Quickstart
This is the path from an empty namespace to an install you can administer from the console, from a terminal, and from Terraform. Each step links to the page that explains it; follow the links the first time through.
1. Install the operator
Section titled “1. Install the operator”Install cert-manager and an ingress controller on your cluster, clone the operator at a release tag, and deploy it:
git clone https://git.authwise.com/authwise/authwise-operator.gitcd authwise-operator && git checkout vOPERATOR_VERSIONkustomize build config/crd | kubectl apply --server-side -f -make deploy IMG=registry.authwise.com/authwise/authwise-operator:OPERATOR_VERSIONkubectl -n authwise-operator-system rollout status deploy/authwise-operator-managerOPERATOR_VERSION is a release such as 0.22.0; the operator’s releases page
lists them. Install on Kubernetes has the
prerequisites and what each step does.
2. Prepare the install’s namespace
Section titled “2. Prepare the install’s namespace”Create a namespace, then the Secrets the install references: registry
credentials for registry.authwise.com, a server secret, the two database
owner passwords, and the platform keyset. Enrol the first administrator’s
password into a hash you can commit. Each is one command on
Prepare the namespace.
3. Apply the install
Section titled “3. Apply the install”Write an AuthwiseIdentityServer from the sample on
Write the install, with
your hostnames, database, and SMTP relay, and apply it:
kubectl apply -f authwise.yamlkubectl -n NAMESPACE get authwiseidentityservers -wREADY turns True once the database is bootstrapped and every workload has
its replicas. kubectl describe on the object explains a False.
4. Sign in and read the credential
Section titled “4. Sign in and read the credential”Open https://CONSOLE_HOST and sign in with the administrator’s email address
and the password you enrolled. Then read the machine credential the operator
minted for automation:
kubectl -n NAMESPACE get secret CR_NAME-admin-credential \ -o jsonpath='{.data.credential\.json}' | base64 -dStore it somewhere durable: deleting the Secret does not mint another. See After the install.
5. Connect awctl
Section titled “5. Connect awctl”Install awctl, export the credential’s values as AWCTL_*
variables, point AWCTL_ENDPOINT at the Admin API, and list the realms in the
admin tenant:
awctl identity realms list --tenant-id TENANT_IDTENANT_ID is the admin tenant’s AWID, which the console shows.
6. Connect Terraform
Section titled “6. Connect Terraform”Declare the provider with
source = "authwisecom/authwise", export the same credential as AUTHWISE_*
variables, set tenant_id and issuer_id on the provider block, and apply a
first realm and client. From here, configuration inside the tenant is code.