Key terms used across the CIVITAS/CORE V1 platform documentation.
A
API Management
The component in front of platform components such as Stellio that checks whether a user has the role required for a request. Access checks of the individual components are replaced by it where they are disabled.
C
Client
In Keycloak, a client represents a platform component, for example FROST-Server, that interacts with Keycloak to authenticate users. It collects the roles of a user and passes them to the component.
In Superset, a visual representation of data from a specific data space. Dashboards let users explore, analyze, and interact with the data of the associated data sources.
In Superset, a collection of data such as tables, databases, or datasets that users access to create visualizations and dashboards. A data source is part of a data space and defines the scope of data available in it.
A thematic area that contains specific data and resources in different platform components. Data is stored in exactly one data space, and access rights are specific to each data space. Roles within a data space control what users and groups can do in it.
In Stellio, a core data object. Entities are assigned to and stored in tenants. FROST-Server has its own entities, for example Things, Sensors, Datastreams, and Observations.
A server implementation of the OGC SensorThings API for sensor data. On the platform, a data space maps to a project in FROST-Server, and users get access through project-specific roles.
The component for geo-spatial content on the platform. Access to its layers and layer groups is controlled by roles that are specific to each data space.
The component that manages access to data spaces across all platform components. It uses realms, clients, roles, users, and groups, and represents each data space through specific roles.
In GeoServer, the finest level at which permissions can be granted to roles (read, write, or administrative access). A layer belongs to a workspace and inherits its permissions unless it is configured individually.
The authorization to perform a specific action, such as reading, writing, or administrating resources within a data space. Permissions are assigned within roles.
In FROST-Server, a project represents a data space and groups all FROST-Server entities of it. Users need a role within a project to access and change its entities.
The top-level container in Keycloak that holds all users, roles, groups, and permissions of the platform. Realms are independent of each other. All data spaces of a platform are contained in a single realm.
An NGSI-LD compatible context broker. On the platform, a data space maps to a tenant in Stellio with separate roles for reading, writing, and deleting entities.
Apache Superset, the component for data visualizations and dashboards. Roles and permissions per data space control access to its data sources and dashboards.
In Stellio, a grouping of entities to which access can be granted. Each data space is implemented as a tenant. Tenants are separate schemas on database level.
In FROST-Server, the assignment of a role to a user within a specific project. It governs the ability of the user to read, write, or manage the sensor data and related entities of that project.
In GeoServer, a hierarchical structure above entities such as layers and layer groups. CIVITAS/CORE uses a workspace to group all entities of one data space, so permissions and role assignments can be set at workspace level and are inherited.