IAM appliance - iam-app-web-proxy
RPM package with a central web proxy for the appliance’s containerized services. The proxy is implemented by the nGinx service, behind which all other services with a web interface are hidden - IdM, CAS, etc.
The package is a direct part of the appliance. Proxy pass is configured at the level of the internal DNS name of the container running the given application.
Nginx also works as a web server for static files for CAS, the frontpage and other services at the URL /static/. Static files can be modified (logo change, CSS color change) in the appliance at /data/volumes-shared/web-proxy-static/… .
Contains basic support for LE certificates (serving challenges, directories). The certificates themselves and the logic of their operation are provided by the iam-letsencrypt-support package, which supplies them to the proxy.
|
The build is performed the standard way in the bcv-rpmbuild container.
Service
The container used is repo.iamappliance.com:8443/bcv-nginx-modsec:1.26.3-3-deb13u9-r0. In the appliance, the service is known as iam-web-proxy.
Directories on the appliance disk
-
/data/volumes/web-proxy/config- web proxy configuration, some files supplied by this RPM package -
/data/volumes/web-proxy/secrets- HTTPS certificate and key -
/data/volumes/web-proxy/frontpage- index.html for displaying the landing page -
/data/volumes/web-proxy/letsencrypt- empty directory structure from which LE challenges are served -
/data/volumes-shared/web-proxy-static- static CSS, JS and image files, split into directories by service -
/data/logs/web-proxy- logs-
This directory must have correct SELinux labels; the RPM package takes care of this during installation by calling
semanage fcontext ….
-
Configuration files
-
/data/registry/node-active-config/docker-compose-web-proxy.yml- container configuration -
/etc/rsyslog.d/10_web-proxy.conf- diverts logs from syslog into a dedicated file on disk -
/etc/logrotate.d/web-proxy- log rotation configuration
Control
-
The systemd unit is located at
/usr/lib/systemd/system/iam-web-proxy.service; control it the usual way viasystemctl start/stop/enable/disable. -
Starting the unit actually calls
docker-compose … up, which, if the compose file has changed, immediately drops the container and creates a new one.