ooooo oooo oooo
`888' `888 `888
888 .ooooo. .ooooo. .oooo. 888 888 oooo ooo
888 d88' `88b d88' `"Y8 `P )88b 888 888 `88. .8'
888 888 888 888 .oP"888 888 888 `88..8'
888 o 888 888 888 .o8 d8( 888 888 888 `888'
o888ooooood8 `Y8bod8P' `Y8bod8P' `Y888""8o o888o o888o .8'
.o..P'
`Y8P'
This example shows how to deploy a sample SAML-powered CRM - tombuildsstuff/customer-notes-crm-saml as a Container Instance, to Locally Build.
It uses both the Control Plane and the Directory Emulator within Locally to spin the container up as a Container Instance and to authenticate against it.
The application itself is a small CRM, which lists customers and lets you view or edit notes depending on your role. Two roles are available:
Customers.Read- read-only access: browse and view notes.Customers.Write- full access: browse, add customers, and add or view notes.
Locally ships with some built-in Users and Groups, and this example seeds the following identities with the following roles:
| Sign in as | Role | What happens |
|---|---|---|
| Default Identity | Customers.Write |
Full access: browse, add customers, add or view notes. |
ada.lovelace@… |
Customers.Write |
Full access: browse, add customers, add or view notes. |
grace.hopper@… |
Customers.Read |
Read-only: browse and view notes. |
| Any other user | none | Access denied by the identity provider. |
The application authenticates using SAML, so when you navigate to it you're prompted to pick the identity you want to authenticate as - the Default Identity, or one of the users above, will let you in.
- Locally Build.
- Either HashiCorp Terraform or OpenTofu.
- Either Docker or Podman (recommended).
- The Locally Plugin for
Microsoft.ContainerInstanceinstalled (locally plugin install --name Microsoft.ContainerInstance).
First up, we need to ensure our container runtime (Docker or Podman) is running, then launch Locally:
locally buildWith Locally running, in another terminal we can initialise Terraform, which both downloads the providers we need and configures the module for use:
cd environments/locally
terraform initNote
It's possible to use OpenTofu here by substituting terraform for tofu.
With Terraform initialised, we can then provision the example by running:
locally run terraform applyOnce you approve the plan and the resources have been deployed, the application is running at the URL in the outputs:
https://locally-example-saml-group-berlin.gondola.locally:8080
If you open that URL in a browser you'll be redirected to Locally's Directory sign-in page, where you can pick which identity to sign in as. Since Locally is an emulator we're not concerned with you knowing the username or password for the user (although you can use it if you want) - just pick the identity you want and you're in. Once you're logged in, you can sign out from the header to switch to a different user.
cd environments/locally
locally run terraform destroyThe seeded users and groups are untouched; this example only looks up the existing identities.