Docker Compose部署FIWARE组件后,需配置AuthZForce与PEP Proxy优化安全
Alright, let's walk through configuring AuthZForce with your existing PEP Proxy setup to lock down your FIWARE stack properly. Based on your current configuration and test setup, here's a practical step-by-step guide:
First, update your docker-compose.yml to include the AuthZForce service. Add this block alongside your existing Orion, Cygnus, Keyrock, and PEP Proxy services:
authzforce: image: authzforce/server:latest ports: - "8080:8080" environment: - TOMCAT_INIT_HEAP_SIZE=256m - TOMCAT_MAX_HEAP_SIZE=512m restart: always
Run docker-compose up -d to spin up the new service.
Locate your PEP Proxy's configuration file (typically config.js or config.json) and update these settings to enable AuthZForce integration:
config.pep = { enabled: true, // Keep your existing Keyrock/Keystone settings keystone_url: "http://localhost:5000", keyrock_url: "http://localhost:8000", app_host: "http://localhost", app_port: 1026, // Adjust if your Orion uses a different port // Add AuthZForce-specific config authzforce: { enabled: true, url: "http://localhost:8080/authzforce-ce/domains", policyId: "YOUR_POLICY_ID", // We'll get this in the next step retry: 3 } };
Restart your PEP Proxy container for changes to take effect.
Next, you need to define access policies that map Keyrock users/roles to allowed actions in Orion. Here's how to do it:
Create a Domain: First, create a domain in AuthZForce to hold your policies. Use this curl command:
curl -X POST http://localhost:8080/authzforce-ce/domains \ -H "Content-Type: application/xml" \ -d '<domain xmlns="http://authzforce.github.io/core/xmlns/domain/3.6"><name>FIWARE_Orion_Policies</name></domain>'Save the domain ID returned in the response (you'll need it for policy creation).
Create a Policy: Define a policy that restricts actions based on user roles. For example, allow
adminroles full access to Orion, anduserroles only read access. Create an XML file (e.g.,orion_policy.xml) with this content:<xacml3:Policy xmlns:xacml3="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" PolicyId="Orion_Access_Policy" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides"> <xacml3:Description>Control access to Orion entities</xacml3:Description> <!-- Target all Orion entity endpoints --> <xacml3:Target> <xacml3:AnyOf> <xacml3:AllOf> <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-starts-with"> <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">http://localhost:1026/v2/entities</xacml3:AttributeValue> <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:resource:resource-id" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/> </xacml3:Match> </xacml3:AllOf> </xacml3:AnyOf> </xacml3:Target> <!-- Allow admins all actions --> <xacml3:Rule RuleId="Allow_Admin_Full_Access" Effect="Permit"> <xacml3:Target> <xacml3:AnyOf> <xacml3:AllOf> <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">admin</xacml3:AttributeValue> <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:subject" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/> </xacml3:Match> </xacml3:AllOf> </xacml3:AnyOf> </xacml3:Target> </xacml3:Rule> <!-- Allow users only read actions (GET) --> <xacml3:Rule RuleId="Allow_User_Read_Access" Effect="Permit"> <xacml3:Target> <xacml3:AnyOf> <xacml3:AllOf> <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">user</xacml3:AttributeValue> <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:subject" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/> </xacml3:Match> <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">GET</xacml3:AttributeValue> <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:action" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/> </xacml3:Match> </xacml3:AllOf> </xacml3:AnyOf> </xacml3:Target> </xacml3:Rule> <!-- Deny all other requests --> <xacml3:Rule RuleId="Deny_All_Others" Effect="Deny"/> </xacml3:Policy>Then upload this policy to your AuthZForce domain (replace
YOUR_DOMAIN_IDwith the ID from earlier):curl -X POST http://localhost:8080/authzforce-ce/domains/YOUR_DOMAIN_ID/pap/policies \ -H "Content-Type: application/xml" \ -d @orion_policy.xmlSave the policy ID from the response and update your PEP Proxy config's
policyIdfield with it.
Modify your test_authzforce function to test both authorized and unauthorized actions, and ensure roles are assigned correctly:
def test_authzforce(create=0, usuario="idm", nombre="", password="idm", correo=""): if create != 0: ktoken = get_token(keystone_url) create_user(keystone_url, ktoken, usuario, nombre, password, correo) # Assign a role to the user (e.g., 'user' or 'admin') assign_role(keystone_url, ktoken, usuario, "user") # Get the user's access token token = get_access_token(keyrock_url, usuario, password) # Test read access (should be allowed for 'user' role) read_response = requests.get(f"{orion}:1026/v2/entities", headers={"X-Auth-Token": token}) print(f"Read entities status: {read_response.status_code} | Response: {read_response.text}") # Test write access (should be denied for 'user' role) new_entity = { "id": "TestEntity001", "type": "TestType", "temperature": {"type": "Number", "value": 25} } write_response = requests.post(f"{orion}:1026/v2/entities", json=new_entity, headers={"X-Auth-Token": token}) print(f"Create entity status: {write_response.status_code} | Response: {write_response.text}")
Make sure you have an assign_role function that maps users to roles in Keyrock (you can use the Keystone API for this).
- Verify that AuthZForce is running at
http://localhost:8080/authzforce-ce - Confirm PEP Proxy is forwarding authorization requests to AuthZForce
- Test with both
adminanduserroles to ensure policies are enforced correctly
内容的提问来源于stack exchange,提问作者Sevastián Ríos

