Skip to content

Latest commit

 

History

History
78 lines (55 loc) · 3.81 KB

File metadata and controls

78 lines (55 loc) · 3.81 KB

Authorizer on Render

Deploy production ready authorizer.dev instance on Render with a managed PostgreSQL database and build with it in 30seconds

Deploy to Render

After clicking the above button, follow the steps mentioned below:

Step 1: Enter app details

Enter the name for your instance.

Note: Optionally you can choose to deploy a branch without-postgres and configure database env, if you already have a postgres instance running.

Step 2: Configure Required Variables

Authorizer v2 requires the following variables. Configure them in Render's environment settings:

Variable Description Example
DATABASE_TYPE Database type postgres
DATABASE_URL Database connection string (auto-configured by Render)
JWT_TYPE JWT signing algorithm HS256
JWT_SECRET JWT signing secret test
ENCRYPTION_KEY At-rest key for TOTP secrets and OTP digests. Required with RS*/ES* (output of openssl rand -hex 32)
ADMIN_SECRET Admin secret for admin operations admin
CLIENT_ID Client identifier (required) 123456
CLIENT_SECRET Client secret (required) secret

Optional environment variables

Variable Description Default
METRICS_HOST Bind address for /metrics (--metrics-host) 127.0.0.1
METRICS_PORT Port for /metrics (--metrics-port) 8081
RATE_LIMIT_RPS Per-IP requests/sec (--rate-limit-rps) 30
RATE_LIMIT_BURST Per-IP burst (--rate-limit-burst) 20
RATE_LIMIT_FAIL_CLOSED true = 503 on rate-limit backend errors (--rate-limit-fail-closed) false
REDIS_URL Redis for sessions + shared rate limits if you scale to multiple instances (unset)

These are mapped to CLI flags at startup.

Upgrading to 2.4.0

ENABLE_EMAIL_VERIFICATION=true with no SMTP configured is now a fatal boot error, not a warning. Every account-recovery route ends at the same mailbox, so without a mail path a user is created unverified and can never recover. If you set it, also set SMTP_HOST, SMTP_PORT and SMTP_SENDER_EMAIL — all three — or the container will exit on start.

APP_COOKIE_SAME_SITE is now validated at boot too: an unrecognised value exits rather than silently falling back to lax.

Two optional flags were added for the 2.4.0 security changes, both defaulting to the secure behaviour:

  • OAUTH_ALLOW_UNVERIFIED_PROVIDER_EMAIL — a social login whose provider did not attest the email address no longer reaches an existing account. Set true only as a temporary compatibility measure.
  • FGA_ALLOW_UNCONSTRAINED_AGENTS — a delegated (agent-acting-for-user) check against an authorization model with no type agent now denies. Set true only while migrating a model.

MICROSOFT_ALLOWED_TENANTS restricts which Entra tenants may sign in when MICROSOFT_TENANT_ID is a multi-tenant alias (common/organizations/ consumers). Please refer to the server configuration docs for all available flags.

Notes

Updating Authorizer on existing Render instance

  • You can update the docker image to the desired version in your repository which gets created with your deployment.

  • You can find all the versions on github or Quay