blocksos/prod-blocks-iam:tagname
SELISE Blocks IAM is the Identity and Access Management service for the SELISE Blocks platform. It provides the authentication, authorization, identity, and access management capabilities required by the Blocks platform and its associated services.
The application combines an ASP.NET Core / .NET 10 backend with a React/Vite/TypeScript frontend, packaged as a single integrated application. The production frontend is built into the ASP.NET Core application's wwwroot directory and served by the API host. A separate background Worker is included for message consumption and background processing.
The Docker image:
blocksos/prod-blocks-iam:tagname
contains the production build of the Blocks IAM application and is intended to be used as the runtime image for deploying the Blocks Identity and Access Management service.
The image includes:
The repository contains dedicated API and Worker applications.
Blocks IAM follows an integrated frontend/backend architecture:
┌──────────────────────┐
│ User / Client │
└──────────┬───────────┘
│
▼
┌──────────────────────┐
│ Ingress / Gateway │
└──────────┬───────────┘
│
▼
┌─────────────────────────────────┐
│ SELISE Blocks IAM │
│ │
│ ASP.NET Core / Kestrel │
│ │
│ ┌─────────────┐ ┌────────────┐ │
│ │ REST APIs │ │ React SPA │ │
│ └─────────────┘ └────────────┘ │
│ │
│ Image: │
│ blocksos/prod-blocks-iam:tagname│
└────────────────┬────────────────┘
│
┌────────────────┼────────────────┐
▼ ▼ ▼
Database Messaging Blocks Services
│
▼
┌──────────────────────┐
│ IAM Worker │
│ │
│ Background Consumers │
└──────────────────────┘
The React production build is served from server/Api/wwwroot by the ASP.NET Core API host, while the Worker handles background message consumers separately.
The application API is configured to run on port:
5000
The Vite development server uses port:
4000
For the production Docker image, the primary application port is 5000.
Example Docker run command:
docker run -d \
--name blocks-iam \
-p 5000:5000 \
blocksos/prod-blocks-iam:tagname
docker pull blocksos/prod-blocks-iam:tagname
The image can be deployed to Kubernetes using the following container configuration:
containers:
- name: blocks-iam
image: blocksos/prod-blocks-iam:tagname
ports:
- containerPort: 5000
The application can then be exposed through a Kubernetes Service and Ingress or an external application gateway.
The Docker image follows the standard Docker image naming convention:
<organization>/<repository>:<tag>
For Blocks IAM:
| Component | Value |
|---|---|
| Registry | Docker Hub |
| Organization | blocksos |
| Repository | prod-blocks-iam |
| Tag | tagname |
| Full Image | blocksos/prod-blocks-iam:tagname |
The application supports BLOCKS_* environment variables for configuring the frontend and runtime environment.
Important configuration areas include:
| Configuration | Purpose |
|---|---|
BLOCKS_X_BLOCKS_KEY | Blocks tenant/project key |
| CAPTCHA configuration | CAPTCHA integration |
| GitHub SSO client configuration | GitHub authentication |
| OIDC client configuration | OIDC authentication |
| Base domain configuration | Blocks platform domain |
| Service base URLs | Integration with sibling Blocks services |
| Callback URLs | Authentication and OIDC callbacks |
The frontend uses the BLOCKS_* environment variable prefix through Vite. Build-time frontend configuration changes require rebuilding the client.
The Blocks IAM container provides the application runtime. External infrastructure and supporting services are deployed separately according to the target environment.
Depending on the deployment configuration, Blocks IAM may communicate with external services such as:
The API and Worker resolve required secrets, including database, message bus, and signing material, through the Genesis configuration layer.
The image is intended for production deployment environments where the container can be managed using Docker, Kubernetes, or another container orchestration platform.
A typical production setup consists of:
Internet / Users
│
▼
┌─────────────────┐
│ Gateway / WAF │
└────────┬────────┘
│
▼
┌─────────────────┐
│ Kubernetes / │
│ Container │
│ Platform │
└────────┬────────┘
│
▼
┌─────────────────────────┐
│ Blocks IAM │
│ │
│ blocksos/prod-blocks-iam│
│ │
│ ASP.NET Core + React │
└───────────┬─────────────┘
│
┌───────────┼───────────┐
▼ ▼ ▼
Database Messaging Platform APIs
│
▼
┌───────────────────┐
│ IAM Worker │
└───────────────────┘
The complete source code and documentation for SELISE Blocks IAM are available on GitHub:
GitHub Repository:
https://github.com/SELISEdigitalplatforms/blocks-iam
This project is licensed under the MIT License.
The repository includes an MIT LICENSE file.
SELISE Blocks IAM is the Identity and Access Management service for the SELISE Blocks platform. The blocksos/prod-blocks-iam:tagname Docker image provides a deployable production container for the service, combining the ASP.NET Core backend, REST APIs, React-based web console, authentication and authorization capabilities, and supporting application components.
Content type
Image
Digest
sha256:8331b6ec7…
Size
84.2 MB
Last updated
1 day ago
docker pull blocksos/prod-blocks-iam:7492b22612cfa049b6a219f44d5b8587ae927ff2