Loading...
Loading...
Compare original and translation side by side
Global Account (SAP contract)
├── Directory (optional, up to 7 levels)
│ └── Subaccount (region-specific, apps run here)
│ ├── Cloud Foundry Org → Spaces
│ └── Kyma Cluster → Namespaces
└── SubaccountGlobal Account (SAP contract)
├── Directory (optional, up to 7 levels)
│ └── Subaccount (region-specific, apps run here)
│ ├── Cloud Foundry Org → Spaces
│ └── Kyma Cluster → Namespaces
└── Subaccount| Environment | Use Case | Key Features |
|---|---|---|
| Cloud Foundry | Polyglot apps | Multiple buildpacks, spaces |
| Kyma | Cloud-native K8s | Open-source, namespaces |
| ABAP | ABAP extensions | RAP, cloud-ready ABAP |
| Neo | Legacy | Migrate away - HTML5, Java, HANA XS |
| 环境 | 适用场景 | 核心特性 |
|---|---|---|
| Cloud Foundry | 多语言应用 | 多类构建包、空间隔离 |
| Kyma | 云原生K8s应用 | 开源、命名空间隔离 |
| ABAP | ABAP扩展开发 | RAP、云原生ABAP |
| Neo | 遗留系统 | 建议迁移 - 支持HTML5、Java、HANA XS |
Global Account
├── Dev Subaccount
├── Test Subaccount
└── Prod SubaccountGlobal Account
├── Dev Subaccount
├── Test Subaccount
└── Prod SubaccountGlobal Account
├── Directory: HR
│ ├── hr-dev / hr-test / hr-prod
├── Directory: Sales
│ ├── sales-dev / sales-test / sales-prod
└── Directory: Central IT
├── api-management
└── shared-servicesGlobal Account
├── Directory: HR
│ ├── hr-dev / hr-test / hr-prod
├── Directory: Sales
│ ├── sales-dev / sales-test / sales-prod
└── Directory: Central IT
├── api-management
└── shared-services| Entity | Convention | Example |
|---|---|---|
| Subaccount | Natural language | "HR Development" |
| Subdomain | Lowercase, hyphens | |
| CF Org | Company prefix | |
| CF Space | Consistent across stages | |
| 实体 | 规范 | 示例 |
|---|---|---|
| 子账户 | 自然语言 | "HR开发环境" |
| 子域名 | 小写字母、连字符分隔 | |
| CF组织 | 带公司前缀 | |
| CF空间 | 各阶段命名保持一致 | |
Corporate IdP → Identity Authentication (proxy) → SAP BTP企业IdP → Identity Authentication(代理)→ SAP BTP| Method | Best For | Notes |
|---|---|---|
| Provisioning | Production, many users | Centralized roles, automated offboarding |
| Federation | Simple scenarios | Real-time sync, but doesn't scale well |
| Manual | Testing only | Quick setup, not production-ready |
| 方式 | 适用场景 | 说明 |
|---|---|---|
| 自动配置 | 生产环境、用户数量多 | 集中式角色管理、自动化离职处理 |
| 联邦认证 | 简单场景 | 实时同步,但扩展性不佳 |
| 手动配置 | 仅用于测试 | 快速搭建,不适合生产环境 |
PrincipalPropagationOAuth2SAMLBearerAssertionOAuth2JWTBearerBasicAuthenticationOAuth2Passwordreferences/security-and-authentication.mdPrincipalPropagationOAuth2SAMLBearerAssertionOAuth2JWTBearerBasicAuthenticationOAuth2Passwordreferences/security-and-authentication.mdreferences/ai-development-best-practices.mdreferences/ai-development-best-practices.mdreferences/deployment-and-delivery.mdreferences/deployment-and-delivery.mdCustom Domain URL
│
Load Balancer
├── Region 1 (active)
└── Region 2 (passive/active)自定义域名URL
│
负载均衡器
├── 区域1(活跃)
└── 区域2(备用/活跃)references/failover-and-resilience.mdreferences/failover-and-resilience.mdreferences/account-models.mdreferences/governance-and-teams.mdreferences/account-models.mdreferences/governance-and-teams.mdreferences/security-and-authentication.mdreferences/security-and-authentication.mdreferences/deployment-and-delivery.mdreferences/operations-and-monitoring.mdreferences/deployment-and-delivery.mdreferences/operations-and-monitoring.mdreferences/failover-and-resilience.mdreferences/failover-and-resilience.mdreferences/templates-and-examples.mdreferences/templates-and-examples.mdreferences/ai-development-best-practices.mdreferences/ai-development-best-practices.md| Tool | Use Case |
|---|---|
| SAP BTP Cockpit | GUI for all admin tasks |
| btp CLI | Terminal/automation scripting |
| REST APIs | Programmatic administration |
| Terraform Provider | Infrastructure as Code |
| SAP Automation Pilot | Low-code/no-code automation |
| 工具 | 适用场景 |
|---|---|
| SAP BTP Cockpit | 所有管理任务的GUI界面 |
| btp CLI | 终端/自动化脚本 |
| REST APIs | 程序化管理 |
| Terraform Provider | 基础设施即代码 |
| SAP Automation Pilot | 低代码/无代码自动化 |
kyma-systemkyma-system