This container gives you the ability to run a PHP SAML identity provider application in your project's docker system. This allows for local SAML development and debugging without the use of a remote identity provider.
Add the following container configuration to your project's docker-compose.yml file:
saml-idp:
image: saml-idp:1.0
ports:
- 7265:7265
Determine the following environment variable values you will need to configure your identity provider. The following variables are required:
SP_ENTITY_ID: The entity ID of your project's service application. This is generally the Brightspot application and can be configured via context.xmlSP_ASSERTION_CONSUMER_SERVICE: The assertion consumer service URL hosted by the service application that the identity provider will redirect back to upon authentication. This is generally the logIn.jsp path.The following variables are optional:
SP_SINGLE_LOGOUT_SERVICE: The logout URL of the service application so that application logout can be invoked via the identity provider. This is generally the logOut.jsp path.An example configuration with example variables based on a localhost application.
saml-idp:
image: saml-idp:1.0
ports:
- 7265:7265
environment:
- SP_ENTITY_ID=https://localhost
- SP_ASSERTION_CONSUMER_SERVICE=https://localhost/cms/logIn.jsp
- SP_SINGLE_LOGOUT_SERVICE=https://localhost/misc/logout.jsp
After setting up your docker-compose.yml file, run docker-compose up to bring up the new container.
You may navigate to http://localhost:7265/simplesaml/ to hit the identity provider's UI.
The port 7265 is exposed by default by the image to listen to requests on. However, the host may map a local port to 7265 if the port is already in use by changing the ports configuration. Here is an example where the host port 1234 is mapped to the exposed container port 7265.
saml-idp:
image: saml-idp:1.0
ports:
- 1234:7265
environment:
- SP_ENTITY_ID=https://localhost
- SP_ASSERTION_CONSUMER_SERVICE=https://localhost/cms/logIn.jsp
- SP_SINGLE_LOGOUT_SERVICE=https://localhost/misc/logout.jsp
By default, the image is constructed with a default user configuration. This will provide you with with two example users and the admin user:
| UID | Username | Password | |
|---|---|---|---|
| 1 | user1 | user1pass | [email protected] |
| 2 | user2 | user2pass | [email protected] |
The admin user may be signed in using the credentials admin / secret
The resulting authsources.php configuration is as follows:
<?php
$config = array(
'admin' => array(
'core:AdminPassword',
'admin:admin' => array(
"uid" => array('0'),
'email' => '[email protected]',
),
),
'example-userpass' => array(
'exampleauth:UserPass',
'user1:user1pass' => array(
'uid' => array('1'),
'email' => '[email protected]',
),
'user2:user2pass' => array(
'uid' => array('2'),
'email' => '[email protected]',
),
),
);
You may choose to provide your own user configurations to customize the users further and define additional attributes by mounting your own sources file from the host using volumes. Below is an example where the saml-dev-users.php file is located in the same directory as the docker-compose.yml file and mapped to the default authsources.php file.
saml-idp:
image: saml-idp:1.0
ports:
- 7265:7265
volumes:
- ./saml-dev-users.php:/var/www/simplesamlphp/config/authsources.php
environment:
- SP_ENTITY_ID=https://localhost
- SP_ASSERTION_CONSUMER_SERVICE=https://localhost/cms/logIn.jsp
- SP_SINGLE_LOGOUT_SERVICE=https://localhost/misc/logout.jsp
This is primarily a fork of docker-test-saml-idp by kristophjunge to allow for more extensibility within the Brightspot ecosystem.
The internals of this container are built using SimpleSAMLphp and official PHP7 + Apache images
Content type
Image
Digest
Size
172.5 MB
Last updated
over 6 years ago
docker pull brightspot/saml-idp