Güvenlik · troubleshooting
Destination kırıkken Hub ve Joule suçlanmaz
CAP, Joule skill ve Integration Suite, S/4 veya AI Core'a BTP destination ile gider. Bu sayfa ad standardı, authentication tipi ve Cloud Connector hatalarını 401/502 olarak ayırmanızı sağlar. SM59 LLM destination'ı çözüm değildir.
Ad standardı, tip ve yanlış host
Skill ve CAP destination adını harf duyarlı kullanır. S4_API ile s4_api iki kırık çağrıdır. Tip (HTTP) ve proxy type (Internet vs OnPremise) PCE'de Cloud Connector ister; public cloud API Internet'tir. Hub endpoint'ini S/4 dest'ine yazmak klasik kopyala-yapıştır hatasıdır. İstanbul envanter: dest adı, URL host, proxy type, kullanan nesne (CAP, skill, iFlow). Additional properties (sap-client, HTML5.DynamicDestination) Fiori/CAP için şart olabilir; AI Core dest'inde yersizdir. Test Connection yeşil, token kırmızı olabilir — Test Connection OAuth akışını her zaman temsil etmez. Ad listesi Git'te durur, wiki'de şişmez. Destination adı ortamlar arasında aynı kalır, URL ve secret değişir; hardcoded URL CAP’te 401 üretir.
- Dest envanteri: ad, host, proxy type, tüketici
- Harf duyarlı ad: skill/CAP birebir
- Test Connection ≠ OAuth token başarısı notu
OAuth, basic, SAML Bearer
AI Core ve Hub client credentials veya binding kullanır. S/4 iş verisi principal propagation (OAuth2SAMLBearerAssertion) ister. Basic authentication üretim AI çağrısında reddedilir. Token URL yanlış IdP'yi gösterirse 401, IAS değil dest hatasıdır. İstanbul troubleshooting: dest auth tipi, token URL, client, certificate expiry. sap-ai-principal-propagation SAML zincirini derinleştirir; burada dest alanları kapanır. Client secret'i Git'e koymak, dest'i 'No Authentication' bırakmak kadar sık görülür. Refresh: secret rotasyonu dest güncellemesi olmadan 401 üretir — Launchpad connection ile aynı sınıf hata, farklı nesne. Cloud Connector yolu S/4 released API içindir, OpenAI host’u Connector’dan geçmez; LLM BTP Hub’dadır.
- S/4: OAuth2SAMLBearer, AI Core: binding/OAuth
- Token URL ve client, basic auth yasak
- Secret rotasyon tarihi = dest update tarihi
Cloud Connector, Location ID, 502
PCE veya on-prem benzeri API OnPremise dest ister. Connector tüneli down, Location ID uyuşmazlığı veya access control list'te path yokluğu 502/503 üretir. Joule bunu 'yanıt yok' diye gösterir. İstanbul sıra: connector status, Location ID dest=connector, ACL path, backend 403 ayrı. S/4 SM59'un BTP dest ile aynı host'u göstermesi gerekmez; iki dünya. LLM için Connector açmak (çekirdekten dışarı) yasak listededir. Mapping virtual host, gerçek host ve sap-client üçlüsü kayda geçer. sap-cpi-ai iFlow dest'ini, bu sayfa ortak dest katmanını yazar. Log: Cloud Connector audit, BTP dest check, CAP hata gövdesi. OAuth2ClientCredentials teknik kullanıcıdır; iş verisi için SAML Bearer ve principal propagation ayrı destination’dır.
- Connector status ve Location ID eşlemesi
- ACL path ve virtual host / sap-client
- 502 vs backend 403 ayırıcı tablo
Sık sorulanlar
S/4 SM59 ile BTP destination aynı şey mi?
Değil. BTP destination CAP/Joule/CPI tarafındadır. SM59'a LLM koymak clean-core ihlalidir. S/4 released API'yi BTP tarafı tüketir.
Test Connection yeşil, CAP 401 — neden?
Test Connection token veya principal akışını her zaman koşturmaz. Auth tipi, token URL ve secret rotasyonu ayrı bakılır.
Bu konuyu ortamınızda netleştirmek için 48 saatlik ön değerlendirme.
Lisans satmıyoruz. Destination, yetki ve model kararını yazılı notlarız.