CommBank ID + income

Participants · participants/adr-cba

CBA CommBank as ADR

CommBank is the accredited data recipient, and it does every piece of CDR protocol work with the kit's own data-in modules - DCR, PAR, the hybrid flow, token custody, refresh and revocation. CBA adds three things: a thin web layer for the CX screens, one Reference ID adapter that hands the customer to the kit, and a PingDataSync destination that turns token-store changes into events.

What it does

  • Kit PingFederate 13.0.3 with pf-cdr-au-data-in-modules - 13.1 is Jakarta and breaks the kit's javax revocation servlet.
  • Kit PingAccess holds the network certificate (from the Register CA) as its mTLS site authenticator, and mediates every pod read: CDRInjectDataHolderTokenRule swaps in the DH token so the pod never holds one.
  • Kit PingDirectory is the token store (SCIM adr-token, refresh plugin); kit PingDataSync revokes at the DH and, with the CBA pipe, publishes ArrangementEstablished / Revoked / Expired to Redis Streams.
  • Every CBA change to the kit lives in scripts/derive-profiles.py; the profiles are its committed output.
  • A separate PingFederate 13.1.3 (pingfederate/, Terraform-built) is the CBA OIDC OP for the app and MATTR's auth provider. It is on Railway as cba-pf.

Ports and endpoints

Kit PingFederate (ADR public base)9444 (admin 9934)
Kit PingAccess engine7310 (admin 7311)
Kit PingDirectory7312
adr-cba-web (CX screens)7300
CBA OIDC OP (PingFederate 13.1.3)9034

Railway

cba-pfcba-pf-production.up.railway.app success
adr-cba-pfadr-cba-pf-production.up.railway.app success
adr-cba-paadr-cba-pa-production.up.railway.app success
adr-cba-pdservice created, no public domain success
adr-cba-pdsservice created, no public domain success
adr-cba-webadr-cba-web-production.up.railway.app success

Components and versions

Read from participants/adr-cba/docker-compose.yml at build time.

ServiceImageHost ports
pingdirectorypingidentity/pingdirectory:11.0.0.4-latest7312→1443
pingfederatepingidentity/pingfederate:13.0.3-latest9444→9444 9934→9999
pingaccesspingidentity/pingaccess:8.3.2-latest7310→3000 7311→9000
pingdatasyncpingidentity/pingdatasync:11.0.0.4-latestinternal
web(built from repo)7300→7300
configuretamatping/datain-configure-pf:20231123internal

participants/adr-cba/pingfederate/README.md

adr-cba-pf: CBA PingFederate (CBA OIDC OP)

PingFederate 13.1.3 as the CBA OpenID Provider:

It is not the Data Recipient. DCR, PAR and DH token custody live in ../cdr-kit (see docs/adr-notes.md).

Build model

terraform/*.tf is the source. data.zip is the built artefact, a raw zip of server/default/data from a scratch PF the Terraform was applied to, and it is imported at boot by the drop-in deployer. data.zip and overlay/pf.jwk + overlay/pingfederate-system-keys.xml hold the master key, so they are gitignored. Ship with railway up --no-gitignore.

Rebuild loop:

docker run -d --name adr-spike-pf --env-file <devops.env> -e PING_IDENTITY_ACCEPT_EULA=YES \
  -p 39999:9999 -p 39031:9031 pingidentity/pingfederate:13.1.3-latest
# stock image without a profile: accept the licence + create the admin via the admin API
#   PUT /license/agreement {"accepted":true}; POST /administrativeAccounts {...ADMINISTRATOR...}
docker cp templates/cba.login.template.html adr-spike-pf:/opt/out/instance/server/default/conf/template/
cd terraform && PINGFEDERATE_PROVIDER_PRODUCT_VERSION=13.1.0 TF_VAR_pf_admin_password=... \
  terraform apply -var public_base_url=https://<adr-cba-pf domain> -var 'virtual_host_names=["<adr-cba-pf domain>"]'
docker cp adr-spike-pf:/opt/out/instance/server/default/data /tmp/pfdata
(cd /tmp/pfdata && zip -qr $OLDPWD/../data.zip . -x 'drop-in-deployer/*' 'hypersonic/*' 'pingfederate-admin-user.xml' 'archive/*' 'local/*')
cp /tmp/pfdata/pf.jwk /tmp/pfdata/pingfederate-system-keys.xml ../overlay/

Gotchas found on 13.1.3:

data.zip currently bakes public_base_url = http://localhost:9034. Re-apply with the Railway domain before deploying. The issuer is baked into the archive.

Run

docker build -t adr-cba-pf:local . && docker run -d -p 9034:9080 \
  -e PING_IDENTITY_DEVOPS_USER -e PING_IDENTITY_DEVOPS_KEY adr-cba-pf:local

Railway: target port 9080 (plain HTTP behind the edge). Licence comes from the DevOps env vars, which fetch an eval licence each boot.

MATTR wiring

Register this PF as the cba-demo1 authentication provider (url = public base, client mattr-vii, secret = var.mattr_client_secret, client_secret_post, scopes openid profile). If MATTR's redirectUrl differs from var.mattr_redirect_uris, update the variable and rebuild. The id_token carries only sub (cbaSub). Identity claims for the credential come from the cba-issuer claim source.

Config browser

Read-only, from files tracked in git. Keys, keystores, .sec/, real env files and anything gitignored are left out; secret-looking values are shown as «redacted». 180 files.