Participants · participants/dh-westpac
WBC Westpac
Westpac runs the full Ping CDR Kit data holder stack - PingFederate, PingAccess, PingDirectory, PingDataSync and PingAuthorize, plus the kit's consent app and mock banking API - each on its own server profile. The profiles are generated from the vendored kit by deploy/kit/build-dh.mjs, and every deviation from the kit is listed in KIT-CHANGES.md.
What it does
- PingAccess is the only public entry point: mTLS, holder-of-key checks, Register status checks, DCR rewrite
/register→/as/clients.oauth2. - PingFederate with
pf-cdr-au-modules: DCR with SSA validation, PAR, signed request objects,cdr_arrangement_id, consent grants in PingDirectory, arrangement revocation. - Login is identifier-first (mobile) → OTP form (an LDAP PCV against PingDirectory, demo code
000789) → the kit agentless consent app with a branded, CX-laid-out template. - PingAuthorize is the kit's API gateway policy: validates the token, injects
X-USER/X-ACCOUNTS, so only consented accounts come back. - About 4.2 GB per stack at steady state - run one at a time locally.
Ports and endpoints
| PingAccess (only public entry) | 9441 |
|---|---|
| Issuer | https://sso.westpac.localhost:9441 |
| CDS API | https://api.westpac.localhost:9441/cds-au/v1/banking |
| Consent app | https://consent.westpac.localhost:9441 |
Railway
dh-westpac-pa | service created, no public domain success |
|---|---|
dh-westpac-pf | service created, no public domain success |
dh-westpac-pd | service created, no public domain success |
dh-westpac-pds | service created, no public domain success |
dh-westpac-paz | service created, no public domain success |
dh-westpac-consentapp | service created, no public domain success |
dh-westpac-mockapi | service created, no public domain success |
dh-westpac-configure | service created, no public domain success |
Components and versions
Read from participants/dh-westpac/docker-compose.yml at build time.
| Service | Image | Host ports |
|---|---|---|
dh-westpac-pingdirectory | pingidentity/pingdirectory:10.3.0.4-latest | internal |
dh-westpac-pingfederate | pingidentity/pingfederate:13.0.0-edge | internal |
dh-westpac-pingaccess | pingidentity/pingaccess:2601-8.3.2 | 9441→9441 |
dh-westpac-pingdatasync | pingidentity/pingdatasync:10.3.0.4-latest | internal |
dh-westpac-pingauthorize | pingidentity/pingauthorize:10.3.0.4-latest | internal |
dh-westpac-consentapp | tamatping/agentless-consentapp:20231123 | internal |
dh-westpac-mock-dh-api | tamatping/mock-dh-apis:20231123 | internal |
dh-westpac-kit-configure | tamatping/datain-configure-pf:20231123 | internal |
participants/dh-westpac/server-profiles/KIT-CHANGES.md
Westpac: changes from the Ping CDR Kit profiles
Generated by deploy/kit/build-dh.mjs westpac from vendor/pingidentity-cdr-sandbox/server_profiles. Do not edit by hand; change the generator and rebuild.
- Copied kit profiles
pingfederate,pingaccess,pingdirectory,pingdatasyncandpingdatagovernance(aspingauthorize), including the kit jars, unchanged except as listed. - PF: added LDAP PCV
cdrOtpPCV(clone of kitadrUserPCV) searchingou=peoplebyentryUUID,uidormobile; PD users carry the fixed demo OTP as their password. - PF: added HTML Form adapter
cdrOtpFormAdapter(clone of kithtmlFormAdapter) with templatehtml.form.otp.template.htmland PCVcdrOtpPCV. - PF:
identityFirstAdapterLDAP attribute source filteruid=${subject}->(|(uid=${subject})(mobile=${subject}))so customers sign in with their mobile. - PF: fragment
cdrPolicyFragmentNoMFAstepclickatellAdapter->cdrOtpFormAdapter(incoming user id = identifier-firstentryUUID, as the kit does for its consent adapter). The Clickatell adapter definition is kept, unused. - PF + PA: every
:6443(the kit's local-dev listener) ->:${DH_PUBLIC_PORT}so each DH has its own issuer port. - PF templates:
identifier.first.template.htmlre-skinned (mobile number), newhtml.form.otp.template.html,assets/brand/{brand.css,logo.svg}. - PA: engine listener "Local Dev Listener" and the
*:6443virtual hosts ->${DH_PUBLIC_PORT}; groovy rules referencing:6443and the hard-codedX-Forwarded-Port: 443likewise. - PD:
pd.profile/ldif/userRoot/10-users.ldifreplaced (kit CRN0-5) with this brand's customers fromdata/customers.json(uid = DH customer id, mobile, userPassword = demo OTP, entryUUID = nameUUIDFromBytes(customerId)). - Consent app: kit
agentless-consentappimage unchanged;consent-app/templates/index.html(same Thymeleaf model as the kit template) is loaded throughSPRING_THYMELEAF_PREFIX. - mock-dh-apis:
mock-dh-api/cachepre-seeds the kit image's own cache (/tmp/cache/<model>/<X-USER>/) fromdata/seed.json, keyed by PD entryUUID. - Compose fragment
docker-compose.yml,env/dh.env(fromdeploy/kit/templates), the kit's ownenv/pf.env+env/pa.env(kit demo key material), andscripts/smoke.{sh,mjs}.
Config browser
Read-only, from files tracked in git. Keys, keystores, .sec/, real env files and anything gitignored are left out; secret-looking values are shown as «redacted». 168 files.