to ADOIT as an encrypted credentials string.

Remarque

If you do not have a database yet, you can skip the section Change an Existing Database User.

Change an Existing Database User​

If you already have an ADOIT database and the database user ADOxx still uses the predefined default password, change the user's password using the mechanisms provided by your database system, such as pgAdmin for PostgreSQL or SQL Server Management Studio for SQL Server.

Choose a new, secure password.

With psql, you can change the password using the following command:

ALTER USER "ADOxx" WITH PASSWORD '<new-password>';

Create an Encrypted Credentials String​

The credentials of the database user (ADOxx or an individual database user) must be made available to ADOIT in the form of an encrypted string.

To create this string, execute the following command using the ADOIT application server image, from the Linux machine or WSL environment:

docker run -it --rm \
--entrypoint /aserver/acredential_writer \
<fully-qualified-image-name> \
-t "ADOxx" \
-u "<database-user-name>" \
-p "<database-user-password>"

The important command parameters are:

  • --entrypoint /aserver/acredential_writer: Executes the tool acredential_writer directly instead of starting the application server.

  • <fully-qualified-image-name>: Specifies the fully qualified name of the application server image in your OCI registry.

  • -t "ADOxx": Specifies that credentials for the dedicated database user (ADOxx or an individual database user) are being created.

  • -u "<database-user-name>": Specifies the user name of the database user that ADOIT uses to connect to the database.

  • -p "<database-user-password>": Specifies the password of the database user.

The command starts a short-lived Docker container using the ADOIT application server image. The container executes the tool acredential_writer and creates an encrypted string based on the specified database user name and password.

acredential_writer prints the encrypted credentials string directly to the console.

After acredential_writer has finished, the short-lived Docker container is removed immediately.

Copy the generated encrypted credentials string for further use.

Provide the Encrypted Credentials String​

If you already have a deployment of ADOIT, adapt the configuration file and add the environment variable ADOXX_DBMS_CREDENTIALS to the aserver - env section.

Set the value of this variable to the encrypted credentials string generated in the previous section:

...
aserver:
env:
- name: ADOXX_SERVER_DBHOST
value: <database-hostname>
...
- name: ADOXX_DBMS_CREDENTIALS
value: <encrypted-credentials>
...