The Docker image for demilleTech's open-source Single Sign-On software, Indra
1M+
Indra is a Single Sign-On application written with Flask in Python, used by demilleTech
Have questions? Comments? Concerns? Send us a message at [email protected]
Every password in the database is stored using argon2. It recently won the Password Hashing Competition, and is on track to become the password hashing standard.
In addition, all tokens, keys, and requests are encrypted over the wire, at rest, and on client computers.
There are no server-specific files, keys, or codes needed to run this. The only necessary system is a database connection, and you're ready to go. Run this anywhere, load balanced, under different domains, however you like. Indra can do it.
You can edit Indra however you like. It is fully customizable, with the ability to use custom HTML, or even write your own API scheme.
There are a couple primary ways of installing Indra. You can either download the source and run it from the command line, or you can use our Docker image.
Indra requires:
indra under the supplied user (postgres >= 9.2)To run Indra from source, it is recommended to git clone the repo, then use gunicorn to serve. It is also recommended that Indra does not directly serve requests, and instead is proxied by another service, such as Nginx
For convenience, there is a scripts/serve.sh file, which is used in our Docker images, but can be repurposed to serve in a server other than our Docker image.
Pipenv is used for dependency management.
Never heard of pipenv? Read up on it here.
$ git clone https://gitlab.com/demilletech/indra/indra.git
$ cd indra
$ pipenv sync
$ pipenv run gunicorn server:application_factory --worker-class aiohttp.GunicornWebWorker
Or, alternatively, if you want to run without gunicorn (HIGHLY NOT RECOMMENDED)
$ git clone https://gitlab.com/demilletech/indra/indra.git
$ cd indra
$ pipenv sync
$ pipenv run python server.py
https://hub.docker.com/repository/docker/demilletech/indra-server
To run the Docker image, there are two required environment variables, described below.
Sample script to run the Indra docker image:
$ docker pull demilletech/indra-server
$ docker run -d -p 80:80 \
-e POSTGRES_HOST="postgres://indra:[email protected]" \
-e REDIS_HOST="redis://1.2.3.4" \
demilletech/indra-server
This is the url to the PostgreSQL server, including the username & password. Indra will automatically use the database called indra.
Sample:
postgres://indra:[email protected]
This is the url to the Redis instance. It is recommended that this is hosted on a separate server from the one running Indra, in the event of a server failure.
Sample
redis://1.2.3.4
openiduname (Username only)full_name (Full name)email (Email only)profile (Full profile)groups (Groups only)You can mix and match scopes as you please, Indra will automatically figure out what data to provide you
GET /oauth/authorize
Available Parameters:
scopeclient_idredirect_uristateresponse_typecode_challenge_methodcode_challengeThis endpoint follows standard oAuth 2 spec. If you have an oauth library, just point it to the <yourdomain.tld>/oauth/authorize url
POST /api/oauth/token
Available Parameters:
client_idclient_secretgrant_typecode_verifiercoderefresh_tokenThis endpoint follows standard oAuth 2 spec. If you have an oauth library, just point it to the <yourdomain.tld>/api/oauth/token url
POST /api/oauth/userinfo
Required Parameters:
bearer_token
ORAuthorization: Bearer <token> in HTTP headersThis endpoint follows standard oAuth 2 spec. If you have an oauth library, just point it to the <yourdomain.tld>/api/oauth/userinfo url
POST /api/oauth/token_info
Required Parameters:
tokenThis endpoint follows standard oAuth 2 spec. If you have an oauth library, just point it to the <yourdomain.tld>/api/oauth/token_info url
GET /api/oauth/jwks
This would be if you wanted SCIM access to Indra, for example, using Indra only for sign-in, and not for signups or user management
POST /api/scim/user
Required Parameters:
key (API Key)emailpasswordgiven_namefamily_namename (Username)PUT /api/scim/user
Required Parameters:
key (API Key)userid (User's ID)Available Parameters:
emailgiven_namefamily_namename (Username)groupsGET /api/scim/user
Required parameters:
key (API Key)userid (User's ID)GET /api/scim/user/email
Required parameters:
key (API Key)email (User's email)POST /api/scim/user/password
Required parameters:
key (API Key)userid (User's ID)passwordpassword must be in plaintext
This would be used if you wanted to write your own UI
POST /signin
Parameters:
emailpasswordpassword must be in plaintext
POST /signup
Parameters:
emailpasswordpassconffnamelnameunamepassword & passconf must be in plaintext
GET /signout
Available parameters:
redirect_url (Where to redirect user after signing out)POST /forgot
Required Parameters:
emailGET /email/verify
Required Parameters:
tokenPOST /email/reset
Parameters:
reset_tokennewpasspassconfnewpass & passconf must be in plaintext
Content type
Image
Digest
Size
425.9 MB
Last updated
over 6 years ago
docker pull demilletech/indra-server