Documentation PI Nexus+ Documentation

PI Nexus+ / Installation Guide

Split Deployment

This chapter installs the web application and the scanner service on two servers, converts a single server, and covers operating and changing a split deployment.

Overview

This chapter installs the web application and the scanner service on two servers, converts a single server, and covers operating and changing a split deployment.

Both servers use the same database and never connect to each other. PI Nexus+ supports one scanner service per database.

Before you start

  • Prepare both servers as described in Plan the Deployment, including the AF Client and the PI connections on the web server.
  • Use the same PI Nexus+ version and the same Windows time zone on both.
  • Each server may use its own service account, for example DOMAIN\svc-pinexus-web and DOMAIN\svc-pinexus-scan. Each needs the logon right for its server, db_owner on the database, and the PI, AF and PI Vision read access.
  • If a PI Data Archive or AF Server target uses OpenID Connect, both servers need the same secret certificate with its private key, readable by both accounts. See Protect the client secret with a certificate in the Administration Guide.

Install a new split deployment

  1. Database. Run Prepare-Database.sql with both accounts, or enter the second account in Database Setup in step 2.
  2. Web server. Install with only Web application (IIS), and the thumbprint in Secret certificate if needed. Run Database Setup.
  3. Scanner server. Install with only Scanner service, the same SQL Server, database and thumbprint. The service waits until the schema is current.
  4. In Admin > Support > Readiness, check that Topology reads Split: web application on WEB01, scanner service on SCAN01 and that the version, time zone and certificate checks are Good.
  5. Run a scoped scan of one target per type (see First Targets and First Scan).

Convert an existing single server

Usually the existing server keeps the web application, so users keep their URL, and a new server gets the scanner service. All data is kept. Wait until no scan is running.

  1. With OpenID Connect only: on the existing server, set up the secret certificate and restart PI Nexus+. Check that API: Secret certificate and Worker: Secret certificate are Good.
  2. Copy the certificate with its private key to the new server; give the new account Read access to the key.
  3. Prepare the new server. Give a different account db_owner with Prepare-Database.sql, or with Setup-Database.ps1 -SecondServiceAccount and -SkipBootstrapWrite on the existing server.
  4. On the existing server, run msiexec /i {ProductCode} REMOVE=ScannerService.
  5. On the new server, install the same version with only Scanner service, the same SQL settings and the thumbprint.
  6. Check readiness as above and run a scoped scan.

Note: Do step 1 while the existing server still runs both components: only it can convert the stored OpenID Connect client secret. Otherwise regenerate the secret under Admin > OpenID Connect and update the client in AVEVA Identity Manager.

To move the web application instead, install it on the new server with Run PI Nexus+ Database Setup now cleared, then remove it from the old server with REMOVE=WebApplication.

Operate and change a split deployment

  • Logs stay on the server that wrote them. A support bundle holds only the web server's logs; add the scanner server's log files.
  • Admin > SQL Server and the log level change only the web server's bootstrap.json. On the scanner server, edit its file and restart the service.
  • Upgrade the web server first, then the scanner server, with the same version. Don't pass ADDLOCAL or REMOVE on an upgrade.
  • Add or remove a component with a maintenance installation, for example msiexec /i {ProductCode} REMOVE=ScannerService. Adding needs SERVICEACCOUNT and SERVICEPASSWORD. If you add the web application to a server whose Hosting Bundle was installed without IIS, repair the Hosting Bundle afterwards.

Reference: Installer and Script Parameters