Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SPSH-1137 #750

Merged
merged 37 commits into from
Nov 29, 2024
Merged
Show file tree
Hide file tree
Changes from 26 commits
Commits
Show all changes
37 commits
Select commit Hold shift + click to select a range
305d183
Implement VIDIS module/service to request VIDIS offers from VIDIS Off…
he-meyer Nov 11, 2024
6776041
Implement new mapping table between Organisation and ServiceProvider
he-meyer Nov 11, 2024
4608900
Implement logic to create or update ServiceProviders for VIDIS offers
he-meyer Nov 11, 2024
59ff21e
Implement cron job endpoint for VIDIS ServiceProvider update
he-meyer Nov 11, 2024
7728bcf
Merge branch 'main' into SPSH-1137
he-meyer Nov 11, 2024
822b7ec
Use faker in test
he-meyer Nov 11, 2024
001557b
Add VIDIS config keys
he-meyer Nov 11, 2024
86a693e
Add config keys for test
he-meyer Nov 11, 2024
073649c
Add dummy test data for config test
he-meyer Nov 11, 2024
3f7d879
Fix tests
he-meyer Nov 11, 2024
98d5604
Add tests
he-meyer Nov 11, 2024
ad617ca
Add keys
he-meyer Nov 12, 2024
0a2f74f
Add and adapt tests
he-meyer Nov 12, 2024
1736010
Change arguments to correct parameter order
he-meyer Nov 12, 2024
81c8598
Add permission check to cron controller endpoint
he-meyer Nov 12, 2024
a9e5a2a
Adapt tests
he-meyer Nov 12, 2024
bb9b893
Use root Organisation as schulstrukturknoten for VIDIS offers
he-meyer Nov 14, 2024
2d37c69
Externalize VIDIS related config
he-meyer Nov 14, 2024
c362052
Use MissingPermissionsError, remove no longer required CronJobError
he-meyer Nov 14, 2024
74d4993
Remove unnecessary import
he-meyer Nov 14, 2024
9987ab0
Rename variable
he-meyer Nov 14, 2024
1a04cdd
Rename test files
he-meyer Nov 14, 2024
86b1af4
Fix vidisConfig declaration
he-meyer Nov 14, 2024
1ed5157
Change findByName
he-meyer Nov 14, 2024
73ae7f9
Avoid try-catch
he-meyer Nov 15, 2024
5ca53ca
Fix check
he-meyer Nov 15, 2024
dfec33d
Merge branch 'main' of https://github.com/dBildungsplattform/dbildung…
he-meyer Nov 15, 2024
3e65e3b
Fix migration
he-meyer Nov 15, 2024
7fe62ba
Add or adapt logs
he-meyer Nov 20, 2024
a1f319c
Fix missing logging dependency for test
he-meyer Nov 20, 2024
5a02eb2
Add missing import of ClassLogger
he-meyer Nov 21, 2024
bbc6d16
Change from offer to Angebot
he-meyer Nov 22, 2024
52ff52c
Add logging
he-meyer Nov 22, 2024
3fb0121
Use existing method to retrieve Organisationen, remove unnecessary me…
he-meyer Nov 22, 2024
fdafd0c
Avoid magic numbers for media type file signatures
he-meyer Nov 22, 2024
678c038
Merge branch 'main' of https://github.com/dBildungsplattform/dbildung…
he-meyer Nov 25, 2024
fd15659
Merge branch 'main' of https://github.com/dBildungsplattform/dbildung…
he-meyer Nov 29, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 87 additions & 79 deletions charts/dbildungs-iam-server/config/config.json
Original file line number Diff line number Diff line change
@@ -1,81 +1,89 @@
{
"HOST": {
"PORT": 8080
},
"FRONTEND": {
"PORT": 8080,
"SECURE_COOKIE": true,
"SESSION_SECRET": "SessionSecretForDevelopment",
"SESSION_TTL_MS": 3600000,
"BACKEND_ADDRESS": "http://dbildungs-iam-server-backend:80",
"DEFAULT_AUTH_REDIRECT": "/",
"TRUST_PROXY": 1,
"ERROR_PAGE_REDIRECT": "/login-error"
},
"DB": {
"USE_SSL": true
},
"KEYCLOAK": {
"ADMIN_REALM_NAME": "SPSH",
"REALM_NAME": "SPSH",
"ADMIN_CLIENT_ID": "spsh-admin",
"CLIENT_ID": "spsh",
"TEST_CLIENT_ID": "spsh-test",
"SERVICE_CLIENT_ID": "spsh-service"
},
"REDIS": {
"HOST": "dbildungs-iam-server-redis-cluster",
"PORT": 6379,
"USERNAME": "default",
"PASSWORD": "",
"USE_TLS": false,
"CLUSTERED": true
},
"LDAP": {
"URL": "ldap://spsh-xxx.svc.cluster.local",
"BIND_DN": "cn=admin,dc=schule-sh,dc=de",
"ADMIN_PASSWORD": "password"
},
"DATA": {
"ROOT_ORGANISATION_ID": "d39cb7cf-2f9b-45f1-849f-973661f2f057"
},
"LOGGING": {
"DEFAULT_LOG_LEVEL": "info",
"PERSON_MODULE_LOG_LEVEL": "debug",
"PERSON_API_MODULE_LOG_LEVEL": "debug",
"ORGANISATION_MODULE_LOG_LEVEL": "debug",
"ORGANISATION_API_MODULE_LOG_LEVEL": "debug",
"ROLLE_MODULE_LOG_LEVEL": "debug",
"ROLLE_API_MODULE_LOG_LEVEL": "debug",
"KEYCLOAK_ADMINISTRATION_MODULE_LOG_LEVEL": "debug",
"HEALTH_MODULE_LOG_LEVEL": "debug",
"BACKEND_FOR_FRONTEND_MODULE_LOG_LEVEL": "debug"
},
"ITSLEARNING": {
"ENABLED": "false",
"ENDPOINT": "https://itslearning.example.com",
"USERNAME": "username",
"PASSWORD": "password",
"ROOT": "sh",
"ROOT_OEFFENTLICH": "oeffentlich",
"ROOT_ERSATZ": "ersatz"
},
"OX": {
"ENABLED": "false",
"ENDPOINT": "https://ox_ip:ox_port/webservices/OXUserService",
"CONTEXT_ID": "1337",
"CONTEXT_NAME": "contextname",
"USERNAME": "username",
"PASSWORD": "password"
},
"PRIVACYIDEA": {
"ENDPOINT": "http://localhost:5000",
"USERNAME": "admin",
"PASSWORD": "admin",
"USER_RESOLVER": "mariadb_resolver",
"REALM": "defrealm"
},
"IMPORT": {
"IMPORT_FILE_MAXGROESSE_IN_MB": 10
}
"HOST": {
"PORT": 8080
},
"FRONTEND": {
"PORT": 8080,
"SECURE_COOKIE": true,
"SESSION_SECRET": "SessionSecretForDevelopment",
"SESSION_TTL_MS": 3600000,
"BACKEND_ADDRESS": "http://dbildungs-iam-server-backend:80",
"DEFAULT_AUTH_REDIRECT": "/",
"TRUST_PROXY": 1,
"ERROR_PAGE_REDIRECT": "/login-error"
},
"DB": {
"USE_SSL": true
},
"KEYCLOAK": {
"ADMIN_REALM_NAME": "SPSH",
"REALM_NAME": "SPSH",
"ADMIN_CLIENT_ID": "spsh-admin",
"CLIENT_ID": "spsh",
"TEST_CLIENT_ID": "spsh-test",
"SERVICE_CLIENT_ID": "spsh-service"
},
"REDIS": {
"HOST": "dbildungs-iam-server-redis-cluster",
"PORT": 6379,
"USERNAME": "default",
"PASSWORD": "",
"USE_TLS": false,
"CLUSTERED": true
},
"LDAP": {
"URL": "ldap://spsh-xxx.svc.cluster.local",
"BIND_DN": "cn=admin,dc=schule-sh,dc=de",
"ADMIN_PASSWORD": "password"
},
"DATA": {
"ROOT_ORGANISATION_ID": "d39cb7cf-2f9b-45f1-849f-973661f2f057"
},
"LOGGING": {
"DEFAULT_LOG_LEVEL": "info",
"PERSON_MODULE_LOG_LEVEL": "debug",
"PERSON_API_MODULE_LOG_LEVEL": "debug",
"ORGANISATION_MODULE_LOG_LEVEL": "debug",
"ORGANISATION_API_MODULE_LOG_LEVEL": "debug",
"ROLLE_MODULE_LOG_LEVEL": "debug",
"ROLLE_API_MODULE_LOG_LEVEL": "debug",
"KEYCLOAK_ADMINISTRATION_MODULE_LOG_LEVEL": "debug",
"HEALTH_MODULE_LOG_LEVEL": "debug",
"BACKEND_FOR_FRONTEND_MODULE_LOG_LEVEL": "debug"
},
"ITSLEARNING": {
"ENABLED": "false",
"ENDPOINT": "https://itslearning.example.com",
"USERNAME": "username",
"PASSWORD": "password",
"ROOT": "sh",
"ROOT_OEFFENTLICH": "oeffentlich",
"ROOT_ERSATZ": "ersatz"
},
"OX": {
"ENABLED": "false",
"ENDPOINT": "https://ox_ip:ox_port/webservices/OXUserService",
"CONTEXT_ID": "1337",
"CONTEXT_NAME": "contextname",
"USERNAME": "username",
"PASSWORD": "password"
},
"PRIVACYIDEA": {
"ENDPOINT": "http://localhost:5000",
"USERNAME": "admin",
"PASSWORD": "admin",
"USER_RESOLVER": "mariadb_resolver",
"REALM": "defrealm"
},
"VIDIS": {
"BASE_URL": "https://service-stage.vidis.schule",
"USERNAME": "",
"PASSWORD": "",
"REGION_NAME": "test-region",
"KEYCLOAK_GROUP": "VIDIS-service",
"KEYCLOAK_ROLE": "VIDIS-user"
},
"IMPORT": {
"IMPORT_FILE_MAXGROESSE_IN_MB": 10
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -96,4 +96,34 @@
secretKeyRef:
name: {{ default .Values.auth.existingSecret .Values.auth.secretName }}
key: redis-password
- name: VIDIS_BASE_URL
valueFrom:
secretKeyRef:
name: {{ default .Values.auth.existingSecret .Values.auth.secretName }}
key: vidis-base-url
- name: VIDIS_USERNAME
valueFrom:
secretKeyRef:
name: {{ default .Values.auth.existingSecret .Values.auth.secretName }}
key: vidis-username
- name: VIDIS_PASSWORD
valueFrom:
secretKeyRef:
name: {{ default .Values.auth.existingSecret .Values.auth.secretName }}
key: vidis-password
- name: VIDIS_REGION_NAME
valueFrom:
secretKeyRef:
name: {{ default .Values.auth.existingSecret .Values.auth.secretName }}
key: vidis-region-name
- name: VIDIS_KEYCLOAK_GROUP
valueFrom:
secretKeyRef:
name: {{ default .Values.auth.existingSecret .Values.auth.secretName }}
key: vidis-keycloak-group
- name: VIDIS_KEYCLOAK_ROLE
valueFrom:
secretKeyRef:
name: {{ default .Values.auth.existingSecret .Values.auth.secretName }}
key: vidis-keycloak-role
{{- end}}
6 changes: 6 additions & 0 deletions charts/dbildungs-iam-server/templates/secret.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,4 +25,10 @@ data:
pi-rename-waiting-time: {{ .Values.auth.pi_rename_waiting_time }}
secrets-json: {{ .Values.auth.secrets_json }}
redis-password: {{ .Values.auth.redis_password }}
vidis-base-url: {{ .Values.auth.vidis_base_url }}
vidis-username: {{ .Values.auth.vidis_username }}
vidis-password: {{ .Values.auth.vidis_password }}
vidis-region-name: {{ .Values.auth.vidis_region_name }}
vidis-keycloak-group: {{ .Values.auth.vidis_keycloak_group }}
vidis-keycloak-role: {{ .Values.auth.vidis_keycloak_role }}
{{- end }}
33 changes: 19 additions & 14 deletions charts/dbildungs-iam-server/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,12 @@ auth:
pi_user_realm: ''
pi_rename_waiting_time: ''
redis_password: ''
vidis_base_url: ''
vidis_username: ''
vidis_password: ''
vidis_region_name: ''
vidis_keycloak_group: ''
vidis_keycloak_role: ''

backend:
replicaCount: 1
Expand Down Expand Up @@ -124,11 +130,10 @@ backend:
name: secret-volume
extraVolumeMounts: []


# Reference: https://github.com/bitnami/charts/tree/main/bitnami/redis-cluster
redis-cluster:
enabled: true
persistence:
persistence:
enabled: false
size: 4Gi
image:
Expand All @@ -137,14 +142,14 @@ redis-cluster:
tag: 7.4
existingSecret: dbildungs-iam-server-redis
cluster:
## This is total number of nodes including the replicas. Meaning there will be 3 master and 3 replica
## nodes (as replica count is set to 1 by default, there will be 1 replica per master node).
## Hence, nodes = numberOfMasterNodes + numberOfMasterNodes * replicas
## The number of master nodes should always be >= 3, otherwise cluster creation will fail
nodes: 6
# for staging and prod this could get increased
## @param cluster.replicas Number of replicas for every master in the cluster
replicas: 1
## This is total number of nodes including the replicas. Meaning there will be 3 master and 3 replica
## nodes (as replica count is set to 1 by default, there will be 1 replica per master node).
## Hence, nodes = numberOfMasterNodes + numberOfMasterNodes * replicas
## The number of master nodes should always be >= 3, otherwise cluster creation will fail
nodes: 6
# for staging and prod this could get increased
## @param cluster.replicas Number of replicas for every master in the cluster
replicas: 1
networkPolicy:
enabled: false
pdb:
Expand All @@ -155,9 +160,9 @@ redis-cluster:
tls:
enabled: false
podLabels:
app.kubernetes.io/component: server-redis
app.kubernetes.io/component: server-redis
commonLabels:
app.kubernetes.io/name: dbildungs-iam-server
app.kubernetes.io/name: dbildungs-iam-server
resources:
limits:
cpu: 300m
Expand All @@ -174,5 +179,5 @@ redis-cluster:
requests:
cpu: 50m
memory: 64Mi
serviceMonitor:
enabled: true
serviceMonitor:
enabled: true
8 changes: 8 additions & 0 deletions config/config.json
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,14 @@
"REALM": "defrealm",
"RENAME_WAITING_TIME_IN_SECONDS": 5
},
"VIDIS": {
"BASE_URL": "https://service-stage.vidis.schule",
"USERNAME": "username",
"PASSWORD": "password",
"REGION_NAME": "test-region",
"KEYCLOAK_GROUP": "VIDIS-service",
"KEYCLOAK_ROLE": "VIDIS-user"
},
"IMPORT": {
"IMPORT_FILE_MAXGROESSE_IN_MB": 10
}
Expand Down
Loading
Loading