在容器中設定 Qlik 資料閘道 - 直接存取
上次更新:2026/9/30
本主題概述如何設定容器化的 直接存取閘道。本文件提供先決條件與安裝說明,並說明使用容器化 直接存取閘道 時應注意的限制與考量事項。
資訊備註自 直接存取閘道 1.8.0 起支援。
什麼是容器化 直接存取閘道?
您可以將 直接存取閘道 部署到 Docker 容器中。這種部署類型稱為容器化 直接存取閘道。容器化 直接存取閘道 部署支援 Linux、macOS 和 Windows。
容器化的 直接存取閘道 為您的 直接存取閘道 環境提供可攜性。
使用 Qlik 資料閘道 - 直接存取 時的最佳做法
為了在使用 Qlik 資料閘道 - 直接存取 時有成功的體驗,強烈建議遵守下列最佳做法:
系統必要條件
本區段說明使用容器化 直接存取閘道 的需求。
軟體需求
建議硬體
最低硬體
最低硬體僅適用於使用較小的專用部署 (開發、測試和生產) 的特定情境,搭配持續較低的資料量和數量有限的並行載入。
安裝 Qlik 資料閘道 - 直接存取
設定直接存取閘道涉及在 管理 活動中心和直接存取閘道伺服器都需要執行的程序。
資訊備註需要在 管理 活動中心內執行的資料閘道程序需要租用戶管理員權限。
階段一:下載 Qlik 資料閘道 - 直接存取
-
在 管理 活動中心內,選取 資料閘道。
任何現有資料閘道將列於顯示關於每個閘道基本資訊的表格。
-
按一下部署工具列按鈕。
就會開啟部署資料閘道對話方塊。
-
選取 資料閘道 - 直接存取 - 容器化直接存取閘道,接受 Qlik 客戶合約,並按一下 下載。Direct Access gateway 安裝檔案 (docker-compose.qlik-data-gateway-direct-access.yml) 將會下載至您的電腦。
階段二:透過執行 Docker Compose 檔案來啟動部署
若要開始部署 直接存取閘道,請執行下列命令:
docker compose -f docker-compose.qlik-data-gateway-direct-access.yml up
階段四:註冊資料閘道
下一步是註冊資料閘道。 這可以透過 管理 活動中心或在命令列上完成。
您也可以從命令列自動註冊 直接存取閘道,而無需使用 管理 活動中心。此方法使用由 OAuth 用戶端產生的短效工作階段 Token。
資訊備註自動註冊僅支援透過命令列進行。目前尚未提供用於閘道自動註冊的 REST API。
必要條件
具備建立與管理 OAuth 用戶端之租用戶管理員權限的 API 金鑰。
透過自動註冊來註冊閘道
-
首先,您需要設定 Python 環境以產生 OAuth 用戶端 ID,以及 direct-access-agent 容器中的斷言金鑰 (短期 Token)。依此順序分別執行下列命令:
-
docker exec -it --user root direct-access-agent-1 bash
-
apt-get update && apt-get install -y python3 python3-pip
-
apt install python3.11-venv
-
python3 -m venv .venv
-
source .venv/bin/activate
-
pip install cryptography pyjwt
-
python3 generate_gateway_assertion.py --tenant-url <tenant-url>
-
針對上方清單中的最後一個命令,追蹤互動式提示,並在提供時複製 client_id (OAuth 用戶端 ID) 與 assertion。請先將這些詳細資訊記錄在紙上或暫存的文字檔案中—後續的流程步驟將會需要這些資訊。
-
當您記下 client_id 和 assertion 後,請使用下列命令清理 Python 環境:
deactivate
-
將 OAuth 用戶端的同意方法設定為受信任。
curl "https://<tenant-url>/api/v1/oauth-clients/<client-id>/connection-configs/me" -X PATCH -H 'accept: application/json' -H 'content-type: application/json' -H 'authorization: Bearer <api-key>' -d '[{"op":"replace","path":"/consentMethod","value":"trusted"}]'
-
要求存取 Token。這也會觸發自動建立閘道所使用的機器人使用者帳戶。
curl "https://<tenant-url>/oauth/token" -X POST -H 'content-type: application/x-www-form-urlencoded' -d "grant_type=client_credentials" -d "client_id=<client-id>" -d "client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer" -d "client_assertion=<assertion>" -d "scope=admin.direct-access-gateways:register_gateway admin.direct-access-gateways:delete_gateway"
資訊備註
如果判斷提示已過期,請從虛擬環境重新執行指令碼。
-
查詢自動建立的機器人使用者。
curl "https://<tenant-url>/api/v1/users" -H 'accept: application/json' -H 'authorization: Bearer <API-key>'
-
複製 my-bot-client 的 ID。
-
建立 "DAG Registration" 角色。
curl "https://<tenant-url>/api/v1/roles" -X POST -H 'accept: application/json' -H 'content-type: application/json' -H 'authorization: Bearer <API-key>' -d '{"name":"DAG Registration","description":"Role for registering a gateway","assignedScopes":["admin.direct-access-gateways:register_gateway", "admin.direct-access-gateways:delete_gateway"]}'
-
將租用戶層級的角色指派給 Bot 使用者。
curl "https://<tenant-url>/api/v1/users/<bot-user-ID>" -X PATCH -H 'accept: application/json' -H 'content-type: application/json' -H 'authorization: Bearer <API-key>' -d ' [ { "op": "replace", "path": "/assignedRoles", "value": [ { "name": "DAG Registration" } ] } ]'
-
取得直接存取閘道空間。
curl "https://<tenant-url>/api/v1/spaces" -H 'authorization: Bearer <API-key>'
-
複製 Direct Access Gateway 空間 ID。
-
將機器人使用者新增至空間,並賦予可編輯權限。
curl "https://<tenant-url>/api/v1/spaces/<DAG-space-ID>/assignments" -X POST -H 'accept: application/json' -H 'content-type: application/json' -H 'authorization: Bearer <API-key>' -d '{"assigneeId": "<bot-user-ID>","roles": ["consumer","dataconsumer","producer"], "type": "user"}'
-
如果現有的斷言已過期,請產生新的斷言。執行下列命令:
python3 generate_gateway_assertion.py --tenant-url <tenant-url>
-
請依照命令提示字元中的所需步驟進行操作。由於 OAuth 用戶端已建立,因此需要使用此 API 呼叫來更新 JWK:
curl "https://<tenant-url>/api/v1/oauth-clients/<client-ID>" -X PATCH -H 'accept: application/json' -H 'content-type: application/json' -H 'authorization: Bearer <API-key>' -d '[{"op":"replace","path":"/publicKeys/0/y","value":"<Y-value-from-JWK>"},{"op":"replace","path":"/publicKeys/0/x","value":"<X-value-from-JWK>"},{"op":"remove","path":"/publicKeys/0/use"},{"op":"replace","path":"/publicKeys/0/kid","value":"<kid-value-from-JWK>"}]'
-
註冊閘道:
dotnet ConnectorAgent.dll qcs register_gateway --tenant_url <tenant-url> --gateway_name <DAG-name> --gateway_description <DAG-description> --space_name <space-name> --client-id <client-ID> --assertion <assertion>
移除自動註冊的閘道
請依照下列步驟,取消註冊使用上述自動、基於工作階段 Token 的方法所註冊的閘道。這些步驟也會移除為其建立的 OAuth 用戶端、機器人使用者和角色。
-
如上方區段所述,產生判斷提示。
-
刪除閘道:
dotnet ConnectorAgent.dll qcs delete_gateway --tenant_url <tenant-url> --gateway_name <gateway-name> --client-id <client-ID> --assertion <assertion>
-
查詢為閘道建立的 Bot 使用者帳戶。
curl "https://<tenant-url>/api/v1/users" -H 'accept: application/json' -H 'authorization: Bearer <api-key>'
-
複製機器人 ID。
-
刪除此機器人使用者帳戶。
curl -X DELETE "https://<tenant-url>/api/v1/users/<bot-user-ID>" -H "Authorization: Bearer <api-key>"
-
查詢為閘道建立的「DAG Registration」角色。
curl "https://<tenant-url>/api/v1/roles?limit=1&filter=(name%20eq%20%22DAG%20Registration%22)" -H "Authorization: Bearer <api-key>"
-
複製角色 ID。
-
刪除此角色。
curl -X DELETE "https://<tenant-url>/api/v1/roles/<role-ID> -H "Authorization: Bearer <api-key>"
-
刪除 OAuth 用戶端。
curl -X DELETE https://<tenant-url>/api/v1/oauth-clients/<OAuth-client-ID> -H "qlik-confirm-delete: <OAuth-client-ID>" -H "Authorization: Bearer <api-key>
階段五:在 Direct Access gateway 伺服器上啟動 Qlik 資料閘道 - 直接存取 服務
若要啟動 Qlik 資料閘道 - 直接存取 服務,請啟動 dcaas-dg 和 direct-access-agent 容器。
階段六:將連線新增至資料來源
請參閱 階段六:將連線新增至資料來源。
環境設定
本區段列出來自 docker-compose.qlik-data-gateway-direct-access.yml 檔案的特定環境變數,您可能需要設定這些變數,才能透過閘道正確連線您的資料來源。
支援的資料來源