gRPC transport modes#
This section summarizes the supported gRPC transport modes between SAF GLOW Engine and product instances. These modes apply when using product instance managers that expose gRPC services and use product configurations that have enable_secure_flags=True, such as GeometrySecureManager.
Important
Existing Product Instance managers and configurations that use gRPC continue to use insecure gRPC connections in all cases to avoid breaking changes. To benefit from the supported secure connection modes, make sure to use product instance managers and configurations with secure_flags enabled, such as GeometrySecureManager.
Supported modes by product instance system#
The effective transport mode depends on:
Product instance system:
PIM Light ServerorHPS.Operating system of the product instance.
Product binding host (localhost vs non-localhost).
Availability of gRPC certificates.
Product instance system |
Product host scenario |
Supported mode |
Required configuration |
|---|---|---|---|
|
Windows + localhost binding |
|
No certificate directory required. |
|
Any other scenario |
|
No secure mode currently supported. |
|
Windows + localhost binding |
|
No certificate directory required. |
|
Linux + localhost binding |
|
No certificate directory required. |
|
Windows or Linux + non-localhost binding, certificates available |
|
Requires certificate directory. |
|
Windows or Linux + non-localhost binding, certificates not available |
|
This behavior is a compatibility fallback. |
Important
When using PIM Light Server, even if WNUA is used, SAF GLOW Engine logs that insecure gRPC connections is being used. This is because SAF GLOW Engine doesn’t have enough information to reliably say if the product is running with WNUA or in insecure mode. Nevertheless, in the products instance output, you can verify that it’s running with WNUA.
These modes describe the product instance system capabilities. However, the actual transport availability also depends on the capabilities of the product and its client. Check the notes for each product in Supported product instance managers.
Configuration variables#
Use
GLOW_PRODUCT_BINDING_HOSTto control whether the product binds to localhost or a non-localhost IP. This is set in the environment where the product instance is running, NOT in the GLOW API environment. When using products withsecure_flagsenabled, it defaults tolocalhost, which enables eitherWNUAorUDSmodes depending on the operating system. On the other hand, in insecure products, it defaults to all interfaces (0.0.0.0) to avoid breaking changes.Use
ANSYS_GRPC_CERTIFICATESto enablemTLSin non-localhost scenarios. Certificates directory must contain:client.crtclient.keyca.crt