Docker (All-in-One)
tags:
- administration
- installation
- quick-start
- docker
- aio
- all-in-one
The quickest way to get Gluu Flex up and running is a Docker container-based full-featured Flex using the All-In-One (AIO) script.
#System Requirements
System should meet the following requirements:
- 8 GB RAM
- 4 CPU
- 20 GB Disk
#Install
To deploy Flex AIO, first download the installation script and make it executable:
wget https://raw.githubusercontent.com/GluuFederation/flex/nightly/automation/start_flex_aio_demo.sh
chmod u+x start_flex_aio_demo.sh
Next, execute the script. You will need to provide the following details:
- Fully qualified domain name (FQDN)
- Persistence type (
MYSQLorPGSQL) - Flex version (leave empty
""for the default) - Virtual Machine's Public IP address in place of
<VM_IP>
sudo bash start_flex_aio_demo.sh demoexample.gluu.org MYSQL "" <VM_IP>sudo bash start_flex_aio_demo.sh demoexample.gluu.org PGSQL "" <VM_IP>Console messages like below will confirm the successful startup and readiness of the services:
[I] Flex is starting up!
[I] To check the progress, run 'docker compose logs -f' in a separate terminal
[I] Checking if Flex is ready to accept requests (expected time ~3–5 minutes) ...
[I] Waiting 120 seconds for services to initialize before starting health checks. Hang on...
[W] Flex is not ready yet; retrying in 10 seconds ...
[I] Flex is ready to accept requests#Verify Installation By Accessing Standard Endpoints
#Update the IP domain record
To access Flex standard endpoints from outside the Docker container, your system's /etc/hosts file needs to be updated. Open the file and add the IP domain record, which should be the IP of the instance where Docker is installed (your <VM_IP>), followed by the hostname used during installation (demoexample.gluu.org).
# For example
VM_IP demoexample.gluu.org#Test the well-known endpoint
After adding the record, test the standard endpoints such as:
https://demoexample.gluu.org/.well-known/openid-configuration#Configure Flex
Flex can be configured using the Text-based User Interface (TUI).
Download the
jans-cli-tuifrom the release assets depending on your OS. For example:wget https://github.com/JanssenProject/jans/releases/download/nightly/jans-cli-tui-linux-ubuntu-X86-64.pyzTo connect to the TUI, you need your FQDN, Client ID, and Client Secret. Since the AIO deployment stores configurations in Consul and Vault, you can extract these credentials directly from the running Docker containers.
Run the following commands on your host machine to store the credentials in environment variables:
FQDN="demoexample.gluu.org"TUI_CLIENT_ID=$(docker exec consul consul kv get flex/config/tui_client_id)VAULT_TOKEN=$(docker exec vault grep 'Initial Root Token' /vault/config/vault_key_token.txt | awk -F ': ' '{print $2}')TUI_CLIENT_SECRET=$(docker exec -e VAULT_TOKEN=$VAULT_TOKEN vault vault read -field=value secret/flex/tui_client_pw)Connect to the TUI using the downloaded
.pyzfile and the extracted credentials. Add-noverifyif you are using the self-signed certificates generated by the demo script.python3 jans-cli-tui-linux-ubuntu-X86-64.pyz \ --host $FQDN --client-id $TUI_CLIENT_ID \ --client-secret $TUI_CLIENT_SECRET -noverifyNote that the default
adminpassword isTest1234#
#Uninstall / Remove Flex
This Docker-based installation uses docker compose under the hood to create the network and containers, and it stores volume data and templates in a local flex-aio-demo directory.
Run the command below in the same directory where you executed the installation script to stop the containers, remove them, and clean up the generated files and volumes:
sudo docker compose down -v && sudo rm -rf flex-aio-demo compose.yaml compose.override.yamlConsole messages like below confirm the successful removal:
[+] down 6/6
✔ Container flex Removed 3.8s
✔ Container traefik Removed 0.9s
✔ Container mysql Removed 3.8s
✔ Container vault Removed 10.4s
✔ Container consul Removed 0.2s
✔ Network flex-aio-demo Removed 0.1s