Use the Maverics API to automate deployments
This guide walks you through the process of automating app deployments using our API. First you’ll create a user flow as a template for the policy and an environment as the deployment strategy for your orchestrators. Our API then enables you to create new applications and automatically deploy the policies.
This guide is structured to provide both overview and detailed instructions, making it suitable for IT professionals and administrators who are tasked with setting up and managing digital identities. We’ll cover the following steps:
- Prepare your environment
- Define your identity fabric
- Create a placeholder application
- Create a user flow with the placeholder
- Generate an access token
- Use the Maverics API
Prepare your environment
Before downloading and deploying an orchestrator, you’ll need to create an environment. For detailed information on how to set up an environment with different cloud storage services, see Configure environments.
When creating your environment:
- Ensure the environment you configure in the Maverics Cloud Console is configured to be a SAML or OIDC provider with, at minimum, an orchestrator URL.
- Validate that network and firewall settings allow communication between the auth provider and the orchestrator.
- Enable the Registration Endpoint, which will allow you to use the Maverics API.
Note that you must provide a URL for your orchestrator, which Maverics can use to automatically define several endpoints. Example endpoints are shown in the configuration example below.
issuer: https://maverics.sonarsystems.com
endpoints:
metadata: https://maverics.sonarsystems.com/idp/saml/metadata.xml
singleSignOnService: https://maverics.sonarsystems.com/sso
singleLogoutService: https://maverics.sonarsystems.com/slo
After you’ve created your environment, you will be directed to the Environment page, where you can download and install the orchestrator. See Install an orchestrator.
Define your identity fabric
The Maverics identity fabric includes an identity provider and optional attribute providers. Maverics identity providers integrate with several OIDC and SAML legacy and cloud identity providers and leverage them as either authentication providers or attribute providers. Some identity systems act as both authentication and attribute providers.
Go to Identity Fabric and make a selection in the Identity Services panel on the right. You can select any service for use with a SAML or OIDC app.
For more information on setting up an identity fabric, see Configure identity fabric.
Create a placeholder application
From the Applications page, create either a SAML app or OIDC app.
Use placeholder text for all of the values, as you will only be using this app to set up the user flow.
Click Create to save the configuration.
Create a user flow with the placeholder
Next, you’ll create a user flow selecting the app you’ve created.
From the dashboard, click Create user flow. Alternatively, from the sidebar, click User Flows, and click New. Enter a name for the user flow and select an application to use. Click Create.
When configuring your user flow:
- Under Authentication Provider, select an IDP you’ve configured.
- In the Attribute Providers section, select an attribute provider, a username mapping provider, and a username mapping attribute. Click Add to save your attribute. Repeat this process to add multiple attributes.
- The Claims section allows you to provide additional claims to this user. This maps claims to session attributes provided by the IDP(s) and any optionally defined AttributeProvider(s).
- Use the Attribute Providers section to select an attribute provider, a username mapping provider, and a username mapping attribute. Click Add to save your claim. Repeat this process to add multiple claims.
- Under NameID mapping, you can define custom NameID mappings in SAML responses. Select a provider and enter the attribute you want to define. Click Add to save the mapping.
- If you’ve configured Build Claims or Build Relay State service extensions, you can select them under Service Extensions.
- To save the complete user flow, click Deploy… at the top of the page.
- The Choose revision and environment modal appears. The Revision field reflects the latest number. Select an environment to deploy to and click Preview.
- On the Deployment Preview screen, you can view the revision history and a diff view of the current user flow against the new user flow (if you’re editing an existing user flow).
- Click Deploy at the top of the screen to deploy the latest revision to your selected environment.
Generate an access token
In order to use the Maverics Console API, you will need to create an access token. Click your user profile menu in the upper right corner and go to Developer settings. From the Developer settings page, click Generate access token.
- Enter a name for your access token.
- Select the environment you want to use.
- Select an expiration option.
- Click Submit.
Be sure to copy the access token immediately, as you will not be able to access this token again. You will need this token to call the Maverics API.
Use the Maverics API
By following the steps outlined in this guide, you have successfully set up automated app deployment in Maverics, laying the groundwork for a robust and secure identity management system.