IAM appliance - iam-app-web-proxy

RPM package with a central web proxy for the appliance’s containerized services. The proxy is implemented by the nGinx service, behind which all other services with a web interface are hidden - IdM, CAS, etc.

The package is a direct part of the appliance. Proxy pass is configured at the level of the internal DNS name of the container running the given application.

Nginx also works as a web server for static files for CAS, the frontpage and other services at the URL /static/. Static files can be modified (logo change, CSS color change) in the appliance at /data/volumes-shared/web-proxy-static/…​ .

Contains basic support for LE certificates (serving challenges, directories). The certificates themselves and the logic of their operation are provided by the iam-letsencrypt-support package, which supplies them to the proxy.

  • Contains ModSecurity (intentionally) running in DetectionOnly mode. These will be changed later - around 02-03/2027.

The build is performed the standard way in the bcv-rpmbuild container.

Service

The container used is repo.iamappliance.com:8443/bcv-nginx-modsec:1.26.3-3-deb13u9-r0. In the appliance, the service is known as iam-web-proxy.

Directories on the appliance disk

  • /data/volumes/web-proxy/config - web proxy configuration, some files supplied by this RPM package

  • /data/volumes/web-proxy/secrets - HTTPS certificate and key

  • /data/volumes/web-proxy/frontpage - index.html for displaying the landing page

  • /data/volumes/web-proxy/letsencrypt - empty directory structure from which LE challenges are served

  • /data/volumes-shared/web-proxy-static - static CSS, JS and image files, split into directories by service

  • /data/logs/web-proxy - logs

    • This directory must have correct SELinux labels; the RPM package takes care of this during installation by calling semanage fcontext …​.

Configuration files

  • /data/registry/node-active-config/docker-compose-web-proxy.yml - container configuration

  • /etc/rsyslog.d/10_web-proxy.conf - diverts logs from syslog into a dedicated file on disk

  • /etc/logrotate.d/web-proxy - log rotation configuration

Control

  • The systemd unit is located at /usr/lib/systemd/system/iam-web-proxy.service; control it the usual way via systemctl start/stop/enable/disable.

  • Starting the unit actually calls docker-compose …​ up, which, if the compose file has changed, immediately drops the container and creates a new one.

Dependencies

  • The service has no dependencies for its installation.

  • The service has no dependencies for its operation.