← Back to plugin index

Service Container

Description
The server component used to run services such as the RADIUS interface or the task scheduler.
Type name
ServiceContainer
Class
com.airlock.iam.servicecontainer.app.application.configuration.Server
Properties
Services (services)
Description
The list of services to run.
Attributes
Plugin-List
Optional
Assignable plugins
Outbox Repository (outboxRepository)
Description

Settings for the event outbox repository. If configured, all events are stored in an outbox database table until they have successfully been forwarded to a message broker.

If no outbox repository is configured, no events are stored. To forward events to a message broker, configure an Event Outbox Processor Service.

Currently, only the "Delete Users Task" and the "Lock Inactive Accounts Task" publish events

Attributes
Plugin-Link
Optional
Assignable plugins
User Store (userStore)
Description

User store to load context data values that are added as customData to the stored events. If not configured, no custom data is added to the events.

The data contains all context data values configured in this user store. Note that these values might contain sensitive information such as email addresses or phone numbers.

Attributes
Plugin-Link
Optional
Assignable plugins
Session Idle Timeout [m] (sessionTimeout)
Description
Session idle timeout of the service container UI in minutes.
Attributes
Integer
Optional
Default value
30
Statistics Log Interval [s] (statisticLogInterval)
Description
The server logs a line with statistic information periodically. This setting defines the amount of seconds between such logs.
Attributes
Integer
Optional
Default value
60
Minimum Threads (minimumThreads)
Description
Minimum number of threads in pool.
Attributes
Integer
Optional
Default value
10
Maximum Threads (maximumThreads)
Description
Maximum number of threads in pool.
Attributes
Integer
Optional
Default value
100
Service Container Shared Secret (serviceContainerSharedSecret)
Description
The service container secret is used to access the service container from the Adminapp. The shared secret will be used to encrypt the SSO ticket, sent from the Adminapp to the service container in order to authenticate the admin. The shared secret must be identical to the property Service Container Shared Secret in the Adminapp (Advanced Settings).
Attributes
String
Mandatory
Sensitive
Accepted SSO Tickets Repository (acceptedSsoTicketRepository)
Description

Configures the repository used to store accepted SSO tickets and reject previously accepted ones.

The in-memory repository cannot be used if multiple instances of IAM are deployed in parallel (failover, horizontal scaling). Furthermore, the in-memory repository does not preserve previously accepted SSO tickets across IAM restarts.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Log User Trail To Database (logUserTrailToDatabase)
Description

Configures the database settings to use when persisting user trail log entries.

If this value is defined, then all user trail log messages generated by the Service Container App module will additionally be forwarded to the database configured within the referenced repository plugin.

All forwarded log entries are stored inside the table "USER_TRAIL_LOG". Note that setting this value does not disable writing log messages to the Service Container App log file.

Attributes
Plugin-Link
Optional
Assignable plugins
Correlation ID Settings (correlationIdSettings)
Description

Defines settings for correlation ID transfer and logging inside the Service Container module.

If undefined, no correlation ID will be logged for this module.

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: ServiceContainer
id: ServiceContainer-xxxxxx
displayName: 
comment: 
properties:
  acceptedSsoTicketRepository:
  correlationIdSettings:
  logUserTrailToDatabase:
  maximumThreads: 100
  minimumThreads: 10
  outboxRepository:
  serviceContainerSharedSecret:
  services:
  sessionTimeout: 30
  statisticLogInterval: 60
  userStore: