Running IAM with Docker

This article explains how to get Airlock IAM up and running with Docker. The required IAM Docker image is pulled directly from the (private image respository) Quay.io and used locally.

To get you started quickly, the IAM image is initialized with the integrated H2 database. This database facilitates integration work and enables seamless use of the IAM demo configuration.

 
Notice

We recommend using the embedded H2 database only for demo and testing purposes. For production database use, see User data source configuration.

Prerequisites

Getting IAM up and running with Docker

The following instructions help you getting IAM up and running with Docker, by creating and starting the default IAM instance auth.

 
Notice

The following instructions apply to the current IAM release version. To install a previous release, replace the current release number in the commands with the relevant one.

Perform the following steps:

  1. Use the Docker CLI to check that the Docker daemon is running:
  2.  
    Terminal box
    docker info
  3. Log in to the Quay.io respository:
  4.  
    Terminal box
    docker login quay.io
  5. Pull the IAM image from the https://quay.io/airlock/iam repository with the following command.
  6.  
    Terminal box
    docker pull quay.io/airlock/iam:8.7
  7. Create a new local, empty directory, to store the Airlock IAM configuration files during the installation:
  8.  
    Terminal box
    mkdir -p ~/airlock-iam-docker
  9. Change to the new directory:
  10.  
    Terminal box
    cd ~/airlock-iam-docker
  11. Linux

    • When using native Docker on Linux, run the following commands to set the correct permissions:
    •  
      Terminal box
      mkdir -p "$(pwd)/iam" && sudo chown -R 1000:0 "$(pwd)/iam"
  12. Create and start a new IAM instance named auth with the following command. It starts the IAM container with required services and mounts the local configuration directory.
  13.  
    Terminal box
    docker run --rm \
    --name airlock-iam \
    --env "TZ=Europe/Zurich" \
    --env "IAM_LOG_LEVEL=DEBUG" \
    --env "IAM_ANALYTICS_MODE=LICENSE_DATA" \
    --env "IAM_MODULES=adminapp,loginapp,transaction-approval,api-policy-service,service-container,h2" \
    -v "$(pwd)/iam:/home/airlock/iam" \
    -p 8443:8443 \
    quay.io/airlock/iam:8.7
  14. Deep dive: Click the Show button in the box below to find out what the above command does (optional information).

  15.  
    Info

    Folder structure

    • It creates an iam folder and subfolders inside your local airlock-iam-docker directory. The iam folder will contain all locally created IAM instances.
    • This also includes the auth instance folder with corresponding configuration files: $CUSTOM_DIRECTORY/airlock-iam-docker/iam/instances/auth.

    Volume mounting

    • The expression “$(pwd)/iam:/home/airlock/iam” is a Docker volume mount. It maps your local iam folder and subfolders to the /home/airlock/iam directory inside the Docker container. As a result, any changes you make locally will instantly appear inside the container at /home/airlock/iam.
    • “$(pwd)” means “print working directory”. You must run this command from your local airlock-iam-docker folder. Otherwise, Docker will mount the wrong local path and the setup will not work correctly.

    Environment variables

    • The command initiates and starts the auth instance based on the following environment variables:

    • --env “TZ=Europe/Zurich” : Sets the timezone to Europe/Zurich.
    • --env “IAM_LOG_LEVEL=DEBUG” : Sets the log level to “debug”.
    • --env “IAM_ANALYTICS_MODE=LICENSE_DATA”: Initializes the IAM license analytics configuration. Starting with IAM 8.5, the IAM license and analytics feature is mandatory. If it is not configured, configuration activation will fail. For more information, see License and usage analytics.
    • --env “IAM_MODULES=...” : Enables the required IAM components. Here, the Adminapp, Loginapp, Transaction Approval modules, the API Policy Service and the Service Container, as well as the embedded H2 database are enabled.

    Other settings

    • --name assigns a name to the Docker container with the IAM instance. Here, the assigned name is airlock-iam. Without this, Docker will generate a random name for the container.
    • 8443:8443 maps your local port https://localhost:8443 to the Docker container port 8443, and thus exposes the IAM web interface to your browser.
    • To monitor the startup of your container / auth IAM instance, use the following command (airlock-iam is the name of the container):
    •  
      Terminal box
      docker logs airlock-iam
  16. You have now installed Airlock IAM locally with Docker as well as created and started the IAM instance auth.
    • To view the available application parameters and their default values, run the following command:
    •  
      Terminal box
      docker run --rm quay.io/airlock/iam:8.7 default-parameters
  17. To check that the new IAM instance auth is up, running, and ready for use, enter https://localhost:8443/auth-admin/ui/app/login in your browser. This will open the IAM Adminapp login page. Note that it may take some time before the application is available.
    • If the login page is unavailable or does not exist, the port 8443 may already be in use by another application. Stop this application and try again.
  18. If you see the login page, the setup was successful.
  19. Log in to the Adminapp and proceed with the next steps below.
    • The initial Adminapp includes only the minimum required properties needed to access the Config Editor. It does not yet implement access control, so you can currently use any password to log in.

Next steps

After installing IAM, you need to

Advanced: Creating instances with different names

In the above instructions, we initiate and start the IAM instance auth in one, single step - without explicitly running the init command. This only works with the default IAM instance auth, and only when the instance has not been initialized yet (i.e., the directory /home/airlock/iam/instances does not yet exist). In this case, Docker automatically performs the init step itself before starting the instance.

However, IAM instances with another name must be explicitly initialized. In this case, perform the following steps:

  1. Initiate the instance by executing the following init command:
  2.  
    Terminal box
    docker run --rm \
    -v "$(pwd)/iam:/home/airlock/iam" \
    quay.io/airlock/iam:8.7 \
    init --instance <instance-name> --analytics LICENSE_DATA
  3. Start this instance by running this command:
  4.  
    Terminal box
    docker run --rm \
    --name airlock-iam \
    --env "TZ=Europe/Zurich" \
    --env "IAM_LOG_LEVEL=DEBUG" \
    --env "IAM_MODULES=adminapp,loginapp,transaction-approval,api-policy-service,service-container,h2" \
    -v "$(pwd)/iam:/home/airlock/iam" \
    -p 8443:8443 \
    quay.io/airlock/iam:8.7 \
    run --instance <instance-name>
    

Further information and links

Internal links