Installation¶
What it needs¶
| What | Why |
|---|---|
| PHP | 8.4 or later |
| Database | PostgreSQL, through Doctrine ORM |
| A key management service | To seal the signing keys and the data keys. For development, a local file-backed client is enough; a deployment uses Vault, AWS KMS or another provider symfony/key-management supports |
| TLS | The provider serves nothing useful over plain HTTP, and the specifications require HTTPS on every endpoint |
A message broker is recommended but not required to start: writes that the protocol does not need the result of are dispatched asynchronously, and the synchronous transport works until you wire a real one.
Nothing is published yet
The beffroi/* packages are not on Packagist at this point, so the commands below describe the
installation of the version this documentation follows rather than one you can run today. The pages are
written now so that the first release does not ship undocumented.
In a Symfony application¶
Without Symfony Flex, register the bundle yourself:
Then import the routes of the bundle under the path your issuer uses. A provider whose issuer is
https://op.example.com imports them at the root:
The smallest configuration that boots names the issuer and the key management client the private keys are sealed with:
beffroi:
tenant:
issuer: '%env(BEFFROI_ISSUER)%'
keys:
kms: default
key_id: '%env(BEFFROI_KMS_KEY_ID)%'
storage: '%kernel.project_dir%/var/keys'
clients: []
The issuer is the exact string the provider announces as iss and the prefix every endpoint is served
under. It is not a cosmetic setting: a client compares it byte by byte, and changing it later invalidates
every token in flight.
As an application of its own¶
If you have no application to host it, do not write one. beffroi/op is the Symfony skeleton, the bundle
and FrankenPHP already assembled, and it is the deployment the project supports.
Then¶
- The tenant and its keys, without which nothing can be signed.
- Your first client, so something can ask for a token.
- A Symfony relying party, to see a sign-in end to end.