Sign inSign up

jtenorio/duende-idp

By jtenorio

•Updated 11 months ago

Duende test server

Image
Security
Web servers
0

1.0K

jtenorio/duende-idp repository overview

⁠Duende IdentityServer - Docker Image

A production-ready Duende IdentityServer for testing purposes only instance with HTTPS support, pre-configured clients, and flexible authentication options including X.509 certificates and JSON Web Keys.

⁠Quick Start

Pull and run the image:

docker pull jtenorio/duende-idp:latest
docker run -d -p 5000:5000 -p 5001:5001 --name duende-idp duende-idp:latest

Access the IdentityServer:

⁠Features

  • HTTPS Enabled: Auto-generated self-signed certificate with 1-year validity
  • Multiple Secret Types: Supports SharedSecret, X509CertificateBase64, and JsonWebKey
  • Pre-configured Clients: 7 ready-to-use OAuth/OIDC clients
  • Test Users: 4 pre-configured test users with different roles
  • In-Memory Storage: Perfect for testing, CI/CD, and development
  • Lightweight: ~269 MB image size

⁠Pre-configured Test Users

UsernamePasswordRoleEmail
alicealice-[email protected]⁠
bobbob-[email protected]⁠
adminadminadmin[email protected]⁠
dseldonmycomplexPassword33#45%admin[email protected]⁠

⁠Pre-configured Clients

⁠1. Interactive Client
ClientId: interactive
ClientSecret: secret
Grant Type: Authorization Code + PKCE
Redirect URI: https://localhost:5444/signin-oidc
Scopes: openid, profile, email, api1
⁠2. Machine-to-Machine (M2M)
ClientId: m2m
ClientSecret: secret
Grant Type: Client Credentials
Scopes: api1, api2
⁠3. SPA Client
ClientId: spa
Grant Type: Authorization Code + PKCE
Redirect URI: http://localhost:4200/callback
CORS Origin: http://localhost:4200
Scopes: openid, profile, email, api1
⁠4. Test Client
ClientId: test.client
ClientSecret: test.secret
Grant Type: Resource Owner Password
Scopes: openid, profile, email, api1, api2
⁠5-7. JWT Authentication Clients
  • client.jwt.x509: X509 certificate authentication
  • client.jwt.jwk: JSON Web Key authentication
  • client.jwt.mixed: Multiple secret types (demonstrates rotation)

⁠HTTPS & Certificate

The image automatically generates a self-signed certificate during build:

  • Algorithm: RSA 4096-bit
  • Hash: SHA-256
  • Validity: 365 days from image build
  • DNS Names: localhost, *.localhost
⁠Using Your Own Certificate

Mount your certificate into the container:

docker run -d \
  -p 5000:5000 -p 5001:5001 \
  -v /path/to/your/certificate.pfx:/app/certificate.pfx \
  -e ASPNETCORE_Kestrel__Certificates__Default__Password=YourPassword \
  --name duende-idp \
  duende-idp:latest

⁠Configuration

⁠Environment Variables
VariableDefaultDescription
ASPNETCORE_ENVIRONMENTProductionEnvironment (Development/Production)
ASPNETCORE_URLShttps://+:5001;http://+:5000URLs to listen on
ASPNETCORE_Kestrel__Certificates__Default__Path/app/certificate.pfxCertificate path
ASPNETCORE_Kestrel__Certificates__Default__Password(empty)Certificate password
⁠Custom Configuration

Mount a custom appsettings.json file:

docker run -d \
  -p 5000:5000 -p 5001:5001 \
  -v /path/to/your/appsettings.json:/app/appsettings.json \
  --name duende-idp \
  duende-idp:latest

⁠Advanced: Secret Types

This image supports three types of client secrets for enhanced security:

⁠1. Shared Secret (Traditional)
{
  "ClientId": "my.client",
  "ClientSecrets": ["my-secret"]
}
⁠2. X509 Certificate (Base64 Encoded)
{
  "ClientId": "my.client",
  "ClientSecretsTyped": [
    {
      "Type": "X509CertificateBase64",
      "Value": "MIID...base64cert...",
      "Description": "Client certificate"
    }
  ]
}
⁠3. JSON Web Key
{
  "ClientId": "my.client",
  "ClientSecretsTyped": [
    {
      "Type": "JsonWebKey",
      "Value": "{\"e\":\"AQAB\",\"kty\":\"RSA\",\"n\":\"...\"}",
      "Description": "JWK for authentication"
    }
  ]
}
⁠4. Multiple Secrets (Rotation)
{
  "ClientId": "my.client",
  "ClientSecretsTyped": [
    {
      "Type": "SharedSecret",
      "Value": "current-secret",
      "Description": "Current secret"
    },
    {
      "Type": "SharedSecret",
      "Value": "old-secret",
      "Description": "Previous secret",
      "Expiration": "2025-12-31T23:59:59Z"
    }
  ]
}

⁠API Scopes

Pre-configured API scopes available for token requests:

  • api1 - My API
  • api2 - Another API
  • scope1 - Custom Scope 1
  • scope2 - Custom Scope 2

⁠Identity Resources

Standard OpenID Connect identity resources:

  • openid - Required for OpenID Connect
  • profile - User profile information
  • email - Email address
  • phone - Phone number
  • address - Physical address

⁠Use Cases

⁠Development & Testing
# Start the server
docker run -d -p 5000:5000 -p 5001:5001 --name duende-idp duende-idp:latest

# Your application connects to https://localhost:5001
# Use pre-configured clients for testing OAuth/OIDC flows
⁠CI/CD Pipeline
services:
  identityserver:
    image: duende-idp:latest
    ports:
      - "5001:5001"
    environment:
      - ASPNETCORE_ENVIRONMENT=Development
⁠Integration Testing
# Start container before tests
docker run -d -p 5001:5001 --name test-idp duende-idp:latest

# Run your integration tests
dotnet test

# Stop container after tests
docker stop test-idp && docker rm test-idp

⁠Docker Compose

Create a docker-compose.yml:

version: '3.8'

services:
  duende-idp:
    image: duende-idp:latest
    container_name: duende-identityserver
    ports:
      - "5000:5000"
      - "5001:5001"
    environment:
      - ASPNETCORE_ENVIRONMENT=Development
      - ASPNETCORE_URLS=https://+:5001;http://+:5000
    restart: unless-stopped

Start with:

docker-compose up -d

⁠Testing the Setup

⁠1. Check Discovery Endpoint
curl -k https://localhost:5001/.well-known/openid-configuration
⁠2. Get Access Token (Client Credentials)
curl -k -X POST https://localhost:5001/connect/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "client_id=m2m" \
  -d "client_secret=secret" \
  -d "grant_type=client_credentials" \
  -d "scope=api1"
⁠3. Test User Login (Resource Owner Password)
curl -k -X POST https://localhost:5001/connect/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "client_id=test.client" \
  -d "client_secret=test.secret" \
  -d "grant_type=password" \
  -d "username=alice" \
  -d "password=alice" \
  -d "scope=openid profile api1"

⁠Troubleshooting

⁠Self-Signed Certificate Warning

When accessing via HTTPS, browsers will show a security warning. This is expected with self-signed certificates:

  • For browsers: Accept the security warning
  • For API clients: Disable certificate validation in test/dev environments
  • For production: Use a CA-signed certificate
⁠View Logs
docker logs duende-idp
⁠Access Container Shell
docker exec -it duende-idp /bin/bash
⁠Port Already in Use

Change the host port mapping:

docker run -d -p 8080:5000 -p 8443:5001 --name duende-idp duende-idp:latest

⁠Production Considerations

This image is optimized for development and testing. For production:

  1. ✅ Use a CA-signed certificate (Let's Encrypt, commercial CA)
  2. ✅ Replace in-memory storage with database-backed stores
  3. ✅ Implement proper secret management (Azure Key Vault, AWS Secrets Manager)
  4. ✅ Replace test users with real user store (ASP.NET Identity, Active Directory)
  5. ✅ Configure production-specific CORS policies
  6. ✅ Enable rate limiting and security headers
  7. ✅ Set up monitoring and logging
  8. ✅ Use typed secrets (X509, JWK) for stronger authentication
  9. ✅ Implement secret rotation strategies

⁠Additional Resources

⁠License

This Docker image uses Duende IdentityServer which requires a license for production use. The software includes:

  • Free tier: Development and testing scenarios
  • Paid tiers: Production use requires Business or Enterprise Edition

Visit Duende Software⁠ for licensing information.

⁠Support

For issues, questions, or contributions:

⁠Tags

  • latest - Latest stable build with .NET 9.0

⁠Image Details

  • Base Image: mcr.microsoft.com/dotnet/aspnet:9.0
  • Framework: .NET 9.0
  • IdentityServer Version: Duende.IdentityServer 7.3.0
  • Size: ~269 MB
  • Architecture: linux/amd64
  • Certificate: Auto-generated self-signed (365-day validity)

Quick Links:

  • Pull: docker pull duende-idp:latest
  • Run: docker run -d -p 5001:5001 duende-idp:latest
  • Discovery: https://localhost:5001/.well-known/openid-configuration

Tag summary

Content type

Image

Digest

sha256:a06735ce7…

Size

105.2 MB

Last updated

11 months ago

docker pull jtenorio/duende-idp