Web Deploy 2.0 Setup Using TFS 2010 Builds

I have a previous blog post about setting up WebDeploy 1.0, which works well but 2.0 has more management features.  Despite the added management features, setting up version 2.0 seemed to be a bit more daunting.  One thing i noticed is that there isn’t much documentation out there but there are a lot of people blogging and posting on it.  In this thread I will summarize what I found was needed to get it working correctly for TFS 2010 or Visual Studio 2010.

Configuring Your IIS 7 Server

We’re using 2008 Server so the screen shots below will be from IIS 7. 

1.  Make sure the IIS Management Service is installed.  Go to Server Manager and add the Role Service as show below.

image

2.  Install the WebDeploy 2.0.You can download the platform version from here x86 or x64, 2008 uses x64.  NOTE:  Something that I ran into which seems to be a bug in the installer is that it missing installing a needed component.  To fix this you first install it then run the installer again but the second time you select Change which will then show you the extra item that wasn’t present the first time.  The installer should look like the image below, the highlighted section is what showed up the second time I ran the installer.  You must have all these components.

image 

3.  Go into IIS manager (Start^Run then type inetmgr).  Here you will need to configure a few items.  Select you server from the the connection dialog on the left.  You will be working in the Management section of the screen.

image 

4.  In the Management section, double click Management Service Delegation.  Once the delegation screen has come up you will want to add some new Rules.  In the upper right click Add Rule.  The rule that I needed was “Deploy Applications with Content” but you can add other predefined rules if needed.  I’ve found that the delegation providers I needed were “contentPath, iisApp, setAcl, createApp”.

image

The only thing I set on the rule was which type of user was going to connect to do the deployment.  In my case it was a specific AD account but it can be and IIS account.

image

5.   Go back to the Management home screen show in step 3.  This time double click Management Service.  In order to make changes you must stop the service first, which can be done on the right navigator.  The items that you want to take not for configuration are highlighted below.  Ensure that he check box “Enable remote connections” is checked.  The default port the service listens on is 8172, which I left.  By default the the install of the Management Service creates a self signed certificate.  I chose to create my own and use that.  Make sure the service is started before leaving this dialog (you can also find service is services applet with name “Web Management Service”).

image

NOTE:  If you enterprise uses a firewall, the call to the management service may not work.  You can check by going into a browser and navigating to https://youserver:8172/msdeploy.adx, if you are prompted for credentials it’s working otherwise the firewall is blocking it.

6.  This completes the IIS setup.

 

TFS Build Setup

Now that IIS is configured for remote deploy, we can create a build definition to deploy our web application to.  This is much like the previous blog post on setting up the parameters.  I’m going to skip all some of the attributes of the build definition as they don’t apply to making the WebDeploy work.

1.  Within your project in Team Explorer, right click Builds and select New Build definition.  Setup the basic build information:

  • General: build definition
  • Triggers: whatever triggers you want for this build
  • Workspace: select the workspace for the build
  • Build Defaults: select a build controller and drop location
  • Retention Policy: set any retentions you want

2.  The part that gets the web deploy working is in the Process section.  Expand all the numbered sections so you can see the attributes that need to be set.  First set the “Items to Build” which will specify the build flavor (i.e. Debug, Release, etc.) and the Solution/Project that represents you web application that you are deploying.

image

3.  The most critical piece is the MSBuild Arguments shown in the image above.  Unfortunately the arguments for Web Deploy are not well documented, but the ones below worked for my configuration.  You may have to grant you user permissions on the IIS machine to folders which pertain to you deployment, see this other good thread on configuration web deploy, Configuring MSDeploy in IIS 7.

/p:DeployOnBuild=True

/p:DeployTarget=MsDeployPublish

/p:CreatePackageOnPublish=True

/p:DeployIisAppPath="My Web Site Name"

/p:MsDeployServiceUrl=MyServerName:8172/msdeploy.axd

/p:username=MyUserName

/p:password=MyPassword

/p:AllowUntrustedCertificate=True

4.  Save the build and queue it.

TFS 2010 Web Deploy Unauthorized Operation During Build

I’ve been working on using web deploy to automate our builds of some particular web sites we have built internally.  I’m using Web Deploy 2.0, IIS 7.5, and TFS 2010.  It’s been working fine until today when we get this message:

C:\Program Files (x86)\MSBuild\Microsoft\VisualStudio\v10.0\Web\Microsoft.Web.Publishing.targets (3847): Web deployment task failed.  An error occurred when the request was processed on the remote computer. Failed to invoke or execute createApp provider on the web server.  The Web Deployment Tool’s createApp provider is either not enabled or failed to executed specific commands on the server.  Please contact your server administrator for assistance. (Web Deploy Provider is "createApp"). Error details: An error occurred when the request was processed on the remote computer. Attempted to perform an unauthorized operation. createApp http://go.microsoft.com/fwlink/?LinkId=178034

I search around and found that “createApp” is one of the Providers in the IIS Manage Service Delegations (see image below).  Initially when I was setting up web deploy I was following someone blog post on this and their recommendation was using “contentPath, iisApp, setAcl” which worked until today.  When I added “createApp” it fixed the issue.  See my blog on setting up web deploy.

image

Report Manager URL Not Using SSL SSRS 2008 R2

If you’re using SQL Server Reporting Services 2008R2 and have configured it to use SSL but are having issues in Report Manager where the context menus and other links are non-SSL, read on.  Apparently when you follow the simple steps to enable SSL with a certificate that you’ve installed on your Report Manager machine, they don’t point out that you need to remove the the port 80 URL otherwise Report Manager links won’t always be https!  Follow the steps below to fix this issue.

1.  Open the Report Service Configuration Manager.

2.  Go to the Web Service URL tab on the left.  Click the Advanced… button.  Remove the HTTP identity of the report server.  Click OK.

image

After it is removed for the Web Server you should see the following.

image

3.  Now navigate to the Report Manager URL.  Click the Advanced… button.  Remove the HTTP identity of the report server.  Click OK.

image

After it is removed for the Web Server you should see the following.

image

Using SSL and TFS 2010 for Reporting Services All-In-One Install

A current deployment I’m working on for TFS requires that everything use SSL, which includes the TFS part and SQL Reporting Services (SSRS) reports (report manager/report web services).  We are diving into customization on some of the reports and someone mentioned that our Reports folder in Visual Studio has a red X on it (see below).

image

Everything else with regard to TFS was working fine over SSL, we could even access the report manager for SSRS, so I knew it had to be some in TFS that drove Visual Studio and the link in the Team Web Access.  Follow the steps below to fix this predicament.

1.  Log on to your TFS server and open the TFS administration console.
2.  Select the Reporting node in the left navigator

image

3.  Click the Edit link on the right side of the screen.  It will ask if you want to stop the schedule jobs, click OK.  A dialog with 3 tabs will come up.  Select the Reports tab.  In this tab, set the Web Service and the Report Manager to the SSL base URLs that represent your SSRS installation, for example https://tfs.mytfsmachine.com.  Note that once you change the Web Service url you will have to re-enter the data source user’s password.  Once you have update the fields, click OK.  See the image below.

image

4.  Start the jobs again by clicking “Start Jobs” on the right.  You are done.

To check that it all works go into Visual Studio and connect to your TFS server.  The red X should be gone from a team project’s Reports folder.  Also check you Team Web Access (https://{your dns name}/tfs/web/) to make sure that the link to the reports from the web page correctly uses the SSL url.