Participants · participants/adr-cba
CBA CommBank as ADR
CommBank is the accredited data recipient, and it does every piece of CDR protocol work with the kit's own data-in modules - DCR, PAR, the hybrid flow, token custody, refresh and revocation. CBA adds three things: a thin web layer for the CX screens, one Reference ID adapter that hands the customer to the kit, and a PingDataSync destination that turns token-store changes into events.
What it does
- Kit PingFederate 13.0.3 with
pf-cdr-au-data-in-modules- 13.1 is Jakarta and breaks the kit's javax revocation servlet. - Kit PingAccess holds the network certificate (from the Register CA) as its mTLS site authenticator, and mediates every pod read:
CDRInjectDataHolderTokenRuleswaps in the DH token so the pod never holds one. - Kit PingDirectory is the token store (SCIM
adr-token, refresh plugin); kit PingDataSync revokes at the DH and, with the CBA pipe, publishesArrangementEstablished/Revoked/Expiredto Redis Streams. - Every CBA change to the kit lives in
scripts/derive-profiles.py; the profiles are its committed output. - A separate PingFederate 13.1.3 (
pingfederate/, Terraform-built) is the CBA OIDC OP for the app and MATTR's auth provider. It is on Railway ascba-pf.
Ports and endpoints
| Kit PingFederate (ADR public base) | 9444 (admin 9934) |
|---|---|
| Kit PingAccess engine | 7310 (admin 7311) |
| Kit PingDirectory | 7312 |
| adr-cba-web (CX screens) | 7300 |
| CBA OIDC OP (PingFederate 13.1.3) | 9034 |
Railway
cba-pf | cba-pf-production.up.railway.app success |
|---|---|
adr-cba-pf | adr-cba-pf-production.up.railway.app success |
adr-cba-pa | adr-cba-pa-production.up.railway.app success |
adr-cba-pd | service created, no public domain success |
adr-cba-pds | service created, no public domain success |
adr-cba-web | adr-cba-web-production.up.railway.app success |
Components and versions
Read from participants/adr-cba/docker-compose.yml at build time.
| Service | Image | Host ports |
|---|---|---|
pingdirectory | pingidentity/pingdirectory:11.0.0.4-latest | 7312→1443 |
pingfederate | pingidentity/pingfederate:13.0.3-latest | 9444→9444 9934→9999 |
pingaccess | pingidentity/pingaccess:8.3.2-latest | 7310→3000 7311→9000 |
pingdatasync | pingidentity/pingdatasync:11.0.0.4-latest | internal |
web | (built from repo) | 7300→7300 |
configure | tamatping/datain-configure-pf:20231123 | internal |
participants/adr-cba/pingfederate/README.md
adr-cba-pf: CBA PingFederate (CBA OIDC OP)
PingFederate 13.1.3 as the CBA OpenID Provider:
- iOS app tokens. Client
cba-ios-app(public, auth code + PKCE, redirectcbaapp://oauth-callback). Access tokens are RS256 JWTs withsub= CBA customer id (cba-cust-00x) andiss=public_base_url(=CBA_ISSUER). JWKS:{CBA_ISSUER}/ext/cba/jwks(=CBA_JWKS_URL; the key is also in/pf/JWKS). - MATTR VII authentication provider. Client
mattr-vii(client_secret_post, redirect = the MATTR tenant callback, approval page bypassed). - Login. Demo customer picker (mobile + name) plus the fixed OTP
000789. HTML Form adapter with the templatetemplates/cba.login.template.htmland a Simple PCV whose usernames are the cbaSubs.
It is not the Data Recipient. DCR, PAR and DH token custody live in ../cdr-kit (see docs/adr-notes.md).
Build model
terraform/*.tf is the source. data.zip is the built artefact, a raw zip of server/default/data from a scratch PF the Terraform was applied to, and it is imported at boot by the drop-in deployer. data.zip and overlay/pf.jwk + overlay/pingfederate-system-keys.xml hold the master key, so they are gitignored. Ship with railway up --no-gitignore.
Rebuild loop:
docker run -d --name adr-spike-pf --env-file <devops.env> -e PING_IDENTITY_ACCEPT_EULA=YES \
-p 39999:9999 -p 39031:9031 pingidentity/pingfederate:13.1.3-latest
# stock image without a profile: accept the licence + create the admin via the admin API
# PUT /license/agreement {"accepted":true}; POST /administrativeAccounts {...ADMINISTRATOR...}
docker cp templates/cba.login.template.html adr-spike-pf:/opt/out/instance/server/default/conf/template/
cd terraform && PINGFEDERATE_PROVIDER_PRODUCT_VERSION=13.1.0 TF_VAR_pf_admin_password=... \
terraform apply -var public_base_url=https://<adr-cba-pf domain> -var 'virtual_host_names=["<adr-cba-pf domain>"]'
docker cp adr-spike-pf:/opt/out/instance/server/default/data /tmp/pfdata
(cd /tmp/pfdata && zip -qr $OLDPWD/../data.zip . -x 'drop-in-deployer/*' 'hypersonic/*' 'pingfederate-admin-user.xml' 'archive/*' 'local/*')
cp /tmp/pfdata/pf.jwk /tmp/pfdata/pingfederate-system-keys.xml ../overlay/Gotchas found on 13.1.3:
GET /configArchive/exportreturned 401 RBAC "no EXPORT permission" even with every admin role, so the raw zip is the workaround.- The raw zip must include
pf.jwk,pingfederate-system-keys.xmland the.jksfiles. With the keys only in the/opt/inoverlay, PF minted a fresh master key at boot and the import failed with "Unable to deobfuscate text".
data.zip currently bakes public_base_url = http://localhost:9034. Re-apply with the Railway domain before deploying. The issuer is baked into the archive.
Run
docker build -t adr-cba-pf:local . && docker run -d -p 9034:9080 \
-e PING_IDENTITY_DEVOPS_USER -e PING_IDENTITY_DEVOPS_KEY adr-cba-pf:localRailway: target port 9080 (plain HTTP behind the edge). Licence comes from the DevOps env vars, which fetch an eval licence each boot.
MATTR wiring
Register this PF as the cba-demo1 authentication provider (url = public base, client mattr-vii, secret = var.mattr_client_secret, client_secret_post, scopes openid profile). If MATTR's redirectUrl differs from var.mattr_redirect_uris, update the variable and rebuild. The id_token carries only sub (cbaSub). Identity claims for the credential come from the cba-issuer claim source.
Config browser
Read-only, from files tracked in git. Keys, keystores, .sec/, real env files and anything gitignored are left out; secret-looking values are shown as «redacted». 180 files.