Skip to content

[issue:597] Add PKCS12 keystore support to mock-identity-system as an alternative to SoftHSM - #599

Merged
anushasunkada merged 1 commit into
mosip:developfrom
SwapnilWorks-Devops:issue-597-pkcs12-mock-identity-system-v2
Jul 28, 2026
Merged

[issue:597] Add PKCS12 keystore support to mock-identity-system as an alternative to SoftHSM#599
anushasunkada merged 1 commit into
mosip:developfrom
SwapnilWorks-Devops:issue-597-pkcs12-mock-identity-system-v2

Conversation

@SwapnilWorks-Devops

@SwapnilWorks-Devops SwapnilWorks-Devops commented Jul 15, 2026

Copy link
Copy Markdown

Summary

Closes #597

  • install.sh now prompts to opt into a PKCS12 mounted-volume keystore instead of SoftHSM, creates the keystore password secret (default 1234, overridable), and wires the corresponding persistence/env config into the helm install.
  • SoftHSM provisioning (secret/configmap copy, env vars) now only runs when PKCS12 is not selected — previously applied unconditionally regardless of choice.
  • Helm chart (helm/mock-identity-system):
    • Added a PersistentVolumeClaim template (didn't exist before — persistence.enabled had no backing PVC resource).
    • Fixed the volume-permissions init container, which had a literal unfilled %%commands%% placeholder and stub foo/bar volume mount names — this caused a YAML parse error (found character that cannot start any token) the first time persistence.enabled + volumePermissions.enabled were actually exercised together.
    • Wired the persistence volume into the main container's volumeMounts and the pod's volumes (previously absent).
    • Added extraEnvVarsAdditional support (additive on top of extraEnvVars, doesn't require restating the whole list), matching the existing pattern in the esignet chart.

Test plan

  • Verified chart renders cleanly via helm template for both the PKCS12 branch (PVC + persistence volume + PKCS12 env vars, zero SoftHSM references) and the SoftHSM branch (unchanged env vars/configmap, no PVC).
  • Ran install.sh end-to-end against a live cluster with PKCS12 opted in: PVC created and bound, keystore secret created, deployment came up with correct volume mounts and env vars.
  • Run install.sh end-to-end with the default SoftHSM path (n) to confirm no regression, once the chart changes here are published (script currently references the chart by published version).

(Recreated from #598, which was missing a DCO sign-off.)

… alternative to SoftHSM

install.sh now prompts to opt into a PKCS12 mounted-volume keystore instead
of SoftHSM; SoftHSM provisioning only runs when PKCS12 isn't selected. The
chart gained a PersistentVolumeClaim template, a fixed volume-permissions
init container (was a literal unfilled placeholder), persistence volume
wiring in the deployment, and additive extraEnvVarsAdditional support.

Signed-off-by: Swapnil <swapnil.mohanty@technoforte.co.in>
@coderabbitai

coderabbitai Bot commented Jul 15, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@SwapnilWorks-Devops, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 53 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 64b3cd99-f742-4ab1-891b-ac581ab8d0cb

📥 Commits

Reviewing files that changed from the base of the PR and between 815e67b and 89bbd26.

📒 Files selected for processing (4)
  • deploy/mock-identity-system/install.sh
  • helm/mock-identity-system/templates/deployment.yaml
  • helm/mock-identity-system/templates/pvc.yaml
  • helm/mock-identity-system/values.yaml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@anushasunkada
anushasunkada merged commit 716d0f0 into mosip:develop Jul 28, 2026
19 checks passed
sacrana0 added a commit that referenced this pull request Aug 27, 2026
* Added PKCE implementation

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* fixed coderabbit comment

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* Corrected the logic to full dynamic identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed review comments

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* added proxy pass for par and dpop (#554)

Signed-off-by: Harsh Kashiwal <harsh.kashiwal@infosys.com>

* resolved comments

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* resolved review comment

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* resolve review comments

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* set active_profile_env to "default" in deployment (#558) (#560)

Signed-off-by: Sachin Rana <sacrana324@gmail.com>

* docs: fix typos, remove duplicate overview, and improve README formatting (#561) (#563)

Signed-off-by: Nandhukumar <nandhukumare@gmail.com>

* Added endpoint to fetch identity schema (#564)

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed testcase

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

---------

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed the required field validation error (#565)

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed required fields validation error

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

---------

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Snapshot updates 0.13.0 -> 0.13.1

Signed-off-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com>

* [ES-2962] Added error messages for login_required and request_not_supported error.

Signed-off-by: GurukiranP <talk2gurukiran@gmail.com>

* [ES-1616] Added new error message.

Signed-off-by: GurukiranP <talk2gurukiran@gmail.com>

* [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock

Signed-off-by: Abhi <abhishek.shankarcs@gmail.com>

* [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock (#579)

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* Updating sign-in-with-esignet, removing optional parameter from config (#590)

* [MODIFIED] used npm library for sign-in-with-esignet

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] ignore optional parameter in sign-in-with-esignet

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] readme file

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] coderabbit comment resolved

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] review comment addressed

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] readme updated

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

---------

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1996] added configurable token and userinfo endpoint (#591)

* [1996] added configurable token and userinfo endpoint

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1996] add kid only, if private key has it

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1996] default value of token & userinfo endpoint

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

---------

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1966] bypass for json userInfoResponse (#592)

* [1966] bypass for json userInfoResponse

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1966] bypass for json userInfoResponse

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

---------

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [mosip/mosip-infra#1890] Added domainConfig support in helm charts (#589)

* [mosip/mosip-infra#1890] Removed esignet-global, added domainConfig support in helm charts

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* [mosip/mosip-infra#1890] Set chart versions to 0.0.1-develop

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* migrate to domainConfig helm values
 #1890

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

---------

Signed-off-by: bhumi46 <thisisbn46@gmail.com>
Co-authored-by: bhumi46 <bhumi11111a@gmail.com>

* Gpg update Test  (#596)

* ci: point kattu maven workflows at @develop to test kattu#353

Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis(-new)
reusable-workflow references to mosip/kattu@develop so the GPG-key-import
migration (mosip/kattu#353) is exercised by this repo's CI once it merges.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

* ci: pass GPG_PRIVATE_KEY secret from caller workflows (kattu#353)

kattu#353 imports the signing key from the GPG_PRIVATE_KEY secret (now
required: true in maven-build / maven-publish-to-nexus workflow_call), so
the caller must forward it. Added GPG_PRIVATE_KEY to the maven-build and
maven-publish-to-nexus caller jobs only (sonar workflows don't declare it).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

* ci: point maven workflows at Mahesh-Binayak/kattu@gpgupdate-masterj21

gpgupdate-masterj21 = master-java21 + the GPG-secret-import / key-age /
simplify4u-pgpverify changes, keeping master-java21's interface intact.
Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis to it,
restores MAVEN_NON_EXEC_ARTIFACTS, and forwards GPG_PRIVATE_KEY to the
build/publish jobs. Other workflows (docker-build, npm-*, sonar-new@develop)
and commented refs are left unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

* ci: point maven workflows at mosip/kattu@gpgupdate-masterj21

The gpgupdate-masterj21 branch now lives on mosip/kattu; reference it
there instead of the fork. Interface unchanged; GPG_PRIVATE_KEY forwarded.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

---------

Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* [issue:1963] Updated helm for thunder deployment (#593)

Signed-off-by: Prafulrakhade <prafulrakhade02@gmail.com>

* [issue:597] Add PKCS12 keystore support to mock-identity-system as an alternative to SoftHSM (#599)

install.sh now prompts to opt into a PKCS12 mounted-volume keystore instead
of SoftHSM; SoftHSM provisioning only runs when PKCS12 isn't selected. The
chart gained a PersistentVolumeClaim template, a fixed volume-permissions
init container (was a literal unfilled placeholder), persistence volume
wiring in the deployment, and additive extraEnvVarsAdditional support.

Signed-off-by: Swapnil <swapnil.mohanty@technoforte.co.in>

* Fix default prompt value (#600)

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>
Co-authored-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* #10670: Add AGENTS.md tree for AI coding assistant guidance

Adds a root AGENTS.md hub covering the repository as a whole, plus
per-module AGENTS.md guides for mock-identity-system,
mock-relying-party-service, mock-relying-party-ui,
mock-relying-party-ui-esim, and partner-onboarder — the independently
buildable modules in this repo. Each guide documents purpose, layout,
how to run/build/test, configuration, and explicit agent do/do-not
rules, verified against the actual READMEs, pom.xml/package.json
files, and GitHub Actions workflows in this repo.

Addresses mosip/mosip-config#10670

Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>

* #10670: Address CodeRabbit review feedback on AGENTS.md

- Stop prescribing npm test for every Node/React module; point to
  each module's own AGENTS.md/README.md since scripts differ
  (mock-relying-party-service has no test script at all).
- Fix docker-compose path in mock-identity-system/AGENTS.md: from the
  repo root it's docker-compose/, not ../docker-compose/.
- Use MOCK_RELYING_PARTY_SERVER_URL in the mock-relying-party-ui-esim
  Docker example, matching the variable the Dockerfile/UI actually
  read (MOCK_RELYING_PARTY_BASE_URL has no effect).
- Note that partner-onboarder targets a non-production eSignet
  deployment only, per the root README's repo-wide scope.

Addresses review comments on #601

Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>

* fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps (#603)

* fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps

Helm merges map keys across values layers but replaces lists wholesale,
so any downstream override of extraEnvVars/extraEnvVarsAdditional had
to re-declare the whole list just to change one entry. Convert both to
maps keyed by env var name in mock-identity-system,
mock-relying-party-service, and mock-relying-party-ui, and render them
with a range loop that auto-detects plain scalars vs. valueFrom,
matching the existing domainConfig pattern already used in these
charts. Same fix already applied to mosip/esignet (issue #2380).

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* fix: 602 update mock-identity-system installer for extraEnvVarsAdditional map contract

deploy/mock-identity-system/install.sh generated extraEnvVarsAdditional
as a list in two places (PKCS12 and softhsm branches), which produced
broken index-keyed env entries against the chart's map-shaped default
introduced in this PR. Convert both to the map contract (KEY: value /
KEY: {valueFrom: ...}), matching the fix already applied to esignet's
legacy installer scripts.

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

---------

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* Change image tag from release-0.10.x to develop

Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>

* Change image tag from release-0.10.x to develop

Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>

* Change image tag from release-0.10.x to develop

Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>

* #2347 Update database host and clean up configuration (#610)

Updated the host to include the namespace and removed unused service configurations.

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* #2347 Update database username in postgres config (#611)

* #2347 Update database username in postgres config

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* #2347 Update database username in deploy.properties

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

---------

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* updated version 0.13.0 to 0.14.0

Signed-off-by: Sachin Rana <sacrana324@gmail.com>

* updated helm chart version

Signed-off-by: Sachin Rana <sacrana324@gmail.com>

---------

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>
Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>
Signed-off-by: Harsh Kashiwal <harsh.kashiwal@infosys.com>
Signed-off-by: Sachin Rana <sacrana324@gmail.com>
Signed-off-by: Nandhukumar <nandhukumare@gmail.com>
Signed-off-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com>
Signed-off-by: GurukiranP <talk2gurukiran@gmail.com>
Signed-off-by: Abhi <abhishek.shankarcs@gmail.com>
Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>
Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>
Signed-off-by: bhumi46 <thisisbn46@gmail.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>
Signed-off-by: Prafulrakhade <prafulrakhade02@gmail.com>
Signed-off-by: Swapnil <swapnil.mohanty@technoforte.co.in>
Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>
Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>
Co-authored-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>
Co-authored-by: ase-101 <sunkadaeanusha@gmail.com>
Co-authored-by: Zeeshan Mehboob <82993262+zesu22@users.noreply.github.com>
Co-authored-by: Harsh Kashiwal <77677724+KashiwalHarsh@users.noreply.github.com>
Co-authored-by: Nandhukumar <nandhukumare@gmail.com>
Co-authored-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com>
Co-authored-by: GurukiranP <talk2gurukiran@gmail.com>
Co-authored-by: Abhi <abhishek.shankarcs@gmail.com>
Co-authored-by: Chandra Keshav Mishra <chandrakeshavmishra@gmail.com>
Co-authored-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>
Co-authored-by: bhumi46 <111699703+bhumi46@users.noreply.github.com>
Co-authored-by: bhumi46 <bhumi11111a@gmail.com>
Co-authored-by: Mahesh-Binayak <76687012+Mahesh-Binayak@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Praful Rakhade <prafulrakhade02@gmail.com>
Co-authored-by: Swapnil <swapnil.mohanty@technoforte.co.in>
Co-authored-by: Sajid Mannikeri <sajid.mannikeri@infosys.com>
Co-authored-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants