Use cases

This section provides some use cases when working with Docker Airlock IAM images.

Quick start with docker-compose.yml

The Running IAM with Docker describes how to get Airlock IAM up and running with Docker when using the Docker CLI. However, the same goal can be achieved with the docker-compose.yml file.

See the example below. It corresponds with step 6 in the installation instructions.

 
Terminal box
version: '3.7'
services:
  iam:
    image: quay.io/airlock/iam:8.7
environment: - "TZ=Europe/Zurich" - "IAM_LOG_LEVEL=DEBUG" - "IAM_MODULES=adminapp,loginapp,transaction-approval,api-policy-service,service-container,h2" volumes: - type: bind source: "./iam" target: "/home/airlock/iam" ports: - "8443:8443"

Docker stack

Docker Compose files can also be used in swarm cluster environments.

The following example uses Docker volumes, profiles, secrets and limit the resources to deploy Adminapp and Loginapp as separate containers.

 
Notice

The option -XX:MaxRAMPercentage relates the container memory available to the JVM for the heap to the total amount of container memory.

Do not to set the value of -XX:MaxRAMPercentage too high
If the JVM and additional processes running in the container (e.g., docker exec) exceed the container's memory limit, the container may be killed.

This template can be used with “docker stack”:

docker-compose.yml

 
Example
version: '3.7'
services:
  loginapp:
    image: "${IAM_IMAGE}" # Use container image from local environment variable
    read_only: true
    volumes:
      - type: volume
        source: "airlock_iam_config"
        target: "/home/airlock/iam"
      - type: tmpfs
        target: "/home/airlock/work"
    environment:
      - "TZ=Europe/Zurich"
      - "IAM_JAVA_OPTS=-XX:MaxRAMPercentage=50"
      - "IAM_MODULES=loginapp"
      - "IAM_SENSITIVE_VALUES_CONFIG=/run/secrets/airlock_iam_secrets"
      - "IAM_LICENSE=/run/secrets/airlock_iam_license"
    ports:
      - "8443"
    deploy:
      resources:
        limits:
          memory: "4G"
  adminapp:
    image: "${IAM_IMAGE}"
    read_only: true
    volumes:
      - type: volume
        source: "airlock_iam_config"
        target: "/home/airlock/iam"
      - type: tmpfs
        target: "/home/airlock/work"
    environment:
      - "TZ=Europe/Zurich"
      - "IAM_JAVA_OPTS=-XX:MaxRAMPercentage=50"
      - "IAM_MODULES=adminapp,service-container"
      - "IAM_SENSITIVE_VALUES_CONFIG=/run/secrets/airlock_iam_secrets"
      - "IAM_LICENSE=/run/secrets/airlock_iam_license"
    ports:
      - "8443"
    deploy:
      resources:
        limits:
          memory: "2G"

volumes:
  airlock_iam_config:
    external: true

secrets:
  airlock_iam_secrets:
    external: true
  airlock_iam_license:
    external: true

Custom images

Custom Docker images can be created based on the official Airlock IAM image. See https://docs.docker.com/engine/reference/builder/.

Docker file

 
Example
FROM quay.io/airlock/iam:8.7 
# Uncomment if you need to initialize a default config root directory
#RUN /opt/airlock-iam/bin/iam init

# Copy a prepared config root directory
COPY --chown=1000:0 ./config/ /home/airlock/iam/

ENV TZ="Europe/Zurich"

CMD ["run", "--profile", "integration"]