Step 6: Securing Management Web Endpoints

You can configure authentication, authorization, and TLS for the management web endpoints exposed by the Micro-Integration. For the full list of available endpoints and how to enable them, see Monitoring the Self-Managed Micro-Integration's State. For information about what the health endpoint exposes, see Step 7: Configuring and Using the Health Endpoint.

Authentication and Authorization

Micro-Integrations support basic HTTP authentication.

By default, no users are created unless the operator configures them in their configuration file. The configuration parameters responsible for security are as follows:

solace:
  connector:
    security:
      enabled: true
      users:
      - name: user1
        password: pass
      - name: admin1
        password: admin
        roles:
        - admin

The preceding example creates two users:

  • user1: Has access to perform GET (read) requests.

  • admin1: Has access to perform GET and POST (read and write) requests.

solace.connector.security.users is a list. When users are defined in multiple sources (different application.yml files, environment variables, and so on), overriding works by replacing the entire list. In other words, you must pick one place to define all your users, whether in a single application properties file or as environment variables. For more information, see Spring Boot - Merging Complex Types.

To fully disable security and permit anyone to access the web endpoints of the Micro-Integration, operators can configure the solace.connector.security.enabled parameter to false.

Although these properties can be defined in an application.yml file, we recommend that you use environment variables to set secret values.

To supply users as environment variables (for example, in a Docker Compose file under the environment: key, or as Kubernetes secrets) use the following naming convention, where list indexes start at _0_:

# Create user with no role (i.e., read-only)
SOLACE_CONNECTOR_SECURITY_USERS_0_NAME=user1
SOLACE_CONNECTOR_SECURITY_USERS_0_PASSWORD=pass
# Create user with admin role
SOLACE_CONNECTOR_SECURITY_USERS_1_NAME=admin1
SOLACE_CONNECTOR_SECURITY_USERS_1_PASSWORD=admin
SOLACE_CONNECTOR_SECURITY_USERS_1_ROLES_0=admin

The following table lists the complete set of security configuration properties. The options in the Config Option column must be prefixed with solace.connector:

Config Option Type Valid Values Default Value Description

security.enabled

boolean

(true | false)

true

If true, security is enabled. Otherwise, anyone has access to the Micro-Integration's management endpoints.

security.users[<index>].name

String

Any

null

The name of the user.

security.users[<index>].password

String

Any

null

The password for the user.

security.users[<index>].roles

list<String>

admin

Empty list (i.e., read-only)

The list of roles that the specified user has. It has read-only access if no roles are returned.

TLS

You can use TLS to secure HTTP access to the Micro-Integration's management web endpoints. This configuration is independent of TLS for the event broker connection. To configure security for your event broker connection, see Step 1: Connecting to Your Event Broker .

TLS for the management web server is disabled by default. To configure it, see Spring Boot - Configure SSL and TLS Setup in Spring.