You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制Tomcat Manager用户访问权限?创建仅可读权限用户

如何创建Tomcat Manager只读用户(限制部署/卸载权限)

Hi Ashwini, great question! Creating a read-only user for Tomcat Manager that can view application details but can’t perform deploy/undeploy/reload operations requires adjusting two key configuration files. Let’s walk through the steps:

1. 配置用户与角色(conf/tomcat-users.xml)

First, we’ll define custom roles and assign them to users in Tomcat’s core user configuration file.

Open conf/tomcat-users.xml and add the following inside the <tomcat-users> tag:

<!-- Define custom roles -->
<role rolename="manager-readonly"/>  <!-- For read-only access to app list/status -->
<role rolename="manager-deploy"/>   <!-- For deploy/undeploy/reload permissions -->

<!-- Read-only user: can view apps but can't modify them -->
<user username="readonly_user" password="your_secure_password" roles="manager-readonly,manager-status"/>

<!-- Full-access admin user (for reference) -->
<user username="admin" password="admin_secure_password" roles="manager-gui,manager-deploy,manager-script,manager-jmx"/>
  • manager-readonly: We’ll map this role to allow viewing app lists and status pages.
  • manager-status: Ensures access to the server status dashboard.
  • Important: Use strong, unique passwords for production environments.

2. 调整Manager应用的权限约束(webapps/manager/WEB-INF/web.xml)

By default, the manager-gui role grants full access to the HTML interface (including deploy/undeploy). We need to split the security constraints to restrict modification operations to users with the manager-deploy role.

Open webapps/manager/WEB-INF/web.xml and replace the existing <security-constraint> blocks for the HTML interface with these:

<!-- Allow read-only users to view app lists and status -->
<security-constraint>
  <web-resource-collection>
    <web-resource-name>Manager Read Access</web-resource-name>
    <url-pattern>/html/list</url-pattern>
    <url-pattern>/html/status</url-pattern>
    <url-pattern>/status/*</url-pattern>
  </web-resource-collection>
  <auth-constraint>
    <role-name>manager-readonly</role-name>
    <role-name>manager-gui</role-name>
  </auth-constraint>
</security-constraint>

<!-- Restrict deploy/undeploy/reload operations to authorized users only -->
<security-constraint>
  <web-resource-collection>
    <web-resource-name>Manager Deploy Access</web-resource-name>
    <url-pattern>/html/upload</url-pattern>
    <url-pattern>/html/undeploy</url-pattern>
    <url-pattern>/html/reload</url-pattern>
    <url-pattern>/html/start</url-pattern>
    <url-pattern>/html/stop</url-pattern>
  </web-resource-collection>
  <auth-constraint>
    <role-name>manager-deploy</role-name>
    <role-name>manager-gui</role-name>
  </auth-constraint>
</security-constraint>

<!-- Grant full HTML interface access to admin users (excluding already defined URLs) -->
<security-constraint>
  <web-resource-collection>
    <web-resource-name>Full HTML Manager Access</web-resource-name>
    <url-pattern>/html/*</url-pattern>
    <url-pattern>!/html/list</url-pattern>
    <url-pattern>!/html/status</url-pattern>
    <url-pattern>!/html/upload</url-pattern>
    <url-pattern>!/html/undeploy</url-pattern>
    <url-pattern>!/html/reload</url-pattern>
    <url-pattern>!/html/start</url-pattern>
    <url-pattern>!/html/stop</url-pattern>
  </web-resource-collection>
  <auth-constraint>
    <role-name>manager-gui</role-name>
  </auth-constraint>
</security-constraint>

3. (可选)允许远程访问Manager应用

By default, Tomcat restricts Manager access to localhost. If you need to access it remotely:

  1. Open webapps/manager/META-INF/context.xml
  2. Modify or comment out the RemoteAddrValve block to allow your IP range:
<!-- Example: Allow access from 192.168.1.0/24 and localhost -->
<Valve className="org.apache.catalina.valves.RemoteAddrValve"
       allow="127\.\d+\.\d+\.\d+|::1|0:0:0:0:0:0:0:1|192\.168\.1\.\d+" />

Note: Avoid commenting this out entirely in production environments—always restrict access to trusted IPs.

4. 重启Tomcat

Save all changes and restart your Tomcat server for the configurations to take effect.

Now, when you log in with the readonly_user account, you’ll be able to view the list of deployed applications and server status, but all deploy/undeploy/reload buttons will be inaccessible (or you’ll get a 403 Forbidden error if you try to access those URLs directly).

内容的提问来源于stack exchange,提问作者Ashwini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 17:32:42