Introduction
Before we get into the recipes themselves, here is some background on how to configure service accounts and the information needed for firewall configuration.
Service accounts
As in all production environments, you should consider using dedicated service accounts for connections between different services. For Orchestrator, there are several connections that we should have a look at. The connections between Orchestrator and SMTP, LDAP, and the Orchestrator database should be facilitated with a normal AD service account. The connection between Orchestrator and SSO uses the registered SSO application user.
The connection between Orchestrator and vCenter depends on how you would like to handle the role and rights management between them. You can either use one administrative connection between Orchestrator and vCenter, or choose to limit access by the role and rights of the logged-in Orchestrator user. We will discuss some more details of this in the Plugin basics recipe in this...