Sign inSign up

czertainly/czertainly-core

By czertainly

•Updated 3 months ago

Image
0

10K+

czertainly/czertainly-core repository overview

⁠CZERTAINLY Core

This repository is part of the open source project CZERTAINLY. You can find more information about the project at CZERTAINLY⁠ repository, including the contribution guide.

Core provides the basic functionality for the CZERTAINLY platform. It implements the logic for the certificate lifecycle management and handles all related tasks. You can think about it as a brain of the CZERTAINLY platform.

There are 2 types of communication that the Core is responsible for:

  • client requesting management operations on top of certificates and related objects
  • Connector that provides with the functionality for specific technologies

The management of certificates and cryptographic keys is abstracted through CZERTAINLY objects called Profiles, such as:

  • RA Profile - configuration of the service for certificate lifecycle management
  • Token Profile - configuration of the cryptographic service and management of the keys
  • Compliance Profile - compliance requirements for the certificates and related objects

For more information, refer to the CZERTAINLY documentation⁠.

⁠Access Control

Core access control requires the following to run:

  • CZERTAINLY-Auth⁠ service to manage users, roles, permission. The URL of the Auth service can be configured using AUTH_SERVICE_BASE_URL environment variable.
  • OPA (Open Policy Agent) evaluating policies and providing decisions about authorization. The OPA service URL can be confgiured using OPA_BASE_URL environment variable.
  • OPA policies bundles that are loaded into OPA service and define the rules to be evaluated. The policies are defined in CZERTAINLY-Auth-OPA-Policies⁠

Warning The Core will fail to run when Auth or OPA is missing.

Note OPA can run on the same system with the Core or it can be hosted externally. To improve the performance of the permissions evaluation it is typically running on the same host as Core (e.g. as a sidecar).

⁠Certificate inventory

Certificate inventory contains all Certificates that were discovered or were imported to the platform. Each Certificate provides comprehensive and consistent information which can be managed.

⁠Lifecycle operations

The following basic lifecycle operations are supported for each Certificate:

  • create (request)
  • issue
  • renew
  • rekey
  • revoke

Operations can be automated by the Core, but also can be performed manually by the user.

⁠Cryptographic key inventory

Key inventory contains all Keys that are available for usage. Each Key provides comprehensive and consistent information which can be managed through the Token Profile.

⁠Experimental support for PQC algorithms

Core supports the following PQC algorithms: FALCON, CRYSTALS-Dilithium, SPHINCS+. The support is experimental and it is not recommended to use it in production as the PQC algorithms are still in the development and not fully standardized.

⁠Protocol support

Core support the following protocols for certificate management:

  • ACME
  • SCEP (with optional Intune support)
  • CMP

⁠Message brokers support

Application supports two types of message brokers:

  • RabbitMQ - uses JmsPoolConnectionFactory with configurable connection pool settings
  • Azure Service Bus - uses JmsConnectionFactory with two authentication options:
    • SAS (Shared Access Signature) - uses connection string with policy name and key
    • AAD (Azure Active Directory / Entra ID) - uses OAuth2 with Service Principal credentials
⁠Authentication configuration
BrokerAuthenticationRequired variables
RabbitMQUsername/PasswordBROKER_USERNAME, BROKER_PASSWORD
Azure Service BusSASBROKER_USERNAME, BROKER_PASSWORD
Azure Service BusAADBROKER_AZURE_TENANT_ID, BROKER_AZURE_CLIENT_ID, BROKER_AZURE_CLIENT_SECRET

⁠Docker container

Core is provided as a Docker container. Use the czertainly/czertainly-core:tagname to pull the required image from the repository. It can be configured using the following environment variables:

VariableDescriptionRequiredDefault value
JDBC_URLJDBC URL for database accessN/A
JDBC_USERNAMEUsername to access the databaseN/A
JDBC_PASSWORDPassword to access the databaseN/A
DB_SCHEMADatabase schema to usecore
PORTPort where the service is exposed8080
HEADER_NAMEName of the header where the certificate of the client can be foundssl-client-cert
HEADER_ENABLEDTrue if the certificate should be get from the headerN/A
TS_PASSWORDPassword for the trusted certificate storeN/A
OPA_BASE_URLBase URL of the Open Policy AgentN/A
AUTH_SERVICE_BASE_URLBase URL of the authentication serviceN/A
AUTH_TOKEN_HEADER_NAMEName of the header for the JSON ID contentX-USERINFO
SCHEDULED_TASKS_ENABLEDScheduled certificate status update enable / disabletrue
JAVA_OPTSCustomize Java system properties for running applicationN/A
TRUSTED_CERTIFICATESList of PEM encoded additional trusted certificatesN/A
SCHEDULER_BASE_URLBase URL of the scheduler serviceN/A
BROKER_TYPEMessage broker type - supported values are SERVICEBUS or RABBITMQRABBITMQ
BROKER_URLMessage broker url (include protocol, e.g. amqp://localhost:5672 for RabbitMQ, amqps://namespace.servicebus.windows.net:5671 for ServiceBus)N/A
BROKER_USERNAMEMessage broker username (required for RabbitMQ and ServiceBus+SAS)N/A
BROKER_PASSWORDMessage broker password (required for RabbitMQ and ServiceBus+SAS)N/A
BROKER_AZURE_TENANT_IDAzure AD tenant ID (required for ServiceBus+AAD authentication)N/A
BROKER_AZURE_CLIENT_IDAzure AD application (client) ID (required for ServiceBus+AAD)N/A
BROKER_AZURE_CLIENT_SECRETAzure AD client secret (required for ServiceBus+AAD authentication)N/A
BROKER_AZURE_TOKEN_REFRESH_INTERVALAzure AD token refresh interval in seconds (required for ServiceBus+AAD authentication)300
BROKER_AZURE_TOKEN_GETTING_TIMEOUTAzure AD token getting timeout in seconds (required for ServiceBus+AAD authentication)30
BROKER_EXCHANGEMessage broker exchange/topic nameczertainly
BROKER_VHOSTMessage broker vhost (for RabbitMQ only)N/A
BROKER_SESSION_CACHE_SIZEConnectionCachingFactory session cache size (only for RabbitMQ)25
BROKER_QUEUE_AUDIT_LOGSQueue name for audit logs (for RabbitMQ only)core.audit-logs
BROKER_QUEUE_EVENTQueue name for events (for RabbitMQ only)core.event
BROKER_QUEUE_NOTIFICATIONQueue name for notifications (for RabbitMQ only)core.notification
BROKER_QUEUE_SCHEDULERQueue name for scheduler (for RabbitMQ only)core.scheduler
BROKER_QUEUE_VALIDATIONQueue name for validation (for RabbitMQ only)core.validation
BROKER_ROUTINGKEY_ACTIONSRouting key for actionsactions
BROKER_ROUTINGKEY_AUDIT_LOGSRouting key for audit logsauditlogs
BROKER_ROUTINGKEY_EVENTRouting key for eventsevent
BROKER_ROUTINGKEY_NOTIFICATIONRouting key for notificationsnotification
BROKER_ROUTINGKEY_SCHEDULERRouting key for schedulerscheduler
BROKER_ROUTINGKEY_VALIDATIONRouting key for validationvalidation
SETTINGS_CACHE_REFRESH_INTERVALInterval of scheduled settings cache refresh from DB (in seconds)30
⁠OpenTelemetry settings

Core supports OpenTelemetry for producing signals (metrics, traces, logs) to the observability system. The following environment variables can be used to configure OpenTelemetry:

VariableDescriptionRequiredDefault value
OTEL_SDK_DISABLEDDisables the OpenTelemetry SDK. Supported values: true, false. OpenTelemetry SDK is disabled by defaulttrue
OTEL_LOGS_EXPORTERThe logs exporter to use. Supported values: none, otlp, logging.none
OTEL_METRICS_EXPORTERThe metrics exporter to use. Supported values: none, otlp, logging.none
OTEL_TRACES_EXPORTERThe traces exporter to use. Supported values: none, otlp, logging.none
OTEL_EXPORTER_OTLP_LOGS_ENDPOINTEndpoint URL for log data only, with an optionally-specified port number. Typically ends with v1/logs when using OTLP/HTTP.http://localhost:4317
OTEL_EXPORTER_OTLP_LOGS_PROTOCOLProtocol to use for the logs exporter. Supported values: grpc, http/protobuf, http/json.grpc
OTEL_EXPORTER_OTLP_METRICS_ENDPOINTEndpoint URL for metric data only, with an optionally-specified port number. Typically ends with v1/metrics when using OTLP/HTTP.http://localhost:4317
OTEL_EXPORTER_OTLP_METRICS_PROTOCOLProtocol to use for the metrics exporter. Supported values: grpc, http/protobuf, http/json.grpc
OTEL_EXPORTER_OTLP_TRACES_ENDPOINTEndpoint URL for trace data only, with an optionally-specified port number. Typically ends with v1/traces when using OTLP/HTTP.http://localhost:4317
OTEL_EXPORTER_OTLP_TRACES_PROTOCOLProtocol to use for the traces exporter. Supported values: grpc, http/protobuf, http/json.grpc
⁠Proxy settings

You may need to configure proxy to allow Core to communicate with external systems. To enable proxy, use the following environment variables for docker container:

VariableDescriptionRequiredDefault value
HTTP_PROXYThe proxy URL to use for http connections. Format: <protocol>://<proxy_host>:<proxy_port> or <protocol>://<user>:<password>@<proxy_host>:<proxy_port>N/A
HTTPS_PROXYThe proxy URL to use for https connections. Format: <protocol>://<proxy_host>:<proxy_port> or <protocol>://<user>:<password>@<proxy_host>:<proxy_port>N/A
NO_PROXYA comma-separated list of host names that shouldn't go through any proxyN/A

Example values:

  • HTTP_PROXY=http://user:[email protected]:3128
  • HTTPS_PROXY=http://user:[email protected]:3128
  • NO_PROXY=localhost,127.0.0.1,0.0.0.0,10.0.0.0/8,cattle-system.svc,.svc,.cluster.local,my-domain.local

Tag summary

Content type

Image

Digest

sha256:5421fa9e1…

Size

155.6 MB

Last updated

3 months ago

docker pull czertainly/czertainly-core:signing-ac57eb6