Step 6: Securing Management Web Endpoints
You can configure authentication, authorization, and TLS for the management web endpoints exposed by the Micro-Integration. For the full list of available endpoints and how to enable them, see Monitoring the Self-Managed Micro-Integration's State. For information about what the health endpoint exposes, see Step 7: Configuring and Using the Health Endpoint.
Authentication and Authorization
Micro-Integrations support basic HTTP authentication.
By default, no users are created unless the operator configures them in their configuration file. The configuration parameters responsible for security are as follows:
solace:
connector:
security:
enabled: true
users:
- name: user1
password: pass
- name: admin1
password: admin
roles:
- admin
The preceding example creates two users:
-
user1: Has access to perform GET (read) requests.
-
admin1: Has access to perform GET and POST (read and write) requests.
solace.connector.security.users is a list. When users are defined in multiple sources (different application.yml files, environment variables, and so on), overriding works by replacing the entire list. In other words, you must pick one place to define all your users, whether in a single application properties file or as environment variables. For more information, see Spring Boot - Merging Complex Types.
To fully disable security and permit anyone to access the web endpoints of the Micro-Integration, operators can configure the solace.connector.security.enabled parameter to false.
Although these properties can be defined in an application.yml file, we recommend that you use environment variables to set secret values.
To supply users as environment variables (for example, in a Docker Compose file under the environment: key, or as Kubernetes secrets) use the following naming convention, where list indexes start at _0_:
# Create user with no role (i.e., read-only) SOLACE_CONNECTOR_SECURITY_USERS_0_NAME=user1 SOLACE_CONNECTOR_SECURITY_USERS_0_PASSWORD=pass # Create user with admin role SOLACE_CONNECTOR_SECURITY_USERS_1_NAME=admin1 SOLACE_CONNECTOR_SECURITY_USERS_1_PASSWORD=admin SOLACE_CONNECTOR_SECURITY_USERS_1_ROLES_0=admin
The following table lists the complete set of security configuration properties. The options in the Config Option column must be prefixed with solace.connector:
| Config Option | Type | Valid Values | Default Value | Description |
|---|---|---|---|---|
|
|
|
|
|
If |
|
|
|
Any |
|
The name of the user. |
|
|
|
Any |
|
The password for the user. |
|
|
|
|
Empty list (i.e., read-only) |
The list of roles that the specified user has. It has read-only access if no roles are returned. |
TLS
You can use TLS to secure HTTP access to the Micro-Integration's management web endpoints. This configuration is independent of TLS for the event broker connection. To configure security for your event broker connection, see Step 1: Connecting to Your Event Broker .
TLS for the management web server is disabled by default. To configure it, see Spring Boot - Configure SSL and TLS Setup in Spring.