Skip to content

Quickstart

This is the path from an empty namespace to an install you can administer from the console, from a terminal, and from Terraform. Each step links to the page that explains it; follow the links the first time through.

Install cert-manager and an ingress controller on your cluster, clone the operator at a release tag, and deploy it:

Terminal window
git clone https://git.authwise.com/authwise/authwise-operator.git
cd authwise-operator && git checkout vOPERATOR_VERSION
kustomize build config/crd | kubectl apply --server-side -f -
make deploy IMG=registry.authwise.com/authwise/authwise-operator:OPERATOR_VERSION
kubectl -n authwise-operator-system rollout status deploy/authwise-operator-manager

OPERATOR_VERSION is a release such as 0.22.0; the operator’s releases page lists them. Install on Kubernetes has the prerequisites and what each step does.

Create a namespace, then the Secrets the install references: registry credentials for registry.authwise.com, a server secret, the two database owner passwords, and the platform keyset. Enrol the first administrator’s password into a hash you can commit. Each is one command on Prepare the namespace.

Write an AuthwiseIdentityServer from the sample on Write the install, with your hostnames, database, and SMTP relay, and apply it:

Terminal window
kubectl apply -f authwise.yaml
kubectl -n NAMESPACE get authwiseidentityservers -w

READY turns True once the database is bootstrapped and every workload has its replicas. kubectl describe on the object explains a False.

Open https://CONSOLE_HOST and sign in with the administrator’s email address and the password you enrolled. Then read the machine credential the operator minted for automation:

Terminal window
kubectl -n NAMESPACE get secret CR_NAME-admin-credential \
-o jsonpath='{.data.credential\.json}' | base64 -d

Store it somewhere durable: deleting the Secret does not mint another. See After the install.

Install awctl, export the credential’s values as AWCTL_* variables, point AWCTL_ENDPOINT at the Admin API, and list the realms in the admin tenant:

Terminal window
awctl identity realms list --tenant-id TENANT_ID

TENANT_ID is the admin tenant’s AWID, which the console shows.

Declare the provider with source = "authwisecom/authwise", export the same credential as AUTHWISE_* variables, set tenant_id and issuer_id on the provider block, and apply a first realm and client. From here, configuration inside the tenant is code.