-
Notifications
You must be signed in to change notification settings - Fork 72
Expand file tree
/
Copy pathkeycloak-devstack.env
More file actions
71 lines (63 loc) · 3.17 KB
/
Copy pathkeycloak-devstack.env
File metadata and controls
71 lines (63 loc) · 3.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
# Environment variables containing the SINGLE SOURCE OF TRUTH for values shared
# between both keycloak provisioning and LMS Third Party Auth provisioning.
# ===========================================================================
# Shared across both Gryffindor and Slytherin tenants.
# ===========================================================================
# Keycloak base URL (Docker hostname, reachable from the LMS container and host).
# Reminder: Manually configure this /etc/hosts entry: "127.0.0.1 edx.devstack.keycloak"
KEYCLOAK_URL=http://edx.devstack.keycloak:8080
# LMS Service Provider entity ID.
# Must match the LMS SAMLConfiguration.entity_id AND the Keycloak SAML Client ID.
SP_ENTITY_ID=http://localhost:18000
# SAML Assertion Consumer Service URL — the LMS endpoint that receives the SAML
# response POST from Keycloak after the user authenticates.
ACS_URL=http://localhost:18000/auth/complete/tpa-saml/
# Standard OIDs for SAML assertion attributes. The SAMLProviderConfig in the
# LMS (see provision-tpa.py) references the same OIDs so the pipeline can extract
# user details from the assertion.
# OID_EMAIL: RFC 2798 mail
# OID_GIVEN_NAME: X.520 givenName
# OID_SURNAME: X.520 sn (surname)
OID_EMAIL=urn:oid:0.9.2342.19200300.100.1.3
OID_GIVEN_NAME=urn:oid:2.5.4.42
OID_SURNAME=urn:oid:2.5.4.4
# Keycloak-side password for every SSO test user. Injected into the realm JSON
# user credentials (keycloak-realms/*.json) at import time and echoed by
# provision-tpa.py as the login hint.
SSO_PASSWORD=testpass
# ===========================================================================
# Gryffindor IdP + Enterprise + couple of learners
# ===========================================================================
GRYFFINDOR_REALM=gryffindor
GRYFFINDOR_ENTERPRISE_NAME=Gryffindor
GRYFFINDOR_PRIMARY_COLOR=#740001
GRYFFINDOR_SECONDARY_COLOR=#D3A625
GRYFFINDOR_TERTIARY_COLOR=#EEBA30
# An SSO user fully linked to an existing LMS user.
GRYFFINDOR_LEARNER_USERNAME=gryffindor_learner
GRYFFINDOR_LEARNER_EMAIL=gryffindor_learner@example.com
GRYFFINDOR_LEARNER_FIRST_NAME=Harry
GRYFFINDOR_LEARNER_LAST_NAME=Potter
# A "newcomer" is an SSO user who does not have an LMS user.
GRYFFINDOR_NEWCOMER_USERNAME=gryffindor_newcomer
GRYFFINDOR_NEWCOMER_EMAIL=gryffindor_newcomer@example.com
GRYFFINDOR_NEWCOMER_FIRST_NAME=Newcomer
GRYFFINDOR_NEWCOMER_LAST_NAME=Gryffindor
# ===========================================================================
# Slytherin IdP + Enterprise + couple of learners
# ===========================================================================
SLYTHERIN_REALM=slytherin
SLYTHERIN_ENTERPRISE_NAME=Slytherin
SLYTHERIN_PRIMARY_COLOR=#1A472A
SLYTHERIN_SECONDARY_COLOR=#2A623D
SLYTHERIN_TERTIARY_COLOR=#AAAAAA
# An SSO user fully linked to an existing LMS user.
SLYTHERIN_LEARNER_USERNAME=slytherin_learner
SLYTHERIN_LEARNER_EMAIL=slytherin_learner@example.com
SLYTHERIN_LEARNER_FIRST_NAME=Draco
SLYTHERIN_LEARNER_LAST_NAME=Malfoy
# A "newcomer" is an SSO user who does not have an LMS user.
SLYTHERIN_NEWCOMER_USERNAME=slytherin_newcomer
SLYTHERIN_NEWCOMER_EMAIL=slytherin_newcomer@example.com
SLYTHERIN_NEWCOMER_FIRST_NAME=Newcomer
SLYTHERIN_NEWCOMER_LAST_NAME=Slytherin