Skip to content

Commit 686a635

Browse files
Merge branch 'development' into production
2 parents 5f849e7 + eb08153 commit 686a635

17 files changed

Lines changed: 1435 additions & 84 deletions

File tree

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
---
2+
title: "Private Mendix Platform Deploy API"
3+
url: /apidocs-mxsdk/apidocs/private-platform-deploy-api/
4+
type: swagger
5+
description: "This API allows you to create and manage environments in Private Mendix Platform."
6+
restapi: true
7+
weight: 60
8+
linktitle: "Deploy API"
9+
---
10+
11+
{{% alert color="info" %}}
12+
This document is about [Private Mendix Platform](/private-mendix-platform/) API. This API is only available on instances of Private Mendix Platform. For [Mendix on Kubernetes](/developerportal/deploy/private-cloud/) API, see [Mendix on Kubernetes Build API](/apidocs-mxsdk/apidocs/private-cloud-build-api/) and [Mendix on Kubernetes Deploy API](/apidocs-mxsdk/apidocs/private-cloud-deploy-api/).
13+
{{% /alert %}}
14+
15+
## Introduction
16+
17+
The Private Mendix Platform Group API allows you to manage user groups in Private Mendix Platform. You can use the API to do the following:
18+
19+
* Create a new environment for the application
20+
* Retrieve all environments for the application
21+
* Retrieve a specified environment for the application
22+
* Update a specified environment for the application
23+
* Delete a specified environment for the application
24+
25+
## API Reference
26+
27+
{{< swaggerui src="/openapi-spec/openapi-deploy.yaml" >}}

content/en/docs/deployment/docker-deploy/docker-pad.md

Lines changed: 174 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -235,3 +235,177 @@ The Mendix Runtime exposes health check endpoints that can be used to monitor th
235235
| `/health/ready` | Returns the readiness status — indicates if the app is ready to serve traffic |
236236

237237
These endpoints are especially useful when integrating with orchestration platforms such as Kubernetes, which rely on liveness and readiness probes to manage container lifecycle.
238+
239+
## Reverse Proxy
240+
241+
This section serves as a reference guide and starting point for configuring a reverse proxy on Docker. The configurations provided are intended for illustrative purposes only, as the required settings vary depending on your specific network environment and infrastructure setup.
242+
243+
{{% alert color="info" %}}
244+
This example implementation is provided as-is, and is not covered under official support. Support requests related to this specific configuration cannot be addressed.
245+
{{% /alert %}}
246+
247+
### Configuring Nginx
248+
249+
To configure Nginx, perform the following steps:
250+
251+
1. Define services for the app and Nginx reverse proxy:
252+
253+
```text
254+
services:
255+
app:
256+
build: .
257+
ports:
258+
- "127.0.0.1:8080:8080" # Bind only localhost
259+
environment:
260+
- SPRING_PROFILES_ACTIVE=docker
261+
nginx:
262+
image: nginx:alpine
263+
ports:
264+
- "80:80"
265+
volumes:
266+
- ./nginx.conf:/etc/nginx/nginx.conf:ro
267+
depends_on:
268+
- app
269+
```
270+
271+
2. Run the following command: `docker-compose up --build`.​
272+
3. Create the following `nginx.conf` file to proxy requests to the app:
273+
274+
```text
275+
events {}
276+
http {
277+
server {
278+
listen 80;
279+
location / {
280+
proxy_pass http://app:8080;
281+
proxy_set_header Host $host;
282+
proxy_set_header X-Real-IP $remote_addr;
283+
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
284+
proxy_set_header X-Forwarded-Proto $scheme;
285+
}
286+
}
287+
}
288+
```
289+
290+
This configuration exposes only port 80 publicly while acting as a proxy to your app on the internal port 8080.
291+
292+
### Configuring Traefik
293+
294+
To simplify setting up Traefik as a reverse proxy for your app running in a Docker container, use Docker Compose. This configuration exposes Traefik on ports `80/8080`, automatically discovers your app container through labels, and routes traffic to it.
295+
296+
Traefik uses two networks: *frontend* (public) and *backend* (internal).
297+
298+
1. Add Traefik labels to the app service:
299+
300+
```text
301+
services:
302+
traefik:
303+
image: traefik:v3.0
304+
ports:
305+
- "80:80"
306+
- "8080:8080" # Traefik dashboard
307+
volumes:
308+
- /var/run/docker.sock:/var/run/docker.sock:ro
309+
command:
310+
- --api.dashboard=true
311+
- --providers.docker=true
312+
- --providers.docker.exposedbydefault=false
313+
- --entrypoints.web.address=:80
314+
networks:
315+
- frontend
316+
- backend
317+
restart: unless-stopped
318+
app:
319+
build: .
320+
networks:
321+
- backend
322+
labels:
323+
- traefik.enable=true
324+
- traefik.docker.network=backend
325+
- traefik.http.routers.app.rule=Host(`localhost`) || PathPrefix(`/api`)
326+
- traefik.http.routers.app.entrypoints=web
327+
- traefik.http.services.app.loadbalancer.server.port=8080
328+
restart: unless-stopped
329+
networks:
330+
frontend:
331+
external: false
332+
backend:
333+
external: false
334+
```
335+
336+
2. Run the following command: `docker compose up -d --build`.
337+
338+
You can now access your app at `http://localhost`. Traefik proxies to `app:8080` internally.
339+
340+
#### Key Traefik Labels Explained
341+
342+
This section explains the main labels used by Traefik.
343+
344+
* `traefik.enable=true` - Enables Traefik for this container.
345+
* `traefik.http.routers.java-app.rule=Host(yourapp.example.com)` - Routes requests matching the host to this service.
346+
* `traefik.http.services.java-app.loadbalancer.server.port=8080` - Forwards to your app's internal port.
347+
348+
Traefik automatically detects changes through a Docker socket. You do not need to restart it to update the labels.
349+
350+
#### Main Differences between Traefik and Nginx
351+
352+
This section explains how Traefik proxies differ from Nginx.
353+
354+
* Traefik does not use static config files. Instead, the configuration is automatic through the use of labels.
355+
* A dashboard available at `http://localhost:8080` shows the routes.
356+
* You can easily scale by duplicating the `app service` with unique router rules (for example, `Host(app2.local)`).​
357+
358+
## Example High Availability Implementation
359+
360+
High availability (HA) requires redundancy, health checks, and restarts to handle failures. Scale for HA with Docker Compose (for local or development environments) or Kubernetes.
361+
362+
This section serves as a reference guide and starting point for configuring high availability on Docker. The configurations provided are intended for illustrative purposes only, as the settings will vary depending on your specific network environment and infrastructure setup.
363+
364+
{{% alert color="info" %}}
365+
This example implementation is provided as-is, and is not covered under official support. Support requests related to this specific configuration cannot be addressed.
366+
{{% /alert %}}
367+
368+
1. Configure the *docker-compose.yml* as in the following example:
369+
370+
```text
371+
services:
372+
myapp:
373+
image: myapp
374+
ports:
375+
- "8080:8080"
376+
deploy:
377+
replicas: 3 # Run 3 instances
378+
healthcheck:
379+
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:8080/actuator/health"]
380+
interval: 30s
381+
timeout: 10s
382+
retries: 3
383+
```
384+
385+
2. Start the process by running the following command: `docker-compose up --scale myapp=3`.
386+
3. Add a load balancer like Traefik or an NGINX reverse proxy in the front:
387+
388+
``` text
389+
services:
390+
traefik:
391+
image: traefik:v3.0
392+
command: --providers.docker --entrypoints.web.address=:80
393+
ports: ["80:80"]
394+
myapp:
395+
# No ports exposed; Traefik load balances
396+
```
397+
398+
This creates a redundancy—kill container, and traffic shifts automatically.
399+
400+
4. Build and run manually by running the following script:
401+
402+
``` text
403+
# Build image
404+
docker build -t myapp:latest .
405+
# Test single instance
406+
docker run -p 8080:8080 myapp:latest
407+
# For HA: Run 3 replicas (use docker-compose.yml for production)
408+
docker run -d -p 8081:8080 --name app1 myapp:latest
409+
docker run -d -p 8082:8080 --name app2 myapp:latest
410+
docker run -d -p 8083:8080 --name app3 myapp:latest
411+
```

content/en/docs/deployment/on-premises-design/ms-windows/sql-server/setting-up-a-new-sql-server-database.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,15 +19,15 @@ Some of these steps are only required for specific versions of SQL Server or Men
1919

2020
When setting up a new database for Mendix, you can leave most of the settings to the default configuration. When looking at the general settings, you only need to set up the database name. Set up the database files according to the [Microsoft SQL Server best practices](https://www.mssqltips.com/sqlservertip/4891/sql-server-installation-best-practices/).
2121

22-
{{< figure src="/attachments/deployment/on-premises-design/ms-windows/sql-server/setting-up-a-new-sql-server-database/18580676.png" class="no-border" >}}
22+
{{< figure src="/attachments/deployment/on-premises-design/ms-windows/sql-server/setting-up-a-new-sql-server-database/sql-server-general.png" alt="New Database dialog General page with database name and files configuration" >}}
2323

2424
In the database options, the default properties need to be evaluated. When choosing a collation, pay attention to the type of collation you are going to use. Mendix uses UTF-8 for all data evaluation. Depending on your exact locale, you will most likely want to choose one of the `SQL_Latin1_General_` collations. The exact encoding depends on your OS. For an **en_US** installation, for example, the encoding is `CP1`.
2525

2626
The last two collation arguments identify how sorting and uniqueness are interpreted. For example, the collation argument `CS` indicates that the collation sorting style is case sensitive. For more information on collations and case sensitivity, see [Case-Sensitive Database Behavior](/refguide/case-sensitive-database-behavior/) and the Microsoft documentation [Windows Collation Name](https://docs.microsoft.com/en-us/sql/t-sql/statements/windows-collation-name-transact-sql).
2727

2828
Mendix recommends using the **Simple** recovery model option. Mendix does not use the full functionality offered in the **Full** recovery model option; although you can successfully use the **Full** recovery model, it could increase the data usage of all the transactions and might slow down any rollbacks in case of an error.
2929

30-
{{< figure src="/attachments/deployment/on-premises-design/ms-windows/sql-server/setting-up-a-new-sql-server-database/18580675.png" class="no-border" >}}
30+
{{< figure src="/attachments/deployment/on-premises-design/ms-windows/sql-server/setting-up-a-new-sql-server-database/sql-server-options.png" alt="New Database dialog Options page showing collation and recovery model settings" >}}
3131

3232
After the database is created, the Mendix Runtime can initiate the initial setup and prepare all the tables and functions for usage by the platform. Some of these queries require `sysadmin` privileges. The `sysadmin` role can be temporarily assigned to the user, or these queries can be executed by the administrator. Other queries need privileges that are implicitly assigned to the `db_owner` role. If the user used by the Mendix Runtime does not have enough permissions for any of these queries, you can run them manually – see below for more information.
3333

content/en/docs/marketplace/platform-supported-content/modules/global-inbox.md

Lines changed: 14 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -101,24 +101,23 @@ Make sure the Global Inbox app is deployed and running before deploying the Publ
101101
* **AppBaseUrl**: Must include the protocol (http:// or https://) and must not end with a trailing slash. It is used as the base URL when redirecting users to the publisher apps.
102102
5. When a user opens a task from the **Global Inbox**, they are redirected to the corresponding task page in the Publisher Application through a deeplink. Because the user entered the application through the Global Inbox instead of the normal navigation flow, developers must decide how the application should behave when the user completes the user task and/or closes the page. Developers can either change show page action in the deeplink microflow **DL_WorkflowUserTask_ShowUserTaskPage** to redirect to another page or adjust the default deeplink landing page in **UseMe** > **Deeplink** > **Deeplink Landing Page** to meet their business needs. If further customization is required, it is possible to adjust the logic for the outcome buttons in each of the task pages.
103103

104-
### Setting up Business Events
104+
### Setting up Business Events Locally
105105

106-
Configure the [Mendix Event Broker](https://marketplace.mendix.com/link/component/202907) or [your own Kafka](/appstore/services/business-events-deployment/#byok) cluster. Refer to the [Mendix Event Broker](/appstore/services/event-broker/) documentation for relevant steps.
107-
108-
### Local Setup
109-
110-
For local development and testing, the Event Broker can be deployed using the [Local Setup Tool](https://github.com/mendix/event-broker-tools). For more information, see [Deployment](/appstore/services/business-events-deployment/#deployment).
111-
112-
In both the **Global Inbox** and **Global Inbox Connector** modules, configure the following application constants:
106+
For local development and testing, the Event Broker can be deployed using the [Local Setup Tool](https://github.com/mendix/event-broker-tools). For more information, see the [Deployment](/appstore/services/business-events-deployment/#deployment) section in *Deploy a Business Event*. In both the **Global Inbox** and **Global Inbox Connector** modules, configure the following application constants:
113107

114108
* **ServerUrl**: the URL of the local broker instance
109+
115110
* **ChannelName**: the name of the event channel used for publishing and subscribing to Business Events
116111

117112
These settings ensure that Business Events are correctly routed between Publisher Applications and the Global Inbox during local testing.
118113

114+
For instructions on setting up a local test environment, refer to the Mendix Academy guide: [Set up your Local Test Environment](https://academy.mendix.com/index3.html#/modules/622/lectures/4833/Set-up-your-Local-Test-Environment).
115+
119116
### Deployment
120117

121-
For deployment, the Global Inbox requires the Mendix Event Broker or an external Kafka cluster. For more information, see the [Production Deployment](/appstore/services/business-events-deployment/#production-deployment) section in *Deploy a Business Event*.
118+
#### Mendix Public Cloud
119+
120+
For deployment, the Global Inbox requires the Mendix Event Broker or [Bring Your Own Kafka](/appstore/services/business-events-deployment/#byok). For more information, see the [Production Deployment](/appstore/services/business-events-deployment/#production-deployment) section in *Deploy a Business Event*.
122121

123122
Ensure the Mendix Event Broker is enabled for all apps and environments, and deploy applications in the correct order: Global Inbox application must be running before the publisher applications.
124123

@@ -128,6 +127,12 @@ If you are deploying your apps to Mendix Cloud for the first time, you must firs
128127

129128
Ensure the **Global Inbox Connector** constants are configured in each Publisher Application as part of the deployment process.
130129

130+
#### Mendix Free Cloud
131+
132+
When deploying to the Mendix Free Cloud, the [Mendix Event Broker](/appstore/services/event-broker/) is provided as a shared, multi-tenant service.
133+
134+
Within this setup, no additional configuration or license is required. The Event Broker is automatically available after deploying your app and enabling business events.
135+
131136
## Security
132137

133138
Any user that can see a task in Publisher Application can see the same task in the **Global Inbox**. This is based on the **System.User.Name** attribute that is used as the unique identifier to link users across the applications. For this reason:

content/en/docs/refguide/modeling/security/app-security/anonymous-users.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,10 @@ The properties of anonymous users are described in the table below:
2121
| Allow anonymous users | When **Yes** is selected, anonymous users are allowed. End-users do not have to sign in to access the application. <br />When **No** is selected, anonymous users are not allowed. End-users have to sign in to access the application. |
2222
| Anonymous user role | The user role that end-users of your application have when they are not signed in. This tells the application which role should be automatically applied to anonymous users who access the app. The **Allow anonymous users** property should be set to **Yes** to select an anonymous user role. |
2323

24+
{{% alert color="warning" %}}
25+
Enabling anonymous users allows anyone to use your app without signing in. To prevent unintended data exposure, ensure that the anonymous user role has limited access across your app by configuring appropriate entity and microflow access rules.
26+
{{% /alert %}}
27+
2428
## Read More
2529

2630
* [App Security](/refguide/app-security/)

content/en/docs/refguide10/modeling/security/app-security/anonymous-users.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,10 @@ The properties of anonymous users are described in the table below:
2121
| Allow anonymous users | When **Yes** is selected, anonymous users are allowed. End-users do not have to sign in to access the application. <br />When **No** is selected, anonymous users are not allowed. End-users have to sign in to access the application. |
2222
| Anonymous user role | The user role that end-users of your application have when they are not signed in. This tells the application which role should be automatically applied to anonymous users who access the app. The **Allow anonymous users** property should be set to **Yes** to select an anonymous user role. |
2323

24+
{{% alert color="warning" %}}
25+
Enabling anonymous users allows anyone to use your app without signing in. To prevent unintended data exposure, ensure that the anonymous user role has limited access across your app by configuring appropriate entity and microflow access rules.
26+
{{% /alert %}}
27+
2428
## Read More
2529

2630
* [App Security](/refguide10/app-security/)

content/en/docs/refguide9/modeling/app-explorer/security/app-security/anonymous-users.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,10 @@ The properties of anonymous users are described in the table below:
2121
| Allow anonymous users | When **Yes** is selected, anonymous users are allowed. End-users do not have to sign in to access the application. <br />When **No** is selected, anonymous users are not allowed. End-users have to sign in to access the application. |
2222
| Anonymous user role | The user role that end-users of your application have when they are not signed in. This tells the application which role should be automatically applied to anonymous users who access the app. The **Allow anonymous users** property should be set to **Yes** to select an anonymous user role. |
2323

24+
{{% alert color="warning" %}}
25+
Enabling anonymous users allows anyone to use your app without signing in. To prevent unintended data exposure, ensure that the anonymous user role has limited access across your app by configuring appropriate entity and microflow access rules.
26+
{{% /alert %}}
27+
2428
## Read More
2529

2630
* [App Security](/refguide9/app-security/)

content/en/docs/releasenotes/feature-release-calendar/_index.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -36,9 +36,9 @@ General Availability means that a feature is available for all users. This type
3636
| Global Inbox Workflow Tasks | General Availability: Mx 11.9 |
3737
| Global Inbox Other Tasks | General Availability: Mx 11.12 |
3838
| Workflow Non-interrupting Event Subprocesses (Message trigger) | Public Beta: Mx 11.8 <br/>General Availability: Mx 11.9 |
39-
| Workflow Interrupting Event Subprocesses (Message trigger) | General Availability: Mx 11.12 |
40-
| Workflow Interrupting Event Subprocesses (Timer trigger) | General Availability: Mx 11.12 |
41-
| Workflow Message Events | General Availability: Mx 11.12 |
39+
| Workflow Interrupting Event Subprocesses (Message trigger) | General Availability: Mx 11.10 |
40+
| Workflow Interrupting Event Subprocesses (Timer trigger) | General Availability: Mx 11.14 |
41+
| Workflow Message Events | General Availability: Mx 11.11 |
4242

4343
{{% alert color="info" %}}
4444
¹Limitations: Initially only Mendix Cloud GenAI Resources as provider, and only design-time modification of prompts and other agent settings. Incrementally, we will remove these limitations.

0 commit comments

Comments
 (0)