Skip to content
Open
Show file tree
Hide file tree
Changes from 19 commits
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
1ad60d6
W-14219104-Traffic-inspection-LDS
luanamulesoft Oct 6, 2023
1299a88
fixed format
luanamulesoft Oct 6, 2023
4c224b7
fixed format2
luanamulesoft Oct 6, 2023
9332bf4
fixed format3
luanamulesoft Oct 6, 2023
114ef81
fixed format4
luanamulesoft Oct 6, 2023
7b010f0
fixed format5
luanamulesoft Oct 6, 2023
8083fac
added images
luanamulesoft Oct 6, 2023
cc645b2
added images2
luanamulesoft Oct 6, 2023
038b4d5
added images3
luanamulesoft Oct 6, 2023
868b02c
fixed images
luanamulesoft Oct 6, 2023
d0509b0
fixed images2
luanamulesoft Oct 6, 2023
4398f2f
fixed images3
luanamulesoft Oct 6, 2023
035fcb0
fixed images34
luanamulesoft Oct 6, 2023
a114d4a
fixed images5
luanamulesoft Oct 6, 2023
49d9a50
fixed images6
luanamulesoft Oct 6, 2023
9479a14
fixed vale problems
luanamulesoft Oct 6, 2023
353ba57
added page to nav
luanamulesoft Oct 6, 2023
e571e09
fixed nav
luanamulesoft Oct 6, 2023
b4874ad
fixed wrapper conf description
luanamulesoft Oct 6, 2023
090ca85
Merge branch 'latest' into W-14219104-Traffic-inspection-LDS
luanamulesoft Oct 9, 2023
b4c11d1
apply review
luanamulesoft Oct 9, 2023
e6f9a52
apply reviews2
luanamulesoft Oct 9, 2023
ea5217c
format test1
luanamulesoft Oct 9, 2023
cb0b57d
format test2
luanamulesoft Oct 9, 2023
4bcaf3e
format test3
luanamulesoft Oct 9, 2023
14b567a
format test4
luanamulesoft Oct 9, 2023
541ac51
applied SMEs reviews
luanamulesoft Oct 9, 2023
74bebab
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 9, 2023
33d51ea
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
7f2b735
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
b53c0bc
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
eb4ff84
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
095da9f
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
06f8a78
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
4b549bc
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
c1cfbe3
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
d9183df
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
7bf6bcf
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
a1a7c51
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 10, 2023
ed3f26a
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
9901cab
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
563c92b
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
f831d28
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
7738010
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
07d52a7
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
a34b538
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
e03791e
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
7efdacb
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
6ccbce1
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
c550aab
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
7b2fb75
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
4d2fe6a
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
7acf989
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
1df3302
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
4865eb3
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
503406b
format test5
luanamulesoft Oct 11, 2023
517fc66
structure1
luanamulesoft Oct 11, 2023
78249c6
structure2
luanamulesoft Oct 11, 2023
e41972e
added mule runtime xrefs
luanamulesoft Oct 11, 2023
d134b47
Merge branch 'latest' into W-14219104-Traffic-inspection-LDS
luanamulesoft Oct 11, 2023
c72dddb
Update rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
043ab60
structure4
luanamulesoft Oct 11, 2023
6d9c755
structure5
luanamulesoft Oct 11, 2023
e1d7298
structure6
luanamulesoft Oct 11, 2023
82ab10b
Update runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
luanamulesoft Oct 11, 2023
f4f33a7
Merge branch 'latest' into W-14219104-Traffic-inspection-LDS
luanamulesoft Jul 25, 2024
e6e06c8
added info to renew certificates via RTM.
luanamulesoft Jul 26, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file not shown.
Binary file not shown.
Binary file not shown.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions runtime-manager/modules/ROOT/nav.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@
*** xref:rtm-agent-REST-connections.adoc[Configure REST Connections with amc_setup Parameters]
** xref:rtm-agent-config-yaml.adoc[Update Agent Configuration in mule-agent.yml]
** xref:rtm-agent-proxy-config.adoc[Connect the Agent Through a Proxy Server]
** xref:rtm-traffic-inspection.adoc[Traffic Inspection for Standalone Mules]
** xref:debugging-the-runtime-manager-agent.adoc[Troubleshoot the Runtime Manager Agent]
** xref:advanced-usage.adoc[Advanced Usage]
*** xref:runtime-manager-agent-architecture.adoc[Runtime Manager Agent Architecture]
Expand Down
10 changes: 6 additions & 4 deletions runtime-manager/modules/ROOT/pages/rtm-agent-proxy-config.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -89,11 +89,13 @@ amc_setup -H myToken myMuleServer -P acme.proxy.com 443 internalAdmin Ins1d3V0ic
To specify proxy server configuration in the `$MULE_HOME/conf/wrapper.conf` file,
add your proxy server information to the following properties:

* `anypoint.platform.proxy_host=_hostname_`
* `anypoint.platform.proxy_port=_port_`
* `anypoint.platform.proxy_username=_username_`
* `anypoint.platform.proxy_password=_password_`
* `wrapper.java.additional.<n>=-Danypoint.platform.proxy_host={hostname}`
* `wrapper.java.additional.<n>=-Danypoint.platform.proxy_port={port}`
* `wrapper.java.additional.<n>=-Danypoint.platform.proxy_username={username}`
* `wrapper.java.additional.<n>=-Danypoint.platform.proxy_password={password}`

[IMPORTANT]
These are additional parameters to pass to Java when it is launched. The <n> element refers to the number of the additional parameters in the configuration. It is indicated with an integer number counting up from `1` and must follow a sequence without any gaps.

== Verify That the Proxy Server Does Not Modify the Runtime Manager Certificate

Expand Down
110 changes: 110 additions & 0 deletions runtime-manager/modules/ROOT/pages/rtm-traffic-inspection.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
= Traffic Inspection for Standalone Mules
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated

@hannanelson hannanelson Oct 10, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This topic doesn't appear in the TOC on the beta site. Where will it live?

I think we need to take a closer look at the hierarchy of sections in this topic.

= Traffic Inspection for Standalone Mules
== Prerequisites
=== Traffic Inspection Proxy
== Mule Installation and Registration Steps
=== Provision the Truststore of the JVM with the Proxy Root CA
=== Install the Mule Runtime
=== Upgrade the Mule Runtime Agent
=== Register the Mule Runtime
=== Check that the Mule Runtime is Connected to the Control Plane
== Notes

The Mule Installation section structure is good (and task oriented) (Bravo!), but I think you can combine some of them and/or link to existing topics to reduce the amount of text here.

I would love to figure out how to flatten the hierarchy a little so that the main tasks (H2) appear in the right-hand TOC, if possible.

ifndef::env-site,env-github[]
include::_attributes.adoc[]
endif::[]
:keywords: agent, runtime manager, traffic inspection, standalone
:page-deployment-options: hybrid

The Traffic Inspection feature for Mules adds support in the agent for a forward proxy that is deployed in customer premises and acts as a man in the middle between the Mule and the control plane by intercepting and inspecting all HTTPS traffic.

== Prerequisites

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We use "Before You Begin" for prereq topics.


Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our style is to not have two headings in a row without content.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think you can remove the === Traffic Inspection Proxy heading because there's only one heading in the Prereqs - no need to distinguish.

Once you revise the bullet list to be more paragraphy, you can make it clear that the prereqs are for the Proxy.

=== Traffic Inspection Proxy

* An HTTP Inspection Proxy is required, with support for TLS connections to the runtime client, and mTLS connections to the control plane server.

@hannanelson hannanelson Oct 10, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure why this is a bullet list. Perhaps the first two bullets should be a paragraph and the third a separate paragraph/intro to the sub-bullet list?

Review the guidelines in the Style Ref on bullet lists:
https://confluence.internal.salesforce.com/display/MTDT/MuleSoft+CX+Writing+Style+Reference#MuleSoftCXWritingStyleReference-bulletlists

* The Inspection Proxy server does not require client authentication from the agents. The proxy does not require the Mule Agent to present a client certificate. The communication between the Mule Agent and the inspection proxy is TLS, not mTLS.
* The inspection proxy must be provisioned to send a BofA private certificate to the Mule Agent. The Mule Agent uses a Certificate Authority from the JVM's keystore to validate the public certificate presented by the inspection proxy.
* The the inspection proxy and the MuleSoft control plane communicate via mTLS communication. There are two certificates involved:
** The control plane presents a MuleSoft Public server certificate to the Inspection Proxy. The proxy must be provisioned with the correct Certificate Authority to validate the server certificate presented by the MuleSoft Control Plane
** The control plane requires a client certificate from the inspection roxy. This certificate must be the one shared by BofA to MuleSoft on April 17th, 2023, with serial number `133250979737618478378908091430693006357` and Common Name `anypoint-test.bankofamerica.com`.
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated
+
[NOTE]
Communication with the control plane might fail if the certificate does not match the specified serial number and common name.
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated

== Mule Installation and Registration Steps

@hannanelson hannanelson Oct 9, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Need some content between headings here.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our style is to not use self-referential language like "steps". Instead, reframe to be a task (with an imperative).

== Install and Register Mule

Provision the truststore of the Java Virtual Machine with the Root CA of the Proxy::

. Identify the folder location of the Java Virtual Machine.
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated
. Insert the Root CA of the proxy in the truststore of the mule's JVM: in your terminal window run the following command, replacing `$JAVA_HOME` with the actual path:
+
[source,console,linenums]
----
sudo keytool -import -alias testCert -keystore $JAVA_HOME/jre/lib/security/cacerts -file proxy_cacert.pem
----
+
. Password is `changeit`.
. If you have multiple versions of Java, insert the certificate in the version that is being used by the Mule runtime.
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated

[[install-mule-runtime]]Install the Mule Runtime::

. Install the latest available Mule Runtime version, which currently is `4.4.0-20230918`. You can skip this step if already installed.
+
To check the latest Mule Runtime version, see xref:release-notes::mule-runtime/mule-esb.adoc[].
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated
+
[NOTE]
The Mule Runtime Installation bundle includes both the Mule Runtime Engine and the Mule Runtime Agent.

Upgrade the Mule Runtime Agent::

Make sure that the version of the Mule Runtime Agent is `2.5.6` or later. If you have an earlier version, update the runtime agent before registering.
+
To update the Runtime Agent:
+
. Download the Agent's zip file
. Extract the downloaded `agent-setup-2.5.6.zip` file to `$MULE_HOME/bin`.
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated
+
If prompted, overwrite any conflicting files.
. Do NOT run `amc_setup -U`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(This is not a step.)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
. Do NOT run `amc_setup -U`.
+
Do not run `amc_setup -U`.


Register the Mule Runtime::

. Update the file `wrapper.conf` file with the IP and port of the traffic inspection proxy by following instructions in xref:rtm-agent-proxy-config.adoc#set-up-proxy-server-configuration-in-the-wrapper-conf-file[Set Up Proxy Server Configuration in the wrapper.conf File].

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

file is duplicated here.

. Login in to the Anypoint console.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"Login in"

@hannanelson hannanelson Oct 10, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
. Login in to the Anypoint console.
. Log in to Anypoint Platform and select *Runtime Manager*.

. From the Anypoint Platform, select *Runtime Manager*.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
. From the Anypoint Platform, select *Runtime Manager*.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Product names don't get articles (the).

. Click *Servers* in the navigation menu.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

. Click *Add Server* .

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
. Click *Add Server* .
. Click *Add Server*.

+
image::traffic-add-server.png[]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing alt text.

+
. In a terminal window, change the `$MULE_HOME/bin` directory to the Mule instance that you're registering.
. Paste the command on the command line and append the proxy's IP address or domain name and port, and the `--enable-traffic-inspection `configuration flag.
+
[source,console,linenums]
----
./amc_setup -H 42081e44-288b-4ebc-a1b5-6092a7cbd9d5---1 server-name -P proxy.bofa.com 4128 --enable-traffic-inspection
----
+
[NOTE]
Make sure to leave a space between the proxy's domain name and port number.
+
. Confirm that the mule has registered successfully. The runtime should show up as *Created* in the Anypoint console:
Comment thread
luanamulesoft marked this conversation as resolved.
Outdated
+
image::mule-registered.png[]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing alt text

+
. Edit the file `$MULE_HOME/conf/mule-agent.yml` and set the property `authenticationProxy.endpoint` to `null`.
. Start the mule.

Check that the mule runtime is connected to the control plane::

If the connection was successful, you should see the runtime with status *Running* in the Anypoint console:
+
image::mule-running.jpg[]
+
Also, if the connection has been established, the mule agent terminal window displays the following message:
+
[source,console,linenums]
----
INFO 2023-04-19 17:27:41,307 [WebSocketInboundExecutor] [processor: ; event: ] com.mulesoft.agent.transport.handlers.GenericWebSocketHandler: Opening Mule Agent WebSocket
INFO 2023-04-19 17:27:41,316 [WebSocketInboundExecutor] [processor: ; event: ] com.mulesoft.agent.transport.handlers.GenericWebSocketHandler: Mule Agent WebSocket opened
INFO 2023-04-19 17:27:41,316 [pool-12-thread-1] [processor: ; event: ] com.mulesoft.agent.transport.connections.AsyncHttpWSConnectionThread: Mule Agent WebSocket connection was initialized after: 1 attempts
INFO 2023-04-19 17:27:42,179 [WebSocketInboundExecutor] [processor: ; event: ] com.mulesoft.agent.services.security.HandshakeAuthorizationService: WebSocket Client connection authorized
----

== Notes

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems like a catch-all section. Is there any way to include this information elsewhere? Maybe in the intro? In general, we want to avoid headings like "Notes" and put important things earlier in the topic, with descriptive headings.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Take a look at the bullet list guidance. I think this might be better presented as paragraphs.


* For agent version 2.5.6, you cannot renew mule certificates from Runtime Manager. If you need to renew your certificates, follow the instructions in xref:servers-cert-renewal.adoc#renew-a-certificate-via-the-command-line[Renew a Certificate via the Command Line].

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mule

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* For agent version 2.5.6, you cannot renew mule certificates from Runtime Manager. If you need to renew your certificates, follow the instructions in xref:servers-cert-renewal.adoc#renew-a-certificate-via-the-command-line[Renew a Certificate via the Command Line].
* For agent version 2.5.6, you cannot renew Mule certificates from Runtime Manager. To renew your certificates, follow the instructions in xref:servers-cert-renewal.adoc#renew-a-certificate-via-the-command-line[Renew a Certificate via the Command Line].

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That anchor looks autogenerated. Might be worth defining a custom one :)

** Use version `2.4.37` of the application.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Which application? Certificate?

** Certificates are valid for 2 years out of the box.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our style is to spell out numbers one through nine.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What does "out of the box" mean in this context? Two years after they're applied?

* To enable traffic inspection, the mule runtime and agent must be installed from scratch as per instructions in this document. Upgrading from a standalone mule deployed in a PCE environment is not supported.
** Using a runtime version earlier than the one specified in <<install-mule-runtime>> might result in some functionality not working as expected.