You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置FIWARE组件解决AZF域未创建应用报错的技术求助

Fix: "AZF domain not created for application XYZ" in FIWARE Stack

Let's break down why you're seeing this error and walk through the exact fixes to get Keyrock, Authzforce, and Wilma working together properly.

Root Cause

The error means Keyrock hasn't created a matching authorization domain (Domain) in Authzforce for your application. Normally, Keyrock should auto-sync this domain when you create an app, but issues like network isolation between containers or missing PDP configuration in Keyrock block this sync.


Step 1: Fix Network Connectivity Between Keyrock and Authzforce

Your Keyrock runs in a custom Docker network (172.18.1.0/24), but Authzforce is in the default bridge network—so they can't reach each other. Let's fix that:

  1. Stop and remove your existing Authzforce container:
    docker stop authzforce_server && docker rm authzforce_server
    
  2. Find the name of Keyrock's Docker network (it's usually fiware-idm_default if you used the provided compose file):
    docker network ls
    
  3. Re-launch Authzforce in the same network as Keyrock:
    docker run -d -p 8085:8080 --name authzforce_server --network fiware-idm_default authzforce/server
    
  4. Verify Keyrock can reach Authzforce (run this from your host):
    docker exec -it fiware-keyrock curl http://authzforce_server:8080/authzforce-ce/domains
    
    You should get a 200 OK response (even if the domain list is empty).

Step 2: Configure Keyrock to Use Authzforce as Default PDP

Now tell Keyrock how to connect to Authzforce so it can auto-sync domains:

  1. Log into Keyrock's admin UI at http://localhost:3000 using your admin credentials.
  2. Go to Settings → PDP Servers.
  3. Click Add PDP Server and fill in these details:
    • Name: Authzforce Server
    • Type: Authzforce
    • Host: authzforce_server (use the container name since they're in the same network)
    • Port: 8080 (Authzforce's internal port, not the host-mapped 8085)
    • Protocol: http
    • Path: /authzforce-ce
    • Check Default to set this as the primary PDP.
  4. Save the configuration.

Step 3: Sync Your Application Domain to Authzforce

Since your app was created before configuring Authzforce, you need to either re-create the app or manually add the domain:

Option A: Re-create the Application (Easiest)

  1. Delete your existing application (XYZ) from Keyrock's UI.
  2. Create a new application with the same settings.
  3. Keyrock will now auto-create a matching domain in Authzforce for this new app.

Option B: Manually Create the Domain via API

If you don't want to re-create the app, send this POST request to Authzforce (replace YOUR_APP_ID with your actual app ID from the error message):

curl -X POST http://localhost:8085/authzforce-ce/domains \
  -H "Content-Type: application/xml" \
  -d '<domains xmlns="http://authzforce.github.io/rest-api-model/xmlns/authz/5">
        <domain>
          <id>YOUR_APP_ID</id>
          <name>Your Application Domain</name>
        </domain>
      </domains>'

A 201 Created response confirms the domain was added successfully.


Step 4: Update Wilma PEP Configuration

Double-check your Wilma config.js to ensure it points to the correct Authzforce endpoint:

config.authorization = {
  enabled: true,
  pdp: 'authzforce',
  azf: {
    protocol: 'http',
    host: 'localhost', // Use 'authzforce_server' if Wilma runs in a Docker container
    port: 8085, // Host-mapped port for Authzforce
    custom_policy: undefined,
  }
}

Restart Wilma with sudo node server after making changes.


Step 5: Verify the Flow

  1. Use Postman to get a valid token from Keyrock's /oauth2/token endpoint.
  2. Send a request to Wilma:
    GET http://localhost:5056/version
    Authorization: Bearer YOUR_TOKEN
    
  3. If you get Orion's version response back, the error is fixed!

Don't forget to confirm your user has the correct roles/permissions in Keyrock for the Orion resource you're accessing (e.g., GET /version).

内容的提问来源于stack exchange,提问作者t.montanaro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:36:29