Compare commits
5
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8ab38e2816 | ||
|
|
eb1ede4f0c | ||
|
|
4cc2d9ac80 | ||
|
|
421683115c | ||
|
|
bfa4d5ba85 |
@@ -19,9 +19,5 @@ COPY --from=build /src/dist/apps/behandel/browser /usr/share/nginx/html
|
|||||||
# Compose-time OIDC config: the browser (Playwright, on the compose network) reaches Keycloak by
|
# Compose-time OIDC config: the browser (Playwright, on the compose network) reaches Keycloak by
|
||||||
# service name, so the token issuer matches the BFF's medewerker authority (host-consistent, ADR-0013).
|
# service name, so the token issuer matches the BFF's medewerker authority (host-consistent, ADR-0013).
|
||||||
RUN printf '{ "authority": "http://keycloak:8080/realms/medewerker" }\n' > /usr/share/nginx/html/config.json
|
RUN printf '{ "authority": "http://keycloak:8080/realms/medewerker" }\n' > /usr/share/nginx/html/config.json
|
||||||
# Make the reverse-proxy resolver engine-portable (Docker 127.0.0.11 vs podman aardvark); runs from
|
|
||||||
# the nginx image's /docker-entrypoint.d before nginx starts.
|
|
||||||
COPY apps/portal-nginx-resolver.sh /docker-entrypoint.d/40-resolver.sh
|
|
||||||
RUN chmod +x /docker-entrypoint.d/40-resolver.sh
|
|
||||||
|
|
||||||
EXPOSE 80
|
EXPOSE 80
|
||||||
|
|||||||
@@ -17,9 +17,5 @@ FROM nginx:1.27-alpine AS runtime
|
|||||||
COPY apps/openbaar/nginx.conf /etc/nginx/conf.d/default.conf
|
COPY apps/openbaar/nginx.conf /etc/nginx/conf.d/default.conf
|
||||||
COPY --from=build /src/dist/apps/openbaar/browser /usr/share/nginx/html
|
COPY --from=build /src/dist/apps/openbaar/browser /usr/share/nginx/html
|
||||||
# No runtime config: the openbaar register is anonymous (no OIDC authority to inject).
|
# No runtime config: the openbaar register is anonymous (no OIDC authority to inject).
|
||||||
# Make the reverse-proxy resolver engine-portable (Docker 127.0.0.11 vs podman aardvark); runs from
|
|
||||||
# the nginx image's /docker-entrypoint.d before nginx starts.
|
|
||||||
COPY apps/portal-nginx-resolver.sh /docker-entrypoint.d/40-resolver.sh
|
|
||||||
RUN chmod +x /docker-entrypoint.d/40-resolver.sh
|
|
||||||
|
|
||||||
EXPOSE 80
|
EXPOSE 80
|
||||||
|
|||||||
@@ -1,17 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
# Point nginx's reverse-proxy `resolver` at THIS container's real DNS server.
|
|
||||||
#
|
|
||||||
# The portal nginx configs use a variable proxy_pass, which needs a `resolver` so the BFF hostname is
|
|
||||||
# resolved at request time (nginx can start before the BFF is up). The config hardcodes Docker's
|
|
||||||
# embedded DNS (127.0.0.11) — correct on Docker/Docker Desktop, but rootless podman uses a
|
|
||||||
# network-specific address (aardvark, e.g. 10.89.0.1), so proxied calls 502 there. Read the actual
|
|
||||||
# nameserver from /etc/resolv.conf and substitute it, so the reverse proxy works on any engine.
|
|
||||||
#
|
|
||||||
# Runs from the nginx image's /docker-entrypoint.d/ before nginx starts. On Docker the nameserver IS
|
|
||||||
# 127.0.0.11, so the substitution is a no-op. Guarded (no `set -e`) so it's safe whether the nginx
|
|
||||||
# entrypoint executes or sources it.
|
|
||||||
ns="$(awk '/^nameserver/{print $2; exit}' /etc/resolv.conf 2>/dev/null)"
|
|
||||||
if [ -n "$ns" ] && [ "$ns" != "127.0.0.11" ]; then
|
|
||||||
sed -i "s/resolver 127\.0\.0\.11/resolver $ns/" /etc/nginx/conf.d/default.conf 2>/dev/null || true
|
|
||||||
echo "portal-nginx-resolver: set resolver to $ns"
|
|
||||||
fi
|
|
||||||
@@ -19,9 +19,5 @@ COPY --from=build /src/dist/apps/self-service/browser /usr/share/nginx/html
|
|||||||
# Compose-time OIDC config: the browser (Playwright, on the compose network) reaches Keycloak by
|
# Compose-time OIDC config: the browser (Playwright, on the compose network) reaches Keycloak by
|
||||||
# service name, so the token issuer matches the BFF's authority (host-consistent, ADR-0010).
|
# service name, so the token issuer matches the BFF's authority (host-consistent, ADR-0010).
|
||||||
RUN printf '{ "authority": "http://keycloak:8080/realms/digid" }\n' > /usr/share/nginx/html/config.json
|
RUN printf '{ "authority": "http://keycloak:8080/realms/digid" }\n' > /usr/share/nginx/html/config.json
|
||||||
# Make the reverse-proxy resolver engine-portable (Docker 127.0.0.11 vs podman aardvark); runs from
|
|
||||||
# the nginx image's /docker-entrypoint.d before nginx starts.
|
|
||||||
COPY apps/portal-nginx-resolver.sh /docker-entrypoint.d/40-resolver.sh
|
|
||||||
RUN chmod +x /docker-entrypoint.d/40-resolver.sh
|
|
||||||
|
|
||||||
EXPOSE 80
|
EXPOSE 80
|
||||||
|
|||||||
@@ -17,12 +17,7 @@
|
|||||||
#
|
#
|
||||||
# Port map (host):
|
# Port map (host):
|
||||||
# 8000 OpenZaak · 8001 Open Notificaties · 8080 BFF · 8090 Flowable REST
|
# 8000 OpenZaak · 8001 Open Notificaties · 8080 BFF · 8090 Flowable REST
|
||||||
# 8100 ACL · 8130 Domain · 8180 Keycloak (all admin: admin / admin — dev only)
|
# 8100 ACL · 8180 Keycloak (all admin: admin / admin — dev only)
|
||||||
# 8140 self-service portal · 8141 openbaar register · 8142 behandel portal
|
|
||||||
#
|
|
||||||
# Portal OIDC on the HOST: browse the portals at their 8140/8141/8142 ports and log in via
|
|
||||||
# Keycloak on localhost:8180 (KC_HOSTNAME below pins the issuer there; the BFF still validates
|
|
||||||
# in-network via keycloak:8080). Test users are in docs/synthetic-data.md.
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
|
|
||||||
@@ -210,12 +205,6 @@ services:
|
|||||||
KEYCLOAK_ADMIN_PASSWORD: admin
|
KEYCLOAK_ADMIN_PASSWORD: admin
|
||||||
KC_HEALTH_ENABLED: "true"
|
KC_HEALTH_ENABLED: "true"
|
||||||
KC_HTTP_ENABLED: "true"
|
KC_HTTP_ENABLED: "true"
|
||||||
# Pin the frontend/issuer URL to the host-published address so a browser on the host and the
|
|
||||||
# tokens it gets both use localhost:8180. KC_HOSTNAME_BACKCHANNEL_DYNAMIC lets in-network
|
|
||||||
# callers (the BFF via keycloak:8080) still resolve token/jwks endpoints to their request host,
|
|
||||||
# so the BFF validates the localhost:8180 issuer while fetching keys over the compose network.
|
|
||||||
KC_HOSTNAME: http://localhost:8180
|
|
||||||
KC_HOSTNAME_BACKCHANNEL_DYNAMIC: "true"
|
|
||||||
ports:
|
ports:
|
||||||
- "8180:8080"
|
- "8180:8080"
|
||||||
volumes:
|
volumes:
|
||||||
@@ -306,14 +295,6 @@ services:
|
|||||||
context: ../services/bff
|
context: ../services/bff
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
image: register-referentie/bff:dev
|
image: register-referentie/bff:dev
|
||||||
environment:
|
|
||||||
# Reach Keycloak over the compose network for metadata/keys; the discovered issuer is the
|
|
||||||
# host-pinned localhost:8180 (KC_HOSTNAME above), which is what browser tokens carry — so
|
|
||||||
# validation matches without the BFF ever needing to resolve localhost:8180 itself.
|
|
||||||
Keycloak__Authority: http://keycloak:8080/realms/digid
|
|
||||||
Keycloak__MedewerkerAuthority: http://keycloak:8080/realms/medewerker
|
|
||||||
Downstream__Domain__BaseUrl: http://domain:8080/
|
|
||||||
Downstream__Projection__BaseUrl: http://projection-api:8080/
|
|
||||||
ports:
|
ports:
|
||||||
- "8080:8080"
|
- "8080:8080"
|
||||||
healthcheck:
|
healthcheck:
|
||||||
@@ -322,39 +303,6 @@ services:
|
|||||||
timeout: 3s
|
timeout: 3s
|
||||||
retries: 5
|
retries: 5
|
||||||
start_period: 10s
|
start_period: 10s
|
||||||
depends_on:
|
|
||||||
domain:
|
|
||||||
condition: service_healthy
|
|
||||||
projection-api:
|
|
||||||
condition: service_healthy
|
|
||||||
keycloak:
|
|
||||||
condition: service_started
|
|
||||||
networks: [cg]
|
|
||||||
|
|
||||||
# ── BIG Domain Service (S-05) ─────────────────────────────────────────────
|
|
||||||
domain:
|
|
||||||
build:
|
|
||||||
context: ../services/domain
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
image: register-referentie/domain:dev
|
|
||||||
environment:
|
|
||||||
Flowable__BaseUrl: http://flowable-rest:8080/flowable-rest/
|
|
||||||
Flowable__Username: rest-admin
|
|
||||||
Flowable__Password: test
|
|
||||||
Acl__BaseUrl: http://acl:8080/
|
|
||||||
ports:
|
|
||||||
- "8130:8080"
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD", "curl", "-fsS", "http://localhost:8080/health"]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 3s
|
|
||||||
retries: 5
|
|
||||||
start_period: 10s
|
|
||||||
depends_on:
|
|
||||||
acl:
|
|
||||||
condition: service_healthy
|
|
||||||
flowable-init:
|
|
||||||
condition: service_completed_successfully
|
|
||||||
networks: [cg]
|
networks: [cg]
|
||||||
|
|
||||||
# ── Read projection (S-06) ────────────────────────────────────────────────
|
# ── Read projection (S-06) ────────────────────────────────────────────────
|
||||||
@@ -380,10 +328,6 @@ services:
|
|||||||
image: register-referentie/event-subscriber:dev
|
image: register-referentie/event-subscriber:dev
|
||||||
environment:
|
environment:
|
||||||
ConnectionStrings__Projection: Host=projection-db;Database=projection;Username=projection;Password=projection
|
ConnectionStrings__Projection: Host=projection-db;Database=projection;Username=projection;Password=projection
|
||||||
# The subscriber enriches the projection with each zaak's reference by asking the ACL — the only
|
|
||||||
# code allowed to read ZGW (§8.1, #78). Required: startup throws without it (parity with the
|
|
||||||
# canonical compose).
|
|
||||||
Acl__BaseUrl: http://acl:8080/
|
|
||||||
EventSubscriber__Webhook__AuthToken: ${NOTIFICATION_WEBHOOK_TOKEN:-Bearer big-reference-notifications}
|
EventSubscriber__Webhook__AuthToken: ${NOTIFICATION_WEBHOOK_TOKEN:-Bearer big-reference-notifications}
|
||||||
ports:
|
ports:
|
||||||
- "8110:8080"
|
- "8110:8080"
|
||||||
@@ -396,8 +340,6 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
projection-db:
|
projection-db:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
acl:
|
|
||||||
condition: service_healthy
|
|
||||||
networks: [cg]
|
networks: [cg]
|
||||||
|
|
||||||
projection-api:
|
projection-api:
|
||||||
@@ -420,73 +362,6 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
networks: [cg]
|
networks: [cg]
|
||||||
|
|
||||||
# ── Portals (S-08/S-09/S-12) ──────────────────────────────────────────────
|
|
||||||
# nginx serves each Angular app and reverse-proxies its endpoint group to the BFF (same-origin).
|
|
||||||
# The images bake config.json with the compose authority (keycloak:8080), which a HOST browser
|
|
||||||
# can't resolve — so here we bind-mount a config.json pointing at the host-published localhost:8180
|
|
||||||
# (matching KC_HOSTNAME). openbaar is anonymous and needs no config.
|
|
||||||
self-service:
|
|
||||||
build:
|
|
||||||
context: ..
|
|
||||||
dockerfile: apps/self-service/Dockerfile
|
|
||||||
image: register-referentie/self-service:dev
|
|
||||||
ports:
|
|
||||||
- "8140:80"
|
|
||||||
volumes:
|
|
||||||
- ./local-config/self-service.config.json:/usr/share/nginx/html/config.json:ro,z
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD-SHELL", "wget -q -O /dev/null http://127.0.0.1/ || exit 1"]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 3s
|
|
||||||
retries: 5
|
|
||||||
start_period: 10s
|
|
||||||
depends_on:
|
|
||||||
bff:
|
|
||||||
condition: service_healthy
|
|
||||||
keycloak:
|
|
||||||
condition: service_started
|
|
||||||
networks: [cg]
|
|
||||||
|
|
||||||
openbaar:
|
|
||||||
build:
|
|
||||||
context: ..
|
|
||||||
dockerfile: apps/openbaar/Dockerfile
|
|
||||||
image: register-referentie/openbaar:dev
|
|
||||||
ports:
|
|
||||||
- "8141:80"
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD-SHELL", "wget -q -O /dev/null http://127.0.0.1/ || exit 1"]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 3s
|
|
||||||
retries: 5
|
|
||||||
start_period: 10s
|
|
||||||
depends_on:
|
|
||||||
bff:
|
|
||||||
condition: service_healthy
|
|
||||||
networks: [cg]
|
|
||||||
|
|
||||||
behandel:
|
|
||||||
build:
|
|
||||||
context: ..
|
|
||||||
dockerfile: apps/behandel/Dockerfile
|
|
||||||
image: register-referentie/behandel:dev
|
|
||||||
ports:
|
|
||||||
- "8142:80"
|
|
||||||
volumes:
|
|
||||||
- ./local-config/behandel.config.json:/usr/share/nginx/html/config.json:ro,z
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD-SHELL", "wget -q -O /dev/null http://127.0.0.1/ || exit 1"]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 3s
|
|
||||||
retries: 5
|
|
||||||
start_period: 10s
|
|
||||||
depends_on:
|
|
||||||
bff:
|
|
||||||
condition: service_healthy
|
|
||||||
keycloak:
|
|
||||||
condition: service_started
|
|
||||||
networks: [cg]
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
oz-db:
|
oz-db:
|
||||||
nrc-db:
|
nrc-db:
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
"authority": "http://localhost:8180/realms/medewerker"
|
|
||||||
}
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
"authority": "http://localhost:8180/realms/digid"
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user