You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Compose部署FIWARE组件后,需配置AuthZForce与PEP Proxy优化安全

Alright, let's walk through configuring AuthZForce with your existing PEP Proxy setup to lock down your FIWARE stack properly. Based on your current configuration and test setup, here's a practical step-by-step guide:

1. Add AuthZForce to Your Docker Compose Deployment

First, update your docker-compose.yml to include the AuthZForce service. Add this block alongside your existing Orion, Cygnus, Keyrock, and PEP Proxy services:

authzforce:
  image: authzforce/server:latest
  ports:
    - "8080:8080"
  environment:
    - TOMCAT_INIT_HEAP_SIZE=256m
    - TOMCAT_MAX_HEAP_SIZE=512m
  restart: always

Run docker-compose up -d to spin up the new service.

2. Configure PEP Proxy to Use AuthZForce for Authorization

Locate your PEP Proxy's configuration file (typically config.js or config.json) and update these settings to enable AuthZForce integration:

config.pep = {
  enabled: true,
  // Keep your existing Keyrock/Keystone settings
  keystone_url: "http://localhost:5000",
  keyrock_url: "http://localhost:8000",
  app_host: "http://localhost",
  app_port: 1026, // Adjust if your Orion uses a different port
  // Add AuthZForce-specific config
  authzforce: {
    enabled: true,
    url: "http://localhost:8080/authzforce-ce/domains",
    policyId: "YOUR_POLICY_ID", // We'll get this in the next step
    retry: 3
  }
};

Restart your PEP Proxy container for changes to take effect.

3. Set Up Authorization Policies in AuthZForce

Next, you need to define access policies that map Keyrock users/roles to allowed actions in Orion. Here's how to do it:

  • Create a Domain: First, create a domain in AuthZForce to hold your policies. Use this curl command:

    curl -X POST http://localhost:8080/authzforce-ce/domains \
      -H "Content-Type: application/xml" \
      -d '<domain xmlns="http://authzforce.github.io/core/xmlns/domain/3.6"><name>FIWARE_Orion_Policies</name></domain>'
    

    Save the domain ID returned in the response (you'll need it for policy creation).

  • Create a Policy: Define a policy that restricts actions based on user roles. For example, allow admin roles full access to Orion, and user roles only read access. Create an XML file (e.g., orion_policy.xml) with this content:

    <xacml3:Policy xmlns:xacml3="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" PolicyId="Orion_Access_Policy" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides">
      <xacml3:Description>Control access to Orion entities</xacml3:Description>
      <!-- Target all Orion entity endpoints -->
      <xacml3:Target>
        <xacml3:AnyOf>
          <xacml3:AllOf>
            <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-starts-with">
              <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">http://localhost:1026/v2/entities</xacml3:AttributeValue>
              <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:resource:resource-id" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/>
            </xacml3:Match>
          </xacml3:AllOf>
        </xacml3:AnyOf>
      </xacml3:Target>
      <!-- Allow admins all actions -->
      <xacml3:Rule RuleId="Allow_Admin_Full_Access" Effect="Permit">
        <xacml3:Target>
          <xacml3:AnyOf>
            <xacml3:AllOf>
              <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">admin</xacml3:AttributeValue>
                <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:subject" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/>
              </xacml3:Match>
            </xacml3:AllOf>
          </xacml3:AnyOf>
        </xacml3:Target>
      </xacml3:Rule>
      <!-- Allow users only read actions (GET) -->
      <xacml3:Rule RuleId="Allow_User_Read_Access" Effect="Permit">
        <xacml3:Target>
          <xacml3:AnyOf>
            <xacml3:AllOf>
              <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">user</xacml3:AttributeValue>
                <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:subject" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/>
              </xacml3:Match>
              <xacml3:Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                <xacml3:AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">GET</xacml3:AttributeValue>
                <xacml3:AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:action" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"/>
              </xacml3:Match>
            </xacml3:AllOf>
          </xacml3:AnyOf>
        </xacml3:Target>
      </xacml3:Rule>
      <!-- Deny all other requests -->
      <xacml3:Rule RuleId="Deny_All_Others" Effect="Deny"/>
    </xacml3:Policy>
    

    Then upload this policy to your AuthZForce domain (replace YOUR_DOMAIN_ID with the ID from earlier):

    curl -X POST http://localhost:8080/authzforce-ce/domains/YOUR_DOMAIN_ID/pap/policies \
      -H "Content-Type: application/xml" \
      -d @orion_policy.xml
    

    Save the policy ID from the response and update your PEP Proxy config's policyId field with it.

4. Update Your Test Function to Validate Authorization

Modify your test_authzforce function to test both authorized and unauthorized actions, and ensure roles are assigned correctly:

def test_authzforce(create=0, usuario="idm", nombre="", password="idm", correo=""):
    if create != 0:
        ktoken = get_token(keystone_url)
        create_user(keystone_url, ktoken, usuario, nombre, password, correo)
        # Assign a role to the user (e.g., 'user' or 'admin')
        assign_role(keystone_url, ktoken, usuario, "user")
    
    # Get the user's access token
    token = get_access_token(keyrock_url, usuario, password)
    
    # Test read access (should be allowed for 'user' role)
    read_response = requests.get(f"{orion}:1026/v2/entities", headers={"X-Auth-Token": token})
    print(f"Read entities status: {read_response.status_code} | Response: {read_response.text}")
    
    # Test write access (should be denied for 'user' role)
    new_entity = {
        "id": "TestEntity001",
        "type": "TestType",
        "temperature": {"type": "Number", "value": 25}
    }
    write_response = requests.post(f"{orion}:1026/v2/entities", json=new_entity, headers={"X-Auth-Token": token})
    print(f"Create entity status: {write_response.status_code} | Response: {write_response.text}")

Make sure you have an assign_role function that maps users to roles in Keyrock (you can use the Keystone API for this).

Final Checks
  • Verify that AuthZForce is running at http://localhost:8080/authzforce-ce
  • Confirm PEP Proxy is forwarding authorization requests to AuthZForce
  • Test with both admin and user roles to ensure policies are enforced correctly

内容的提问来源于stack exchange,提问作者Sevastián Ríos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:21:37