Ansible is a really nice "dev-ops" automation tool in the spirit of Chef, Puppet, etc. It's virtues are simplicity, an "agentless" installation model and a very active and growing community . One of the neat features of Ansible is the concept of "roles". These are reusable chunks of dev-ops code that perform a specific task. Ansible "Playbooks" orchestrate a number of roles together to perform software installation and configuration. Roles by themselves are not sufficient to drive reusability. We need a way to collaborate and share roles. Enter Ansible Galaxy , the central repository for Ansible roles. If you have ever used apt or yum , galaxy will appear quite familiar. For example, to install and use the "opendj" role, you issue the following command: $ ansible-galaxy install warren.strange.opendj (Roles are prefixed with a contributor name to avoid name collisions). If you want to install ForgeRock's...
Oracle Access Manager 11g R2 provides several new REST APIs. This continues a trend to expose key functionality via Web Services. The OAM Mobile and Social service provides APIs for Authentication, Authorization and User Profile services. I will cover those APIs in a future article (have a look here for examples) - but today I want to focus on the policy management APIs. The Policy Administration API enables to you to interact with OAM to create a variety of Policy objects such as Application Domains, Resources, AuthN Schemes, and AuthN/AuthZ policies. The policy model is shown below: For example, if you want to retrieve all of the resources in an Application Domain you can perform a GET against the /resource URI: curl -u USER:PASSWORD http://<SERVER>:<PORT>/oam/services/rest/11.1.2.0.0/ssa/policyadmin/resource?appdomain="IAM Suite" Note: The port above is where the OAM Admin Server is deployed (often 7001). It ...
ForgeRock Directory Services 7.0 was a big achievement for the Grenoble Directory team. It is the only "Kubernetes native" directory where you can add a new replica using kubectl: kubectl scale sts/ds-idrepo --replicas=3 The 7.0 deployment is assembled using standard Kubernetes primitives such as StatefulSets , Persistent Volume Claims, and Services. This is all built and orchestrated using Skaffold and Kustomize . An emerging pattern in the Kubernetes world is the use of Custom Resources and Operators . Broadly speaking, a custom resource is the declaration of the desired system state, and the operator's job is to observe the current state and bring the system into alignment with the declared state: source: https://blog.container-solutions.com/kubernetes-operators-explained The Kubernetes API server (the thing that responds to your kubectl commands) can be extended to handle new custom types. A custom resource definition (CRD) describes to the API se...
Comments