-
Notifications
You must be signed in to change notification settings - Fork 9
How to set up the external‐api module in docker‐compose.yaml
The external-api Docker image is a module that provides additional programming interfaces for accessing refined core component information. This guide illustrates how to set it up on a system already configured with a docker-compose.yaml. The system should be connected to an OpenID Connect (OIDC) provider, which provides the JSON Web Key (JWK) endpoint for user authentication. For information on connecting to OIDC, please refer to the OIDC setup guide before proceeding.
This guide assumes that the system has already connected to the OIDC provider and that connectCenter has been deployed using the docker-compose.yaml in the installation guide. Deploying the external-api module requires defining a new service external-api in the docker-compose.yaml and providing the RS_JWK_SET_URI property to the gateway module. The following is an example docker-compose.yaml file demonstrating the external-api module settings:
version: "3.0" services: frontend: image: oagi1docker/srt-web:3.2.1 ports: - 4200:4200 links: - backend environment: - GATEWAY_HOST=backend - GATEWAY_PORT=8080 depends_on: - backend backend: image: oagi1docker/srt-http-gateway:3.2.1 ports: - 8080:8080 links: - db - redis environment: - DB_HOST=db - DB_PORT=3306 - REDIS_HOST=redis - REDIS_PORT=6379 - JAVA_OPTS="-Xmx4096m" + - RS_JWK_SET_URI=https://auth.<mycompany>.com/pf/JWKS depends_on: - db - redis deploy: resources: limits: memory: 8192M reservations: memory: 4096M + external-api: + image: oagi1docker/srt-external-api:3.2.1 + ports: + - 3000:3000 + environment: + - backend_server=http://backend:8080 + depends_on: + - backend db: image: oagi1docker/srt-repo:3.2.0 ports: - 3306:3306 volumes: - db-volume:/var/lib/mysql redis: image: redis:6 ports: - 6379:6379 volumes: - redis-volume:/data volumes: db-volume: redis-volume:
where the RS_JWK_SET_URI will correspond to your OIDC provider's "jwks_uri" configuration. You can obtain this URI using the OIDC Discovery, where an OpenID server publishes its metadata at a well-known URL, typically
https://auth.<mycompany>.com/.well-known/openid-configuration
The deployment should be analogous to the frontend service. Like the frontend, your deployment environment will need to expose an HTTPS URL mapped to the container's port (3000 by default). This makes it accessible within your network. Additionally, depending on your specific deployment environment, you may need to add environment variables for proxy settings.