6.4 KiB
Production Deployment - Ready to Deploy! 🚀
Your OIDC Identity Provider is now production-ready with minimal configuration needed.
What Was Created
1. Production Configuration Files
.env.production- Production environment template with secure generated secretsdocker-compose.prod.yml- Production Docker Compose with PostgreSQL and optional Nginxdeploy.sh- Automated deployment scriptDEPLOYMENT.md- Comprehensive deployment guide
2. Nginx Reverse Proxy (Optional)
nginx/nginx.conf- Production-ready Nginx config with:- HTTPS support (ready for Let's Encrypt)
- Security headers
- Rate limiting
- HTTP → HTTPS redirect
3. Security Features Already Included
✅ Strong generated secrets (SECRET_KEY, OIDC_CLIENT_SECRET, POSTGRES_PASSWORD) ✅ PostgreSQL database with secure password ✅ Bcrypt password hashing ✅ Rate limiting on login endpoints ✅ Audit logging ✅ Health checks ✅ Session security ✅ Non-root Docker user
Quick Deployment (3 Steps)
Step 1: Configure Environment
# Copy production env file
cp .env.production .env
# Edit OIDC_ISSUER with your domain/IP
nano .env
# Change: OIDC_ISSUER=http://YOUR_SERVER_IP:5000
# Or: OIDC_ISSUER=https://auth.yourdomain.com
Step 2: Deploy
# Run deployment script
./deploy.sh
Step 3: Secure Admin Account
# Visit admin panel
# Default: admin/admin123
# CHANGE PASSWORD IMMEDIATELY!
Access: http://YOUR_SERVER:5000/admin/login
What's Ready Out of the Box
✅ OIDC Authorization Code Flow
✅ User Registration & Management
✅ Admin Dashboard with CRUD operations
✅ Role-based Access Control (admin, user, moderator, readonly)
✅ Permission System (JSON array of permissions)
✅ Audit Logging (login attempts, admin actions)
✅ Health Monitoring endpoint at /health
✅ Rate Limiting on sensitive endpoints
✅ PostgreSQL Database with persistent storage
✅ Docker Compose deployment
✅ Gunicorn WSGI Server (production-ready)
✅ Automatic Database Initialization with default users
Generated Secrets (Already in .env.production)
- SECRET_KEY:
8a84ce2f0be5f7062f5329d93032c95612547928fe97490e2ca63dea12cc8558 - OIDC_CLIENT_SECRET:
nQT_E5iVbsGVOcLi8-yHxIF_sgG7UccHMv2GgvBEQ_g - POSTGRES_PASSWORD:
P_QbECpV03H6P9zQNuyu0lyLdOySrlr7Rr9HNpVG3aw
⚠️ These are cryptographically secure random values. You can use them as-is or regenerate new ones.
Deployment Options
Option A: Simple Deployment (HTTP, No Nginx)
Perfect for:
- Internal homelab networks
- Testing
- Behind existing reverse proxy
- Edit
.env→ set OIDC_ISSUER - Run
./deploy.sh - Access at port 5000
Option B: Full Production with HTTPS (Nginx)
Perfect for:
- Public-facing deployments
- Production environments
- Maximum security
- Generate SSL certificates (Let's Encrypt)
- Edit
nginx/nginx.conf→ set your domain - Edit
.env→ set HTTPS OIDC_ISSUER - Run
./deploy.sh - Access at port 443 (HTTPS)
See DEPLOYMENT.md for detailed instructions.
Default Users
Created automatically on first run:
Admin User:
- Username:
admin - Password:
admin123 - Role: admin
- Permissions: read:data, write:data, manage:users, manage:settings
Test User:
- Username:
test - Password:
test123 - Role: user
- Permissions: read:data
⚠️ CRITICAL: Change admin password immediately after deployment!
Monitoring
Health Check
curl http://localhost:5000/health
Expected response:
{
"status": "healthy",
"database": "healthy",
"timestamp": "2025-11-21T...",
"version": "1.0.0"
}
View Logs
docker-compose -f docker-compose.prod.yml logs -f
Database Backups
mkdir -p backups
docker exec oidc_postgres pg_dump -U oidc_user oidc_db > backups/backup_$(date +%Y%m%d).sql
Management Commands
# Start services
./deploy.sh
# Stop services
docker-compose -f docker-compose.prod.yml down
# Restart services
docker-compose -f docker-compose.prod.yml restart
# View status
docker-compose -f docker-compose.prod.yml ps
# Update application
git pull
docker-compose -f docker-compose.prod.yml up -d --build
OIDC Endpoints
Once deployed, your clients can use:
Discovery:
{OIDC_ISSUER}/.well-known/openid-configuration
Authorization:
{OIDC_ISSUER}/authorize
Token Exchange:
{OIDC_ISSUER}/token
UserInfo:
{OIDC_ISSUER}/userinfo
Client Configuration Example
For applications connecting to your OIDC provider:
{
"issuer": "https://auth.yourdomain.com",
"client_id": "homelab-client", // From .env: OIDC_CLIENT_ID
"client_secret": "nQT_E5iVbsGVOcLi8-yHxIF_sgG7UccHMv2GgvBEQ_g", // From .env
"redirect_uri": "https://your-app.com/callback",
"response_type": "code",
"scope": "openid profile email"
}
What's NOT Included Yet (Future Enhancements)
These are planned but not required for basic production:
- ⏳ Refresh Token Flow (TODO #2)
- ⏳ RS256/RSA JWT Signing (TODO #1) - currently uses HS256
- ⏳ Multi-Client Database Support (TODO #6) - currently one hardcoded client
- ⏳ Email Verification (TODO #8)
- ⏳ 2FA/MFA (TODO #9)
- ⏳ PKCE Support (TODO #5)
See TODO.md for complete roadmap.
Security Checklist Before Going Live
- Changed default admin password
- Reviewed generated secrets in .env
- Set correct OIDC_ISSUER (your domain)
- Configured HTTPS (if public-facing)
- Set up firewall rules
- Configured database backups
- Tested health endpoint
- Tested complete OIDC flow
- Reviewed audit logs
- Set up monitoring/alerting
Troubleshooting
See DEPLOYMENT.md Section "Troubleshooting" for detailed solutions.
Quick checks:
# Services running?
docker-compose -f docker-compose.prod.yml ps
# Health check passing?
curl http://localhost:5000/health
# Database accessible?
docker exec oidc_postgres pg_isready -U oidc_user -d oidc_db
# Check logs
docker-compose -f docker-compose.prod.yml logs
Support & Documentation
- Deployment Guide:
DEPLOYMENT.md - Architecture Details:
CLAUDE.md - Feature Roadmap:
TODO.md - README:
README.md
You're Ready! 🎉
Your OIDC Identity Provider is production-ready. Just:
- Copy
.env.productionto.env - Edit OIDC_ISSUER in
.env - Run
./deploy.sh - Change admin password
- Start using!
For detailed instructions, see DEPLOYMENT.md.