如何将SOPS文件中的值加载到Java Spring Boot本地开发应用
直接加载SOPS加密配置到Spring Boot应用的方案
方案一:使用Spring Boot SOPS Starter(推荐)
这是最简便的实现方式,借助现成的starter自动完成SOPS文件的解密与配置加载。
1. 添加依赖
根据你的构建工具引入对应依赖:
- Maven:在
pom.xml中加入
<dependency> <groupId>com.maciejwalkowiak.spring.boot</groupId> <artifactId>spring-boot-sops-starter</artifactId> <version>1.0.0</version> <!-- 可替换为最新稳定版本 --> </dependency>
- Gradle:在
build.gradle中加入
implementation 'com.maciejwalkowiak.spring.boot:spring-boot-sops-starter:1.0.0'
2. 配置SOPS文件路径
在application-local.properties中指定你的SOPS加密文件路径(比如文件名为config.sops.properties):
spring.sops.files=classpath:config.sops.properties
也可以直接通过启动参数传递路径:
java -jar your-app.jar --spring.sops.files=/local/path/to/config.sops.properties
3. 准备本地解密环境
- 确保本地已安装SOPS工具
- 持有解密该SOPS文件的密钥(比如已导入本地GPG密钥环,或具备对应云KMS权限)
启动应用后,starter会自动解密SOPS文件,并将其中的键值对注入Spring环境,你原有的@Value("${some.value}")代码无需任何修改即可读取到配置值。
方案二:自定义PropertySource(灵活可控)
如果不想依赖第三方starter,可以手动实现自定义PropertySource来处理SOPS文件的解密与加载。
1. 编写SOPS解密工具类
实现调用SOPS命令解密文件的工具方法:
import java.io.BufferedReader; import java.io.InputStreamReader; public class SopsDecryptor { public static String decryptFile(String filePath) throws Exception { Process process = new ProcessBuilder("sops", "-d", filePath).start(); try (BufferedReader reader = new BufferedReader(new InputStreamReader(process.getInputStream()))) { StringBuilder content = new StringBuilder(); String line; while ((line = reader.readLine()) != null) { content.append(line).append("\n"); } int exitCode = process.waitFor(); if (exitCode != 0) { throw new RuntimeException("SOPS解密失败,退出码:" + exitCode); } return content.toString(); } } }
2. 自定义PropertySource
创建自定义PropertySource加载解密后的配置:
import org.springframework.core.env.PropertySource; import org.springframework.core.io.Resource; import org.springframework.core.io.ResourceLoader; import java.util.Properties; public class SopsPropertySource extends PropertySource<String> { private final Properties properties = new Properties(); public SopsPropertySource(String name, ResourceLoader resourceLoader, String sopsFilePath) throws Exception { super(name); Resource resource = resourceLoader.getResource(sopsFilePath); String decryptedContent = SopsDecryptor.decryptFile(resource.getFile().getAbsolutePath()); properties.load(new java.io.StringReader(decryptedContent)); } @Override public Object getProperty(String name) { return properties.getProperty(name); } }
3. 注册PropertySource
通过ApplicationContextInitializer将自定义PropertySource注册到Spring环境:
import org.springframework.context.ApplicationContextInitializer; import org.springframework.context.ConfigurableApplicationContext; import org.springframework.core.env.ConfigurableEnvironment; public class SopsPropertySourceInitializer implements ApplicationContextInitializer<ConfigurableApplicationContext> { @Override public void initialize(ConfigurableApplicationContext applicationContext) { ConfigurableEnvironment environment = applicationContext.getEnvironment(); try { SopsPropertySource sopsPropertySource = new SopsPropertySource( "sopsPropertySource", applicationContext.getResourceLoader(), "classpath:config.sops.properties" // 替换为你的SOPS文件路径 ); environment.getPropertySources().addFirst(sopsPropertySource); } catch (Exception e) { throw new RuntimeException("加载SOPS配置失败", e); } } }
然后在src/main/resources/META-INF/spring.factories中注册初始化器:
org.springframework.context.ApplicationContextInitializer=com.yourpackage.SopsPropertySourceInitializer
完成以上步骤后,启动应用即可直接读取SOPS文件中的配置值,无需手动复制到application-local.properties。
内容的提问来源于stack exchange,提问作者Ebad
相关产品推荐
相关产品推荐

