Where communities thrive


  • Join over 1.5M+ people
  • Join over 100K+ communities
  • Free without limits
  • Create your own community
People
Repo info
Activity
  • 17:13

    bogdan-bondar on master

    DDI API: /controller/v1/{contro… (compare)

  • 17:13
    bogdan-bondar closed #1220
  • Jan 21 09:07
    Nkyn synchronize #1220
  • Jan 20 08:44
    Nkyn synchronize #1220
  • Jan 19 11:58
    Nkyn synchronize #1220
  • Jan 19 10:31
    Nkyn synchronize #1220
  • Jan 19 07:21
    Nkyn synchronize #1220
  • Jan 18 14:00
    lreinecke closed #1222
  • Jan 18 13:17
    hawkbit-bot commented #1223
  • Jan 18 13:16
    lreinecke opened #1223
  • Jan 18 12:52
    lreinecke commented #1222
  • Jan 18 12:23
    lreinecke opened #1222
  • Jan 18 10:46

    bogdan-bondar on master

    add license header for Bosch.IO… (compare)

  • Jan 18 10:46
    bogdan-bondar closed #1221
  • Jan 18 07:37
    hawkbit-bot commented #1221
  • Jan 18 07:29
    Nkyn opened #1221
  • Jan 17 16:37
    hawkbit-bot commented #1220
  • Jan 17 16:29
    Nkyn opened #1220
  • Jan 13 09:21

    bogdan-bondar on master

    fix distribution set tag api do… (compare)

  • Jan 13 09:21
    bogdan-bondar closed #1219
Diego Rondini
@diegorondini
@mdymov-hayward are you using a custom theme?
sounds somehow similar to:
eclipse/hawkbit-examples#56
mdymov-hayward
@mdymov-hayward
@diegorondini We do use some customization but its limited; however, the Transport.WEBSOCKET difference looks spot on as we have it set to Transport.WEBSOCKET instead of Transport.WEBSOCKET_XHR. We have Hawkbit running before the eclipse/hawkbit-examples#56 and I wanted to minimize the changes when moving from M6 to M7.
I am rebuilding docker image right now with Transport.WEBSOCKET_XHR.
mdymov-hayward
@mdymov-hayward
That was it - changing from Transport.WEBSOCKET to Transport.WEBSOCKET_XHR resolved the issue! I can now access all devices/distribution sets/rollouts as usual. This is running in local docker container, next step will be to push the change to Google Cloud Run and see if this works in GCP K8 cluster too. Thank you guys!
1 reply
Aswin-png
@Aswin-png
Hey guys, I just wanted to share with you on how I changed the GUI of hawkbit, the recommended way on this site also worked for me https://www.eclipse.org/hawkbit/guides/customtheme/
But i did it like this i cloned hawkbit seperately(Not the usual place i run hawkbit from but an extra) to a folder and then I went to hawkbit-ui /src/main/resources/VAADIN/themes/hawkbit/customstyles and then opened "hawkbitvariables.scss" and then made the changes i wanted and then went to my original hawkbit folder deleted the hawkbit-ui folder and replaced it with the new one(alwayshave a backup of the original hawkbit-ui folder). Finally i compiled everything together and run hawkbit. Worked like a charm. I do not know if this is reccommended but if it not please do tell me
Thank you very much
Cameron Miller
@cameron.miller:matrix.org
[m]
Hey everyone, I had a quick question about configuring API ports. Ideally I'd like to only publicly expose the DDI endpoint and limit access to the Management API/UI to clients within our VPC, so I was wondering if it's possible to separate which ports the Management API/UI and DDI API run on
mangexl
@mangexl
Hello, I'm upgrading to hawkbit 0.3.0M7 and configuring to use oauth2. But I have problems with oauth2. I am fetching a token using autorization_code, and I see that I get a valid token back. But it seems that the org.springframework.security.web.authentication.AnonymousAuthenticationFilter is triggered in the filterChain, setting the authentication to Anonymous. And this results in that the token-response is not processed (at least it looks like). Do you know if there is any running example of hawkbit running oauth2 which I can look at an compare? Or have you seen any problem like this before? Most probably I miss some config..
mdymov-hayward
@mdymov-hayward

@All,

In case anyone downgrades from 0.3.0M7 to 0.3.0M6 with MySQL as data backend... However rare that may be.

The upgrade to M7 alters 2 tables in database definition used by M6. This is fine for upgrade path M6->M7 but when reverted/downgraded back to M6 the new data table definitions prevent any Distribution Set to be assigned to any target. Effectively the OTA service is not functional at that point even though UI is accessible and shows all previously assigned Distribution Sets info correctly.

There is no error produced by UI when new Distribution Set fails to be assigned via UI. Clue to root cause was found in Hawkbit container logs where JDBC SQL exception was logged for "Field 'initiated_by' doesn't have a default value;".

In order to restore ability to assign new Distribution Sets to targets you'll need to DROP COLUMNS in MySQL database used by Hawkbit as follows:

  • drop column 'initiated_by' from table 'sp_action';
  • drop column 'auto_assign_initiated_by' from table 'sp_target_filter_query'.

This can be done on live database. Of course create copies of both tables just in case or backup the database before altering anything in database.

Hope this helps.

axelroy
@axelroy
image.png

Hello,
I've implemented an hawkbit amqp client, which receives correctly the download instruction, download the files to local storage, and verify the hashes. However, in the dmf documentation, there's only modules id, never a name : https://www.eclipse.org/hawkbit/apis/dmf_api/

Which is not exactly usefull to give meaning to the modules directory. Can we retrieve the modules name directly from a target ?

BigPandaWithBanano
@BigPandaWithBanano
Hi everyone,
currently i try to implement a Open Id Connect authentication via Azure AD. I followed the description on the subject Open Id Connect in the documentary. Unfortunately i got the following error :
2021-09-24 10:17:05.654 DEBUG 1 --- [qtp634638280-26] o.s.web.servlet.DispatcherServlet        : GET "/", parameters={},
2021-09-24 10:17:06.346 DEBUG 1 --- [qtp634638280-26] o.s.web.servlet.DispatcherServlet        : Exiting from "ERROR" dispatch, status 404,
2021-09-24 10:17:05.655 DEBUG 1 --- [qtp634638280-26] o.s.web.servlet.view.RedirectView        : View name 'redirect:', model {},
2021-09-24 10:17:05.654 DEBUG 1 --- [qtp634638280-26] s.w.s.m.m.a.RequestMappingHandlerMapping : Mapped to org.eclipse.hawkbit.autoconfigure.mgmt.ui.RedirectController#home(),
2021-09-24 10:17:05.655 DEBUG 1 --- [qtp634638280-26] o.s.web.servlet.DispatcherServlet        : Completed 302 FOUND,
2021-09-24 10:17:05.857 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : HTTP POST https://login.microsoftonline.com/06846365-0bcb-4951-b004-9ace50ff7b85/oauth2/v2.0/token,
2021-09-24 10:17:05.858 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Accept=[application/json, application/*+json],
2021-09-24 10:17:05.858 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Writing [{grant_type=[authorization_code], code=[0.AS8AZWOEBssLUUmwBJrOUP97hXO6B[.....]HXUw9S7xL5q2Kd4sTbbJJsh_OC1PgDJp8T-G70yJikguICqkgQ5MyAA], redirect_uri=[http://localhost:8080/login/oauth2/code/oidc]}] as "application/x-www-form-urlencoded;charset=UTF-8",
2021-09-24 10:17:06.076 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Reading to [org.springframework.security.oauth2.core.endpoint.OAuth2AccessTokenResponse] as "application/json;charset=utf-8",
2021-09-24 10:17:06.075 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Response 200 OK,
2021-09-24 10:17:06.084 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : HTTP GET https://graph.microsoft.com/oidc/userinfo,
2021-09-24 10:17:06.084 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Accept=[application/json, application/cbor, application/*+json],
2021-09-24 10:17:06.252 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Response 200 OK,
2021-09-24 10:17:06.253 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Reading to [java.util.Map<java.lang.String, java.lang.Object>],
2021-09-24 10:17:06.265 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : HTTP GET https://login.microsoftonline.com/06846365-0bcb-4951-b004-9ace50ff7b85/discovery/v2.0/keys,
2021-09-24 10:17:06.266 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Accept=[text/plain, application/json, application/cbor, application/*+json, */*],
2021-09-24 10:17:06.336 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Response 200 OK,
2021-09-24 10:17:06.336 DEBUG 1 --- [qtp634638280-25] o.s.web.client.RestTemplate              : Reading to [java.lang.String] as "application/json;charset=utf-8",
2021-09-24 10:17:06.342 DEBUG 1 --- [qtp634638280-26] o.s.web.servlet.DispatcherServlet        : GET "/login?error", parameters={masked},
2021-09-24 10:17:06.343 DEBUG 1 --- [qtp634638280-26] o.s.w.s.handler.SimpleUrlHandlerMapping  : Mapped to ResourceHttpRequestHandler ["classpath:/META-INF/resources/", "classpath:/resources/", "classpath:/static/", "classpath:/public/", "/"],
2021-09-24 10:17:06.344 DEBUG 1 --- [qtp634638280-26] o.s.w.s.r.ResourceHttpRequestHandler     : Resource not found,
2021-09-24 10:17:06.344 DEBUG 1 --- [qtp634638280-26] o.s.web.servlet.DispatcherServlet        : Completed 404 NOT_FOUND,
2021-09-24 10:17:06.345 DEBUG 1 --- [qtp634638280-26] o.s.web.servlet.DispatcherServlet        : "ERROR" dispatch for GET "/error?error", parameters={masked},
is anyone fimilar with this topic and can help me ?
Sahaya cyril
@sahaya_cyril:matrix.org
[m]

Hello Everyone,
I'm trying to set up a reverse proxy to allow certificate authentication.
For testing purpose I'm using self signed certificate. Client and Server are kept at same local network.

I'm using swupdate from client side, when trying to connect the hawkbit server, I get the following error.

Client logs:

ERROR: Channel operation returned HTTP error code 401.
- Connected to 192.168.1.121 (192.168.1.121) port 8443 (#2)
- found 1 certificates in /root/caroot.cer
- found 592 certificates in /etc/ssl/certs
- ALPN, offering http/1.1
- SSL re-using session ID
- SSL connection using TLS1.2 / ECDHE_RSA_AES_128_GCM_SHA256
- server certificate verification OK
- server certificate status verification SKIPPED
- common name: 192.168.1.121 (matched)
- server certificate expiration date OK
- server certificate activation date OK
- certificate public key: RSA
- certificate version: #1
- subject: C=IN,ST=MH,L=MU,O=Test,OU=Development,CN=192.168.1.121,EMAIL=test@gmail.com
- start date: Mon, 27 Sep 2021 09:51:04 GMT
- expire date: Tue, 27 Sep 2022 09:51:04 GMT
- issuer: C=IN,ST=MH,L=MU,O=Test,OU=Development,CN=192.168.1.121,EMAIL=test@gmail.com
- compression: NULL
- ALPN, server did not agree to a protocol
> GET /DEFAULT/controller/v1/scv HTTP/1.1

Hawkbit server logs:

2021-09-27 18:47:00.907  INFO 52737 --- [           main] o.e.jetty.server.AbstractConnector       : Started SslValidatingServerConnector@2e34384c{SSL, (ssl, alpn, h2, http/1.1)}{0.0.0.0:8443}
2021-09-27 18:47:00.909  INFO 52737 --- [           main] o.s.b.web.embedded.jetty.JettyWebServer  : Jetty started on port(s) 8443 (ssl, alpn, h2, http/1.1) with context path '/'

Can anyone please confirm this is failing just because of ALPN offering http/1.1, If yes please guide me.

Is there any documentation available for allowing targets to authenticate via a certificate authenticated by a reverse proxy?

Gunnar
@gunnarpn:matrix.org
[m]

Hello guys, I have a question regarding hawkbit and SWupdate.

Our embedded systems do not have an IP address, we thus need the systems to create any connections.

Is this something that HawkBit and SWupdate allows?

Thank you :)

Mamta singh
@mamtasingh2304_gitlab
Hi, I am new to this hawkbit swupdate. I am using hawkbit server as docker image. I want to change the login username and password of management UI. Can anyone please help me with correct steps. Thanks....
Sahaya cyril
@sahaya_cyril:matrix.org
[m]

Hi @mamtasingh2304_gitlab ,
Sorry for late response.

You have to add below given code to your hawkbit application.properties

Define own users instead of default "admin" user:

hawkbit.server.im.users[0].username=hawkbit
hawkbit.server.im.users[0].password={noop}isAwesome!
hawkbit.server.im.users[0].firstname=Eclipse
hawkbit.server.im.users[0].lastname=HawkBit
hawkbit.server.im.users[0].permissions=ALL

You can also add multiple users by incrementing the array count.
eg. hawkbit.server.im.users[1].username=2nduser

Reference: https://github.com/eclipse/hawkbit/blob/master/hawkbit-runtime/hawkbit-update-server/src/main/resources/application.properties

Hope this helps!

Regards,
Sahaya Cyril

mangexl
@mangexl
Hi, I am running oidc login and want to set tenant on login. But it looks like its hard-coded to DEFAULT in org.eclipse.hawkbit.autoconfigure.securit.OidcAuthenticationSuccessHandler. Do you know if there is another way to supply tentat in oidc flow? I can not override the OidcAuthenticationSuccessHandler bean.
rmk544
@rmk544
Hi All,
Need help using Hawkbit with SWUpdate integration purpose.
I know we can use DDI on the client side to download software release from Hawkbit.
Since SWUpdate has pre-install scripting support, Need to write a script here and just download the image without updating the Device.
Please note : I am not interested to update the device, since I have my own update service..
Kindly help.
Regards,
Mohan
13 replies
Akaarir Mohamed
@Akanichi
Hi everyone,
I'm using hawkbit/hawkbit-update-server container 6 months now, and i came to the problem that my server is full, how can i migrate just the data to another one?
3 replies
Akaarir Mohamed
@Akanichi
any link that help would be apreciable.
Thank you,
Mohamed
Gunnar
@gunnarpn:matrix.org
[m]
Cant you use docker volumes?
Akaarir Mohamed
@Akanichi
thank you @gunnarpn:matrix.org , I never used docker volumes so i will look how it works.
Abu
@AbuTahir_11_twitter
How do i set up hawkbit in intelij ?
Akaarir Mohamed
@Akanichi
Hi, i find the solution of migrating my data of docker from a partition to another using the method on this website and it works! https://www.digitalocean.com/community/questions/how-to-move-the-default-var-lib-docker-to-another-directory-for-docker-on-linux
@gunnarpn:matrix.org thank you for the help!
Abu
@AbuTahir_11_twitter
@floruschbaschan Can you give an idea on how can we customize the s3 artifact plugin. Basically I would like add some side effects upon successful upload. is it possible to do so?
1 reply
Thomas Karl Pietrowski
@thopiekar
Hey! I'm running Hawkbit in AKS and every time I restart my pod with hawkbit in there, I get an HTTP 500 internal error on every rollout. However, as long as hawkbit is running and I create a new distribution and roll that one out, everything is fine. Looks like restarting the service kills something.
I tweaked the log level, but I see no error message relating to the 500 internal error. Is there a way I can get more info out?
Thomas Karl Pietrowski
@thopiekar
To be more precise, I did the log level tweaking by setting the environment variable LOGGING_LEVEL_ROOT="DEBUG" . Do I need to set other levels of other modules, too? I remember something like this from openHAB, but I don't have the orientation to know whether we have the same where.
KOTTIRAMSAI
@KOTTIRAMSAI
I have integrated the keycloak with hawkbit after successful validation it redirect to hawkbit but it is not showing distrubution in deployment page I have created the distrubution in distrubution page.And I have assigned all client level roles to the user
Thomas Karl Pietrowski
@thopiekar
I found the error when setting the debug level to trace. At least I could find it better then.
The problem is basically that the Dockerfile is misleading. It defines a volume that doesn't seem to be used (anymore?).
So in /opt/hawkbit there shall be a data directory for persistent data, however, the relevant directory is artifactory instead. That's basically the reason why I lost the artifacts when recreating the container in k8s.
I only found a Dockerfile in the .dev-container directory in the projects repo. Is there a different place where the one from docker hub is maintained?
Thanks!
Krishna Subramanian
@krishna-devolo

Hello hawkBit community,

We are using hawkBit over reverse proxy TLS. We recently merged changes from 0.3.0M7 into our fork, and found that we get HTTP response instead of HTTPS. Setting hawkbit.server.security.require-ssl to true (a previous recommendation on Gitter) did not help. The migration guide does not include anything relevant for this - could this be caused by the Spring Boot 2.3.7 upgrade? Or any other upgraded dependencies?

Thanks!

Thomas Karl Pietrowski
@thopiekar
@krishna-devolo Moin! When does it happen? When your devices connect to hawkbit?
Krishna Subramanian
@krishna-devolo
@thopiekar Moin! Yes, when devices connect to hawkBit.
Thomas Karl Pietrowski
@thopiekar
Screenshot_20211109_075854.png
Last time I went into this, I found these properties.
It will influence the generated urls sent by Hawkbit to your device.
Krishna Subramanian
@krishna-devolo
Thanks! Those lines are in our application.properties file. When I switch to 0.3.0M6, I am able to receive HTTPS response with an unchanged application.properties file, but as soon as I switch to 0.3.0M7 it switches back to HTTP.
Thomas Karl Pietrowski
@thopiekar
Pew, might have happened to our instance, too, but we didn't notice. Maybe make a diff between both tags in GitHub and hunt the commit that changes the behaviour?
Don't have time at the moment, but would start there to find the change :)
Krishna Subramanian
@krishna-devolo
Thanks @thopiekar, shall do that! :)
KOTTIRAMSAI
@KOTTIRAMSAI

Hi all! I have integrated the keycloak with hawkbit after successful validation it redirect to hawkbit I am not able to assign distrubution to target.But through target filter it is assigning to ds.And I have assigned all client level roles to the user
I have given all client roles to the user like

APPROVE_ROLLOUT
CREATE_ROLLOUT
DELETE_ROLLOUT
UPDATE_ROLLOUT
READ_ROLLOUT
HANDLE_ROLLOUT
ROLLOUT_MANAGEMENT

CREATE_TARGET
DELETE_TARGET
READ_TARGET
UPDATE_TARGET

CREATE_REPOSITORY
DELETE_REPOSITORY
READ_REPOSITORY
UPDATE_REPOSITORY

TENANT_CONFIGURATION

DOWNLOAD_REPOSITORY_ARTIFACT

READ_TARGET_SECURITY_TOKEN

I am getting error like this in terminal
image
image
image

I have decoded Access token it is getting client roles also Whatever I have assigned
image

image

Thomas Karl Pietrowski
@thopiekar
At this moment I'm working an API connector to remote control some processes. I want to list all targettags and I would expect READ_TARGET to be the needed permission for this job. However, I need to give my user ALL to make it working.
Looks like a bug to me..
@KOTTIRAMSAI Sounds like an interesting project! Don't know how good the permissions are handled generally.
@krishna-devolo How is it going? :)
1 reply
Thomas Karl Pietrowski
@thopiekar
Does someone know a place in the sources where the permissions are listed? I expect ALL to be a union of all permissions and I can imagine that the current documentation misses a few. Any hints?
KOTTIRAMSAI
@KOTTIRAMSAI
Hi @thopiekar Thanks for giving reply ! I have created permission "ALL" in keycloak and I have assigned to the user but it is not taking(when i login it showing emply screen) and I have find the roles list from this link https://www.eclipse.org/hawkbit/concepts/authorization/#:~:text=Authorization%20is%20handled%20separately%20for,is%20based%20on%20Spring%20security%20.