AuthBox documentation — Getting started

Documentation embedded in this build.

1. Run it

Everything below happens on one machine, from a checkout. This is a worked deployment for looking at, not a deployment of your own — when you want one of those, the first boot wizard is the last page in this series.

You need Go 1.27 or newer and docker. Dependencies are vendored, so the build makes no network call at all.

One command

$ make all-in-one

That builds the images, generates a fresh certificate authority and every piece of runtime material the stack needs, brings the containers up, and then runs a live smoke over all of it. The first run spends most of its time building. When it finishes it prints a directory of everything it stood up.

What comes up

Every certificate in that list was minted a minute ago by an authority that exists only in your runtime directory.

Where to look

The epilogue prints a runtime directory. Inside it, under gen/, are the fixture credentials the bring-up made — including browser-importable bundles, passphrase authbox, which are the fastest way to see the console as somebody in particular. Import one and open the console door.

Two things are worth doing before you move on. Open the console and click through a person's record; then look at the audit page and find the decision the smoke just made. The reason a request was refused is in that record and never in the response — a refusal that explains itself is a way of asking questions about other people's standing.

When you are finished

$ make all-in-one-down          # stop the containers
$ make all-in-one-down CLEAN=1  # and remove the runtime directory

Every full run mints a fresh authority, so certificates you imported into a browser stop working the next time you bring it up. That is deliberate.

Next: Enrol your first person