SOT
    • Introduction
    • User manual
      • Getting started
        • Device registration overview
          • Registering a device
          • Self-registration of devices
        • Device claiming
          • Adding a ctrlX Core device
          • Adding a Rexroth connectivity unit device
      • Device overview
        • Setting the filter for the search
        • Device details
        • Edit device properties
        • Roll out artifacts on one or more devices
        • Rolling out a distribution
      • Device groups
        • Creating a device group
      • Machine overview
        • Create, edit and delete machines
        • Adding machines and devices via CSV file import
        • Structure of the CSV import file
      • Activity overview
      • Distribution overview
        • Managing distributions
        • Managing commands in a distribution
    • Operations manual
      • Overview
      • System architecture and interfaces
        • Element descriptions
        • Network connections overview
      • System requirements
        • General system requirements
        • Ingress controller
        • idm/idm-device-administration-app
        • idm/idm-software-management-app
        • idm/idm-device-monitoring-app
        • idm/idm-device-master-data-mgmt-app
        • idm/idm-device-app
        • idm/idm-solution-app
        • idm/idm-webapp-backend
        • idm/idm-device-tunnel-app
        • idm/idm-artifact-repository
        • bci-app/opensearch
        • bci-app/opensearch-dashboards
        • bci-app/valkey
        • bci-app/nginx
        • bci-kube/nexeed-ansible-operator
      • Migration from previous versions
      • Setup and configuration
        • Installation guide
          • How to initialize OpenSearch
          • How to create MACMA tenants with basic authentication
          • How to configure tenants for artifact-related use cases
        • Configuration
          • Detailed configuration parameters
          • Recommendations for service meshes
      • Start and shutdown
      • Regular operations
        • Whitelist new certificate
      • Failure handling
        • Device Portal data is out of sync
        • How to synchronize devices and machines to OpenSearch
        • Synchronize communication id mapping to key-value store (Redis/Valkey)
      • Backup and Restore
      • Logging and monitoring
      • Known limitations
    • Developer guide
      • Communication ID
      • Adding diagnostic functionality to devices
      • Add command processing to devices
      • Add the backup/restore functionality to devices
      • Reducing data consumption of device communication
      • Access through a custom application
    • Artifact Repository guide
      • Introduction
      • Providing artifacts for roll-out
        • Establishing a connection to the Device Portal
        • Uploading and managing artifacts in the repository
      • Downloading artifacts
      • Sending commands
    • API documentation
    • Glossary
Device Portal
  • Smart Operations Toolkit
    • Deviation Processor
    • Multitenant Access Control
    • Notification Service
    • Ticket Management
    • Web Portal
  • Shopfloor Management
    • Andon Live
    • KPI Reporting
    • Operational Routines
    • Shift Book
    • Shopfloor Management Administration
  • Product & Quality
    • Process Quality
    • AI Services
  • Machine & Equipment
    • Condition Monitoring
    • Device Portal
  • Enterprise & Shopfloor Integration
    • Information Router
    • Master Data Management

SOT Learning Portal

  • Device Portal
  • Operations manual
  • Setup and configuration
  • Configuration

Configuration

This section contains the …​

  • configuration that is shared between components,

  • and configuration of each component.

These variables are configured by the operator. There are different options available to choose from for some components. Only the corresponding variables of the chosen component have to be configured. Typical deployment scenarios either always use the first or the second option for mutual TLS authentication and key-value store.

  • For mutual TLS authentication there are two configuration options:

Option Description Chapter

Kubernetes NGINX Ingress Controller

The Kubernetes Ingress Controller is used.

General mTLS variables

Deploying an NGINX

A self-hosted NGINX component is deployed.

General mTLS variables

Additional Nginx variables

  • Device Portal requires a key-value store which can be provided in two ways:

Option Description Chapter

Using an external Redis

An external Redis Cache instance is used.

redis-external-variables

Using a Valkey within the cluster

A high available Valkey Sentinel which is deployed as part of the cluster.

valkey-variables

  • The Artifact Repository provided by the Device Portal can be deployed in two ways:

Option Description Chapter

Managed Artifact Repository

Typically, it will be deployed in form of a "Managed Artifact Repository" which supports multi-tenancy and is deployed as part of the Device Portal.

Detailed configuration parameters

Private Artifact Repository

In an installation with internet connectivity it is possible to connect multiple customer-specific Private Artifact Repository instances (operated by the customers in Azure Cloud) in addition.

artifact-repository-external-variables

  • If the Device Portal is deployed via its own umbrella chart, the following additional configurations have to be made:

Module Description Chapter

Portal configuration

Configuration where the Portal module is located & reachable

Portal-Configuration_for_Device-Portal_Umbrella_chart_deployment

Macma configuration

Configuration where the Macma module is located & reachable

Macma-Configuration_for_Device-Portal_Umbrella_chart_deployment

Ansible Operator configuration

Configuration of the Ansible Operator namespace (must be in same cluster)

AnsibleOperator-Configuration_for_Device-Portal_Umbrella_chart_deployment

Contents

© Robert Bosch Manufacturing Solutions GmbH 2023-2026, all rights reserved

Changelog Corporate information Legal notice Data protection notice Third party licenses