Upgrade from 10.1.6.x to 10.2.3
The guide describes the upgrade to the 10.2.3 version of WorkFusion Intelligent Automation Cloud Enterprise. Note that this operation uses the installer, so the procedure is similar to the installation.
note
Only the upgrade option for the six-server topology is currently valid.
Before you start
The 10.2.3 non-HA topology requires only five servers:
- MASTER
- AGENT
- RPA
- BI
- DB
Note the following changes in server roles:
- The separate INT, APP, and BEP Master servers no longer exist. Instead, WorkFusion has introduced a single MASTER server. It contains all services that previously ran on the three servers. For the single-point installation, MASTER becomes the server to run the setup on.
- BEP Agent servers are renamed to AGENT servers.
The upgrade starts with preparing the environment to bring the topology to the appropriate state.
Before the upgrade, ensure that:
- You created the additional DNS record for Keycloak (See DNS names).
- No Business Process or Manual Task is running.
- You prepared fleets for migration.
- You backed up the following components:
- The
/opt/workfusion/workfusionand/opt/workfusion/workspacedirectories - Vault properties for all components
- ZooKeeper settings changed since the previous installation
- Any system files changed since the previous installation
- The
- You enabled the SSH access to all Linux hosts.
- You verified that the SSO or LDAP authentication you enabled in the existing environment is working.
Back up previous installation
In v.10.1.6, you can back up the existing INSTALL_DIR and restore WorkFusion IA Cloud Enterprise to the previous version after the upgrade. Note that the backup files occupy the same amount of disk space as INSTALL_DIR. Before performing the procedure, make sure that there is enough space in the filesystem.
To roll back to the previous state, back up the following components:
MSSQL database. You can do it according to your standard backup process.
The
INSTALL_DIRdirectory. You can do it during the upgrade.Shared directories. If you use any existing NAS, back up the following shared directories as per your standard process:
/sharedand/vds-datafor the HA mode/vds-datafor the non-HA mode
Save fleet names for Bot Units
To save the currently used fleet names for Bot Units, do the following:
Log in to Control Tower and click Bot Manager.
In the Bot Manager UI window, click your RPA server to expand the fleets.
Copy the value into the fleet column → Actions → Edit Fleet.

In the Edit Fleet window, click Create new, and paste the values copied earlier.

Repeat steps 3-4 for all fleets.
Check running Business Processes
Before the upgrade, check that no Business Processes are running:
Go to
INSTALL_DIRthat contains the installer directory created during the installation of 10.1.6, for example:/opt/workfusion:$ cd INSTALL_DIRCheck the output of the following command:
./zookeeper/bin/zkCli.sh ls /control-tower/execution/active-instances | egrep -qo '^\[[0-9a-f-]+' && echo 'There are running business processes. Please stop them first to continue upgrade.' || echo 'There are no running business processes. You are OK to continue update procedure.'
Continue the update procedure if the command displays the following message: "There are no running business processes. You are OK to continue update procedure." Otherwise, stop the running processes first.
Stop services
Stop unnecessary OCR servers.
IA Cloud v.10.2.3 doesn't use dedicated OCR servers. You can stop them. For more details, see the Hardware and OS section. If you plan to leave an opportunity for rollback, don't stop the OCR server.
note
If no rollback is necessary and you want to use OCR servers as AGENT servers, add their hostnames as
agent_hostnamesinhosts.yml.Stop IA Cloud services on the rest of the servers:
Connect to the server with the previous installation package via SSH and run the following commands as <linux_installation_user>:
$ cd PACKAGE_DIR
$ export ANSIBLE_PRIVATE_KEY_FILE="<path_to_ssh_key>" # Path to SSH key for connection to all Linux servers as WFUSER.
$ export ANSIBLE_VAULT_PASS="<ansible_vault_password>" # Password for decryption of config.yml.
$ ./install.sh stop_services full
Connect to all Linux servers via SSH and run the following command as WFUSER on each of them:
$ wfmanager stop all
Prepare application user
Versions beyond 10.1.6.1 feature only one application user (WFUSER in this case) to install and run the Product.
To perform the upgrade, provide the following permissions to the application user:
Grant the
sudopermissions.If you upgrade the system using the multi-point approach, skip step 2. Provide SSH access via the SSH key to all Linux servers with the installation package.
Provide the application user with the owner permissions for
PACKAGE_DIRthat contains the installer extracted during the initial installation of 10.1.6, for example:/opt/workfusion/wf_installer.$ sudo chown -R WFUSER PACKAGE_DIR
Prepare environment
Prerequisites
Before upgrading IA Cloud Enterprise, make sure that your environment meets the following requirements. Failing to do so results in an extended time of the upgrade and can cause errors:
The environment must meet all the requirements listed in the System requirements section:
-
Make sure that you have created all domain names listed on the page.
-
Make sure that all ports listed on the page are open.
-
Make sure that the required Bot Master and Bot Unit users are present on the RPA server.
-
Also, make sure that your database has a user with the enabled db_owner role.
-
Make sure that installation users on the Analytics and RPA server have either WinRM or RDP access.
Ensure that the environment has sufficient hardware resources.
Before you use the existing INT server as MASTER, upgrade your server hardware, if necessary. Note that the MASTER server uses more resources than INT. As you no longer need separate APP and BEP Master servers, you can use them as additional AGENT servers.
Ensure that shared folders are created and mounted correctly.
Skip this requirement if you use an external NFS server.
The
INSTALL_DIR/vds-dataandINSTALL_DIR/sharedshared folders must be located on the MASTER server. To ensure that:- Move the preceding folders to the MASTER server using any convenient method.
- To share the folders via NFS and mount them to AGENT servers, either perform all root-related steps manually by following the guide or, if the WFUSER has the
sudoprivileges, proceed with the guide.
Before upgrading IA Cloud Enterprise, make sure that your environment meets the following requirements. Failing to do so results in an extended time of the upgrade and may cause errors.
-
For eight-server installation only: ensure that all lb records (like marathon-lb.example.com) now point to the INT server's IP address.
Also, note that it's not mandatory to change the actual hostnames of servers. For example, if your current server has the int1.example.com FQDN, you don't need to rename it to master1.example.com.
-
Ensure that all listed ports are open.
-
Ensure that the required Bot Master and Bot Unit users are present on the RPA server.
-
Make sure to create a new mssql_keycloak_user login in the database. Also, ensure that your database has a user with the enabled db_owner role.
-
Ensure that installation users on the Analytics and RPA server have either WinRM or RDP access.
Set the external load balancer's parameters and ports as described in Configure Load Balancer. The load balancer must route all TCP traffic from the specified ports to the same ports on Master1, Master2, and Master3 servers (round-robin balancing between Master1, Master2, and Master3).
-
Prepare certificates
In 10.2.3, the server.crt certificate must mandatorily include the end certificate and all intermediate ones if they exist. Ensure that your certificates comply with the requirements.
Then, on the MASTER server, add ca.crt, server.crt, and server.key to the PACKAGE_DIR/certificates/ directory.
Skip the step if you don't have those certificates. In this case, self-signed certificates get generated automatically during the installation.
$ ls -la PACKAGE_DIR/certificates/
total 24
drwxr-xr-x. 3 ec2-user ec2-user 78 Sep 24 14:47 .
drwxr-xr-x. 12 ec2-user ec2-user 4096 Sep 27 17:20 ..
-rw-r--r--. 1 ec2-user ec2-user 2984 Sep 24 14:42 ca.crt
-rw-r--r--. 1 ec2-user ec2-user 4835 Sep 24 14:42 server.crt
-rw-r--r--. 1 ec2-user ec2-user 1674 Sep 24 14:42 server.key
Verify prerequisites
After you prepare the environment for the upgrade, you can use the dedicated checking script for verification. For more information, read the check readiness instruction.
Download and extract installer
To download and extract the installer, connect to the server with the installation package from the previous version via SSH and run the following commands as WFUSER:
Go to
INSTALL_DIRthat contains the installer directory created during the installation of 10.1.6, for example:/opt/workfusion:$ cd INSTALL_DIRCreate the
wf_installer_newdirectory for the new version of the installer. Ensure that the directory is writable for WFUSER.note
Use only the wf_installer_new name for the directory to store the new installation package. Otherwise, the backup doesn't start.
$ mkdir wf_installer_newDownload the installer v.10.2.3 to
INSTALL_DIR/wf_installer_new:$ curl -o '<10.2.3-installer-archive>' '<link-to-installer-10.2.3>'If the Internet is unavailable on the server, download the package to the
PACKAGE_DIRdirectory using any convenient method.Extract the installer:
$ tar xzf <10.2.3-installer-archive> --strip 1Copy configuration files for the current environment from
INSTALL_DIR/wf_installertoINSTALL_DIR/wf_installer_new:$ cp -r INSTALL_DIR/wf_installer/{license.properties,certificates,.agreement,rpa.yml} INSTALL_DIR/wf_installer_new/Generate new configuration files from the existing ones:
$ export ANSIBLE_VAULT_PASS="<ansible_vault_password>" # Password for decryption of config.yml. $ cd INSTALL_DIR/wf_installer_new $ ./install.sh hosts_yml generate -e @INSTALL_DIR/wf_installer/hosts.yml $ ./install.sh config_yml generate -e @INSTALL_DIR/wf_installer/config.ymlAfter executing
./install.sh hosts_yml generate, inhosts.yml, specify the correct value forkeycloak_lb_hostname.$ ./install.sh ports_yml generate -e @INSTALL_DIR/wf_installer/ports.yml $ ./install.sh rpa_yml generate -e @INSTALL_DIR/wf_installer/config.ymlnote
The new mssql_keycloak_user is introduced with the default password in
config.yml. Change it to the password of mssql_keycloak_user that you created on the Prepare the database step.important
In the 10.2.3 version, IA Cloud supports Active Directory logins. If you want to switch to MS SQL AD logins, in
config.yml, change the correspondingmssqllogins to the logins and password you created when preparing the database.note
BI workbooks are not published by default during the installation process. If you need them to be published during the installation, go to
config.ymland set thepublish_bi_dashboardsvariable toTrue. Another option to publish BI workbooks is to run the following command at any time after the installation is completed.$ ./install.sh install bi_workbooks -e publish_bi_dashboards=trueEncrypt
config.yml:$ ./install.sh encrypt configIn the 10.2.3 version, the
server.crtcertificate must mandatorily include the end certificate and all intermediate ones if they exist. If your certificates don't comply with the requirements, prepare new ones according to the requirements.Generate required internal certificates:
$ ./install.sh certs generate
If you upgrade using the multi-point approach
- On the MASTER server, generate configuration files as described earlier.
- Ensure that
PACKAGE_DIR, including the installer package, the certificates folder,config.yml,rpa.yml,ports.yml, andhosts.yml, are synchronized across all Linux hosts.
Back up old installation directory
The procedure is optional.
To back up the old installation directory:
Connect to each Linux server via SSH and, on each of them, run the following commands as WFUSER to create a backup directory:
$ mkdir </path/to/backup_dir>Connect to the server containing the new installation package via SSH and run the following commands as WFUSER to back up the old installation directory (
INSTALL_DIR):$ cd INSTALL_DIR/wf_installer_new $ export ANSIBLE_PRIVATE_KEY_FILE="<path_to_ssh_key>" # Path to the SSH key for connection to all Linux servers as WFUSER $ export ANSIBLE_REMOTE_USER="WFUSER" # Application user specified in config.yml $ export ANSIBLE_VAULT_PASS="<ansible_vault_password>" # Password for decrypting config.yml $ ./install.sh backup full -e backup_dir=/path/to/backup_dir # Path to the directory to place a backup. Make sure it is writable for WFUSER.
note
The preceding procedure is intended for the single-point installation. To back up the directory created during the multi-point installation, specify <server_role> instead of full in the previous command, for example:
$ ./install.sh backup <server_role> -e backup_dir=/path/to/backup_dir -c local --limit <current_hostname> # here, <server_role> may be int, app, bepagent, etc.
Check users' passwords
Ensure that config.yml contains valid user passwords. In most cases, you don't need to change anything in the file. You may proceed further and skip this step. If you encounter issues, for example, an error message with invalid credentials, then:
Open
config.ymlfor editing:./install.sh edit_config master # you'll be prompted for the decryption passwordUpdate it with valid passwords:
nexus_admin_pass mssql_dba_pass mssql_ct_pass mssql_ws_pass mssql_sqc_pass mssql_rpa_pass mssql_pm_pass mssql_dm_pass mssql_ocr_pass mssql_automl_mms_pass mssql_keycloak_passRe-run the installation script.
For example, after the initial 10.1.6 installation, you may change the Nexus or MSSQL passwords manually in the environment. In this case, actualize them in config.yml because the installer uses them to update DB schemas and Nexus artifacts.
Upgrade components on servers
caution
Before uninstalling the RPA component, manually copy the log content if you want to preserve the logs as the corresponding folder and all of its content gets deleted.
Log locations:
- bot-agent logs:
..\RPA\bot-agent\logs - worker logs:
..\RPA\logs - nginx logs:
..\RPA\nginx\logs - WFSvc logs:
..\RPA\tools\logs
Upgrade the components, depending on your installation approach:
Remember to run the following command on the MASTER server as WFUSER.
Go to
INSTALL_DIR/wf_installer_new:$ cd INSTALL_DIR/wf_installer_newRun the following command to set up the application user:
$ export ANSIBLE_PRIVATE_KEY_FILE="<path_to_ssh_key>" # Path to SSH key for connection to all Linux servers as WFUSER.
$ export ANSIBLE_VAULT_PASS="<ansible_vault_password>" # Password for decryption of config.yml.Run the following command to remove outdated components of the previous installation:
$ cd PACKAGE_DIR
$ ./install.sh cleanup rudimentsRun the following commands:
$ ./install.sh precheck mssql # Checks that MSSQL credentials are set correctly in config.yml, Database exists, wf_dba_user exists and has db_owner role
$ ./install.sh configure mssql # Creates all required schemas in Workfusion DB, creates and maps DB users to provided MSSQL logins, and assigns correct user permissions per schemasRun the upgrade commands:
$ ./install.sh preinstall full -e skip_bi=true -e skip_rpa=true -e skip_ocrwin=true
$ ./install.sh install full -e skip_bi=true -e skip_rpa=true -e skip_ocrwin=true
$ ./install.sh check full -e skip_bi=true -e skip_rpa=true -e skip_ocrwin=trueBefore updating the RPA server, uninstall the current RPA and perform a clean installation of a new RPA:
$ ./install.sh uninstall rpa
$ ./install.sh preinstall rpa
$ ./install.sh install rpa
$ ./install.sh check rpaCleanup RabbitMQ queues:
On the server with the installation packages, run the command:
$ ./install.sh stop_services full # stop all servicesOn the server with RabbitMQ (the first MASTER server in the HA mode or the MASTER server), run the commands:
$ wfmanager start rabbitmq
$ rabbitmq-diagnostics ping -q # repeat untill Ping succeeded (echo $? == 0)
$ rabbitmqctl --silent list_queues --vhost bep | awk '{ print $1 }' | xargs -r -L1 rabbitmqctl delete_queue --vhost bepOn the server with the installation package, run the command:
$ ./install.sh start_services full # start all services
The upgrade is complete. It may take about five minutes for Control Tower to start. So, if you see error 503 in a browser right now, wait a bit.
On each Linux server, run the following commands as WFUSER:
Stop all IA Cloud services:
$ wfmanager stop allTo verify the status of services, use the
wfmanager statuscommand.In the
PACKAGE_DIR, run the following command to remove outdated components of the previous installation:$ ./install.sh cleanup rudiments -c local --limit=<current_server_dns_name>Run the following commands once on any Linux server:
$ ./install.sh precheck mssql # Checks that MSSQL credentials are set correctly in config.yml, Database exists, wf_dba_user exists and has db_owner role
$ ./install.sh configure mssql # Creates all required schemas in Workfusion DB, creates and maps DB users to provided MSSQL logins, and assigns correct user permissions per schemasOn all Linux servers, install IA Cloud Enterprise components by following the corresponding guide.
Note the server changes:
- For a six-server environment: your current APP server means MASTER, and BEP AGENT servers mean AGENT.
- For an eight-server environment: your current INT server means MASTER, and BEP AGENT servers mean AGENT.
Log in to the RPA server and uninstall the RPA components: Control Panel → Programs and Features → RPA (Uninstall). After that, remove the
RPAfolder.Re-install RPA by following the instructions in the Install RPA package section.
Clean up the RabbitMQ queues to ensure that old workers don't spawn queues:
$ wfmanager stop all # Run on each Linux server
$ wfmanager start rabbitmq # Run on all MASTER servers
$ rabbitmqctl --silent list_queues --vhost bep | awk '{ print $1 }' | xargs -r -L1 rabbitmqctl delete_queue --vhost bep # Run on first MASTER server
$ wfmanager start all # Run on each Linux server
Before starting the installation, ensure that config.yml, ports.yml, rpa.yml, hosts.yml, and the /certificates directory are the same on all hosts.
To upgrade components, run the following command on the server with the installation package as WFUSER:
On all Linux servers, prepare the environment variables:
$ export ANSIBLE_VAULT_PASS="<ansible_vault_password>" # Run on each Linux server to disable password prompt (not mandatory, just for convenience)On all Linux servers, enter the
PACKAGE_DIRdirectory and run the following command to remove the outdated components of the previous installation:$ cd /opt/workfusion/wf_installer
$ ./install.sh cleanup rudiments -c localOn any MASTER server, run the following commands once:
$ ./install.sh precheck mssql # Checks that MSSQL credentials are set correctly in config.yml, Database exists, wf_dba_user exists and has db_owner role
$ ./install.sh configure mssql # Creates all required schemas in Workfusion DB, creates and maps DB users to provided MSSQL logins, and assigns correct user permissions per schemasInstall the IA Cloud Enterprise components on all Linux servers by following the corresponding guide.
Note the server changes:
- For a six-server environment: your current APP server means MASTER, and BEP AGENT servers mean AGENT.
- For an eight-server environment: your current INT server means MASTER, and BEP AGENT servers mean AGENT.
After installing the Linux components, log in to the RPA server and uninstall RPA components: Control Panel → Programs and Features → RPA (Uninstall).
Re-install RPA by following the instructions in the Install RPA package section.
Clean up the RabbitMQ queues to ensure that old workers don't spawn queues:
$ wfmanager stop all # Run on each Linux server
$ wfmanager start rabbitmq # Run on all MASTER servers
$ rabbitmqctl --silent list_queues --vhost bep | awk '{ print $1 }' | xargs -r -L1 rabbitmqctl delete_queue --vhost bep # Run on first MASTER server
$ wfmanager start all # Run on each Linux server
Upgrade Analytics server
Back up site configuration
Before upgrading the Analytics components, connect to the BI server via RDP as a Windows Administrator user and save all your custom workbooks and datasources to a predefined location on a local disk.
important
Download custom workbooks and datasources to separate directories. For example, c:\patch_10_1_6_backup\workbooks\ and c:\patch_10_1_6_backup\datasources\.
Don't save backup files in the Analytics (BI) server installation directory, for example, c:\workfusion\ as it gets deleted during the upgrade.
To download the custom workbooks from the Analytics server UI:
- Go to a particular site. On the Content tab, click Workbooks. To identify custom workbooks, look for the _custom postfix in their names.
- In the right corner of the Name column, click More (...), click Download, and save the file as a Tableau workbook.


To download the custom datasources from the Analytics server UI:
Go to a particular site. On the Content tab, click Datasources.
In the right corner of the Name column, click More (...), click Download, and save the file as a Tableau datasource.


Remember to rename the custom dashboards by replacing all occurrences of the underscore character ("_") with the plus symbol ("+") in the titles, except for the first and last two underscores.
To restore custom dashboards, follow the instructions in the Backup and restore custom Analytics dashboards section.
Upgrade Analytics
To upgrade the Analytics Server:
On the MASTER server, run the following command:
$ cd /opt/workfusion/wf_installer_new
$ ./install.sh uninstall biRestart the Analytics server to apply changes.
On the MASTER server, run the following command:
$ ./install.sh preinstall bi
$ ./install.sh install bi
$ ./install.sh check bi
To upgrade the Analytics Server:
On the Analytics (BI) server, launch the New PowerShell ISE.
Launch PowerShell ISE as Administrator, copy the following script, and execute it in PowerShell on the relevant Analytics server:
# UNINSTALL TABLEAU SERVER
# FILL IN THE PARAMETERS BELOW
$install_dir = "c:\workfusion" # The value of "install_dir" you've set in config.yml during Linux servers installation.
$env:win_user="username" # The value of "bi_user" you've set in config.yml during Linux servers installation.
$env:win_pass='"password"' # Leave single and double quotes in place. Replace only word password. The value of "bi_pass" you've set in config.yml during Linux servers installation.
# =========================================
$package_dir = "${install_dir}\WorkFusionAnalyticsServer"
Write-Host "Uninstalling filebeat"
$service = Get-WmiObject -Class Win32_Service -Filter "name='filebeat'"
if ($service) {
$service.StopService()
Start-Sleep -s 1
$service.delete()
}
Write-Host "Uninstalling metricbeat"
$service = Get-WmiObject -Class Win32_Service -Filter "name='metricbeat'"
if ($service) {
$service.StopService()
Start-Sleep -s 1
$service.delete()
}
Write-Host "Stop PostgreSQL process"
$proceses = "postgress"
Get-Process | Where-Object {$proceses.Contains($_.Name)} | Stop-Process -Force
Write-Host "Uninstall WorkFusion Analytics Server"
$path = Get-ChildItem -Path $install_dir\WorkFusionAnalyticsServer\packages -Recurse tableau-server-obliterate.cmd
if ($path) {
&$path.FullName -y -y -y
}
Write-Host "Uninstall PostgreSQL Server"
$app = Get-WmiObject -Class Win32_Product | Where-Object {$_.Name -match "psql"}
if ($app) {$app.Uninstall()}
Write-Host "Remove installation directory"
If (Test-Path $install_dir){
Get-ChildItem -Path $install_dir -Recurse | Remove-Item -force -recurse
Remove-Item $install_dir -Force
}Restart the Analytics server to apply changes.
Install the Analytics (BI) server by following the instructions in the Install Analytics Server section.
Restore custom parameters from previous versions
note
When upgrading to v.10.2.3, you need to configure LDAP/AD and IDP/SSO manually in Keycloak.
- For LDAP and AD configuration instructions, refer to the Configure LDAP section.
- For IDP and SSO configuration instructions, refer to the Configure Identity Providers section.
Custom workers
If you have changed workers' settings in IA Cloud 10.1.6, you can migrate them after the upgrade.
For that, after upgrading, on the MASTER server, open the file with workers' settings for Control Tower, for
example, /opt/workfusion/vds-data/workers/app/com.workfusion.spa.ct/worker-app/10.1.0.32/worker.yml, and enter the previous corresponding settings, such as memory, CPU, and so on. Note that the structure of the new file differs from the previous one.
worker.yml for 10.1.6:
#cat /opt/workfusion/vds-data/workers/app/com.workfusion.spa.ct/worker-app/10.1.0.10/worker.yml
command: ${java} -XX:CICompilerCount=2 -XX:+UseSerialGC -XX:MaxMetaspaceSize=${metaspace}M -Xmx${heap}M -XX:+ExitOnOutOfMemoryError -Dgroovy.use.classvalue=true -Dgroovy.target.indy=true -Dfile.encoding=UTF8 -Dexecution.task.queue.input=${tasks.queue} -Dlogging.path=${log.dir} -Dlogging.file=${log.file} -Djava.io.tmpdir=${temp.dir} -Dwebharvest.machine.config.bundle.dir=${working.dir}/bcb -jar ${worker.jar} ${config.server.parameters}
cpu: 0.25
memory:
heap: 1024
worker.yml for 10.2.3:
# cat /opt/workfusion/vds-data/workers/app/com.workfusion.spa.ct/worker-app/10.1.0.32/worker.yml
command: ${java} -XX:CICompilerCount=2 -XX:+UseSerialGC -XX:MaxMetaspaceSize=${metaspace}M -Xmx${heap}M -XX:+ExitOnOutOfMemoryError -Dgroovy.use.classvalue=true -Dgroovy.target.indy=true -Dfile.encoding=UTF8 -Dexecution.task.queue.input=${tasks.queue} -Dlogging.path=${log.dir} -Dlogging.file=${log.file} -Djava.io.tmpdir=${temp.dir} -Dwebharvest.machine.config.bundle.dir=${temp.dir}/bcb -jar ${worker.jar} ${config.server.parameters}
cpu: 0.4
memory:
heap: 1024
metaspace: 512
health-checks:
- protocol: MESOS_HTTP
path: /actuator/health
grace-period-sec: 180
interval-sec: 60
timeout-sec: 10
max-failures: 3
Upgrade Business Processes
Migrate your Business Processes with Manual Tasks that use qualifications. To do that, refer to the following guides:
Check upgrade
Once the upgrade is complete, check the WorkFusion Platform with Business Process (BP) and Manual Task. The OCR must be activated. For more information on post-installation checks, see Install components.