Tango Reserve Serverless Custom UMP

Modified on Tue, 3 Mar at 1:15 AM

WHAT IS THE SERVERLESS USER MANAGEMENT PROCESS (UMP)

The Serverless User Management Process (UMP) is an Tango provided cloud-based solution hosted in AWS which allows a client to upload their HR data Extract into an S3 bucket which will then have the data appropriately Transformed by the process and finally Loaded into the client Tango Reserve using the Reserve APIs.

The UMP is implemented through AWS S3 buckets, a serverless database back-end, and ETL (Extract, Transform, Load) logic deployed using AWS lambda functions. The process uses tables that are created using AWS Aurora (MySQL) database platform (RDBMS) using AWS Secrets.

The ETL “Extract” is the client source file produced by the client from their HR source system (i.e., AD, Peoplesoft, etc.) and then uploaded to an S3 bucket. The ETL “Load” is handled by accessing user management APIs (provided by Tango with associated documentation as needed). The “Transform” process is handled primarily through the use of AWS Lambda functions (using Python modules).  

 

WHAT ARE THE AWS ENVIRONMENT REQUIREMENTS FOR THE SERVERLESS UMP?

The client hosted AWS environment will primarily need to employ the following services provided by AWS:

  • IAM service for creating user accounts, roles and policies. An account with access to deploy the services in conjunction with the process.
  • AWS S3 bucket service for maintaining the implementation artifacts, the user source file and supporting files and subfolders for the process.
  • Aurora Serverless RDS (using MySQL) service for the data objects used during the process.
    1. Also uses Secrets Manager service for creating Secrets for connections to the Aurora Serverless RDS cluster.
  • AWS Lambda for the layers and function code that performs the ETL operations and accesses the Reserve APIs directly for user management.

FUNCTIONALITY

The Serverless UMP imports the user related data from the HR Feed. The process applies logic to the source data to produce the adds, changes, and deletes (archives) to user information in Reserve to be pushed through the APIs. Once a user is considered “under management” by the UMP, the client user data feed source is considered the source of truth for the user profile information. This means that any conflicting data that is managed by the UMP will be remediated based on what is in the source feed regardless of what a user may manually change through the Reserve front end application interface(s).

 

SOLUTION OVERVIEW

Serverless UMP Solution Architecture Diagram - Client Hosted

 

 

Serverless_UMP.png

SYSTEM ARCHITECTURE

Serverless UMP Solution - Data Flow Diagram

Serverless_UMP_Data_Flow.png

 

WHAT IS INCLUDED IN THE SERVERLESS UMP?

The functionality of the UMP includes fields that can be updated based on the client source data along with configuration options related to initial user ADDs. UMP process notifications and UMP process logging for overall execution, processing errors and user data errors are also available with the UMP.

Custom Feature Set

The following Reserve user attributes are available to be updated on a nightly basis in the UMP per the client custom request:

  • First Name
  • Last Name
  • Primary Email Address
  • SAML (optional)

The following Reserve user attributes are available for default configuration during the initial ADD ONLY for users in the UMP:

  • Bump (TRUE/FALSE)
  • Bump Makes Asset Available (TRUE/FALSE)
  • Autobump (TRUE/FALSE)
  • Autobump Makes Asset Available (TRUE/FALSE)
  • Gap Conflicting Workspace Reservation (TRUE/FALSE)
  • Language
  • Default Role
  • Maximum Days in Advance
  • Maximum Workspace Reservation Days
  • Location
  • Location Preference
  • Asset Category Preference

The following additional items are available for the UMP for the administration and tracking of the UMP process.

Email Notifications (OPTIONAL).

  • Success Notifications may include the following:
    • Number of successfully added users during the UMP execution.
    • Number of successfully updated users during the UMP execution.
    • Number of successfully archived users during the UMP execution.
    • Total number of successfully processed user records.
    • Total number of records that failed to be processed.
    • Number of user records that failed the standard user validation logic of the UMP.
    • List of user records that failed the standard user validation logic of the UMP.
  •  
    • Failure Notification may include the following:
      • Batch ID of the UMP Execution batch.
      • List of user records that failed the standard user validation logic of the UMP (if available at execution failure point).
  • User Management Daily Execution Log:
    • Includes details of the UMP execution steps including any failure points.
  • User Management Report Log:
    • Includes the same information included in the Success Email Notification (text file version).

 AUTOMATION OPTIONS

Once implemented, the Serverless User Management Process is triggered by uploading the client provided user file to the AWS S3 bucket used for the process. This file upload can be executed manually or scheduled to executed unattended where the client environment allows using a scheduling tool of the clients choosing (i.e., Windows Task Scheduler, etc).

 

Upload Scheduling

It is recommended that the Reserve Serverless UMP be triggered by the file upload outside of normal business hours so that the client user population is not affected.

 

LIMITATIONS

Manually Added Users

User profiles can be added to Reserve either via the user interface or via the Data Management Utility. Whichever way the user profile was created, if the unique identifier for the profile is in the UMP source data feed, the UMP will manage the profile. Conversely, if the unique identifier for a profile is not in the UMP data feed, then that user profile must be managed manually.

 

REQUIREMENTS

This section will cover the requirements for the user management process to include the hardware requirements, operating system, minimum data requirements and 3rd party software requirements. It will also cover requirements for optional features.

 

SYSTEM REQUIREMENTS

The Serverless UMP solution does not require additional hardware to be deployed for the solution itself. However, it is the responsibility of the client to produce and provide the source user data in the required format via upload to the AWS S3 target bucket. Producing the file and uploading it may require resources on the client environment which are the responsibility of the client to manage.

The AWS S3 file upload may require the client to download and install the AWS CLI tool on the environment where they wish to execute the source data file upload from. This is a 3rd party software tool provided by AWS. There will be a separate document provided that will cover the AWS S3 upload process.

Additionally, if the client would like to receive the optional mail notifications in conjunction with the process, the client must provide access to an SMTP mail server that can relay email notifications from AWS

 

MINIMUM DATA REQUIREMENTS

The Reserve User Management Process standard requires a pipe (|) delimited .txt file which contains the following fields as ordered (with no field headers). **Note:  Any deviation from the standard will require UMP customizations.

 

Data Field Description
Emplid/Unique ID The unique field in the data feed file.
Last Name Last name of the user
First Name First name of the user
Email Email address of the user
Active 1 = Active, 0 = Terminate/Archive

 

3RD PARTY SOFTWARE REQUIREMENTS

The AWS S3 upload may require the client to download and install the AWS CLI on the environment where they wish to execute the upload from. 

This is a 3rd party software tool provided by AWS. The latest version can be obtained aby accessing the following URL:

 https://awscli.amazonaws.com/AWSCLIV2.msi

 

REQUIREMENTS FOR OPTIONAL FEATURES

The Reserve Serverless User Management Process allows for email notifications to be delivered for successful and failed UMP executions. For this feature to be enabled, the client must have the following available:

  • A mail server that will allow mail notifications to be relayed from AWS.
  • An allowed email FROM address.
  • An allowed email TO address for mail delivery.
  • User credentials to access the mail server securely (over port 587).

TANGO RESERVE SERVERLESS DEPLOYMENT REQUIREMENTS

The Serverless User Management Process will require that the client create (or have available) an Administrator level user account that can create, manage and archive end user accounts within the client’s Reserve. This is the account that the UMP will use during execution for user management.

 

WORKSHOP

A Workshop with your project team and Tango Reserve team will be scheduled to provide you with an overview of the User Management Process, as well as to capture the requirements so we can customize the solution. During this session, we recommend having a resource to join the call who is a SME on the source system that you will use to extract the user information from like user firstname, lastname, email, status etc. Also, a good understanding of your use cases around restrictions on space and policies would help with the discussion.

 

Download the Serverless AWS Setup Documentation below.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article