SharePoint Connector - Operator Manual — Unique AI Documentation

SharePoint Connector - Operator Manual

Overview

This guide provides IT operators with the technical information needed to deploy, configure, and maintain the SharePoint Connector.

For end-user and administrator documentation, see the SharePoint Connector Overview.

Documentation

Document Description
Deployment Container images, Helm charts, Terraform modules, release/support policy
Configuration Tenant configuration, site configuration, scheduling
Authentication Azure AD setup, certificates, service principals
FAQ Frequently asked questions and common issues

Configuration Approach

The connector uses a YAML-based tenant configuration file that can source site configurations from:

Source Description
config_file Static YAML configuration for fixed site list
sharepoint_list Dynamic configuration from a SharePoint list

See Configuration Guide for details.

Architecture Overview

The SharePoint Connector runs as a single pod that periodically scans SharePoint sites and synchronizes flagged documents to the Unique knowledge base.

Cluster-Internal Deployment

When deployed within the same Kubernetes cluster as Unique services:

In cluster-internal mode, Zitadel token validation is not needed as services communicate securely within the cluster using custom request headers for company and user scope.

Quick Start

Unique SaaS

When Unique hosts the SharePoint Connector, Unique provisions the app registration, certificate, and deployment infrastructure. Your side of the setup is:

  1. Provide the information below to Unique Support or Solution Engineering

  2. Grant admin consent using the URL Unique sends you

  3. Grant site-specific access for Unique's app registration to each SharePoint site (see Grant Site-Specific Access

What to provide to Unique (all items are required):

- [ ] Microsoft Entra Tenant ID — Azure Portal → Microsoft Entra ID → Overview → Directory (tenant) ID (e.g. ``)

- [ ] SharePoint base URL — the root URL of your SharePoint Online tenant (e.g. https://contoso.sharepoint.com)

- [ ] Site configuration source — how the connector discovers which sites to sync:

For Multi Tenant deployments, grant site access to Unique's shared app ID ``. For Single Tenant deployments, Unique will provide the dedicated app ID after provisioning.

Infrastructure Requirements

Component Requirement Notes
Kubernetes 1.25+ Any Kubernetes distribution
Container Runtime Docker/containerd Standard container runtime
Memory 2 GB Minimum allocation
CPU 1 core Minimum allocation

Network Requirements

Destination Port Protocol Direction
login.microsoftonline.com 443 HTTPS Outbound
graph.microsoft.com 443 HTTPS Outbound
{tenant}.sharepoint.com 443 HTTPS Outbound
Unique API 443/8080 HTTPS/HTTP Outbound/Internal
DNS 53 UDP/TCP Outbound

Deployment Checklist

1. Infrastructure

2. Microsoft Entra ID

3. Unique Platform

4. Application

5. Verification