CommBank ID + income

Participants · participants/dh-westpac

WBC Westpac

Westpac runs the full Ping CDR Kit data holder stack - PingFederate, PingAccess, PingDirectory, PingDataSync and PingAuthorize, plus the kit's consent app and mock banking API - each on its own server profile. The profiles are generated from the vendored kit by deploy/kit/build-dh.mjs, and every deviation from the kit is listed in KIT-CHANGES.md.

What it does

  • PingAccess is the only public entry point: mTLS, holder-of-key checks, Register status checks, DCR rewrite /register → /as/clients.oauth2.
  • PingFederate with pf-cdr-au-modules: DCR with SSA validation, PAR, signed request objects, cdr_arrangement_id, consent grants in PingDirectory, arrangement revocation.
  • Login is identifier-first (mobile) → OTP form (an LDAP PCV against PingDirectory, demo code 000789) → the kit agentless consent app with a branded, CX-laid-out template.
  • PingAuthorize is the kit's API gateway policy: validates the token, injects X-USER / X-ACCOUNTS, so only consented accounts come back.
  • About 4.2 GB per stack at steady state - run one at a time locally.

Ports and endpoints

PingAccess (only public entry)9441
Issuerhttps://sso.westpac.localhost:9441
CDS APIhttps://api.westpac.localhost:9441/cds-au/v1/banking
Consent apphttps://consent.westpac.localhost:9441

Railway

dh-westpac-paservice created, no public domain success
dh-westpac-pfservice created, no public domain success
dh-westpac-pdservice created, no public domain success
dh-westpac-pdsservice created, no public domain success
dh-westpac-pazservice created, no public domain success
dh-westpac-consentappservice created, no public domain success
dh-westpac-mockapiservice created, no public domain success
dh-westpac-configureservice created, no public domain success

Components and versions

Read from participants/dh-westpac/docker-compose.yml at build time.

ServiceImageHost ports
dh-westpac-pingdirectorypingidentity/pingdirectory:10.3.0.4-latestinternal
dh-westpac-pingfederatepingidentity/pingfederate:13.0.0-edgeinternal
dh-westpac-pingaccesspingidentity/pingaccess:2601-8.3.29441→9441
dh-westpac-pingdatasyncpingidentity/pingdatasync:10.3.0.4-latestinternal
dh-westpac-pingauthorizepingidentity/pingauthorize:10.3.0.4-latestinternal
dh-westpac-consentapptamatping/agentless-consentapp:20231123internal
dh-westpac-mock-dh-apitamatping/mock-dh-apis:20231123internal
dh-westpac-kit-configuretamatping/datain-configure-pf:20231123internal

participants/dh-westpac/server-profiles/KIT-CHANGES.md

Westpac: changes from the Ping CDR Kit profiles

Generated by deploy/kit/build-dh.mjs westpac from vendor/pingidentity-cdr-sandbox/server_profiles. Do not edit by hand; change the generator and rebuild.

Config browser

Read-only, from files tracked in git. Keys, keystores, .sec/, real env files and anything gitignored are left out; secret-looking values are shown as «redacted». 168 files.