You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将SOPS文件中的值加载到Java Spring Boot本地开发应用

直接加载SOPS加密配置到Spring Boot应用的方案

方案一:使用Spring Boot SOPS Starter(推荐)

这是最简便的实现方式,借助现成的starter自动完成SOPS文件的解密与配置加载。

1. 添加依赖

根据你的构建工具引入对应依赖:

  • Maven:在pom.xml中加入
<dependency>
    <groupId>com.maciejwalkowiak.spring.boot</groupId>
    <artifactId>spring-boot-sops-starter</artifactId>
    <version>1.0.0</version> <!-- 可替换为最新稳定版本 -->
</dependency>
  • Gradle:在build.gradle中加入
implementation 'com.maciejwalkowiak.spring.boot:spring-boot-sops-starter:1.0.0'

2. 配置SOPS文件路径

在application-local.properties中指定你的SOPS加密文件路径(比如文件名为config.sops.properties):

spring.sops.files=classpath:config.sops.properties

也可以直接通过启动参数传递路径:

java -jar your-app.jar --spring.sops.files=/local/path/to/config.sops.properties

3. 准备本地解密环境

  • 确保本地已安装SOPS工具
  • 持有解密该SOPS文件的密钥(比如已导入本地GPG密钥环,或具备对应云KMS权限)

启动应用后,starter会自动解密SOPS文件,并将其中的键值对注入Spring环境,你原有的@Value("${some.value}")代码无需任何修改即可读取到配置值。

方案二:自定义PropertySource(灵活可控)

如果不想依赖第三方starter,可以手动实现自定义PropertySource来处理SOPS文件的解密与加载。

1. 编写SOPS解密工具类

实现调用SOPS命令解密文件的工具方法:

import java.io.BufferedReader;
import java.io.InputStreamReader;

public class SopsDecryptor {
    public static String decryptFile(String filePath) throws Exception {
        Process process = new ProcessBuilder("sops", "-d", filePath).start();
        try (BufferedReader reader = new BufferedReader(new InputStreamReader(process.getInputStream()))) {
            StringBuilder content = new StringBuilder();
            String line;
            while ((line = reader.readLine()) != null) {
                content.append(line).append("\n");
            }
            int exitCode = process.waitFor();
            if (exitCode != 0) {
                throw new RuntimeException("SOPS解密失败,退出码:" + exitCode);
            }
            return content.toString();
        }
    }
}

2. 自定义PropertySource

创建自定义PropertySource加载解密后的配置:

import org.springframework.core.env.PropertySource;
import org.springframework.core.io.Resource;
import org.springframework.core.io.ResourceLoader;
import java.util.Properties;

public class SopsPropertySource extends PropertySource<String> {
    private final Properties properties = new Properties();

    public SopsPropertySource(String name, ResourceLoader resourceLoader, String sopsFilePath) throws Exception {
        super(name);
        Resource resource = resourceLoader.getResource(sopsFilePath);
        String decryptedContent = SopsDecryptor.decryptFile(resource.getFile().getAbsolutePath());
        properties.load(new java.io.StringReader(decryptedContent));
    }

    @Override
    public Object getProperty(String name) {
        return properties.getProperty(name);
    }
}

3. 注册PropertySource

通过ApplicationContextInitializer将自定义PropertySource注册到Spring环境:

import org.springframework.context.ApplicationContextInitializer;
import org.springframework.context.ConfigurableApplicationContext;
import org.springframework.core.env.ConfigurableEnvironment;

public class SopsPropertySourceInitializer implements ApplicationContextInitializer<ConfigurableApplicationContext> {
    @Override
    public void initialize(ConfigurableApplicationContext applicationContext) {
        ConfigurableEnvironment environment = applicationContext.getEnvironment();
        try {
            SopsPropertySource sopsPropertySource = new SopsPropertySource(
                    "sopsPropertySource",
                    applicationContext.getResourceLoader(),
                    "classpath:config.sops.properties" // 替换为你的SOPS文件路径
            );
            environment.getPropertySources().addFirst(sopsPropertySource);
        } catch (Exception e) {
            throw new RuntimeException("加载SOPS配置失败", e);
        }
    }
}

然后在src/main/resources/META-INF/spring.factories中注册初始化器:

org.springframework.context.ApplicationContextInitializer=com.yourpackage.SopsPropertySourceInitializer

完成以上步骤后,启动应用即可直接读取SOPS文件中的配置值,无需手动复制到application-local.properties。


内容的提问来源于stack exchange,提问作者Ebad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 17:37:03