Issue 1: The latest Project structure recommends deployment of third-party packages via embed statement. Though, I was able to deploy “accesscontroltool-oakindex-package” via embed, “accesscontroltool-package” didn’t install.
Resolution: Use sub-package for deployment of “accesscontroltool-package“ [No longer an issue with latest version. Was able to install “accesscontroltool-oakindex-package” via embed]
Issue 2: We had created a separate module for ACL deployment. The module needs to be deployed only after “accesscontroltool-package” is installed. When using Cloud Manager, the acl module was deployed prior to deployment of any other maven module.
Resolution: Declare the dependency of acl module on “accesscontroltool-package“. Also assure that the cloudManagerTarget is set to none.
Issue 3: Custom user groups are created in AEM, but ACLs are missing.
Resolution: If the issue occurs only on first installation for the maven project, then one should check the order in which modules are deployed. For example: If ACL should be applied on a content path, which is unavailable, then ACL set-up would fail. In this case, ACL module should be installed only after all necessary paths are available in AEM. So, either ui.content is deployed prior to ACL module or repo-init script should be used for creating paths before installing ACLs
Code Snippets
Sharing the configurations that need to be part of multiple pom.xml in the project structure. Appending the snippets in the appropriate pom.xml should resolve both the challenges mentioned above.
Step-1: Create a new maven module for deploying ACLs. (Lets call it acl module)
Create basic structure to put the yaml files for setting up ACLs. Example: /apps/techrevel/acls/runmodes/groups.author. The ACL tool respects runmodes, so you should create the folders accordingly.
Include the path in filter.xml
Add a config “biz.netcentric.cq.tools.actool.impl.AcInstallationServiceImpl.cfg.json” to ui.config module. It defines the paths that the Netcentric tool would scan for yaml files
Create yaml files to create groups and assign ACLs. Start with very basic.
Step-2: Configure “acl” module for deployment in parent pom.xml
Update the module section of parent pom to include the acl module.
<module>acl</module>
Step-3: Declare “Netcentric Accesscontroltool” dependency in project’s main pom.xml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Step-4: Embed “Netcentric Accesscontroltool” + ACL module for deployment via “all” module
Add the following snippets in relevant sections of “all“ module’s pom.xml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Step-5: Declare the “Netcentric Accesscontroltool” + “ui.apps.structure” dependency in acl module
This step assures that the acl module is installed after accesscontroltool-package. Thus, the install hook needed by acl module will be available. Add the following snippets in relevant sections of “acl” module’s pom.xml
Also, configure cloudManagerTarget as none. This assures that the acl module is installed via all module and not separately. Refer link for details.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<!– declare the install hook also for cloud to ease local development with the AEM SDK (when installed in the actual cloud service the startup hook is used automatically instead, even with this configuration –>
Always keep a buffer for any surprises on deploying to AEM as a Cloud Service. There can be surprises/issues.
As you are not allowed to install immutable content manually, order of the packages is very important. So, even if all looks fine locally, you might see surprises on Cloud.
To simulate Cloud deployments, deploy “all” package, not individual modules
To set permissions in /libs, use repo-init scripts.
3 thoughts on “Deploying ACLs with Netcentric accesscontroltool in AEM”
nice step by step information. I use the archetype 25. The newest archetype has new module “analyse”. Deployment on local i works fine, but on AaaCS failed.
Project Analyser …………….. FAILURE [ 0.017 s]
The following artifacts could not be resolved: biz.netcentric.cq.tools.accesscontroltool:accesscontroltool-package:content-package:2.7.1
nice step by step information. I use the archetype 25. The newest archetype has new module “analyse”. Deployment on local i works fine, but on AaaCS failed.
Project Analyser …………….. FAILURE [ 0.017 s]
The following artifacts could not be resolved: biz.netcentric.cq.tools.accesscontroltool:accesscontroltool-package:content-package:2.7.1
any idea?
LikeLike
hello VT,
Apologies for a late response.
I have updated the blog as per the latest Netcentric tool version + Maven Archtype
LikeLike