Skip to main content

CIVITAS/CORE V1 Glossary

Key terms used across the CIVITAS/CORE V1 platform documentation.

A

API Management
The component in front of platform components such as Stellio that checks whether a user has the role required for a request. Access checks of the individual components are replaced by it where they are disabled.

C

Client
In Keycloak, a client represents a platform component, for example FROST-Server, that interacts with Keycloak to authenticate users. It collects the roles of a user and passes them to the component.
Related terms: Keycloak, Client Role
Client Role
A Keycloak role that belongs to one client and controls access to resources within that client.
Related terms: Realm Role, Composite Role
Composite Role
A Keycloak role that aggregates other roles, both realm roles and client roles. It allows complex role hierarchies.
Related terms: Realm Role, Client Role

D

Dashboard
In Superset, a visual representation of data from a specific data space. Dashboards let users explore, analyze, and interact with the data of the associated data sources.
Related terms: Superset, Data space
Data source
In Superset, a collection of data such as tables, databases, or datasets that users access to create visualizations and dashboards. A data source is part of a data space and defines the scope of data available in it.
Related terms: Superset, Data space
Data space
A thematic area that contains specific data and resources in different platform components. Data is stored in exactly one data space, and access rights are specific to each data space. Roles within a data space control what users and groups can do in it.
Related terms: Role, Group, Tenant, Project, Workspace

E

Entity
In Stellio, a core data object. Entities are assigned to and stored in tenants. FROST-Server has its own entities, for example Things, Sensors, Datastreams, and Observations.
Related terms: Stellio, Tenant, FROST-Server

F

FROST-Server
A server implementation of the OGC SensorThings API for sensor data. On the platform, a data space maps to a project in FROST-Server, and users get access through project-specific roles.

G

GeoServer
The component for geo-spatial content on the platform. Access to its layers and layer groups is controlled by roles that are specific to each data space.
Related terms: Layer, Layer-group, Workspace
Group
A collection of users that inherit the roles assigned to the group.
Related terms: User, Role

K

Keycloak
The component that manages access to data spaces across all platform components. It uses realms, clients, roles, users, and groups, and represents each data space through specific roles.
Related terms: Realm, Client, Role Mapping

L

Layer
In GeoServer, the finest level at which permissions can be granted to roles (read, write, or administrative access). A layer belongs to a workspace and inherits its permissions unless it is configured individually.
Layer-group
In GeoServer, a special layer type that is managed in the same way as a layer from a security perspective.
Related terms: GeoServer, Layer

N

NGSI-LD
An open API and data model specification for context management, published by ETSI. Stellio implements it.
Related terms: Stellio

P

Permission
The authorization to perform a specific action, such as reading, writing, or administrating resources within a data space. Permissions are assigned within roles.
Related terms: Role, Data space
Project
In FROST-Server, a project represents a data space and groups all FROST-Server entities of it. Users need a role within a project to access and change its entities.

R

Realm
The top-level container in Keycloak that holds all users, roles, groups, and permissions of the platform. Realms are independent of each other. All data spaces of a platform are contained in a single realm.
Related terms: Keycloak, Realm Role
Realm Role
A Keycloak role that applies across all clients within a realm and is not specific to one client.
Related terms: Client Role, Composite Role
Role
A set of permissions granted to a user or a group. Roles are specific to each data space and define which actions the user or group can perform in it.
Role Mapping
In Keycloak, the assignment of roles to users or groups. It lets data-space-specific roles control access.
Related terms: Keycloak, Role

S

SensorThings API
A standard API of the Open Geospatial Consortium (OGC) for sensor data. FROST-Server implements it.
Related terms: FROST-Server
Stellio
An NGSI-LD compatible context broker. On the platform, a data space maps to a tenant in Stellio with separate roles for reading, writing, and deleting entities.
Related terms: NGSI-LD, Tenant, API Management
Superset
Apache Superset, the component for data visualizations and dashboards. Roles and permissions per data space control access to its data sources and dashboards.
Related terms: Dashboard, Data source

T

Tenant
In Stellio, a grouping of entities to which access can be granted. Each data space is implemented as a tenant. Tenants are separate schemas on database level.
Related terms: Stellio, Entity, Data space

U

User
An individual or entity that accesses the platform. A user belongs to one or more groups and can have one or more roles.
Related terms: Group, Role
UserProjectRole
In FROST-Server, the assignment of a role to a user within a specific project. It governs the ability of the user to read, write, or manage the sensor data and related entities of that project.
Related terms: FROST-Server, Project

W

Workspace
In GeoServer, a hierarchical structure above entities such as layers and layer groups. CIVITAS/CORE uses a workspace to group all entities of one data space, so permissions and role assignments can be set at workspace level and are inherited.
Related terms: GeoServer, Layer, Data space

Total terms: 28