Sign inSign up

blocksos/prod-blocks-iam

By blocksos

•Updated 1 day ago

Image
0

1.8K

blocksos/prod-blocks-iam repository overview

⁠SELISE Blocks IAM

⁠Docker Image

blocksos/prod-blocks-iam:tagname

⁠Overview

SELISE Blocks IAM is the Identity and Access Management service for the SELISE Blocks platform. It provides the authentication, authorization, identity, and access management capabilities required by the Blocks platform and its associated services.

The application combines an ASP.NET Core / .NET 10 backend with a React/Vite/TypeScript frontend, packaged as a single integrated application. The production frontend is built into the ASP.NET Core application's wwwroot directory and served by the API host. A separate background Worker is included for message consumption and background processing.

⁠Image Purpose

The Docker image:

blocksos/prod-blocks-iam:tagname

contains the production build of the Blocks IAM application and is intended to be used as the runtime image for deploying the Blocks Identity and Access Management service.

The image includes:

  • Blocks IAM Web Console
  • REST APIs
  • React production frontend
  • ASP.NET Core backend
  • Authentication and authorization
  • User and account management
  • Organization management
  • Role and permission management
  • OIDC client management
  • Session and device management
  • Multi-factor authentication (MFA)
  • Token and Personal Access Token management
  • CAPTCHA integration
  • SSO integrations
  • Application services

⁠Technology Stack

⁠Backend
  • ASP.NET Core
  • .NET 10
  • C#
  • Kestrel web server
  • REST APIs
  • Genesis configuration layer
  • Authentication and IAM domain services
⁠Frontend
  • React
  • TypeScript
  • Vite
  • npm
⁠Background Processing
  • .NET Worker
  • Background message consumers
  • Blocks / Genesis messaging infrastructure

The repository contains dedicated API and Worker applications.

⁠Application Architecture

Blocks IAM follows an integrated frontend/backend architecture:

                    ┌──────────────────────┐
                    │     User / Client    │
                    └──────────┬───────────┘
                               │
                               ▼
                    ┌──────────────────────┐
                    │   Ingress / Gateway  │
                    └──────────┬───────────┘
                               │
                               ▼
              ┌─────────────────────────────────┐
              │          SELISE Blocks IAM      │
              │                                 │
              │       ASP.NET Core / Kestrel    │
              │                                 │
              │  ┌─────────────┐ ┌────────────┐ │
              │  │ REST APIs   │ │ React SPA  │ │
              │  └─────────────┘ └────────────┘ │
              │                                 │
              │  Image:                         │
              │  blocksos/prod-blocks-iam:tagname│
              └────────────────┬────────────────┘
                               │
              ┌────────────────┼────────────────┐
              ▼                ▼                ▼
         Database          Messaging       Blocks Services
                               │
                               ▼
                    ┌──────────────────────┐
                    │      IAM Worker      │
                    │                      │
                    │ Background Consumers │
                    └──────────────────────┘

The React production build is served from server/Api/wwwroot by the ASP.NET Core API host, while the Worker handles background message consumers separately.

⁠Container Port

The application API is configured to run on port:

5000

The Vite development server uses port:

4000

For the production Docker image, the primary application port is 5000.

Example Docker run command:

docker run -d \
  --name blocks-iam \
  -p 5000:5000 \
  blocksos/prod-blocks-iam:tagname

⁠Pull the Image

docker pull blocksos/prod-blocks-iam:tagname

⁠Kubernetes Deployment

The image can be deployed to Kubernetes using the following container configuration:

containers:
  - name: blocks-iam
    image: blocksos/prod-blocks-iam:tagname
    ports:
      - containerPort: 5000

The application can then be exposed through a Kubernetes Service and Ingress or an external application gateway.

⁠Image Naming

The Docker image follows the standard Docker image naming convention:

<organization>/<repository>:<tag>

For Blocks IAM:

ComponentValue
RegistryDocker Hub
Organizationblocksos
Repositoryprod-blocks-iam
Tagtagname
Full Imageblocksos/prod-blocks-iam:tagname

⁠Runtime Configuration

The application supports BLOCKS_* environment variables for configuring the frontend and runtime environment.

Important configuration areas include:

ConfigurationPurpose
BLOCKS_X_BLOCKS_KEYBlocks tenant/project key
CAPTCHA configurationCAPTCHA integration
GitHub SSO client configurationGitHub authentication
OIDC client configurationOIDC authentication
Base domain configurationBlocks platform domain
Service base URLsIntegration with sibling Blocks services
Callback URLsAuthentication and OIDC callbacks

The frontend uses the BLOCKS_* environment variable prefix through Vite. Build-time frontend configuration changes require rebuilding the client.

⁠Runtime Dependencies

The Blocks IAM container provides the application runtime. External infrastructure and supporting services are deployed separately according to the target environment.

Depending on the deployment configuration, Blocks IAM may communicate with external services such as:

  • Databases
  • Message queues
  • Blocks / Genesis services
  • Vault / secret management
  • Authentication services
  • Identity services
  • Logging services
  • Monitoring services
  • Tracing services
  • Other SELISE Blocks platform services

The API and Worker resolve required secrets, including database, message bus, and signing material, through the Genesis configuration layer.

⁠Production Deployment

The image is intended for production deployment environments where the container can be managed using Docker, Kubernetes, or another container orchestration platform.

A typical production setup consists of:

                    Internet / Users
                           │
                           ▼
                  ┌─────────────────┐
                  │ Gateway / WAF   │
                  └────────┬────────┘
                           │
                           ▼
                  ┌─────────────────┐
                  │ Kubernetes /    │
                  │ Container       │
                  │ Platform        │
                  └────────┬────────┘
                           │
                           ▼
              ┌─────────────────────────┐
              │       Blocks IAM        │
              │                         │
              │ blocksos/prod-blocks-iam│
              │                         │
              │ ASP.NET Core + React    │
              └───────────┬─────────────┘
                          │
              ┌───────────┼───────────┐
              ▼           ▼           ▼
           Database    Messaging   Platform APIs
                          │
                          ▼
                 ┌───────────────────┐
                 │    IAM Worker     │
                 └───────────────────┘

⁠Source Repository

The complete source code and documentation for SELISE Blocks IAM are available on GitHub:

GitHub Repository:

https://github.com/SELISEdigitalplatforms/blocks-iam

⁠License

This project is licensed under the MIT License.

The repository includes an MIT LICENSE file.

⁠Summary

SELISE Blocks IAM is the Identity and Access Management service for the SELISE Blocks platform. The blocksos/prod-blocks-iam:tagname Docker image provides a deployable production container for the service, combining the ASP.NET Core backend, REST APIs, React-based web console, authentication and authorization capabilities, and supporting application components.

Tag summary

Content type

Image

Digest

sha256:8331b6ec7…

Size

84.2 MB

Last updated

1 day ago

docker pull blocksos/prod-blocks-iam:7492b22612cfa049b6a219f44d5b8587ae927ff2