Authn & Authz for Microservice: Docs Index

Explanation and walkthrough for the mobile-banking authn/authz PoC.

The story in one paragraph

A client logs in via Keycloak (IdP) and gets a JWT. It calls the banking API through
Kong (gateway / PEP). Kong introspects the token with Keycloak, then asks OPA (PDP)
whether this caller may take this action. If allowed, Kong forwards the request to
banking-api-service (resource server), which independently re-validates the JWT before
returning data. alice can read only her own accounts; ops-admin can read any account.

Reading map

Part I — Foundations

Part II — Component Deep Dives

  • 05 — Component Tour — one-paragraph map of all five components
  • 06 — Keycloak / IdP — the IdP that issues tokens
  • 07 — Kong — the gateway / PEP and its OPA plugin
  • 08 — OPA — the PDP and its Rego policy
  • 09 — banking-api-service — the resource server that re-validates
  • 10 — identity-bootstrap-service — demo user setup

Part III — Token Mechanics

  • 11 — JWT Signature, Validation & Introspection — signature, validation, introspection
  • 12 — JWKS Deep Dive — JWK/JWKS and key selection by kid
  • 13 — Access & Refresh Token Lifecycle — access/refresh tokens and renewal

Part IV — Reference

  • 14 — Request & Response Details — wire-level headers, bodies, claims

Where to start

Design and planning docs

  • Docs reorganization — design
  • Docs reorganization — plan
  • Mobile-banking auth — design
  • Mobile-banking auth — plan
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值