You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Quarkus 2.7:如何通过文件路径配置密钥库密码而非硬编码

Quarkus 2.7 从外部文件加载密钥库密码方案

关于启动前拦截器的说明

Quarkus 2.7没有专门的"启动前拦截器"API,但可以通过扩展MicroProfile的配置源(ConfigSource)来实现从外部文件加载密码的需求——本质上是在配置加载阶段重写目标配置项的值,达到类似拦截覆盖的效果。

方案一:自定义ConfigSource实现文件密码加载

这是最贴合你需求的方案,通过自定义配置源,读取你在application.yaml中指定的外部文件路径,替换内置的SSL密钥库密码配置。

实现步骤

  1. 创建自定义ConfigSource类
    实现org.eclipse.microprofile.config.spi.ConfigSource接口,在getValue方法中处理目标配置项:
import org.eclipse.microprofile.config.Config;
import org.eclipse.microprofile.config.spi.ConfigProviderResolver;
import org.eclipse.microprofile.config.spi.ConfigSource;

import java.io.IOException;
import java.nio.file.Files;
import java.nio.file.Paths;
import java.util.Collections;
import java.util.Map;

// 设置优先级高于默认配置源,确保能覆盖原配置
@javax.annotation.Priority(100)
public class ExternalKeystorePasswordSource implements ConfigSource {

    @Override
    public Map<String, String> getProperties() {
        return Collections.emptyMap();
    }

    @Override
    public String getValue(String propertyName) {
        // 匹配目标配置项
        if ("quarkus.http.ssl.certificate.key-store-password".equals(propertyName)) {
            Config config = ConfigProviderResolver.instance().getConfig();
            // 读取application.yaml中配置的密码文件路径
            String passwordFilePath = config.getValue("custom.ssl.keystore-password-path", String.class);
            
            try {
                // 读取文件内容并去除换行/空格
                return new String(Files.readAllBytes(Paths.get(passwordFilePath))).trim();
            } catch (IOException e) {
                throw new RuntimeException("Failed to read keystore password from file: " + passwordFilePath, e);
            }
        }
        return null;
    }

    @Override
    public String getName() {
        return "ExternalKeystorePasswordSource";
    }
}
  1. 注册自定义ConfigSource
    在项目的src/main/resources/META-INF/services目录下创建文件org.eclipse.microprofile.config.spi.ConfigSource,文件内容为自定义类的全限定名:
com.yourpackage.ExternalKeystorePasswordSource
  1. 配置application.yaml
    指定外部密码文件路径,同时给目标配置项填占位符(会被自定义配置源覆盖):
custom:
  ssl:
    keystore-password-path: /opt/server/ssl/keystore-password.txt # 服务器上的绝对路径

quarkus:
  http:
    ssl:
      certificate:
        key-store-password: placeholder # 占位符,无实际作用

方案二:启动脚本注入密码(无需代码修改)

如果不想修改代码,可以通过启动命令直接将文件内容作为系统属性传入,覆盖内置配置:

./quarkus-run.sh -Dquarkus.http.ssl.certificate.key-store-password=$(cat /opt/server/ssl/keystore-password.txt)

这种方式无需修改application.yaml,但依赖启动脚本支持命令替换(如bash环境)。

方案三:使用Quarkus Vault扩展(更安全的Vault集成)

既然你的密码存储在服务器Vault中,推荐直接使用Quarkus的Vault扩展从Vault读取密码,避免维护明文密码文件。

配置示例

  1. 添加Vault扩展依赖(pom.xml):
<dependency>
    <groupId>io.quarkus</groupId>
    <artifactId>quarkus-vault</artifactId>
</dependency>
  1. 在application.yaml中配置Vault连接及密码引用:
quarkus:
  vault:
    url: http://your-vault-server:8200
    token: your-vault-token # 或者通过其他认证方式(如approle)
    kv-secret-engine:
      enabled: true
  http:
    ssl:
      certificate:
        key-store-password: ${vault:ssl/secrets:keystore-password} # 格式:${vault:secret-path:key}

这种方式直接从Vault拉取密码,安全性更高,无需手动管理密码文件。

内容的提问来源于stack exchange,提问作者Aman Saxena

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 17:17:40