Files
ThothII/install/dwh-auth-client-enrollment/index.html
T

170 lines
6.2 KiB
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/dwh-auth-client-enrollment/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Client enrollment - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "DWH REST client enrollment", url: "#_top", children: [
{title: "Delivery and storage", url: "#delivery-and-storage" },
{title: "ACME Limited configuration", url: "#acme-limited-configuration" },
{title: "Rotation and revocation", url: "#rotation-and-revocation" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../dwh-auth-tls/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../dwh-auth-tls/" class="btn btn-xs btn-link">
TLS
</a>
</div>
<div class="wm-article-nav">
<a href="../dwh-auth-server/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-server/" class="btn btn-xs btn-link">
Server
</a>
</div>
</div>
<h1 id="dwh-rest-client-enrollment">DWH REST client enrollment<a class="headerlink" href="#dwh-rest-client-enrollment" title="Permanent link">&para;</a></h1>
<p>The <code>dwh-auth</code> credential belongs to one ThothII installation and is needed only when the
workspace uses the <code>rest_api</code> transport.</p>
<table>
<thead>
<tr>
<th>Trasporto</th>
<th>Materiale richiesto</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>rest_api</code></td>
<td>URL HTTPS, <code>API_KEY_FILE</code>, eventuale <code>TLS_CA_FILE</code></td>
</tr>
<tr>
<td><code>postgres_direct</code></td>
<td>Credenziali PostgreSQL e configurazione TLS PostgreSQL</td>
</tr>
<tr>
<td><code>ssh_tunnel</code></td>
<td>Credenziali PostgreSQL e materiale SSH</td>
</tr>
</tbody>
</table>
<h2 id="delivery-and-storage">Delivery and storage<a class="headerlink" href="#delivery-and-storage" title="Permanent link">&para;</a></h2>
<p>Receive the key and CA through separate protected channels. Store the key in the installation
vault or in a regular file accessible only to the authorized account. Do not put it in Git, YAML
files, arguments, logs, or shared screens.</p>
<h2 id="acme-limited-configuration">ACME Limited configuration<a class="headerlink" href="#acme-limited-configuration" title="Permanent link">&para;</a></h2>
<p>Esempio di binding headless per il workspace <code>acme-ebikes</code>:</p>
<pre class="highlight"><code class="language-dotenv">THT_WS_ACME_EBIKES_DWH_TRANSPORT=rest_api
THT_WS_ACME_EBIKES_DWH_BASE_URL=https://dwh.acme.example/dwh/
THT_WS_ACME_EBIKES_DWH_API_KEY_FILE=/run/secrets/acme-ebikes-dwh-api-key
THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem</code></pre>
<p>The workspace suffix comes from the immutable ID, with hyphens changed to underscores and letters
converted to uppercase. <code>API_KEY_FILE</code> contains the mounted file path, not the key value.</p>
<h2 id="rotation-and-revocation">Rotation and revocation<a class="headerlink" href="#rotation-and-revocation" title="Permanent link">&para;</a></h2>
<p>During rotation, receive the new generation, update the vault or mounted file, and confirm
connectivity through the harmless <code>/rpc/ping</code> route. The server owner revokes the previous
generation only after this confirmation.</p>
<p>A <code>401</code> means the key is missing, unknown, expired, or revoked. A <code>503</code> means the authorization
service or registry is unavailable. In either case, do not bypass REST or weaken TLS verification.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../dwh-auth-tls/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../dwh-auth-tls/" class="btn btn-xs btn-link">
TLS
</a>
</div>
<div class="wm-article-nav">
<a href="../dwh-auth-server/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-server/" class="btn btn-xs btn-link">
Server
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>