Airlock Microgateway for Airlock IAM configuration

One primary use case for Airlock Microgateway is to protect applications such as Airlock IAM against attacks.

For Airlock IAM to operate correctly, it requires information about the connection between the browser (or another HTTP client) and the first server-side HTTP endpoint. This includes the client IP address, URL path, and client certificate.

In an Airlock Microgateway deployment, this connection information may be provided by a load balancer, an ingress controller, or Microgateway itself. It must be collected at the point in the network architecture where the TLS connection is terminated and forwarded in the appropriate format so that Airlock Microgateway and Airlock IAM can process it correctly.

Procedure-related prerequisites

Supported Features

Airlock IAM supports the following features when used with Microgateway.

  • Configuration of the following HTTP header extractors:
    • HTTP Request Client IP Extractor is used by IAM in risk-based authentication and for logging purposes.
    • HTTP Request ID Extractor is used by IAM for log correlation purposes.
    • HTTP Request URL Extractor is used by IAM to create URLs, e.g., in OAuth 2.0 redirects and REST responses.
    • HTTP Request mTLS Client Certificate Extractor is used by IAM to verify the client, e.g., in OAuth 2.0. It is used in OAuth/OIDC use cases and to authenticate REST requests sent to IAM REST APIs. PEM and XFCC formats are supported – for more information, see the IAM plugin documentation.
  • CSRF protection, as provided by Microgateway, can be used with Airlock IAM.

The following features are handled by Airlock IAM independent of Microgateway:

  • Session Idle Timeout and Session Lifetime are configured for Loginapp and Adminapp and enforced by IAM locally. These timeouts are synchronized across IAM instances if used with the Redis session store.
  •  
    Info

    In setups with Airlock Gateway, session idle timeout and session lifetimes are enforced by the Gateway using the values configured in the Gateway.

    When migrating from a Gateway to a Microgateway setup, verify the configuration of session idle timeout and session lifetime in Airlock IAM.

The following context extractors are supported if IAM is used behind an Airlock Microgateway:

  • Client Certificate Context Extractor
  • IP Address Context Extractor
  • URL Context Extractor
  • Static Context Extractor
  • HTTP Parameter Context Extractor
  • Combining Context Extractor (as long as only extractors from this list are used)
  • Concatenating Context Extractor (as long as only extractors from this list are used)
  • No Context Extractor
  • Currently, only the above-listed types of context extractors are supported. However, future versions may include additional context extractors.

Configure Airlock IAM for Microgateway

By default, Airlock IAM is configured to run behind an Airlock Gateway. To use Airlock IAM with the Airlock Microgateway, perform the following steps:

  1. Go to:
    Loginapp
  2. In the Basic Settings section, Gateway Settings property, add an Airlock Microgateway Settings plugin.
  3. Go to:
    Adminapp
  4. In the Basic Settings section, Gateway Settings property, add an Airlock Microgateway Settings plugin.

The Airlock Microgateway Settings plugin is automatically configured for Airlock Microgateway.

Microgateway configuration

To configure the Microgateway, a Helm Chart is provided. The Helm Chart can be obtained from Quay.io: Microgateway Helm Chart for IAM.

Further information and links

External links: