CData Virtuality Authentication Management Component
791
The CData Virtuality Authentication Management Component application requires an external database server to be connected for normal work. The database server connection details along with credentials and other settings can be passed to the service using environment variables:
mariadb - MariaDB server,mysql - MySQL Database server,mssql - Microsoft SQL Server,oracle - Oracle Database,postgres - PostgreSQL server.The above variables are minimal required to attach a database for the Authentication Management Component; there are a few more that allow to set connection details:
Additionally, the service requires a few settings to be set for HTTP protocol depending on how exactly Authentication Management Component will be set and how exactly it will be accessed.
First, if the service is supposed to run behind a balancer or reverse proxy, then the plain HTTP should be explicitly enabled:
It may also make sense to explicitly set the port which the HTTP server will be listening:
Also, the service has to be informed which type of headers will bring the proxy information:
forwardedxforwardedAdditionally, if your reverse proxy overwrites the Host header, then dynamically resolving the hostname should be enabled:
true to enable resolving, false otherwise. If disabled, the hostname must be explicitly set.If, on the other hand, the service is supposed to be accessed directly, then the HTTP connection must be secured with TLS/SSL. In this case, the HTTPS port has to be set:
Besides the above, an SSL certificate has to be provided to secure the connection. Here are the variables that sets the certificates:
The certificates files must be present in the container by either attaching a volume that contains those files or building a new image on top of this base image embedding those files into the image.
In addition to the above, the hostname must also be configured:
http://<hostname>:<port>/Note: At first login CData Virtuality Authentication Management Component shows a pop-up: "Temporary admin user account. Ensure it is replaced with a permanent admin user account as soon as possible." Follow this procedure:
Here is an example of a docker run command that starts a CData Virtuality Authentication Management Component container with a PostgreSQL database attached, a volume with certificates mounted, and HTTPS communication:
docker run --name cdv-auth-service \
-p 8443:8443 \
-v <host filesystem path>:/opt/ssl \
-e KC_HOSTNAME=<hostname> \
-e KC_HTTPS_PORT=9443 \
-e KC_HTTPS_CERTIFICATE_FILE=/opt/ssl/cert.pem \
-e KC_HTTPS_CERTIFICATE_KEY_FILE=/opt/ssl/key.pem \
-e KC_DB=postgres \
-e KC_DB_SCHEMA=<schema> \
-e KC_DB_URL_HOST=<server host> \
-e KC_DB_URL_PORT=5432 \
-e KC_DB_USERNAME=<username> \
-e KC_DB_PASSWORD=<password> \
datavirtuality/dv-auth-mgmt:26.1.4
Content type
Image
Digest
sha256:43a994a06…
Size
607.4 MB
Last updated
10 months ago
docker pull datavirtuality/dv-auth-mgmt:25.3