配置FIWARE组件解决AZF域未创建应用报错的技术求助
Let's break down why you're seeing this error and walk through the exact fixes to get Keyrock, Authzforce, and Wilma working together properly.
Root Cause
The error means Keyrock hasn't created a matching authorization domain (Domain) in Authzforce for your application. Normally, Keyrock should auto-sync this domain when you create an app, but issues like network isolation between containers or missing PDP configuration in Keyrock block this sync.
Step 1: Fix Network Connectivity Between Keyrock and Authzforce
Your Keyrock runs in a custom Docker network (172.18.1.0/24), but Authzforce is in the default bridge network—so they can't reach each other. Let's fix that:
- Stop and remove your existing Authzforce container:
docker stop authzforce_server && docker rm authzforce_server - Find the name of Keyrock's Docker network (it's usually
fiware-idm_defaultif you used the provided compose file):docker network ls - Re-launch Authzforce in the same network as Keyrock:
docker run -d -p 8085:8080 --name authzforce_server --network fiware-idm_default authzforce/server - Verify Keyrock can reach Authzforce (run this from your host):
You should get a 200 OK response (even if the domain list is empty).docker exec -it fiware-keyrock curl http://authzforce_server:8080/authzforce-ce/domains
Step 2: Configure Keyrock to Use Authzforce as Default PDP
Now tell Keyrock how to connect to Authzforce so it can auto-sync domains:
- Log into Keyrock's admin UI at
http://localhost:3000using your admin credentials. - Go to Settings → PDP Servers.
- Click Add PDP Server and fill in these details:
- Name: Authzforce Server
- Type: Authzforce
- Host:
authzforce_server(use the container name since they're in the same network) - Port:
8080(Authzforce's internal port, not the host-mapped 8085) - Protocol:
http - Path:
/authzforce-ce - Check Default to set this as the primary PDP.
- Save the configuration.
Step 3: Sync Your Application Domain to Authzforce
Since your app was created before configuring Authzforce, you need to either re-create the app or manually add the domain:
Option A: Re-create the Application (Easiest)
- Delete your existing application (XYZ) from Keyrock's UI.
- Create a new application with the same settings.
- Keyrock will now auto-create a matching domain in Authzforce for this new app.
Option B: Manually Create the Domain via API
If you don't want to re-create the app, send this POST request to Authzforce (replace YOUR_APP_ID with your actual app ID from the error message):
curl -X POST http://localhost:8085/authzforce-ce/domains \ -H "Content-Type: application/xml" \ -d '<domains xmlns="http://authzforce.github.io/rest-api-model/xmlns/authz/5"> <domain> <id>YOUR_APP_ID</id> <name>Your Application Domain</name> </domain> </domains>'
A 201 Created response confirms the domain was added successfully.
Step 4: Update Wilma PEP Configuration
Double-check your Wilma config.js to ensure it points to the correct Authzforce endpoint:
config.authorization = { enabled: true, pdp: 'authzforce', azf: { protocol: 'http', host: 'localhost', // Use 'authzforce_server' if Wilma runs in a Docker container port: 8085, // Host-mapped port for Authzforce custom_policy: undefined, } }
Restart Wilma with sudo node server after making changes.
Step 5: Verify the Flow
- Use Postman to get a valid token from Keyrock's
/oauth2/tokenendpoint. - Send a request to Wilma:
GET http://localhost:5056/version Authorization: Bearer YOUR_TOKEN - If you get Orion's version response back, the error is fixed!
Don't forget to confirm your user has the correct roles/permissions in Keyrock for the Orion resource you're accessing (e.g., GET /version).
内容的提问来源于stack exchange,提问作者t.montanaro

