device.opc-ua

OpcUa device

type

object

properties

  • authenticationMethod

The OpcUa authentication method. You can choose the option to pass either a Username/Password combination or a certificate with a private key.

The default is Anonymous.

Learn more about OPC UA ↗️.

oneOf

Anonymous

UsernamePassword

Certificate

  • clientCertificate

This certificate is used to establish a secure connection with the OPC UA server and should be a valid X.509 certificate in PEM or DER format. By default the module will use his own certificate.

Certificate details

To be usage for opc-ua a certificate must declare the following key-usage
  • nonRepudiation

  • digitalSignature

  • keyEncipherment

  • dataEncipherment

  • keyCertSign

An SAN (subject alternative name), must be defined and set in the clientUri configuration. Learn more about OPC UA ↗️.

Default value is [{“caPath”:”ca.crt”,”privateKeyPath”:”module.key”,”providerType”:”SECRETS”,”publicKeyPath”:”module.crt”}]

default

caPath

ca.crt

privateKeyPath

module.key

providerType

SECRETS

publicKeyPath

module.crt

ClientCertificate

  • clientURI

This parameter is used to validate the certificate on the client side. Its value must exactly match one of the certificate’s subject alternative names (SAN). Although it is theoretically possible to define multiple subject alternative names in the same certificate, most OPC-UA servers only support the first one.

The default value in OnSphere generated certificate is ‘urn:swissdotnet:onsphere’.

Learn more about OPC UA ↗️.

Default value is [”urn:swissdotnet:onsphere”]

type

string

default

urn:swissdotnet:onsphere

  • connectionRetryDelay

The connection retry frequency, it’s used for retry a connection when OPC-UA device is not connected.

Learn more about OPC UA ↗️.

Default value is [{“unit”:”SECONDS”,”value”:10}]

default

unit

SECONDS

value

10

DurationConfigurationEntity

  • folder

The OpcUa folder that you want to connect to (placed after the port in the tcp url). This is used only if you want to target a certain folder specifically.

For example if you are only interested in /rootFolder/subrootFolder/deviceA and /rootFolder/subrootFolder/deviceB that are situated in folder ‘/rootFolder/subrootFolder’, you can set this parameter to ‘/rootFolder/subrootFolder’ so that when you declare the identifier part deviceA and B you don’t have to repeat ‘/rootFolder/subrootFolder’.

Learn more about OPC UA ↗️.

type

string

  • hostname

The hostname of the OPC UA device. This address is used by the client to locate and connect to the OPC UA server on the network.

For the moment only URL construction using opc.tcp prefix is handled.

For example opc.tcp://192.168.42.1:4840 is valid and this parameter (ipAddress) will be 192.168.42.1.

Learn more about OPC UA ↗️.

type

string

  • isTemplateGeneratedByOspComposer

Name of the playbook that generated this file. If present, the file is managed by the Composer and may be overwritten on regeneration. Used for selective clean. Do not edit or set manually.

type

string

  • keepAliveFrequency

The interval for sending keep-alive messages; a shorter interval improves the detection of disconnected devices but increases network traffic.

Default value is [{“unit”:”SECONDS”,”value”:15}]

default

unit

SECONDS

value

15

DurationConfigurationEntity

  • messageSecurityMode

The security of the messaging.

Learn more about OPC UA ↗️.

Default value is [“SignAndEncrypt”]

type

string

enum

Invalid, None, Sign, SignAndEncrypt

default

SignAndEncrypt

  • moduleId

The OPC UA module module.opc-ua ↗️ that this device will use to communicate.

For example modules.opc-ua.opc-ua-1 is the default OnSphere path of the OPC UA module.

type

string

  • numberOfThreads

Custom number of threads used to communicate and split charge on this specific device communications.

Can be useful if there is a lot of value that are in polling mode.

Learn more about OPC UA ↗️.

Default value is [1]

type

integer

default

1

  • pollingFrequency

The polling frequency used by default for every value using this device. This poll the values at the given frequency so that they make a request to the server and read the data of a Node.

Learn more about OPC UA ↗️.

Default value is [{“unit”:”SECONDS”,”value”:10}]

default

unit

SECONDS

value

10

DurationConfigurationEntity

  • port

The port number on which the OPC UA device’s server is listening. This port is used by the client to establish a connection with the server. It should be a valid port number between 0 and 65535.

The value that OPC UA servers are set to by default is 4840.

Learn more about OPC UA ↗️.

type

integer

  • publishingInterval

Regulates the rate at which the server transmits data updates to the client, effectively limiting the frequency of notifications.

For instance, if a value changes every millisecond but the sampling interval is set to 100 milliseconds, the server will only notify the client of value changes at most every 100 milliseconds, preventing excessive notification spam.

Learn more about OPC UA ↗️.

Default value is [{“unit”:”SECONDS”,”value”:10}]

default

unit

SECONDS

value

10

DurationConfigurationEntity

  • securityPolicyType

The OpcUa security policy. It’s important to choose the right security policy to ensure that both the client and server support the chosen policy.

The default is Basic256Sha256.

Learn more about OPC UA ↗️.

Default value is [“Basic256Sha256”]

type

string

enum

None, Basic128Rsa15, Basic256, Basic256Sha256, Aes128_Sha256_RsaOaep, Aes256_Sha256_RsaPss

default

Basic256Sha256

  • templateId

The id of the template to use for this file

type

string

  • templateVariables

The variables and their values to be replaced from the template

type

object

additionalProperties

  • useInsecureCertificateValidator

If set to true, the client will accept certificates from the server without validating them.

This is useful when the server certificate is not valid. However, using this option can expose the client to security risks.

Default value is [false]

type

boolean

default

False

  • variablesFiles

The variables files to use to replace the variables. The first file of the list will take precedence over the following one. Template variables take precedence over the contents of the files.

type

array

items

type

string

additionalProperties

False

Anonymous

type

object

properties

  • type

type

string

enum

Anonymous

default

Anonymous

additionalProperties

False

UsernamePassword

type

object

properties

  • type

type

string

enum

UsernamePassword

default

UsernamePassword

  • passwordProvider

The password to use for the connection to the device.

It can be defined as plaintext or via a secret.

Learn more about OPC UA ↗️.

oneOf

PLAINTEXT

SECRET

ENCRYPTED

  • username

The username to use for the connection to the device.

It can be for example sysadmin.

Learn more about OPC UA ↗️.

type

string

additionalProperties

False

PLAINTEXT

type

object

properties

  • type

type

string

enum

PLAINTEXT

default

PLAINTEXT

  • password

The password to use in plaintext. It can be for example thisIs@TestPassword123.

type

string

additionalProperties

False

SECRET

type

object

properties

  • type

type

string

enum

SECRET

default

SECRET

  • secretPath

The path of the secret containing the password. This is a path to the secret containing the password.

type

string

additionalProperties

False

ENCRYPTED

type

object

properties

  • type

type

string

enum

ENCRYPTED

default

ENCRYPTED

  • encryptedPassword

The password encrypted Base64(IV+AES256(password, input)) the password must be a shared secret available for the osp-configuration-dispatcher

see documentation ↗️ see toolbox ↗️

type

string

  • secretPath

The full path to the secret exposed by the orchestrator; this password is used to encrypt the encryptedPassword.

type

string

additionalProperties

False

Certificate

type

object

properties

  • type

type

string

enum

Certificate

default

Certificate

additionalProperties

False

ClientCertificate

type

object

properties

  • caPath

The CA (public key) used for the generation of the client certificate

type

string

  • privateKeyPath

The private key used for authentication by the OSP client is located at a path relative to either the secret directory or the base configuration file (which is /, not /root/).

type

string

  • providerType

The following value are * SECRET : provided by the docker orchestrator (must be in /run/secrets folder) * CONFIG : the certificate is provided by the configuration

In the example below the configuration of the key publicKeyPath is equals to the destination /test.crt

{
  "resources": [
    {
      "source": "</root/opc-certs/test.crt",
      "destination": "/test.crt"
    }
  ]
}

type

string

enum

SECRETS, CONFIG

  • publicKeyPath

The public key used for authentication by the OSP client is located at a path relative to either the secret directory or the base configuration file (which is /, not /root/).

type

string

additionalProperties

False

DurationConfigurationEntity

type

object

properties

  • unit

The unit of time expressed

type

string

enum

NANOSECONDS, MICROSECONDS, MILLISECONDS, SECONDS, MINUTES, HOURS, DAYS

  • value

The amount of time expressed with the unit

type

integer

additionalProperties

False