Workload Manager for SAP solutions uses Google Cloud's Agent for SAP to detect and collect metadata for evaluating your SAP system configurations. The Agent for SAP, along with the SAP Host Agent, are required on all VM instances that run SAP systems for support and monitoring of your SAP systems running on Google Cloud, including SAP NetWeaver, SAP HANA, SAP ASE, and SAP MaxDB.
Before you begin
Before you install and configure Google Cloud's Agent for SAP, you need to make sure that the following prerequisites are met:
- You've deployed an SAP workload on one or more compute instances.
- You've reviewed the supported regions where you can create Workload Manager evaluations.
- Your administrator has granted you IAM roles required to create and run Workload Manager evaluations.
- You've granted the required IAM roles for the agent.
- You've enabled access to Cloud APIs.
Required IAM roles for the agent
Agent for SAP uses the service account attached to the compute instance for authentication and to access Google Cloud resources.
To improve security, we recommend that you use a single-purpose service account rather than using the Compute Engine default service account.
To ensure that the service account has the necessary permissions to let Agent for SAP authenticate with Google Cloud and access Google Cloud resources, ask your administrator to grant the following IAM roles to the service account on your project:
-
Collect metrics from the compute instance:
Compute Viewer (
roles/compute.viewer) -
Write data to Workload Manager data warehouse:
Workload Manager Insights Writer (
roles/workloadmanager.insightWriter) -
Send agent logs to Cloud Logging:
Logs Writer (
roles/logging.logWriter) -
If you are using Secret Manager to store the password to connect with the SAP workload:
Secret Manager Secret Accessor (
roles/secretmanager.secretAccessor)
For more information about granting roles, see Manage access to projects, folders, and organizations.
Your administrator might also be able to give the service account the required permissions through custom roles or other predefined roles.
Enable access to Cloud APIs
Compute Engine recommends configuring your instances to allow all access scopes to all Cloud APIs. To control access to Google Cloud resources, use only the IAM permissions of the instance service account. For more information, see Create a VM that uses a user-managed service account.
If you limit access to the Cloud APIs, then the Agent for SAP requires at minimum the following Cloud APIs access scopes on the host compute instance:
https://www.googleapis.com/auth/cloud-platform
For more information, see Scopes best practice.
If you're running SAP applications on a compute instance that doesn't have an external IP address, then you need to enable Private Google Access on the instance's subnet so that Agent for Compute Workloads can access the Google APIs and services. For information about how to enable Private Google Access, see Configure Private Google Access.
Install and configure the agent by using package manager
This section shows you how to install the Agent for SAP on your compute instance, and configure it to connect with your SAP workload, by using a package manager.
If you want to install and configure the agent on a fleet of VMs, then you can use a VM Extension Manager policy instead. For more information, see Install and manage the agent on a fleet of VMs by using VM Extension Manager.
Install the agent
If not already done, then install Google Cloud's Agent for SAP on all compute instances that run your SAP workload:
To install the agent on a Compute Engine instance, follow these steps:
- Establish an SSH connection to your compute instance.
- In your terminal, install the agent by running the command that is specific
to your operating system:
- (Recommended) To install version 3.15 (latest) of the
agent:
RHEL
sudo tee /etc/yum.repos.d/google-cloud-sap-agent.repo << EOM [google-cloud-sap-agent] name=Google Cloud Agent for SAP baseurl=https://packages.cloud.google.com/yum/repos/google-cloud-sap-agent-el$(cat /etc/redhat-release | cut -d . -f 1 | tr -d -c 0-9)-x86_64 enabled=1 gpgcheck=1 repo_gpgcheck=0 gpgkey=https://packages.cloud.google.com/yum/doc/yum-key.gpg https://packages.cloud.google.com/yum/doc/rpm-package-key.gpg EOM sudo yum install google-cloud-sap-agent
SLES15
sudo zypper addrepo --refresh https://packages.cloud.google.com/yum/repos/google-cloud-sap-agent-sles15-x86_64 google-cloud-sap-agent sudo zypper install google-cloud-sap-agent
SLES 12
sudo zypper addrepo --refresh https://packages.cloud.google.com/yum/repos/google-cloud-sap-agent-sles12-x86_64 google-cloud-sap-agent sudo zypper install google-cloud-sap-agent
- To install a specific version of the agent:
RHEL
sudo tee /etc/yum.repos.d/google-cloud-sap-agent.repo << EOM [google-cloud-sap-agent] name=Google Cloud Agent for SAP baseurl=https://packages.cloud.google.com/yum/repos/google-cloud-sap-agent-el$(cat /etc/redhat-release | cut -d . -f 1 | tr -d -c 0-9)-x86_64 enabled=1 gpgcheck=1 repo_gpgcheck=0 gpgkey=https://packages.cloud.google.com/yum/doc/yum-key.gpg https://packages.cloud.google.com/yum/doc/rpm-package-key.gpg EOM sudo yum install google-cloud-sap-agent-VERSION_NUMBER.x86_64
SLES15
sudo zypper addrepo --refresh https://packages.cloud.google.com/yum/repos/google-cloud-sap-agent-sles15-x86_64 google-cloud-sap-agent sudo zypper install google-cloud-sap-agent-VERSION_NUMBER.x86_64
SLES 12
sudo zypper addrepo --refresh https://packages.cloud.google.com/yum/repos/google-cloud-sap-agent-sles12-x86_64 google-cloud-sap-agent sudo zypper install google-cloud-sap-agent-VERSION_NUMBER.x86_64
Replace
VERSION_NUMBERwith the agent's version number that you want to install, such as3.1-606637668. For information about the agent versions that you can install, see List all available versions of the agent.For information about downgrading the agent to a specific version, see Downgrade Google Cloud's Agent for SAP.
- (Recommended) To install version 3.15 (latest) of the
agent:
Configure the collection of Workload Manager evaluation metrics
After you install Agent for SAP, you need to configure the agent for the collection of the Workload Manager evaluation metrics.
To configure Google Cloud's Agent for SAP, complete the following steps:
To let the agent collect the Workload Manager evaluation metrics:
sudo /usr/bin/google_cloud_sap_agent configure -feature=workload_evaluation -enable
Optional: To enable the collection of "SAP HANA Insights" and "SAP HANA Security Best Practices" metrics in Workload Manager, add the
workload_validation_db_metrics_configsection aftercollect_workload_validation_metricsin the agent's configuration file, and then specify the following parameters:hana_db_user: specify the user account that is used to query the SAP HANA instance.hostname: specify the identifier for the machine, either local or remote, that hosts your SAP HANA instance.port: specify the port on which your SAP HANA instance accepts queries.hana_db_password_secret_name: specify the name of the secret in Secret Manager that stores the user account's passwordAs an alternative to the secret, you can use the
hdbuserstore_keyconfiguration parameter.hdbuserstore_key: specify thehdbuserstorekey that authenticates the user you specified forhana_db_userIf you specify
hdbuserstore_key, then you skip specifying thehostnameandportparameters.
For information about these parameters, see Configuration parameters.
The following examples are completed configuration files of Google Cloud's Agent for SAP running on a Compute Engine instance, where the collection of Workload Manager evaluation metrics is enabled.
For SAP HANA authentication, the agent uses the following order of preference: if specified, the
hdbuserstore_keyconfiguration parameter is preferred over thehana_db_passwordparameter, which is preferred over thehana_db_password_secret_nameparameter. We recommend that you set only one authentication option in your configuration file.- The following example uses a
Secure user store (
hdbuserstore) key for SAP HANA authentication:{ "provide_sap_host_agent_metrics": true, "bare_metal": false, "log_level": "INFO", "log_to_cloud": true, "collection_configuration": { "collect_workload_validation_metrics": true, "workload_validation_db_metrics_frequency": 3600, "workload_validation_db_metrics_config": { "hana_db_user": "system", "sid": "DEH", "hdbuserstore_key": "user_store_key" }, "collect_process_metrics": false }, "discovery_configuration": { "enable_discovery": true, "enable_workload_discovery": true }, "hana_monitoring_configuration": { "enabled": false } }
- The following example uses a username and Secret Manager
secret for SAP HANA authentication:
{ "provide_sap_host_agent_metrics": true, "bare_metal": false, "log_level": "INFO", "log_to_cloud": true, "collection_configuration": { "collect_workload_validation_metrics": true, "workload_validation_db_metrics_frequency": 3600, "workload_validation_db_metrics_config": { "hana_db_user": "system", "sid": "DEH", "hana_db_password_secret_name": "instance-id-hana-db-password-secret", "hostname":