CommBank ID + income

Participants · participants/dh-nab

NAB NAB

NAB runs the full Ping CDR Kit data holder stack - PingFederate, PingAccess, PingDirectory, PingDataSync and PingAuthorize, plus the kit's consent app and mock banking API - each on its own server profile. The profiles are generated from the vendored kit by deploy/kit/build-dh.mjs, and every deviation from the kit is listed in KIT-CHANGES.md.

What it does

  • PingAccess is the only public entry point: mTLS, holder-of-key checks, Register status checks, DCR rewrite /register → /as/clients.oauth2.
  • PingFederate with pf-cdr-au-modules: DCR with SSA validation, PAR, signed request objects, cdr_arrangement_id, consent grants in PingDirectory, arrangement revocation.
  • Login is identifier-first (mobile) → OTP form (an LDAP PCV against PingDirectory, demo code 000789) → the kit agentless consent app with a branded, CX-laid-out template.
  • PingAuthorize is the kit's API gateway policy: validates the token, injects X-USER / X-ACCOUNTS, so only consented accounts come back.
  • About 4.2 GB per stack at steady state - run one at a time locally.

Ports and endpoints

PingAccess (only public entry)9442
Issuerhttps://sso.nab.localhost:9442
CDS APIhttps://api.nab.localhost:9442/cds-au/v1/banking
Consent apphttps://consent.nab.localhost:9442

Railway

dh-nab-panot on Railway yet
dh-nab-pfnot on Railway yet
dh-nab-pdnot on Railway yet
dh-nab-pdsnot on Railway yet
dh-nab-paznot on Railway yet
dh-nab-consentappnot on Railway yet
dh-nab-mockapinot on Railway yet
dh-nab-configurenot on Railway yet

Components and versions

Read from participants/dh-nab/docker-compose.yml at build time.

ServiceImageHost ports
dh-nab-pingdirectorypingidentity/pingdirectory:10.3.0.4-latestinternal
dh-nab-pingfederatepingidentity/pingfederate:13.0.0-edgeinternal
dh-nab-pingaccesspingidentity/pingaccess:2601-8.3.29442→9442
dh-nab-pingdatasyncpingidentity/pingdatasync:10.3.0.4-latestinternal
dh-nab-pingauthorizepingidentity/pingauthorize:10.3.0.4-latestinternal
dh-nab-consentapptamatping/agentless-consentapp:20231123internal
dh-nab-mock-dh-apitamatping/mock-dh-apis:20231123internal
dh-nab-kit-configuretamatping/datain-configure-pf:20231123internal

participants/dh-nab/server-profiles/KIT-CHANGES.md

NAB: changes from the Ping CDR Kit profiles

Generated by deploy/kit/build-dh.mjs nab from vendor/pingidentity-cdr-sandbox/server_profiles. Do not edit by hand; change the generator and rebuild.

Config browser

Read-only, from files tracked in git. Keys, keystores, .sec/, real env files and anything gitignored are left out; secret-looking values are shown as «redacted». 168 files.