Sign inSign up

jdwlabs/identity-service

By jdwlabs

•Updated 2 days ago

Authentication, users and roles API for the jdwlabs platform.

Image
0

414

jdwlabs/identity-service repository overview

⁠jdwlabs/identity-service

Authentication, users and roles API for the jdwlabs platform.

Docker Image Version Docker Image Size Docker Pulls

⁠What it is

A Go service serving the eighteen /auth, /api/users and /api/roles operations of the jdwlabs auth surface: sign-in, self-registration, user records and the role catalogue with its grants. It reads and writes the same auth schema the JVM usersrole service uses, issues the HMAC-signed tokens the rest of the platform verifies, and stores passwords bcrypt-encoded. Built on distroless for a minimal attack surface, running as a numeric non-root uid.

⁠Quick start

docker run -p 8080:8080 \
  -e UR_JWT_SECRET_KEY="$(base64 < /dev/urandom | head -c 44)" \
  -e UR_PG_DATASOURCE_URL="jdbc:postgresql://authdb:5432/jdw" \
  -e UR_PG_USERNAME=jdw \
  -e UR_PG_PASSWORD=jdw \
  -e ID_JWT_ISSUER_ORIGIN="http://localhost:8080" \
  jdwlabs/identity-service:latest

curl http://localhost:8080/actuator/health

The service needs a reachable Postgres carrying the auth schema — the jdwlabs/authdb image ships it — and refuses to start without one.

The HMAC key must be byte-identical everywhere and 32 to 47 bytes once decoded; a longer key makes the JVM sign with a stronger HMAC variant that the Go verifiers refuse.

⁠Exposed ports

PortPurpose
8080HTTP API

⁠Environment

VariableDefaultPurpose
UR_JWT_SECRET_KEYrequiredBase64 HMAC key shared with every verifier
UR_JWT_EXPIRATION_TIME_MS7200000Token lifetime
UR_PG_DATASOURCE_URLrequiredJDBC URL of the auth database
UR_PG_USERNAME—Database user
UR_PG_PASSWORD—Database password
ID_PORT8080Listen port
ID_JWT_ISSUER_ORIGINrequiredOrigin stamped into every token this service mints
ID_JWT_ALLOW_ANY_ISSUER_AND_AUDIENCEunsettrue accepts a token from any issuer
ID_DB_MAX_CONNECTIONS5Connection pool ceiling
ID_DB_MIN_CONNECTIONS2Connection pool floor
ID_CORS_ALLOWED_ORIGIN_PATTERNSany originComma-separated allowed-origin patterns
ID_CORS_ALLOWED_METHODSsevenComma-separated preflight methods
ID_CORS_ALLOWED_HEADERStwoComma-separated preflight headers
ID_SHUTDOWN_TIMEOUT_SECONDS10Drain window on SIGTERM

⁠Observability

PathPurpose
/actuator/healthLiveness and readiness, {"status":"UP"}
/actuator/prometheusScrape endpoint
/healthAlias, for parity with the sibling Go services

Request timings are published as http_server_requests_seconds, labelled method, uri, status and outcome — the series name and labels Micrometer publishes for the JVM service, so existing dashboards keep working.

⁠Tags

  • latest — most recent release
  • X.Y.Z — immutable semver release

⁠Source

⁠License

PolyForm Noncommercial 1.0.0

Tag summary

Content type

Image

Digest

sha256:507dd11b6…

Size

16.8 MB

Last updated

2 days ago

docker pull jdwlabs/identity-service