Skip to content
Browse Gluu Flex 6.2.0

Configuration


tags:

  • administration
  • admin-ui
  • configuration

This document outlines the configuration process for Gluu Flex Admin UI, with a focus on essential components stored in the Auth Server's persistence layer. These components include Cedarling Configuration, OIDC client details for accessing the Auth Server, OIDC client details for accessing the Token Server, OIDC client details for accessing the License APIs, and license metadata.

#Configuration Components

#Cedarling Configuration

Gluu Flex Admin UI uses Cedarling for GUI access control. The role of the user is mapped with specific permissions (scopes) to ensure that the user can only access and modify functionalities relevant to their roles.

The Cedarling Policy Store configuration screen helps to upload the Policy Store archive file used for the Admin UI access control. The Gluu Flex Admin UI uses a default Policy Store after installation for GUI access control. You can upload a new Cedarling Policy Store and Admin UI backend will automatically synchronize roles and role-to-scope mapping as per the schema and policies defined in the Policy Store.

image

#Steps to create and upload Policy Store archive file

  1. Fork the project GluuFlexAdminUIPolicyStore.
  2. Open the forked GitHub repository using Agama Lab's Policy Designer.
  3. Make the required modifications in the policies for Admin UI access control and save the changes.
  4. Release the policy store archive file (with .cjar extension) from Agama Lab. image
  5. Download the released Policy Store archive file (with .cjar extension) from the releases section GitHub policy-store repository. image
  6. Open Cedarling Policy Store configuration screen on Admin UI and upload the Policy Store archive file.

#OIDC Client Details for Auth Server

To establish secure communication with the Auth Server, Gluu Flex Admin UI requires the OIDC client details, including client ID and client secret. These details are used for authentication and authorization purposes.

The information is stored in json format with following attributes.

Attribute NameDescription
auiWebClientObject with Web OIDC client details
opHostAuth Server hostname
clientIdClient Id of OIDC client used to access Auth server
clientSecretClient Secret of OIDC client used to access Auth server
scopesScopes required for Admin UI authentication
acrValuesACR required for Admin UI authentication
redirectUriRedirect UI which is Admin UI home page
postLogoutUriUrl to be redirected after Admin UI logout
frontchannelLogoutUriFront channel Logout Uri
additionalParametersThe custom parameters allow you to pass additional information to the authorization server during Admin UI authentication. Format: [{"key": "custom-param-key", "value": "custom-param-value"}, ...]

#OIDC Client Details for Backend API Server

Similarly, Gluu Flex Admin UI needs OIDC client details to interact with the Janssen Server via. Jans Config API protected APIs. The Backend API client enables the UI to request and manage access tokens required to access Jans Config API protected resources.

The information is stored in json format with following attributes.

Attribute NameDescription
auiBackendApiClientObject with Backend API client details
opHostToken Server hostname
clientIdClient Id of OIDC client used to access Token server
clientSecretClient Secret of OIDC client used to access Token server
tokenEndpointToken endpoint of token server

#Configuration Properties for User-Interface

Attribute NameDescription
uiConfigObject with UI configuration attributes

uiConfig

Attribute NameDescription
sessionTimeoutInMinsAdmin UI Frontend session out time
allowSmtpKeystoreEditAllow to edit SMTP keystore fields. The default value is true.
cedarlingLogTypeSet embeded Cedarling log-type in Admin UI. The allowed values are off and std_out.
auiPolicyStoreUrlPath of Policy Store archive file
auiDefaultPolicyStorePathThe path of the default Policy Store json file on Config Api pod.

#OIDC Client Details for License Server

Access to the License APIs is managed through OIDC client details. These details allows the Gluu Flex Admin UI Backend to generated access token to allow the retrieval of license-related information using license APIs.

The information is stored in json format with following attributes.

Attribute NameDescription
opHostAuth Server hostname used to generate token to access License APIs
clientIdClient Id of OIDC client used to generate token to access License APIs
clientSecretClient Secret of OIDC client used to generate token to access License APIs

#License Metadata

License metadata includes relevant information about the Gluu Flex Admin UI's licensing, such as License Key, Hardware id, License server url, License Auth server url, SSA used to register license auth server client.

The information is stored in json format with following attributes.

Attribute NameDescription
licenseConfigObject with License configuration details
ssaSSA used to register OIDC client to access license APIs
scanLicenseApiHostnameSCAN License server hostname
licenseKeyLicense-key to access Admin UI
licenseHardwareKeyHardware key (org_id) to access license APIs
intervalForSyncLicenseDetailsInDaysThe Admin UI backend syncs license details into the configuration (persistence) after the set interval (default: 30 days).
licenseValidUptoExpiry date to the subscribed flex license
licenseDetailsLastUpdatedOnThe date on which the license details were synced from Agama Lab to the Admin UI's License Configuration
productCodeThe product code of the issued license at LicenseSpring
licenseTypeThe license type of the issued license at LicenseSpring
licenseActiveIs the license configured currently active?
licenseExpiredIs the license configured expired?
licenseMAUThresholdThe allowed monthly active users for issued license
oidcClientObject with details of OIDC client to access license API

Sample configuration stored in persistence


{
  "oidcConfig": {
    "auiWebClient": {
      "introspectionEndpoint": null,
      "tokenEndpoint": null,
      "redirectUri": "https://your.host.com/admin",
      "postLogoutUri": "https://your.host.com/admin",
      "frontchannelLogoutUri": "https://your.host.com/admin/logout",
      "scopes": [
        "openid",
        "https://jans.io/auth/ssa.admin",
        "email",
        "profile",
        "offline_access",
        "jans_stat"
      ],
      "acrValues": [
        "simple_password_auth"
      ],
      "opHost": "https://your.host.com",
      "clientId": "xxxx.xxxxxxx-xxxx-xxxx-xxxx-xxxxxx",
      "clientSecret": "xxxxxxxxxxxxx",
      "additionalParameters": []
    },
    "auiBackendApiClient": {
      "introspectionEndpoint": "https://your.host.com/jans-auth/restv1/introspection",
      "tokenEndpoint": "https://your.host.com/jans-auth/restv1/token",
      "redirectUri": null,
      "postLogoutUri": null,
      "frontchannelLogoutUri": null,
      "scopes": [
        "openid",
        "https://jans.io/auth/ssa.admin"
      ],
      "acrValues": null,
      "opHost": "https://your.host.com",
      "clientId": "xxxx.xxxxxxx-xxxx-xxxx-xxxx-xxxxxx",
      "clientSecret": "xxxxxxxxxxxxx",
      "additionalParameters": null
    }
  },
  "licenseConfig": {
    "ssa": "eyJraWQiOiJzc2FfN2IyMGM1MDYtMDlhNi00MTU1LWF....",
    "scanLicenseApiHostname": "https://license-server-hostname.gluu.org",
    "licenseKey": "xxxx.xxxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "licenseHardwareKey": "xxxx.xxxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "licenseValidUpto": "2026-07-07",
    "licenseDetailsLastUpdatedOn": "2026-06-18",
    "productCode": "adminui001",
    "productName": "Gluu Admin UI",
    "licenseType": "time-limited",
    "customerFirstName": "",
    "customerLastName": "",
    "customerEmail": "trial_request",
    "companyName": "",
    "licenseActive": true,
    "licenseExpired": false,
    "licenseMAUThreshold": 1000,
    "intervalForSyncLicenseDetailsInDays": 30,
    "oidcClient": {
      "introspectionEndpoint": null,
      "tokenEndpoint": null,
      "redirectUri": null,
      "postLogoutUri": null,
      "frontchannelLogoutUri": null,
      "scopes": null,
      "acrValues": null,
      "opHost": "https://account-server-hostname.gluu.org",
      "clientId": "xxxx.xxxxxxx-xxxx-xxxx-xxxx-xxxxxx",
      "clientSecret": "xxxx.xxxxxxx-xxxx-xxxx-xxxx-xxxxxx",
      "additionalParameters": null
    }
  },
  "uiConfig": {
    "sessionTimeoutInMins": 31,
    "allowSmtpKeystoreEdit": true,
    "cedarlingLogType": "off",
    "auiPolicyStoreUrl": "",
    "auiDefaultPolicyStorePath": "./custom/config/adminUI/policy-store.cjar"
  }
}

We use analytics cookies to measure which pages are useful, so we can improve them. They are only set if you accept. Essential cookies needed for the site to work are always on. See our privacy policy.