This Docker configuration is matched to example-impact scenario and scripts. It exercises the full ImPACT MVP using curl instead of slang-shell. While it runs all containers on a single host for this example it is designed to emulate the environment in which each container is run on a separate host as per ImPACT MVP deployment. For this reason it does not rely on docker-compose.
The structure of example-impact is as follows:
As indicated above, the example comes with keys already created. The curl scripts make use of the Python package pycryptodome in order to generate the hash of public keys.
Make sure you are executing the scripts from a Python3 environment that has pycryptodome installed:
virtualenv -p $(which python3) venv
source venv/bin/activate
pip install pycryptodome
First create a directory structure for /imports volumes for each of the SAFE servers under the example-impact/:
$ cd example-impact
$ mkdir -p imports/wp imports/dso imports/ns imports/presidio
$ mkdir -p riak/data riak/conf
they will be needed by the start-dockers.sh script to volume mount different directories for each of the containers.
Start all containers
$ start-dockers.sh
Wait for a long time, checking logging outputs from each container:
$ docker logs riak
$ docker logs impact-wpdso
$ docker logs impact-ns
$ docker logs impact-presidio
Now we are ready to post statements to the various SAFE servers and validate access. Please refer to the ImPACT MVP script documentation for further explanation. Note that this example uses a combined WP/DSO principal.
Lets check that right now our user someUser in project someProject can't really get access to the dataset:
$ cd scripts
$ ./curl-presidio.sh
Working on behalf of presidio1
WF1 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91
WF2 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
DATASET is wrZvIM4CYb9jvBS_4gJ0VIUVXJQYrc0yrEmveTod5Hk=:26dbc728-3c8d-4433-9c4b-2e065b644db5
User someUser on project someProject
NS is 9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=
Check access to dataset wrZvIM4CYb9jvBS_4gJ0VIUVXJQYrc0yrEmveTod5Hk=:26dbc728-3c8d-4433-9c4b-2e065b644db5, user someUser, NS 9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=, project someProject
"fail"
"Query failed with msg: java.lang.RuntimeException: Unsatisfied queries: List(access('wrZvIM4CYb9jvBS_4gJ0VIUVXJQYrc0yrEmveTod5Hk=:26dbc728-3c8d-4433-9c4b-2e065b644db5', 'someUser', '9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=', 'someProject')?) List()"
Let's post on behalf of the WP/DSO first:
$ ./curl-wp-dso.sh
Working on behalf of wp1
WF1 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91
WF2 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
DATASET is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5
User someUser on project someProject
NS is 9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=
postRawIdSet
"succeed"
"['wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=']"
postPerFlowRule
"succeed"
"['Ni_bWnFF2J1F11t6U2zZ5O_tfwgLVymSjjs9uzBqYXA=']"
postPerFlowRule
"succeed"
"['iYrj3wquhHonGMQMf53cqmpZMPe9efXIEqOZin2o3Lo=']"
postTwoFlowDataOwnerPolicy for dataset wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5, wf1 wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91, wf2 wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
"succeed"
"['svHy8ajGgdTufTZ-sGG9tyzgfBTkbO-rbtsPmAGlhHU=']"
Now on behalf of NS:
./curl-ns.sh
Working on behalf of ns1
WF1 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91
WF2 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
DATASET is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5
User someUser on project someProject
NS is 9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=
postRawIdSet
"succeed"
"['9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=']"
postCommonCompletionReceipt for project someProject, workflow wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91
"succeed"
"['iH7gTihUMsWALNsb5Jml7y6YqRMfal8K2xbj35zcyfI=']"
postUserCompletionReceipt for user someUser, project someProject, workflow wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91
"succeed"
"['51Oe95KJ8ojTOV9H8MpD5wOD5s_lzUUTqbVCClnlNH8=']"
postCommonCompletionReceipt for project someProject, workflow wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
"succeed"
"['X9alnsxY8NKXY9VaoTjulS2XyTgyQW6PhXxe3Er4XjM=']"
postUserCompletionReceipt for user someUser, project someProject, workflow wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
"succeed"
"['LDK4Mf2oAp4RhmRq3u_uAys75RhA9NXY_wHAsGm1X6k=']"
postLinkReceiptForDataset for user someUser, project someProject, dataset wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5, workflow wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91
"succeed"
"['c9SKvye0eGIBwr1VUtCNGRhicutUhkYqChOSuXMs0yI=']"
postLinkReceiptForDataset for user someUser, project someProject, dataset wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5, workflow wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
"succeed"
"['c9SKvye0eGIBwr1VUtCNGRhicutUhkYqChOSuXMs0yI=']"
Finally let's check access again:
$ ./curl-presidio.sh
Working on behalf of presidio1
WF1 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:6ec7211c-caaf-4e00-ad36-0cd413accc91
WF2 is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:1b924687-a317-4bd7-a54f-a5a0151f49d3
DATASET is wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5
User someUser on project someProject
NS is 9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=
Check access to dataset wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5, user someUser, NS 9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=, project someProject
"succeed"
"{ 'BjDPqyYcbTxX__VvRAG8fI3YT7M3eoQJuBjQMJuXhyo=':grantAccess('wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=','wa152R689MgLaTJUxkLE1wNFwEUdOUVzowkiVbOAmmQ=:26dbc728-3c8d-4433-9c4b-2e065b644db5',someUser,'9QbzxpBeorl7MyPRY5JkHj38Xmzs6tssAXbdP5F2-0c=',someProject) }"
This indicates that all the proper assertions have been made and the policy guard is satisfied.
Debugging SAFE is tricky. You can try setting the AKKA debug level higher in start-dockers.sh. Pay attention to messages back from the server after each curl call.
Finally you can always try to inspect what is in Riak using curl calls to it. Every token returned in the post message to SAFE can be queried directly. E.g. for the last token returned from NS posts above: mJmUzi3bUx5Cq6K6RhfpMZ45zRl-BNfEpGVHOndoEks= you should be able to query the results using
$ curl "http://localhost:8098/types/safesets/buckets/safe/keys/mJmUzi3bUx5Cq6K6RhfpMZ45zRl-BNfEpGVHOndoEks="
Interpretation of the outputs other than not found is beyond the scope of this document.
Content type
Image
Digest
Size
475.8 MB
Last updated
about 7 years ago
docker pull rencinrig/safe-server