Service to add API Transaction shields to an Amplify Central API Service
1.0K
Service to add API Transaction shields to an Amplify Central API Service Description and/or an Amplify Central Environment. This service is a Dockerized Axway API Builder project.
API Service Description:

Environment Description

Refer to these blog posts for more details:
This API Builder project exposes three API's:
Note that if you have previously discovered API Services, you can manually add the shields URLs to your API Service description using the Axway CLI or Axway Central API's.
The API Builder project can be found on Github.
Pull image
docker pull lbrenman/shieldstest
Run locally
docker run --rm -e AC_SA_CLIENTID=<YOUR CLIENT ID> -e AC_SA_CLIENTSECRET=<YOUR CLIENT SECRET> -e AC_BASEURL=https://apicentral.axway.com -e APIB_HOST=23cfbb7e5354.ngrok.io -e PORT=8080 -p 8080:8080 --name shieldstest lbrenman/shieldstest
If everything is running properly, then you should see something similar to the following:
1620948998709 INFO API Builder/Lyon (4.63.0) shieldstest/0.0.2
1620948998719 WARN Your server has no authentication, accessControl.apiPrefixSecurity is unset.
1620948999154 INFO Registered plugin: @axway/api-builder-plugin-fn-base64
1620948999235 INFO Registered plugin: @axway/api-builder-plugin-fn-javascript
1620948999273 INFO Registered plugin: @axway/api-builder-plugin-fn-json
1620948999306 INFO Registered plugin: @axway/api-builder-plugin-fn-mustache
1620948999328 INFO Registered plugin: @axway/api-builder-plugin-fn-restclient
1620948999570 INFO Registered plugin: @axway/api-builder-plugin-fn-swagger
1620948999573 INFO Starting connector/memory@built-in
1620948999575 INFO Started connector/memory@built-in
(node:1) [D034] DeprecationWarning: Using the 'optional' property in API parameters and Model fields has been deprecated. Use 'required' instead. See https://docs.axway.com/bundle/API_Builder_4x_allOS_en/page/api_builder_deprecations.html#APIBuilderDeprecations-D034
1620948999739 INFO Access the swagger API documentation at http://localhost:8080/apidoc/swagger.json
1620949000068 WARN Unrestricted access to API Builder Console
1620949000098 INFO Access API Builder Console at http://localhost:8080/console (This will only be available on your dev environment)
1620949000102 INFO server started on port 8080
curl --location -g --request GET '{{apib_baseaddress}}/api/metrics?eid=8a2e862d779860e20177a6888d450233&pid=remoteApiId_o18il3ymuh&metrictype=totalnumcalls'
Response:
{
"schemaVersion": 1,
"label": "Total # Calls",
"message": "185",
"color": "green"
}
curl --location --request GET '{{apib_baseaddress}}/api/metrics?eid=8a2e862d779860e20177a6888d450233&pid=remoteApiId_o18il3ymuh&metrictype=avgresptime'
Response:
{
"schemaVersion": 1,
"label": "Avg Resp Time",
"message": "10.8ms",
"color": "blue"
}
curl --location --request GET '{{apib_baseaddress}}/api/metrics?eid=8a2e862d779860e20177a6888d450233&pid=remoteApiId_o18il3ymuh&metrictype=errorrate'
Response:
{
"schemaVersion": 1,
"label": "Err Rate",
"message": "50.8%",
"color": "red"
}
curl --location --request GET '{{apib_baseaddress}}/api/envmetrics?eid=8a2e862d779860e20177a6888d450233&metrictype=envcallmetrics'
Response:
{
"schemaVersion": 1,
"label": "API Calls",
"message": "Success: 119, Client Errors: 100, Server Errors: 0",
"color": "red"
}
curl --location --request GET '{{apib_baseaddress}}/api/envmetrics?eid=8a2e862d779860e20177a6888d450233&metrictype=envavgresptime'
Response:
{
"schemaVersion": 1,
"label": "Avg Resp Time",
"message": "16.2ms",
"color": "blue"
}
In order for this app to work, it needs to be triggered by an Amplify Central Integration Webhook when a new API Service is discovered by the Discovery Agent.
You can do this using the Axway CLI as follows:
name: apiscintegration
kind: Integration
apiVersion: v1alpha1
title: API Service Created Integration
tags:
- cloud
spec:
description: This is an Integration for when an API Service is created.
---
name: apiscwebhook
kind: Webhook
apiVersion: v1alpha1
title: API Service Created Webhook to invoke an API Builder API
metadata:
scope:
kind: Integration
name: apiscintegration
spec:
enabled: true
url: https://23cfbb7e5354.ngrok.io/api/intwebhook
---
group: management
apiVersion: v1alpha1
kind: ResourceHook
name: apisc-hook
title: Resource Hook to monitor environment aws and new API Service created
metadata:
scope:
kind: Integration
name: apiscintegration
spec:
triggers:
- group: management
kind: APIService
name: '*'
type:
- created
scope:
kind: Environment
name: aws
webhooks:
- apiscwebhook
Note that the url above is the URL of the API Builder API so the API Builder project must be deployed/running before setting up the Integration. Replace with the URL of your container.
Note that the scope for the resource hook is my aws environment. You can replace with your environment name or use an asterisk '*' for all environments
axway auth login
axway central create -f resources.yaml
The response will be something like this:
⠋ Creating resource(s)(node:96292) ExperimentalWarning: The fs.promises API is experimental
✔ "integration/apiscintegration" has successfully been created.
✔ "webhook/apiscwebhook" has successfully been created.
✔ "resourcehook/apisc-hook" has successfully been created.
If you need to make a change to your YAML file, say to update the URL of the webhook, for example, you can use the following command to update the resources:
axway central apply -f resources.yaml
Once everything is working, you can publish this docker image to the hosting service of your choice. Then you need to update the Integration Webhook URL to point to the URL of your published service by editing your YAML file and issuing the axway central apply command above. If this URL is different, then you will need to remove and "re-discover" the API's since any shields will be pointing to the prior address.
Axway ARS can be used to host your docker image. Below are instructions for deploying your docker image:
ARS App Setup
axway acs login
axway acs new <ARS App Name> --force
axway acs list <ARS App Name>
Note that at this point you can see your app's base URL. You will need this for setting the APIB_HOST environment variable below.
The response will be similar to the following:
AXWAY CLI, version 2.1.0
Copyright (c) 2018-2021, Axway, Inc. All Rights Reserved.
ACS: Axway AMPLIFY Runtime Services Services Command-Line Interface, version 2.1.10
Copyright (c) 2012-2021, Axway, Inc. All Rights Reserved.
Organization: Axway Appcelerator SE (100000142)
============
Points:
-- Quota: 1000
-- Used: 258
App name: shieldstest2
-- Created by: [email protected]
-- URL: https://843d2294c82c93c09ad737049b30298fa16ceabc.cloudapp-enterprise.appcelerator.com
-- Created at: 2021-05-18T11:28:14-04:00
-- Status: To be published
Continue to setup the app by setting environment variables:
axway acs config --set PORT=8080 <ARS App Name>
axway acs config --set AC_SA_CLIENTID=<YOUR CLIENT ID> <ARS App Name>
axway acs config --set AC_SA_CLIENTSECRET=<YOUR CLIENT SECRET> <ARS App Name>
axway acs config --set AC_BASEURL=https://apicentral.axway.com <ARS App Name>
axway acs config --set APIB_HOST=<Your ARS App URL> <ARS App Name>
axway acs server --set Medium <ARS App Name>
Check your environment variables:
axway acs config --env <ARS App Name>
Publish Docker Image to ARS
axway acs publish <ARS App Name> --delete_oldest --force --image lbrenman/shieldstest --app_version 0.1
Content type
Image
Digest
Size
66.8 MB
Last updated
almost 5 years ago
docker pull lbrenman/shieldstest