Repo: darkedges/pingfederate-graph-broker*
We've covered the problem, the PingFederate courier flow, introspection and delegations and the token vault. Here is how to run it and where it stands.
1. The zero-credential demo
docker compose -f compose.demo.yaml up --build -d # http://127.0.0.1:8097
docker compose -f compose.demo.yaml down
Local simulators stand in for PingFederate, Entra and Graph, with a temporary encrypted store. State resets on restart.
2. Tests
go test -race -count=1 ./...
go vet ./...
go build -buildvcs=false ./cmd/broker
Go 1.26+ is required. The race detector needs a C compiler, so on Windows use WSL2 or Docker.
3. A live local stack
Terraform is split into separate states because PingFederate must exist before its provider can connect:
-
terraform/runtime: Docker Compose runtime -
terraform/scopes: adopts PF's global OAuth scopes -
terraform(root): Entra app registration, access token managers, clients, IdP connection, Reference ID adapter
make compose-pf, make compose-broker and make compose-portal start the pieces. The portal needs a local trusted certificate (for example from mkcert), and PingFederate needs Ping DevOps credentials.
For public hostnames there's a Cloudflare Tunnel guide. The one rule: never tunnel the PF admin port.
4. Kubernetes
A Helm chart in helm/broker deploys the broker and portal in one pod with a persistent volume. It uses a Recreate strategy and rejects replicas other than 1, because of the file store. Secrets come from an existingSecret.
make helm-lint
make helm-template
make helm-upgrade HELM_VALUES=my-values.yaml
What is not proven
The repo's verification log marks live PingFederate, Entra and Graph integration as not run. Mock-based tests pass; a real tenant acceptance checklist (11 steps in docs/OPERATIONS.md) is yet to be completed. Also:
- Single instance only, no distributed storage or locking
- No application-level rate limiting
- The optional SAML on-behalf-of path (PF token exchange to SAML 1.1 to Entra OBO to Graph) is documented but not provisioned or proven
- Public Microsoft cloud only, single tenant
- Terraform doesn't yet cover the full PF handoff
I'd rather say this up front than have you find out in a test environment.
Roadmap
The next production milestone:
- PostgreSQL transactions with per-connection advisory locks
- Managed key encryption (KMS) and key rotation
- Per-object authorisation policy
- Metrics and rate limiting
- Integration tests against a non-production PF/Entra environment
- Possibly an MCP transport so agent frameworks can consume the directory tools directly
Get involved
If you work on PingFederate, Entra or agent security, I'd love feedback, especially on the broker_principal_type contract and the delegation model. Open an issue at github.com/darkedges/pingfederate-graph-broker.
Thanks for reading the series.
Top comments (0)