# Update\_ood\_portal script does not work

**URL:** <https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375>\
**Category:** Get Help\
**Created:** [June 24, 2019, 1:49am UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375 "2019-06-24T01:49:04Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![neranjan](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/neranjan/32/208_2.png) [@neranjan](https://discourse.openondemand.org/u/neranjan)\
**Post date:** [June 24, 2019, 1:49am UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/1 "2019-06-24T01:49:05Z")

</div>

I’m trying to setup ood 1.6. I’m encountering a problem where the “update\_ood\_portal” script does not produce expected httpd.conf file. Above script worked for SSL setup. However, it did not work for keycloak setup in the authorization step. I was able to get it working following the manual setup described in the documentation. Now I’m in the interactive application setup step but could not get the reverse proxy to work without “update\_ood\_portal”. Please point me to correct documentation on how to set up httpd.conf manually.

---

<div class="post-metadata">

**Author:** ![rodgers.355](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/rodgers.355/32/193_2.png) [@rodgers.355](https://discourse.openondemand.org/u/rodgers.355)\
**Post date:** [June 27, 2019, 1:56pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/2 "2019-06-27T13:56:14Z")

</div>

@neranjan it sounds like you are having trouble using `update_ood_portal` to convert your `ood_portal.yml` into the proper Apache conf. If you let us know what Apache directives you are trying to add we can help you get the YAML right so that `update_ood_portal` works properly.

The documentation we have for using KeyCloak with OnDemand is available at: [https://osc.github.io/ood-documentation/master/authentication/tutorial-oidc-keycloak-rhel7.html](https://osc.github.io/ood-documentation/master/authentication/tutorial-oidc-keycloak-rhel7.html).

The section that is directly relevant to updating the Apache configuration file for OnDemand (`ood-portal.conf`) is here: [https://osc.github.io/ood-documentation/master/authentication/tutorial-oidc-keycloak-rhel7/install\_mod\_auth\_openidc.html#re-generate-main-config-using-ood-portal-generator](https://osc.github.io/ood-documentation/master/authentication/tutorial-oidc-keycloak-rhel7/install_mod_auth_openidc.html#re-generate-main-config-using-ood-portal-generator).

Finally, we do not have documentation posted on setting up `ood-portal.conf` manually.

---

<div class="post-metadata">

**Author:** ![neranjan](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/neranjan/32/208_2.png) [@neranjan](https://discourse.openondemand.org/u/neranjan)\
**Post date:** [June 29, 2019, 12:34am UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/3 "2019-06-29T00:34:06Z")

</div>

Thanks for the reply.

As I mentioned in my original post, I was able to setup KeyCloak. However, I’m having problems setting up Reverse Proxy. [Enable Reverse Proxy](https://osc.github.io/ood-documentation/master/app-development/interactive/setup/enable-reverse-proxy.html)

I followed direction and add the following lines to the /etc/ood/config/ood\_portal.yml.

```
host_regex: '[\w.-]+\.gsu\.edu'
node_uri: '/node'
rnode_uri: '/rnode'

```

But after running sudo /opt/ood/ood-portal-generator/sbin/update\_ood\_portal and restarting the process, the example does not work.

ssh n0001.rs.gsu.edu  
nc -l 5432

then  
[https://ondemand.rs.gsu.edu/node/n0001.rs.gsu.edu/5432/](https://ondemand.rs.gsu.edu/node/n0001.rs.gsu.edu/5432/)

Also, I do not see any changes in the apache conf file. What could be the reason that update\_ood\_portal does not work? what is the proper way to debug this problem?

---

<div class="post-metadata">

**Author:** ![efranz](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/efranz/32/27_2.png) [@efranz](https://discourse.openondemand.org/u/efranz)\
**Post date:** [July 2, 2019, 2:54pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/4 "2019-07-02T14:54:30Z")

</div>

So OSC has this for one of the OnDemand installs:

```auto
host_regex: "[\\w.-]+\\.osc\\.edu"
node_uri: "/node"
rnode_uri: "/rnode"

```

and the corresponding ood-portal.conf generated is:

```auto
  # Reverse proxy traffic to backend webserver through IP sockets:
  #
  # https://ondemand-test.osc.edu:443/node/HOST/PORT/index.html
  # #=> http://HOST:PORT/node/HOST/PORT/index.html
  #
  <LocationMatch "^/node/(?<host>[\w.-]+\.osc\.edu)/(?<port>\d+)">
    AuthType openid-connect
    Require valid-user

    # ProxyPassReverse implementation
    Header edit Location "^[^/]+//[^/]+" ""

    # ProxyPassReverseCookieDomain implemenation
    Header edit* Set-Cookie ";\s*(?i)Domain[^;]*" ""

    # ProxyPassReverseCookiePath implementation
    Header edit* Set-Cookie ";\s*(?i)Path[^;]*" ""
    Header edit Set-Cookie "^([^;]+)" "$1; Path=/node/%{MATCH_HOST}e/%{MATCH_PORT}e"

    LuaHookFixups node_proxy.lua node_proxy_handler
  </LocationMatch>

  # Reverse "relative" proxy traffic to backend webserver through IP sockets:
  #
  # https://ondemand-test.osc.edu:443/rnode/HOST/PORT/index.html
  # #=> http://HOST:PORT/index.html
  #
  <LocationMatch "^/rnode/(?<host>[\w.-]+\.osc\.edu)/(?<port>\d+)(?<uri>/.*|)">
    AuthType openid-connect
    Require valid-user

    # ProxyPassReverse implementation
    Header edit Location "^([^/]+//[^/]+)|(?=/)" "/rnode/%{MATCH_HOST}e/%{MATCH_PORT}e"

    # ProxyPassReverseCookieDomain implemenation
    Header edit* Set-Cookie ";\s*(?i)Domain[^;]*" ""

    # ProxyPassReverseCookiePath implementation
    Header edit* Set-Cookie ";\s*(?i)Path[^;]*" ""
    Header edit Set-Cookie "^([^;]+)" "$1; Path=/rnode/%{MATCH_HOST}e/%{MATCH_PORT}e"

    LuaHookFixups node_proxy.lua node_proxy_handler
  </LocationMatch>

```

And this is because the template that is used to render this is: [https://github.com/OSC/ondemand/blob/7926843ba237cb831762db698e3b538fb10b025b/ood-portal-generator/templates/ood-portal.conf.erb#L126-L174](https://github.com/OSC/ondemand/blob/7926843ba237cb831762db698e3b538fb10b025b/ood-portal-generator/templates/ood-portal.conf.erb#L126-L174)

So if /opt/rh/httpd24/root/etc/httpd/conf.d/ood-portal.conf does not have directives corresponding to the ones above then indeed it appears there is a problem generating the config. Can you confirm that is the case? Is that what you mean when you say “I do not see any changes in the apache conf file”.

If the directives are not there, than adding those would be the first step. I’m not sure why update\_ood\_portal script would not work but confirm that your YAML config file is at /etc/ood/config/ood\_portal.yml.

If the directives are there, what is the error you see when you go to [https://ondemand.rs.gsu.edu/node/n0001.rs.gsu.edu/5432/](https://ondemand.rs.gsu.edu/node/n0001.rs.gsu.edu/5432/)? One common problem is that firewall settings are preventing the request to successfully proxy from the web node to the compute node.

---

<div class="post-metadata">

**Author:** ![neranjan](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/neranjan/32/208_2.png) [@neranjan](https://discourse.openondemand.org/u/neranjan)\
**Post date:** [July 8, 2019, 3:36pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/5 "2019-07-08T15:36:32Z")

</div>

@efranz that’s it. It worked perfectly after manually editing ood\_portal.conf. I had my ood\_portal.yml in the correct location. but for some reason it did not generate correct ood-portal.conf file. Thanks for your help.

---

<div class="post-metadata">

**Author:** ![suzlitz](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/suzlitz/32/104_2.png) [@suzlitz](https://discourse.openondemand.org/u/suzlitz)\
**Post date:** [July 18, 2019, 7:48pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/6 "2019-07-18T19:48:41Z")

</div>

I am also hitting this problem again. The ood-portal.conf file clearly states “DO NOT EDIT THIS FILE” but there are so many lines missing from it - all the reverse proxy stuff. Are we supposed to edit the file since the generator isn’t doing it correctly?

---

<div class="post-metadata">

**Author:** ![efranz](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/efranz/32/27_2.png) [@efranz](https://discourse.openondemand.org/u/efranz)\
**Post date:** [July 18, 2019, 8:07pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/7 "2019-07-18T20:07:02Z")

</div>

I opened an issue [https://github.com/OSC/ondemand/issues/48](https://github.com/OSC/ondemand/issues/48) to track investigating this problem. The old file should be saved to the same directory so you could do a diff and see what was missing and add it back. Unfortunately every time a new rpm is installed the update script will run and will again backup the existing ood-portal.conf file and write its new one.

Which is the reason for the recommendation to not edit it.

---

<div class="post-metadata">

**Author:** ![efranz](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/efranz/32/27_2.png) [@efranz](https://discourse.openondemand.org/u/efranz)\
**Post date:** [July 18, 2019, 8:09pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/8 "2019-07-18T20:09:05Z")

</div>

@suzlitz is your correct YAML config still at /etc/ood/config/ood\_portal.yml

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [July 19, 2019, 3:01pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/9 "2019-07-19T15:01:56Z")

</div>

Yea if you’re still having issues, please attach your ood\_portal.yml to the github issue so we can replicate it. Of course, replacing sensitive information with the actual work ‘sensitive’ or sens.itive.edu or similar.

---

<div class="post-metadata">

**Author:** ![westburg.2](https://avatars.discourse-cdn.com/v4/letter/w/0ea827/32.png) [@westburg.2](https://discourse.openondemand.org/u/westburg.2)\
**Post date:** [May 26, 2022, 3:20pm UTC](https://discourse.openondemand.org/t/update-ood-portal-script-does-not-work/375/10 "2022-05-26T15:20:05Z")

</div>


