Running IAM with Docker
This article explains how to get Airlock IAM up and running with Docker. The required IAM Docker image is pulled directly from the (private image respository) Quay.io and used locally.
To get you started quickly, the IAM image is initialized with the integrated H2 database. This database facilitates integration work and enables seamless use of the IAM demo configuration.
We recommend using the embedded H2 database only for demo and testing purposes. For production database use, see User data source configuration.
Prerequisites
- A Red Hat account (required for using Quay.io).
- Access to the https://quay.io/airlock/iam repository. For this, create a support case via the Techzone - Airlock support process page. Add your Red Hat account to your support ticket.
- Docker, for example Docker Desktop, must be installed and running.
- Have your Airlock IAM license available.
Getting IAM up and running with Docker
The following instructions help you getting IAM up and running with Docker, by creating and starting the default IAM instance auth.
The following instructions apply to the current IAM release version. To install a previous release, replace the current release number in the commands with the relevant one.
Perform the following steps:
- Use the Docker CLI to check that the Docker daemon is running:
- Log in to the Quay.io respository:
- Pull the IAM image from the https://quay.io/airlock/iam repository with the following command.
- Create a new local, empty directory, to store the Airlock IAM configuration files during the installation:
- Change to the new directory:
Linux
- When using native Docker on Linux, run the following commands to set the correct permissions:
- Create and start a new IAM instance named
authwith the following command. It starts the IAM container with required services and mounts the local configuration directory. Deep dive: Click the Show button in the box below to find out what the above command does (optional information).
- To monitor the startup of your container /
authIAM instance, use the following command (airlock-iamis the name of the container): - Terminal box
docker logs airlock-iam
- To monitor the startup of your container /
- You have now installed Airlock IAM locally with Docker as well as created and started the IAM instance
auth. - To view the available application parameters and their default values, run the following command:
- To check that the new IAM instance
authis up, running, and ready for use, enterhttps://localhost:8443/auth-admin/ui/app/loginin your browser. This will open the IAM Adminapp login page. Note that it may take some time before the application is available. - If the login page is unavailable or does not exist, the port
8443may already be in use by another application. Stop this application and try again.
- If the login page is unavailable or does not exist, the port
- If you see the login page, the setup was successful.
- Log in to the Adminapp and proceed with the next steps below.
- The initial Adminapp includes only the minimum required properties needed to access the Config Editor. It does not yet implement access control, so you can currently use any password to log in.
Next steps
After installing IAM, you need to
- Upload your Airlock IAM license into the Adminapp. See Upload a license.
- Choose and activate a suitable configuration template. See Choose a config template.
Advanced: Creating instances with different names
In the above instructions, we initiate and start the IAM instance auth in one, single step - without explicitly running the init command. This only works with the default IAM instance auth, and only when the instance has not been initialized yet (i.e., the directory /home/airlock/iam/instances does not yet exist). In this case, Docker automatically performs the init step itself before starting the instance.
However, IAM instances with another name must be explicitly initialized. In this case, perform the following steps:
- Initiate the instance by executing the following
initcommand: - Start this instance by running this command:
Further information and links
Internal links
- Obtaining the Docker image provides detailed information on obtaining a Docker image,
- either by pulling the image from the repository Quay.io, or
- by downloading it from the Airlock Techzone.
- Using the container image explains how to work with the IAM container after installation.
- Getting started after installation
- User data source configuration
- License and usage analytics
- Sandboxing with profiles