Add a Tanzu Application Service (TAS) connector
Connect Harness to your Tanzu accounts and spaces.
This topic describes how to set up the Harness Delegate in your TAS environment and add the cloud provider used to connect to your Tanzu cloud for deployment.
Install the Harness Delegate
Harness Delegate is a service you run in your local network or VPC to connect your artifacts, TAS infrastructure, and any other providers with the Harness Manager.
Expand the following section to learn how to install the Harness Delegate.
To learn more, watch the Delegate overview video.
Install the Cloud Foundry Command Line Interface (cf CLI) on your Harness Delegate
After the delegate pods are created, you must edit your Harness Delegate YAML to install CF CLI v7, autoscaler, and Create-Service-Push plugins.
Open
delegate.yamlin a text editor.Locate the environment variable
INIT_SCRIPTin theDeploymentobject.- name: INIT_SCRIPT value: ""Replace
value: ""with the following script to install CF CLI,autoscaler, andCreate-Service-Pushplugins.
Apply the profile to the delegate profile and check the logs.
The output for
cf --versioniscf version 7.2.0+be4a5ce2b.2020-12-10.Here is the output for
cf plugins.
Add the Harness TAS provider
You can connect Harness to a TAS space by adding a TAS connector.
Perform the following steps to add a TAS connector.
Open a Harness project, and then select Connectors under Project Setup.
Select New Connector, and select Tanzu Application Service under Cloud Providers.
Enter a connector name, enter an optional description and tag, and then select Continue.
Harness automatically creates an ID for the connector. The ID is based on the connector's name.
Enter the TAS Endpoint URL. For example,
https://api.system.tas-mycompany.com.In Authentication, select one of the following options:
Plaintext - Enter the username and password. For password, you can either create a new secret or use an existing one.
Encrypted - Enter the username and password. You can create a new secret for your username and password or use exiting ones.
Select Continue.
In Connect to the provider, select Connect through a Harness Delegate, and then select Continue.
We don't recommend using the Connect through Harness Platform option here because you'll need a delegate later for connecting to your TAS environment. Typically, the Connect through Harness Platform option is a quick way to make connections without having to use delegates.
In Set Up Delegates, select the Connect using Delegates with the following Tags option, and then enter the name of the delegate you created earlier.
Select Save and Continue.
Once the test connection succeeds, select Finish.
The connector now appears in the Connectors list.
Refresh Token Support
Harness provides the option to use a Refresh token to authenticate with the Tanzu connector. This Refresh token is used by Harness to verify your Tanzu instance. However, you still need to provide a username and password to authenticate with Tanzu. These credentials are used to obtain a new Refresh token. Once the Refresh token is provided in the connector, Harness uses it to authenticate and perform each task. Harness will authenticate with the Refresh token before executing each Tanzu step defined in the pipeline.
You can retrieve the Refresh token via the config.json file you receive when authenticating with the CF client. You can pass the Refresh token as a secret stored in the Harness Secrets Manager or your secrets manager of choice.
Custom configuration for extensible authentication
For Harness Delegate version 23.12.81811 and later, you can create a Tanzu connector by setting the AS_REFRESH_TOKEN_CLIENT_ID, TAS_REFRESH_TOKEN_CLIENT_SECRET, ENABLE_TAS_REFRESH_TOKEN_CLIENT_ID parameters, and providing the Refresh token. The connector will generate a Refresh token using the Client ID and Secret ID env variables.
ENABLE_TAS_REFRESH_TOKEN_CLIENT_ID: This is the setting to configure the alternative authentication mode on the Harness Delegate for Tanzu.
TAS_REFRESH_TOKEN_CLIENT_ID: This is the Client ID parameter for Tanzu Authentication.
TAS_REFRESH_TOKEN_CLIENT_SECRET: This is the Client Secret parameter for Tanzu Authentication.
Configure the delegate YAML
To configure the delegate YAML, do the following:
Go to the Kubernetes delegate YAML (deployment) or the actual deployed resource.
Under
spec.template.spec.containers.env, add the following environment variables.
Demo Video
Last updated
Was this helpful?