Environment Variables Reference
Complete reference for all environment variables used by the CWMS Access Management system.
Java API Configuration
These variables configure the CWMS Data API (Java) authorization behavior.
Variable |
Required |
Default |
Description |
|---|---|---|---|
|
No |
|
Enable access management filtering in the Java API |
Enabling Access Management
The Java API ignores authorization headers by default. To enable filtering:
# Environment variable
export cwms.dataapi.access.management.enabled=true
# Or system property
java -Dcwms.dataapi.access.management.enabled=true -jar cwms-data-api.jar
# Or in docker-compose
environment:
- cwms.dataapi.access.management.enabled=true
Priority order: System Property > Environment Variable > Default (false)
When disabled, the AuthorizationContextHelper and AuthorizationFilterHelper classes return no-op values, allowing the API to function without the authorization proxy.
Proxy Configuration
The following variables configure the Authorization Proxy (TypeScript).
Server Configuration
Variable |
Required |
Default |
Description |
|---|---|---|---|
|
No |
|
HTTP server port |
|
No |
|
HTTP server bind address |
|
No |
|
Logging level: |
|
No |
- |
Environment mode: |
CWMS Data API Configuration
Variable |
Required |
Default |
Description |
|---|---|---|---|
|
Yes |
|
Base URL of the downstream CWMS Data API |
|
No |
|
Request timeout in milliseconds for downstream API calls |
|
No |
- |
API key for authenticating proxy requests to CWMS Data API |
OPA Configuration
Variable |
Required |
Default |
Description |
|---|---|---|---|
|
No |
|
Open Policy Agent server URL |
|
No |
|
OPA policy evaluation endpoint path |
|
No |
|
JSON array of endpoint prefixes requiring OPA authorization |
OPA Whitelist Configuration
The whitelist determines which endpoints go through OPA policy evaluation. Endpoints not in the whitelist bypass authorization and are proxied directly.
# Single endpoint
OPA_WHITELIST_ENDPOINTS='["/cwms-data/timeseries"]'
# Multiple endpoints
OPA_WHITELIST_ENDPOINTS='["/cwms-data/timeseries","/cwms-data/offices","/cwms-data/locations"]'
# All endpoints (use with caution)
OPA_WHITELIST_ENDPOINTS='["/cwms-data"]'
To manage the whitelist using the configuration file:
# Edit the whitelist file
vi opa-whitelist.json
# Load into environment
./scripts/load-whitelist.sh
# Restart the proxy
podman compose -f docker-compose.podman.yml down authorizer-proxy
podman compose -f docker-compose.podman.yml up -d authorizer-proxy
Redis Configuration
Variable |
Required |
Default |
Description |
|---|---|---|---|
|
No |
|
Redis connection URL for user context caching |
Redis URL Format
redis://[[username][:password]@][host][:port][/db-number]
Examples:
# Local development
REDIS_URL=redis://localhost:6379
# With authentication
REDIS_URL=redis://user:password@redis.example.com:6379
# With database selection
REDIS_URL=redis://localhost:6379/1
Cache Configuration
Variable |
Required |
Default |
Description |
|---|---|---|---|
|
No |
|
Time-to-live for cached items in seconds (5 minutes default) |
|
No |
|
Maximum number of items in the in-memory cache |
The proxy uses a two-tier caching strategy:
In-memory cache for fast access (configured by these variables)
Redis for distributed caching across multiple proxy instances
Keycloak Configuration
Variable |
Required |
Default |
Description |
|---|---|---|---|
|
No |
- |
Keycloak server base URL |
|
No |
- |
Keycloak admin username for management operations |
|
No |
- |
Keycloak admin password |
Docker Compose Port Mappings
These variables are used by docker-compose for port mapping:
Variable |
Default |
Description |
|---|---|---|
|
|
Management UI external port |
|
|
Management API external port |
|
|
Authorization Proxy external port |
|
|
Redis external port |
|
|
OPA external port |
|
|
Docker network name |
Example Configuration File
# Server Configuration
NODE_ENV=development
PORT=3001
HOST=0.0.0.0
LOG_LEVEL=debug
# CWMS Data API Configuration
CWMS_API_URL=http://data-api:7000/cwms-data
CWMS_API_TIMEOUT=30000
CWMS_API_KEY=
# OPA Configuration
OPA_URL=http://opa:8181
OPA_POLICY_PATH=/v1/data/cwms/authz/allow
OPA_WHITELIST_ENDPOINTS=["/cwms-data/timeseries","/cwms-data/offices"]
# Redis Configuration
REDIS_URL=redis://redis:6379
# Cache Configuration
CACHE_TTL_SECONDS=300
CACHE_MAX_SIZE=1000
# Authorization
BYPASS_AUTH=false
# Keycloak Configuration
KEYCLOAK_URL=http://auth:8080/auth
KEYCLOAK_ADMIN_USER=admin
KEYCLOAK_ADMIN_PASSWORD=admin
Production Recommendations
Variable |
Recommendation |
|---|---|
|
Set to |
|
Must be |
|
Increase to |
|
Generate and set a secure API key |
|
Use a strong, unique password |