CommBank ID + income

Participants · participants/dh-anz

ANZ ANZ

ANZ runs the full Ping CDR Kit data holder stack - PingFederate, PingAccess, PingDirectory, PingDataSync and PingAuthorize, plus the kit's consent app and mock banking API - each on its own server profile. The profiles are generated from the vendored kit by deploy/kit/build-dh.mjs, and every deviation from the kit is listed in KIT-CHANGES.md.

What it does

  • PingAccess is the only public entry point: mTLS, holder-of-key checks, Register status checks, DCR rewrite /register → /as/clients.oauth2.
  • PingFederate with pf-cdr-au-modules: DCR with SSA validation, PAR, signed request objects, cdr_arrangement_id, consent grants in PingDirectory, arrangement revocation.
  • Login is identifier-first (mobile) → OTP form (an LDAP PCV against PingDirectory, demo code 000789) → the kit agentless consent app with a branded, CX-laid-out template.
  • PingAuthorize is the kit's API gateway policy: validates the token, injects X-USER / X-ACCOUNTS, so only consented accounts come back.
  • About 4.2 GB per stack at steady state - run one at a time locally.

Ports and endpoints

PingAccess (only public entry)9443
Issuerhttps://sso.anz.localhost:9443
CDS APIhttps://api.anz.localhost:9443/cds-au/v1/banking
Consent apphttps://consent.anz.localhost:9443

Railway

dh-anz-panot on Railway yet
dh-anz-pfnot on Railway yet
dh-anz-pdnot on Railway yet
dh-anz-pdsnot on Railway yet
dh-anz-paznot on Railway yet
dh-anz-consentappnot on Railway yet
dh-anz-mockapinot on Railway yet
dh-anz-configurenot on Railway yet

Components and versions

Read from participants/dh-anz/docker-compose.yml at build time.

ServiceImageHost ports
dh-anz-pingdirectorypingidentity/pingdirectory:10.3.0.4-latestinternal
dh-anz-pingfederatepingidentity/pingfederate:13.0.0-edgeinternal
dh-anz-pingaccesspingidentity/pingaccess:2601-8.3.29443→9443
dh-anz-pingdatasyncpingidentity/pingdatasync:10.3.0.4-latestinternal
dh-anz-pingauthorizepingidentity/pingauthorize:10.3.0.4-latestinternal
dh-anz-consentapptamatping/agentless-consentapp:20231123internal
dh-anz-mock-dh-apitamatping/mock-dh-apis:20231123internal
dh-anz-kit-configuretamatping/datain-configure-pf:20231123internal

participants/dh-anz/server-profiles/KIT-CHANGES.md

ANZ: changes from the Ping CDR Kit profiles

Generated by deploy/kit/build-dh.mjs anz from vendor/pingidentity-cdr-sandbox/server_profiles. Do not edit by hand; change the generator and rebuild.

Config browser

Read-only, from files tracked in git. Keys, keystores, .sec/, real env files and anything gitignored are left out; secret-looking values are shown as «redacted». 168 files.