Participants · participants/dh-nab
NAB NAB
NAB runs the full Ping CDR Kit data holder stack - PingFederate, PingAccess, PingDirectory, PingDataSync and PingAuthorize, plus the kit's consent app and mock banking API - each on its own server profile. The profiles are generated from the vendored kit by deploy/kit/build-dh.mjs, and every deviation from the kit is listed in KIT-CHANGES.md.
What it does
- PingAccess is the only public entry point: mTLS, holder-of-key checks, Register status checks, DCR rewrite
/register→/as/clients.oauth2. - PingFederate with
pf-cdr-au-modules: DCR with SSA validation, PAR, signed request objects,cdr_arrangement_id, consent grants in PingDirectory, arrangement revocation. - Login is identifier-first (mobile) → OTP form (an LDAP PCV against PingDirectory, demo code
000789) → the kit agentless consent app with a branded, CX-laid-out template. - PingAuthorize is the kit's API gateway policy: validates the token, injects
X-USER/X-ACCOUNTS, so only consented accounts come back. - About 4.2 GB per stack at steady state - run one at a time locally.
Ports and endpoints
| PingAccess (only public entry) | 9442 |
|---|---|
| Issuer | https://sso.nab.localhost:9442 |
| CDS API | https://api.nab.localhost:9442/cds-au/v1/banking |
| Consent app | https://consent.nab.localhost:9442 |
Railway
dh-nab-pa | not on Railway yet |
|---|---|
dh-nab-pf | not on Railway yet |
dh-nab-pd | not on Railway yet |
dh-nab-pds | not on Railway yet |
dh-nab-paz | not on Railway yet |
dh-nab-consentapp | not on Railway yet |
dh-nab-mockapi | not on Railway yet |
dh-nab-configure | not on Railway yet |
Components and versions
Read from participants/dh-nab/docker-compose.yml at build time.
| Service | Image | Host ports |
|---|---|---|
dh-nab-pingdirectory | pingidentity/pingdirectory:10.3.0.4-latest | internal |
dh-nab-pingfederate | pingidentity/pingfederate:13.0.0-edge | internal |
dh-nab-pingaccess | pingidentity/pingaccess:2601-8.3.2 | 9442→9442 |
dh-nab-pingdatasync | pingidentity/pingdatasync:10.3.0.4-latest | internal |
dh-nab-pingauthorize | pingidentity/pingauthorize:10.3.0.4-latest | internal |
dh-nab-consentapp | tamatping/agentless-consentapp:20231123 | internal |
dh-nab-mock-dh-api | tamatping/mock-dh-apis:20231123 | internal |
dh-nab-kit-configure | tamatping/datain-configure-pf:20231123 | internal |
participants/dh-nab/server-profiles/KIT-CHANGES.md
NAB: changes from the Ping CDR Kit profiles
Generated by deploy/kit/build-dh.mjs nab from vendor/pingidentity-cdr-sandbox/server_profiles. Do not edit by hand; change the generator and rebuild.
- Copied kit profiles
pingfederate,pingaccess,pingdirectory,pingdatasyncandpingdatagovernance(aspingauthorize), including the kit jars, unchanged except as listed. - PF: added LDAP PCV
cdrOtpPCV(clone of kitadrUserPCV) searchingou=peoplebyentryUUID,uidormobile; PD users carry the fixed demo OTP as their password. - PF: added HTML Form adapter
cdrOtpFormAdapter(clone of kithtmlFormAdapter) with templatehtml.form.otp.template.htmland PCVcdrOtpPCV. - PF:
identityFirstAdapterLDAP attribute source filteruid=${subject}->(|(uid=${subject})(mobile=${subject}))so customers sign in with their mobile. - PF: fragment
cdrPolicyFragmentNoMFAstepclickatellAdapter->cdrOtpFormAdapter(incoming user id = identifier-firstentryUUID, as the kit does for its consent adapter). The Clickatell adapter definition is kept, unused. - PF + PA: every
:6443(the kit's local-dev listener) ->:${DH_PUBLIC_PORT}so each DH has its own issuer port. - PF templates:
identifier.first.template.htmlre-skinned (mobile number), newhtml.form.otp.template.html,assets/brand/{brand.css,logo.svg}. - PA: engine listener "Local Dev Listener" and the
*:6443virtual hosts ->${DH_PUBLIC_PORT}; groovy rules referencing:6443and the hard-codedX-Forwarded-Port: 443likewise. - PD:
pd.profile/ldif/userRoot/10-users.ldifreplaced (kit CRN0-5) with this brand's customers fromdata/customers.json(uid = DH customer id, mobile, userPassword = demo OTP, entryUUID = nameUUIDFromBytes(customerId)). - Consent app: kit
agentless-consentappimage unchanged;consent-app/templates/index.html(same Thymeleaf model as the kit template) is loaded throughSPRING_THYMELEAF_PREFIX. - mock-dh-apis:
mock-dh-api/cachepre-seeds the kit image's own cache (/tmp/cache/<model>/<X-USER>/) fromdata/seed.json, keyed by PD entryUUID. - Compose fragment
docker-compose.yml,env/dh.env(fromdeploy/kit/templates), the kit's ownenv/pf.env+env/pa.env(kit demo key material), andscripts/smoke.{sh,mjs}.
Config browser
Read-only, from files tracked in git. Keys, keystores, .sec/, real env files and anything gitignored are left out; secret-looking values are shown as «redacted». 168 files.