Advanced Parameters
Configuring credentials for direct remote storage access
Format
The file is in the YAML format and located at /etc/mediakind/mkp/charts/customer-values.yaml. A specific script must be executed to apply the changes brought to the file that remain after a product update. If no value is specified or if a value is removed from the file, default values from installer are used.
Each entry contains the following elements:
-
url: the base URL of a storage. -
type: the type of credential to be used for this base URL. It can be:
user for access with username and password
-
s3for access using AWS S3 object store credentials -
azureSasTokenfor access using Blob Azure credential -
certificatefor HTTPS access
User credential
The entry should contain the following elements:
-
username -
password
It can be used for FTP or SFTP access (ftp://… or sftp://…).
Blob Azure credential
To configure the Azure authentication for your system, the entry in the credential file should contain the following elements:
url: URL provided at the Blob storage creation.
-
type: Type of credential to be used for this URL. It must be:azureSasToken. -
sasToken: Token provided at the Blob storage creation.
AWS S3 object store credential
This credential corresponds to an AWS access key.
The entry should contain the following elements:
-
accessKeyId: The ID of the access key -
secretAccessKey: The secret access key
Certificate credentials
The entry should contain the following elements:
-
certificateFile: to be defined in client_crt_certificate value -
privateKeyFile: to be defined in client_key_certificate value -
privateKeyPassword
Multiple credentials display
Deployment
This configuration file should be created by the user and needs to be deployed on every Packager server under the following path: /etc/mediakind/mkp/charts/customer-values.yaml.
Once the file customer-values.yaml is configured, the following script must be executed to apply the changes:
Example
When a job is created, it will parse this file to find the associated credentials of the file URL it needs to access.
For example, if the file contains the following credentials:
If a job input file is sftp://server2/share/video.ts, the second credential will be used: the input URL matches with the base URL of the second credential.
The selected credentials configuration is logged into the high-level logs of the job.