Configure GitHub Enterprise Cloud with data residency

Configure GitHub Enterprise Cloud with data residency and the SnapLogic Git Integration.

GitHub Enterprise Cloud with data residency is a separate GitHub product and SnapLogic subscription. Organizations use it to keep their repository data in a specific geographic region. Unlike standard GitHub Enterprise Cloud (GHEC), which uses the shared api.github.com endpoint, it hosts your organization on a dedicated *.ghe.com subdomain (for example, https://acme.ghe.com).

The SnapLogic Git Integration provides a matching connection type for this subscription. When you select GitHub Enterprise Cloud with data residency as the Git integration type in Admin Manager, SnapLogic routes Git Integration requests to your organization's dedicated endpoint instead of the standard GHEC endpoint.

  • A subscription for GitHub Enterprise Cloud with data residency.
  • GitHub organization administrator permissions, to create and install the GitHub App.
Important: The option appears in Admin Manager only if your organization has the GitHub Enterprise Cloud with data residency subscription. Contact your Customer Success Manager (CSM) to enable it.

Create the SnapLogic GitHub App

Important: Because GitHub Enterprise Cloud with data residency isolates your organization within its own *.ghe.com boundary, you can't install SnapLogic's public, multi-tenant GitHub App from github.com. Instead, a GitHub organization administrator must create a private GitHub App within your own *.ghe.com organization.
  1. Create a GitHub App to register SnapLogic with your organization.
    1. In your organization's *.ghe.com instance, follow the GitHub instructions to create a new GitHub App.
      Field Description
      GitHub App name The name of your GitHub App.

      Example: snaplogic-app

      Homepage URL The full URL to the GitHub App's page in your organization.

      Example: https://your-org.ghe.com/github-apps/snaplogic-app/

      Callback URL The full URL to redirect to after installation is authorized: https://control-plane-name/api/1/rest/asset/app/oauthcallback. Where control-plane-name is the control plane you are using. Example:
      • elastic.snaplogic.com
      • uat.elastic.snaplogic.com
      • emea.snaplogic.com
      Expire user authorization tokens Enable this option.
      Permissions > Repository permissions
      • Contents: Read & write.
      • Deployments: Read & write.
      • Issues: Read & write.
      • Pull requests: Read & write.
      Where can this GitHub App be installed

      Select Only on this account.

      Create the app under the GitHub organization that owns your repositories, not a personal user account. If you create it under a personal account, you must transfer it to the organization before you can use it with the Git Integration.

    2. Save the App ID and Client ID, both shown on this page — you'll need them to configure the Git Integration in Admin Manager.
    3. Install the new GitHub App on the organization and select the repositories to which it will have access.
      Important: The GitHub App's permissions apply to the whole app; when you install it, you only choose which repositories it can reach. Make sure the app's Contents: Read & write permission wasn't reduced from what you set during app creation — SnapLogic uses this permission to list branches and tags, and a lower permission causes branch and tag lookups to return empty results and can cause checkout failures. If your branch or tag list is empty after checkout, refer to Branch or tag lists are empty, or checkout fails.
    4. On the About page of the GitHub App, generate and save a client secret and a private key.

      The generated private key is automatically downloaded as a .pem file.

  2. Confirm you have all four values — Client ID, Client secret, App ID, and private key — before continuing.

Configure the Git Integration in Admin Manager

  1. Log in to your SnapLogic environment and configure the Git Integration. In Admin Manager, from the left pane select Git Integration. From the Git integration type dropdown, select GitHub Enterprise Cloud with data residency, and fill in the following settings:
    Field/Field set Description
    Client ID The value stored in the GitHub App.
    Client secret The field displays this value until you save the configuration, then it is hidden. Later, the only way to change it is to replace it.
    API URL Your organization's dedicated API host, for example https://api.company.ghe.com.
    Auth URL The authorization host for your organization's *.ghe.com domain, used for GitHub App sign-in.
    Important: Confirm the exact Auth URL value with your GitHub organization administrator; it can differ depending on how SAML/EMU is configured for your organization.
    App ID The GitHub App's ID, shown on the app's settings page.
    Private key Copy and paste the RSA key from the .pem file generated during the GitHub App creation.
  2. Click Validate. When Connection successful! appears, click Save.
Individual users authorize SnapLogic to access their Git provider account.