Runnable example
Protect an internal API
Run Identity and Policy against disposable PostgreSQL, then exercise an API route that allows or denies access based on the signed-in user's current identity and configured policy.
Requirements
- Node.js 20 or later, npm, Docker Compose, Rust/Cargo, and PostgreSQL client development libraries (for Diesel).
- Run commands from the repository root. The database container uses temporary in-memory storage and binds only to localhost.
1. Create local-only credentials and start PostgreSQL
node examples/internal-api/setup-local-policy.js
set -a
. examples/internal-api/.local/quickstart.env
set +a
docker compose -f examples/internal-api/compose.postgres.yml up -d --wait
npm run migrate
The setup command creates private credentials under the ignored .local/ directory and refuses to overwrite existing files.
2. Verify Identity, Policy, and Diesel
TEST_DATABASE_URL="$DATABASE_URL" npm test --prefix Aarchon_Identity
npm test --prefix aarchon_backend
TEST_DATABASE_URL="$DATABASE_URL" npm test --prefix examples/internal-api
cargo run --manifest-path examples/diesel-postgres/Cargo.toml
The database-backed test creates a throwaway test account, signs in through Identity, then exercises an allowed and a denied API request through Policy. Diesel runs a read-only role-count query against the same schema; it does not create accounts or handle credentials.
3. Exercise the complete HTTP flow
Keep each service in its own terminal. Start Identity:
set -a
. examples/internal-api/.local/quickstart.env
set +a
LEDGER_SIGNING_KEY="$IDENTITY_LEDGER_SIGNING_KEY" npm start
Start Policy in another terminal:
cd aarchon_backend
set -a
. ../examples/internal-api/.local/quickstart.env
. ../examples/internal-api/.local/policy.env
set +a
npm run validate-policy -- ../examples/internal-api/.local/policy.json
PORT=4000 GOVERNANCE_POLICY_FILE=../examples/internal-api/.local/policy.json \
LEDGER_SIGNING_KEY="$POLICY_LEDGER_SIGNING_KEY" npm start
Start the example API in a third terminal:
set -a
. examples/internal-api/.local/policy.env
set +a
npm --prefix examples/internal-api start
Register or sign in at http://127.0.0.1:3000, then use the returned access token:
curl -i -H "Authorization: Bearer $ACCESS_TOKEN" \
http://127.0.0.1:5000/api/reports/team-a
curl -i -H "Authorization: Bearer $ACCESS_TOKEN" \
http://127.0.0.1:5000/api/reports/team-b
The sample policy permits the configured user role to read team A and denies team B. Do not use demo data or local credentials in production.
Stop and clean up
docker compose -f examples/internal-api/compose.postgres.yml down
rm -f examples/internal-api/.local/policy.json \
examples/internal-api/.local/policy.env \
examples/internal-api/.local/quickstart.env
rmdir examples/internal-api/.local
For the policy schema and failure behavior, see the policy guide and trust boundaries.