Giter VIP home page Giter VIP logo

sso-realm-registry's Introduction

SSO Realm Registry

Lifecycle:Stable

repository for SSO realm registry and helm chart

Tech Stack

  • NextJS (ReactJS): a React framework that gives you building blocks to create web applications.

  • Spilo: a Docker image that provides PostgreSQL and Patroni bundled together.

    • Postgres 14 and Patroni 2.1.3 are currently installed in OCP namespaces.

Database Security

Database Backup & Recovery

Recovery Process

  • check if patroni cluster is healthy and running.

    $ patronictl list
    + Cluster: realm-registry (7106273589750788182) -----+---------+----+-----------+
    | Member                   | Host          | Role    | State   | TL | Lag in MB |
    +--------------------------+---------------+---------+---------+----+-----------+
    | realm-registry-patroni-0 | 10.97.122.229 | Replica | running |  6 |         0 |
    | realm-registry-patroni-1 | 10.97.121.116 | Leader  | running |  6 |           |
    +--------------------------+---------------+---------+---------+----+-----------+
  • set the patroni cluster on maintenance mode.

    $ patronictl pause
    Success: cluster management is paused
  • check if the patroni cluster is on maintenance mode.

    $ patronictl list
    + Cluster: realm-registry (7106273589750788182) -----+---------+----+-----------+
    | Member                   | Host          | Role    | State   | TL | Lag in MB |
    +--------------------------+---------------+---------+---------+----+-----------+
    | realm-registry-patroni-0 | 10.97.122.229 | Replica | running |  6 |         0 |
    | realm-registry-patroni-1 | 10.97.121.116 | Leader  | running |  6 |           |
    +--------------------------+---------------+---------+---------+----+-----------+
     Maintenance mode: on
  • stop the postgres client in the leader pod.

    $ pg_ctl stop
    waiting for server to shut down..... done
    server stopped
  • remove the current data directory.

    $ rm -rf "$PGDATA"
  • restore the latest archived data.

    $ wal-g backup-fetch "$PGDATA" LATEST
    INFO: 2022/08/03 18:34:42.443396 Selecting the latest backup...
    INFO: 2022/08/03 18:34:43.023566 Finished extraction of part_003.tar.lz4
    INFO: 2022/08/03 18:34:43.024048 Finished decompression of part_003.tar.lz4
    INFO: 2022/08/03 18:34:46.741348 Finished extraction of part_001.tar.lz4
    INFO: 2022/08/03 18:34:46.741801 Finished decompression of part_001.tar.lz4
    INFO: 2022/08/03 18:34:46.749453 Finished extraction of pg_control.tar.lz4
    INFO: 2022/08/03 18:34:46.749835 Finished decompression of pg_control.tar.lz4
    INFO: 2022/08/03 18:34:46.749866
    Backup extraction complete.
  • resume the patroni cluster

    $ patronictl resume
    Success: cluster management is resumed
  • check if the patroni cluster is on active mode.

    $ patronictl list
    + Cluster: realm-registry (7106273589750788182) -----+---------+----+-----------+
    | Member                   | Host          | Role    | State   | TL | Lag in MB |
    +--------------------------+---------------+---------+---------+----+-----------+
    | realm-registry-patroni-0 | 10.97.122.229 | Leader  | running |  6 |         0 |
    | realm-registry-patroni-1 | 10.97.121.116 | Replica | running |  6 |           |
    +--------------------------+---------------+---------+---------+----+-----------+
  • to list the backups and restore the specific one, run:

    $ wal-g backup-list
    name modified wal_segment_backup_start
    base_00000003000000000000007E 2022-07-31T01:00:10Z 00000003000000000000007E
    base_000000030000000000000080 2022-08-01T01:00:10Z 000000030000000000000080
    base_000000030000000000000082 2022-08-02T01:00:11Z 000000030000000000000082
    base_000000030000000000000088 2022-08-03T01:00:10Z 000000030000000000000088
    $ wal-g backup-fetch "$PGDATA" base_000000030000000000000088
  • see https://github.com/wal-e/wal-e#backup-list

  • see https://github.com/wal-e/wal-e#backup-fetch

Code security & Vulnerability Disclosure

We make use of most of GitHub's security features that help keep code and secrets secure with dependency vulnerability management in this repository.

Security advisories

Privately discuss and fix security vulnerabilities in your repository's code. You can then publish a security advisory to alert your community to the vulnerability and encourage community members to upgrade.

Dependabot alerts and security updates

View alerts about dependencies that are known to contain security vulnerabilities, and choose whether to have pull requests generated automatically to update these dependencies.

Dependabot version updates

Use Dependabot to automatically raise pull requests to keep your dependencies up-to-date. This helps reduce your exposure to older versions of dependencies. Using newer versions makes it easier to apply patches if security vulnerabilities are discovered, and also makes it easier for Dependabot security updates to successfully raise pull requests to upgrade vulnerable dependencies.

Code scanning

Automatically detect security vulnerabilities and coding errors in new or modified code. Potential problems are highlighted, with detailed information, allowing you to fix the code before it's merged into your default branch.

IDIM Web Service proxy API endpoint

The backend API exposes a proxy endpoint that being used by Common Hosted Single Sign-on (CSS) lambda API endpoints to meet the security requirement of IDIM web service and hosted in the same network with it. The IDIM web service backend logic is stored in IDIM Web Service.

  • IDIM web service makes use of two of the environment variables:

    1. BCEID_SERVICE_ID: OSID # to the BCeID Client Web Services.
    2. BCEID_SERVICE_BASIC_AUTH: Basic Auth authorization token.
  • To generate the authorization token with IDIR account credentials:

    echo -n "<idir_username>:<idir_password>" | base64

This secret will be stored with the other Realm Registry secrets in the Platform Services Vault service.

sso-realm-registry's People

Contributors

jlangy avatar junminahn avatar kurokn avatar nithinkuruba avatar thegentlemanphysicist avatar

Stargazers

 avatar

Watchers

 avatar  avatar  avatar  avatar  avatar

Forkers

bruce-wh-li

sso-realm-registry's Issues

It's Been a While Since This Repository has Been Updated

This issue is a kind reminder that your repository has been inactive for 181 days. Some repositories are maintained in accordance with business requirements that infrequently change thus appearing inactive, and some repositories are inactive because they are unmaintained.

To help differentiate products that are unmaintained from products that do not require frequent maintenance, repomountie will open an issue whenever a repository has not been updated in 180 days.

  • If this product is being actively maintained, please close this issue.
  • If this repository isn't being actively maintained anymore, please archive this repository. Also, for bonus points, please add a dormant or retired life cycle badge.

Thank you for your help ensuring effective governance of our open-source ecosystem!

Add missing topics

TL;DR

Topics greatly improve the discoverability of repos; please add the short code from the table below to the topics of your repo so that ministries can use GitHub's search to find out what repos belong to them and other visitors can find useful content (and reuse it!).

Why Topic

In short order we'll add our 800th repo. This large number clearly demonstrates the success of using GitHub and our Open Source initiative. This huge success means it's critical that we work to make our content as discoverable as possible. Through discoverability, we promote code reuse across a large decentralized organization like the Government of British Columbia as well as allow ministries to find the repos they own.

What to do

Below is a table of abbreviation a.k.a short codes for each ministry; they're the ones used in all @gov.bc.ca email addresses. Please add the short codes of the ministry or organization that "owns" this repo as a topic.

add a topic

That's it, you're done!!!

How to use

Once topics are added, you can use them in GitHub's search. For example, enter something like org:bcgov topic:citz to find all the repos that belong to Citizens' Services. You can refine this search by adding key words specific to a subject you're interested in. To learn more about searching through repos check out GitHub's doc on searching.

Pro Tip ๐Ÿค“

  • If your org is not in the list below, or the table contains errors, please create an issue here.

  • While you're doing this, add additional topics that would help someone searching for "something". These can be the language used javascript or R; something like opendata or data for data only repos; or any other key words that are useful.

  • Add a meaningful description to your repo. This is hugely valuable to people looking through our repositories.

  • If your application is live, add the production URL.

Ministry Short Codes

Short Code Organization Name
AEST Advanced Education, Skills & Training
AGRI Agriculture
ALC Agriculture Land Commission
AG Attorney General
MCF Children & Family Development
CITZ Citizens' Services
DBC Destination BC
EMBC Emergency Management BC
EAO Environmental Assessment Office
EDUC Education
EMPR Energy, Mines & Petroleum Resources
ENV Environment & Climate Change Strategy
FIN Finance
FLNR Forests, Lands, Natural Resource Operations & Rural Development
HLTH Health
IRR Indigenous Relations & Reconciliation
JEDC Jobs, Economic Development & Competitiveness
LBR Labour Policy & Legislation
LDB BC Liquor Distribution Branch
MMHA Mental Health & Addictions
MAH Municipal Affairs & Housing
BCPC Pension Corporation
PSA Public Service Agency
PSSG Public Safety and Solicitor General
SDPR Social Development & Poverty Reduction
TCA Tourism, Arts & Culture
TRAN Transportation & Infrastructure

NOTE See an error or omission? Please create an issue here to get it remedied.

It's Been a While Since This Repository has Been Updated

This issue is a kind reminder that your repository has been inactive for 181 days. Some repositories are maintained in accordance with business requirements that infrequently change thus appearing inactive, and some repositories are inactive because they are unmaintained.

To help differentiate products that are unmaintained from products that do not require frequent maintenance, repomountie will open an issue whenever a repository has not been updated in 180 days.

  • If this product is being actively maintained, please close this issue.
  • If this repository isn't being actively maintained anymore, please archive this repository. Also, for bonus points, please add a dormant or retired life cycle badge.

Thank you for your help ensuring effective governance of our open-source ecosystem!

Add project lifecycle badge

No Project Lifecycle Badge found in your readme!

Hello! I scanned your readme and could not find a project lifecycle badge. A project lifecycle badge will provide contributors to your project as well as other stakeholders (platform services, executive) insight into the lifecycle of your repository.

What is a Project Lifecycle Badge?

It is a simple image that neatly describes your project's stage in its lifecycle. More information can be found in the project lifecycle badges documentation.

What do I need to do?

I suggest you make a PR into your README.md and add a project lifecycle badge near the top where it is easy for your users to pick it up :). Once it is merged feel free to close this issue. I will not open up a new one :)

Lets use common phrasing

TL;DR ๐ŸŽ๏ธ

Teams are encouraged to favour modern inclusive phrasing both in their communication as well as in any source checked into their repositories. You'll find a table at the end of this text with preferred phrasing to socialize with your team.

Words Matter

We're aligning our development community to favour inclusive phrasing for common technical expressions. There is a table below that outlines the phrases that are being retired along with the preferred alternatives.

During your team scrum, technical meetings, documentation, the code you write, etc. use the inclusive phrasing from the table below. That's it - it really is that easy.

For the curious mind, the Public Service Agency (PSA) has published a guide describing how Words Matter in our daily communication. Its an insightful read and a good reminder to be curious and open minded.

What about the master branch?

The word "master" is not inherently bad or non-inclusive. For example people get a masters degree; become a master of their craft; or master a skill. It's generally when the word "master" is used along side the word "slave" that it becomes non-inclusive.

Some teams choose to use the word main for the default branch of a repo as opposed to the more commonly used master branch. While it's not required or recommended, your team is empowered to do what works for them. If you do rename the master branch consider using main so that we have consistency among the repos within our organization.

Preferred Phrasing

Non-Inclusive Inclusive
Whitelist => Allowlist
Blacklist => Denylist
Master / Slave => Leader / Follower; Primary / Standby; etc
Grandfathered => Legacy status
Sanity check => Quick check; Confidence check; etc
Dummy value => Placeholder value; Sample value; etc

Pro Tip ๐Ÿค“

This list is not comprehensive. If you're aware of other outdated nomenclature please create an issue (PR preferred) with your suggestion.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.