← Back to plugin index

Gateway REST API Connection

Description
The connection details of an Airlock Gateway REST API. Connecting to the Gateway's REST API requires a valid API key which can be obtained from the Gateway's Configuration Center. Each Gateway has its own API key, it cannot be used for multiple connections. For security reasons, the gateway user, corresponding to the API token, should be configured to have minimal access rights. For this feature to work, only the following gateway endpoints need to be accessible.
  • /session/create
  • /session/terminate
  • /system/status/session
This can be achieved by configuring the user on the gateway similar to this:

user:airlockiam roles:airlock-administrator tenant: password:disabled readPaths:.*
writePaths:^\/session\/(create|terminate)$|^\/system\/status\/sessions\/.*$

Additionally, IAM needs HTTP(S) access to the Gateway's REST API which may not always be the case, depending on the network topology.
Type name
GatewayRestApiConnection
Class
com.airlock.iam.common.application.configuration.event.GatewayRestApiConnectionConfig
May be used by
Properties
URL (url)
Description
The base URL of the Airlock Gateway's REST API. It normally is accessible at https://<airlock-gateway>/airlock/rest. Firewall rules may have to be adapted accordingly so IAM can connect to this URL.
Attributes
String
Mandatory
Example
https://gateway.mycompany.com/airlock/rest/
HTTP Client (httpClient)
Description
The HTTP Client used to connect to the Gateway's REST API. The Gateway's API key must be configured as the HTTP Client's bearer token. It can be obtained from the Gateway's Configuration Center.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)

type: GatewayRestApiConnection
id: GatewayRestApiConnection-xxxxxx
displayName: 
comment: 
properties:
  httpClient:
  url: