6.1. Shared architecture#

This page describes architecture components and connector behavior common to Nubus for UCS and Nubus for Kubernetes.

For deployment-specific details, see For Nubus for UCS and For Nubus for Kubernetes.

6.1.1. Common architecture components#

The OX Connector has the following common architecture components:

Identity Store and Directory Service#

The Identity Store and Directory Service includes the OpenLDAP software that provides the LDAP directory in Nubus. The LDAP directory stores identity and infrastructure data in the domain. For more information, see LDAP directory service in Nubus for UCS 5.2 - Operation Manual [1].

Directory Manager#

The Directory Manager is an abstraction layer of directory objects in the Identity Store and Directory Service. For more information, see Directory Manager in Nubus for Kubernetes - Architecture Manual 1.x [11].

Provisioning Service#

The OX Connector subscribes to the Provisioning Service through the Provisioning API for the Univention Directory Manager (UDM) modules that it provisions. For information about change processing, consumer registration, and prefill, see Provisioning Service in Nubus for Kubernetes - Architecture Manual 1.x [11].

Provisioning API#

The OX Connector subscribes through the Provisioning API for the UDM modules that it provisions. For information about the API and consumer registration, see Consumer Registration HTTP REST API in Nubus for Kubernetes - Architecture Manual 1.x [11].

OX Connector#

OX Connector connects Nubus identity management to OX App Suite. The connector receives data about changes in the LDAP directory. A OX Connector Provisioning Consumer handles the data, processes it, and sends it to the SOAP API in OX App Suite.

OX Connector Provisioning Consumer#

The OX Connector Provisioning Consumer is the OX Connector component that receives provisioning messages, stores work in the connector database, and provisions OX App Suite objects.

OX App Suite#

OX App Suite is the groupware and collaboration software from Open-Xchange.

SOAP API#

OX App Suite provides a SOAP API for receiving data and running remote procedure calls. The connector uses the SOAP API to create, update, or delete OX App Suite objects.

6.1.2. Provisioned attributes#

The OX Connector maps UDM attributes to OX App Suite attributes. The default user attribute mapping provisions the following attributes:

  • User names, email addresses, and aliases

  • Business and personal contact details

  • Organization and address data

  • Profile images and dates

  • Mailbox quotas

  • IMAP and SMTP servers

  • User-defined fields

6.1.3. Database of object state#

OX App Suite assigns an internal ID to each object that it creates or updates. After successfully processing an object, the connector stores its state, including the internal ID, in a local database. The connector doesn’t store the internal ID in the LDAP directory.

The connector uses stored internal IDs for operations that require them. For example, when it updates a group through the SOAP API, the request must include the internal ID of each group member. This avoids a remote lookup in OX App Suite for each group member.