Bootstrapping a configuration in Realms mode
After successfully switching your IAM instance in Realms mode, you can start creating your realm environment. This includes:
- Initial bootstrapping of the Realm Management functionality.
- Setting up your realm environment.
Both steps are explained below.
Initial bootstrapping
The initial bootstrapping of the Realm Management functionality is done by the superadmin user who can create any realm or realm role. This superadmin user was created during the setup of IAM in Realms mode, see Configuration of realm-based access control.
- Log in to the Adminapp with the superadmin user created when configuring the Realms mode.
- Click Realm Management in the navigation menu at the left hand side. In the Realm Management dialog, select the Realm Roles tab.
- Click Create Role to create the first realm role. This role will be a root role, as it has no parent role. Call this role “admin”.
- In the Create Realm Role window:
- Leave the Parent Role field unchanged. Because this is the first role, there is no parent role yet.
- Enter
adminin the Role Name field. - Click Create to create the role.
- Select the Delegations tab, to create a first delegation for the “admin” role, including all permissions. Click Create Delegation.
- In the Create Delegation window:
- Select the admin role. Click Next.
- Delegations connect roles with permissions and realms. In this step, your first realm is created. Select Create new realm... and enter
admin-realmin the New realm name field. Click Next. - The next dialog lists all available permissions. Select all permissions. Click Next.
- You created the first delegation. This delegation assigns all available permissions to the “admin” role for the “admin-realm” realm. It allows a user holding the “admin” role to perform all actions on all users belonging to the “admin-realm” realm.
- Reload the Adminapp UI so that the new permissions are applied to the current session.
- The Users management section will now appear. This is because:
- You assigned the “admin” role to the superadmin user when configuring realm administration (see Step 2c: Create a superadmin user).
- With the delegation created above, you gave the “admin” role the permissions required to access the Users management.
- You can now create the first “regular” admin user. This user will be part of the currently only available realm “admin-realm”.
- In the Users dialog, click Create User.
- In the Create User window,
- Username field: Enter a suitable username.
- First Name field: Enter the admin user's first name.
- Last Name field: Enter the admin user's last name.
- Realm drop-down list: Enter
admin-realm - Click OK.
- Return to the Users dialog and select the Profile tab.
- Assign the new user the “admin” role by selecting admin from the Available roles list and moving it to the Active Roles list. Click Save.
- Select the Password tab, go to the Set new password section and create an initial password for the user. This password must be changed by the user the next time they log in.
- You have now completed the bootstrapping of the IAM instance in Realms mode. You can now set up your realm administration environment. Continue with the section below.
Set up realm administration environment
Next, configure your realm administration environment. This includes:
In the IAM configuration (Config Editor):
- Create a new global user role to perform the realm management. This user role is required for a user who must be able to manage the realms (create realms, create realm roles, create and edit delegations).
- Create other new global user roles if required.
- Assign the above new user role to the global Realm Management actions.
- Assign suitable other user roles to the other global actions (such as Authentication Token Management, Configuration Management).
In the Adminapp (Realm Management functionality):
- Define all required realms, realm roles and delegations
- Create the necessary admin users (e.g., helpdesk users and user admins)
- Give them the corresponding realm roles
The Use case - Set up a realm administration illustrates the configuration of a Realms environment with two realms.