Connector Configuration

Jira Configuration

Required Configuration Properties

Jira Instance Settings

Configuration Options related to establish connection to the target Jira instance.

Name Property Key Description

Jira URL

raytion.connector.agent.jira
.instance.baseUrl

URL of the Jira instance to connect to.

Jira Authentication Type

raytion.connector.agent.jira
.instance.authenticationType

PERSONAL_ACCESS_TOKEN uses a complex, application-specific token that combines user id and password. BASIC uses the standard credentials.

Jira Personal Access Token

raytion.connector.agent.jira
.instance.password

(Only for PERSONAL_ACCESS_TOKEN) The personal access token.

Jira Username

raytion.connector.agent.jira
.instance.username

(Only for BASIC) Username to connect to Jira. This user must be able to log in to Jira and see all projects.

Jira Password

raytion.connector.agent.jira
.instance.password

(Only for BASIC) Password for the user to connect to Jira.

Use Proxy

raytion.connector.agent.jira
.instance.useProxy

Flag to connect to Jira via a proxy.

Use Proxy Authentication

raytion.connector.agent.jira
.instance.proxy.useProxyAuthentication

Flag to connect to proxy with authentication.

Proxy URL

raytion.connector.agent.jira
.instance.proxy.baseUrl

URL for target proxy.

Proxy Username

raytion.connector.agent.jira
.instance.proxy.username

Username of the authenticating user against proxy.

Proxy Password

raytion.connector.agent.jira
.instance.proxy.password

Password of the authenticating user against proxy.

Optional Configuration Properties

Jira Pagination Settings

Configuration options for paginated API requests.

Name Property Key Description

Issue Page Size

raytion.connector.agent.jira
.page.size.issue

Number of Issues requested with a single call.

Comment Page Size

raytion.connector.agent.jira
.page.size.comment

Number of Comments requested with a single call.

User Page Size

raytion.connector.agent.jira
.page.size.user

Number of Users requested with a single call.

Jira Connection Settings

Configuration Options related to establish connection to the target Jira instance.

Name Property Key Description

Socket Timeout

raytion.connector.agent.jira
.connection.socketTimeout

Requests that are not answered within this timeframe will be treated as failed.

Request Timeout

raytion.connector.agent.jira
.connection.requestTimeout

If a request cannot establish a connection to Jira within this timeframe, it will be treated as failed.

Re-Authentication Interval

raytion.connector.agent.jira
.connection.reauthenticationInterval

(Only for basic authentication) Interval between re-authenticating against Jira.

Max. Connection

raytion.connector.agent.jira
.connection.maxConnections

Max. number of connections established to Jira at the same time.

Max. Queries/Second

raytion.connector.agent.jira
.connection.maxRequestsPerSecond

Max. number of requests send to Jira within a second.

Jira Principal Cache Settings

Configuration Options for the principal cache which stores the user-related properties required to synchronize Jira principals.

Name Property Key Description

Principal Cache Page Size

raytion.connector.agent.jira
.principal.cache.pageSize

The number of principals extracted for each query.

Principal Cache ACL Limit

raytion.connector.agent.jira+ .principal.cache.maxAclCacheSize

Cache Size limit for storing ACL entries.

Principal Cache User Limit

raytion.connector.agent.jira
.principal.cache.maxUserCacheSize

Cache Size limit for storing user principals.

Jira User Identifier

raytion.connector.agent.jira
.principal.cache.userIdentifier

Strategy to identify a user. This user property is used to identify a user contained in the ACL. Choices: NAME, MAIL, KEY, DISPLAY_NAME.

Jira Project Filter Settings

Configuration Options for applying to include/exclude list filter on Jira Projects.

Name Property Key Description

Project Include List

raytion.connector.agent.jira
.filter.project.include

Include projects based on project keys. Only projects in this list are processed by the connector if the list is not empty. When a project is contained in the exclude list as well, the project will be excluded.

Project Exclude List

raytion.connector.agent.jira
.filter.project.exclude

Exclude projects based on project keys. All projects configured in this list will not be processed by the connector.

Jira Field Filter Settings

Configuration Options for applying to include/exclude list filter on Jira Fields. This Field Filter is just applied to Issues.

Name Property Key Description

Field Include List

raytion.connector.agent.jira
.filter.field.include

List for including fields. Only fields in this list are processed by the connector if the list is not empty.

Jira Type Filter Settings

Configuration Options for applying type filter on Jira.

Name Property Key Key

Exclude Comments

raytion.connector.agent
.jira.filter.type.comment

Disable processing of comments. If true, comments will not be processed by the connector.

Exclude Attachments

raytion.connector.agent.jira
.filter.type.attachment

Disable processing of attachments. If true, attachments will not be processed by the connector.

Jira Content Filter Settings

Configuration Options for content filter to apply on items exceeding a specified content size limit.

Name Property Key Key

Max Content Size

raytion.connector.agent.jira
.filter.field.content.maxSize

Maximum content size processed by the connector. Items exceeding this limit will be processed without their content.

Jira Comment Filter Settings

Configuration Options on how to treat issue comments.

Name Property Key Description

Embed comments

raytion.connector.agent.jira.filter
.embedding.enableEmbeddedComments

Unprotected comments are embedded in the content and metadata of their issue.

Discard protected comments

raytion.connector.agent.jira.filter
.embedding.discardUnembeddedComments

If true, comments that have an additional access restriction will be discarded. Otherwise, they will be fed as separate documents.

Jira Metadata Settings

Configuration options for documents' metadata.

Name Property Key Description

SourceName

raytion.connector.agent.jira
.metadata.sourceName

The name of the source system field, set for all documents.

Google Cloud Search Configuration

Account Settings

Configuration Options to specify the service account settings.

Name Property Key Description

Account E-Mail Address for Lookup

raytion.connector.backend
.google-cloud-search
.connection.accountEMail

The E-Mail Address of the user to impersonate. It is used in the principal sync to check if users exist before feeding them to Google Cloud Search. This is not the service account.

Datasource Settings

Configuration Options related to the target Google Cloud Search Datasource. The connector will send any search items to the configured datasource.

Name Property Key Description

Datasource ID

raytion.connector.backend
.google-cloud-search
.datasource.id

The ID of the Google Cloud Search Datasource to index the items to. The IDs can be inspected at admin.google.com.

Default Object Type

raytion.connector.backend
.google-cloud-search
.datasource.objectType

If a document has no meta date objectType set, the value from here is used. The object type specifies which schema object definition, registered for the specified datasource, is used.

Identity Source Settings

Configuration Options related to the target Google Cloud Search Identity Source. The connector will feed the principals to the configured Identity Source.

Name Property Key Description

Identity Source ID

raytion.connector.backend
.google-cloud-search
.identitysource.id

The ID of the Google Cloud Search Identity Source to synchronize the external source system principals. The IDs can be inspected at admin.google.com.

Encoding Settings

Configuration Options to specify encoding settings for indexing items.

Name Property Key Description

Group Encoding Scheme

raytion.connector.backend
.google-cloud-search
.encoding
.groupEncodingScheme

When groups were indexed into the Identity Source using GCDS, their IDs are encoded with Base16 or Base64. When the connector is handling groups it also has to encode group IDs in the correct scheme for the connector to work correctly.

HTTP Settings

Configuration Options related to the HTTP connections to Google Cloud Search.

Name Property Key Description

Max Connections (Content)

raytion.connector.backend
.google-cloud-search
.http.maxConnectionsContent

Maximum number of connections to the Google Cloud Search Content Service.

Max Connections (Security)

raytion.connector.backend
.google-cloud-search
.http.maxConnectionsSecurity

Maximum number of connections to the Google Cloud Search Security Service.

Connect Timeout

raytion.connector.backend
.google-cloud-search
.http.connectTimeout

Timeout to establish a connection.

Read Timeout

raytion.connector.backend
.google-cloud-search
.http.readTimeout

Timeout to read data from an established connection.

Use Proxy

raytion.connector.backend
.google-cloud-search
.connection.useProxy

Flag to connect to Google Cloud Search via a proxy.

Use Proxy Authentication

raytion.connector.backend
.google-cloud-search
.connection.proxy
.useProxyAuthentication

Flag to connect to proxy with authentication.

Proxy URL

raytion.connector.backend
.google-cloud-search
.connection.proxy.baseUrl

URL for targeting Proxy.

Proxy Username

raytion.connector.backend
.google-cloud-search
.connection.proxy.username

Username of the authenticating user against proxy.

Proxy Password

raytion.connector.backend
.google-cloud-search
.connection.proxy.password

Password of the authenticating user against proxy.

Request Settings

Configuration Options related to sending synchronous/asynchronous requests to Google Cloud Search.

Name Property Key Description

Request Mode

raytion.connector.backend
.google-cloud-search
.request.mode

Mode of item requests against Google Cloud Search (Synchronous or Asynchronous)

Request Timeout

raytion.connector.backend
.google-cloud-search
.request.timeout

Timeout of synchronous requests against Google Cloud Search.

Request Period

raytion.connector.backend
.google-cloud-search
.request.period

Time Period in which asynchronous requests against Google Cloud Search should be checked for a response.

Request Workers

raytion.connector.backend
.google-cloud-search
.request.workers

Maximum number of workers requesting the callback for asynchronous requests.

Rate Limit Settings

Configuration Options related to rate limiting to reduce network traffic.

Name Property Key Description

Max Queries Per Second (Content)

raytion.connector.backend
.google-cloud-search
.ratelimit
.maxQueriesPerSecondContent

Maximum number of queries per second to the Google Cloud Search Content Service.

Max Queries Per Second (Security)

raytion.connector.backend
.google-cloud-search
.ratelimit
.maxQueriesPerSecondSecurity

Maximum number of queries per second to the Google Cloud Search Security Service.

Retry Settings

Configuration Options related to the retry mechanism of requests against Google Cloud Search.

Name Property Key Description

Max Retries

raytion.connector.backend
.google-cloud-search
.retry.maxRetries

Maximum number of retries for a request.

Initial Waiting Time

raytion.connector.backend
.google-cloud-search
.retry.initialWaitingTime

Initial Waiting Time for the response of a request.

Delay Factor

raytion.connector.backend
.google-cloud-search
.retry.delayFactor

Factor multiplied to the delay after each failed retry.

Feeding Settings

Configuration Options related to feeding (indexing) items and principals.

Name Property Key Description

Feed only existing GCS Users

raytion.connector.backend
.google-cloud-search
.feeding
.feedOnlyExistingUsers

Flag to indicate if only users who exist in Google Cloud Search should be fed. If a user does not exist and this flag is active then the membership of the user to a group is just not fed. The ACE of an item containing the user is dropped if the user does not exist and this flag is active.

Cache Settings

Name Property Key Description

Maximum Cache Size

raytion.connector.backend
.google-cloud-search
.cache.maxCacheSize

Maximum number of entries in the Cache which stores mappings of principal IDs to GCS resource names.

General Configuration

Database Configuration

Name Property Key Description

URL

spring.datasource.url

JDBC URL for the target database. Out of the box, the connector will use H2 file database. For productive usage, use PostgreSQL specifying the URL in format: jdbc:postgresql:<host>:<port>/<database>

Username

spring.datasource.username

Database Username to read and write to database.

Password

spring.datasource.password

Database Password for the specified user

Traversal Configuration

Name Property Key Description

Traversal History Length

raytion.connector.agent.traversal
.store.historyLength

Max. number of traversals to store in the history. Once the limit is exceeded, the connector will automatically remove oldest entries in the history. (default: 100)

Number of Traversal Workers

raytion.connector.agent.traversal
.workers.worker

Number of workers to execute the traversal in parallel. Increasing this value might improve the performance, but will footprint higher memory consumption. It is recommended to keep the default value. (default: 10)

Traversal Job Poll Interval

raytion.connector.agent.traversal
.workers.jobPollInterval

Interval between the workers to be triggered to fetch and process the next tasks. (default: 10ms)

Completion Timeout

raytion.connector.agent.traversal
.workers.completionTimeout

If the search engine indexes the items asynchronously, there might be some processing still in-flight during the completion process of a traversal. This value specifies the timeout value until all asynchronous callbacks are expected to return before completing the traversal. (default: 10m)

Principal Aliaser Configuration

Principal Aliasing is applied on user information as part of Content ACL processing during Content Synchronization and Principal processing during Principal Synchronization. It’s purpose is to map external source system user to the corresponding user in search engines domain. You can configure a list of aliasers in the connector which will be applied in sequence and in order on user ACEs and user principals. The Connector supports following custom aliasing mechanism.

Custom Aliaser Disabled

If the Custom Aliaser checkbox is not selected, the connector will process user information on ACE and user principals unchanged to Search Engine. If all relevant users in the source system can be found with the same identifier in the search engine, this setup is sufficient to reflect the same secure search experience in the search engine as defined by the policy in the source system. The connector uses this option as default to process user information.

Custom Aliaser Enabled

If custom aliasing is enable then there are four types of aliaser avaialble:

Simple XML Table Aliaser

Static mapping table which can be uploaded as XML file. The connector uses the uploaded file as lookup table to map a user in the source system to a user in the search engine. Users missing a record in the file will be dropped from the ACE and during Principal Synchronization. This option is only recommended for environment with a manageable amount of users as for each user the corresponding mapping entry needs to be specified in the file.

Name Description

XML Mapping File

Browse and upload or drag and drop.

Sample XML mapping file:

<?xml version="1.0" encoding="UTF-8"?>
<storeddata>
    <entry keyValue="user1">user1@raytion.com</entry>
    <entry keyValue="user2">user2@raytion.com</entry>
    <entry keyValue="user3">user3@raytion.com</entry>
</storeddata>
Regex Replacer Aliaser

Regex Replacer Aliaser computes aliases based on a regular expression. Principals that match the regular expression are replaced by the Substitution String.

Name Property Key Description

Pattern

raytion.connector.aliaser.aliasers[*]
.replacer.pattern

The regular expression to match, this is the part that will be replaced. If braces (…​) are used in the pattern then the matched value can be retrieved using $1

Substitute String

raytion.connector.aliaser.aliasers[*]
.replacer.substituteString

String to replace the matching part of the find string. Matched value is accessed by employing $1

Regex Extractor Aliaser

Regex Extractor Aliaser computes aliases based on a regular expression. Principals that match the regular expression are inserted into the Insert-Into String.

Name PropertyKey Description

Pattern

raytion.connector.aliaser.aliasers[*]
.extractor.pattern

The regular expression to match, this is the part that will be inserted into the new value. If braces (…​) are used in the pattern then the matched value can be retrieved using $$

Insert-Into String

raytion.connector.aliaser.aliasers[*]
.extractor.insertIntoString

String to replace the matching part of the pattern. Matched value is accessed by employing $$

LDAP Aliaser

Ldap Aliaser searches for an LDAP entry with the requested name in the input value and returns the specified output attribute.

Name Property Key Description

Host

raytion.connector.aliaser.aliasers[*]
.ldap.host

Fully Qualified Domain Name of an LDAP server

Port

raytion.connector.aliaser.aliasers[*]
.ldap.port

Port to use for LDAP connection, defaults are 389/636 or (recommended) 3268/3269 for simple/SSL

AccountDN

raytion.connector.aliaser.aliasers[*]
.ldap.bindAccountDN

AccountDN for bind to LDAP

Password

raytion.connector.aliaser.aliasers[*]
.ldap.password

Password part of credentials

Input Field

raytion.connector.aliaser.aliasers[*]
.ldap.inputField

The Active Directory attribute name for this equality filter

Search Root DN

raytion.connector.aliaser.aliasers[*]
.ldap.baseDN

Distinguished Name of the subtree which is searched. The smaller the subtree the better the performance but the higher the chance of encountering principals which are not part of this subtree

Output Field

raytion.connector.aliaser.aliasers[*]
.ldap.outputField

Attribute that should be returned in result entries