如何在Thorntail WildFly服务器中最简方式添加应用用户?是否有类似add-user.sh -a的方法?
Great question! Thorntail (now often referenced as WildFly Bootable Jar) doesn’t ship with the exact same tooling as the full WildFly server distribution, but there are straightforward ways to add application users—including a lightweight alternative to the add-user.sh -a workflow you’re familiar with.
The Simplest Method: Property File User Store
If you want to skip complex external user storage setups, using a property file-based user store is your best bet. It’s lightweight, easy to maintain, and avoids overcomplicating your configuration:
Create user/role property files
- Make two plain-text files:
application-users.properties(stores usernames and encrypted passwords) andapplication-roles.properties(maps users to their roles). - To generate encrypted passwords, use the Elytron Tool from a full WildFly distribution (this is the same tool
add-user.shuses under the hood):# Navigate to your full WildFly bin directory $WILDFLY_HOME/bin/elytron-tool.sh encrypt --password=your-secure-password - Add entries to your files like this:
# application-users.properties jdoe=ENC(your-encrypted-password-here)# application-roles.properties jdoe=admin,app-user
- Make two plain-text files:
Configure Thorntail to use these files
Add the following to your Thorntail config file (e.g.,project-defaults.ymlorthorntail.yml) to wire up a security domain pointing to your property files:thorntail: security: security-domains: app-security-domain: classic-authentication: login-modules: - code: Properties flag: required module-options: usersProperties: "application-users.properties" rolesProperties: "application-roles.properties" hashAlgorithm: "PBKDF2WithHmacSHA256" # Match the encryption algorithm you used hashEncoding: "base64"
Adding new users is as simple as adding lines to these property files—no fancy setup required.
Can You Use an add-user.sh-Style Script?
Unfortunately, Thorntail doesn’t include the add-user.sh script out of the box (it’s designed as a self-contained, lightweight bootable jar). However, you can replicate the runtime user-addition functionality using WildFly’s remote CLI:
Enable the management interface in Thorntail
Add this to your config to open up the management port for CLI access:thorntail: management: http-interface: security-realm: ManagementRealm socket-binding: management-http socket-bindings: default-sockets: socket-binding: management-http: port: 9990Connect with WildFly CLI
Use thejboss-cli.shfrom a full WildFly distribution to connect to your running Thorntail instance:./jboss-cli.sh --controller=localhost:9990 --connectAdd users via CLI commands
Once connected, you can create a filesystem-based realm and add users to it (mirroringadd-user.sh's behavior):# Create a filesystem realm to store users /subsystem=elytron/filesystem-realm=app-realm:add(path=app-user-store) # Add a new user identity /subsystem=elytron/filesystem-realm=app-realm:add-identity(identity=jsmith) # Set the user's password (use a secure password in production!) /subsystem=elytron/filesystem-realm=app-realm:set-password(identity=jsmith, clear={password=secure-pass-123}) # Link the realm to your application security domain /subsystem=elytron/security-domain=app-security-domain:add(realms=[{realm=app-realm, role-decoder=groups-to-roles}], default-realm=app-realm)
This gives you the same runtime user-addition capability as add-user.sh, though it requires having the full WildFly CLI tooling available.
内容的提问来源于stack exchange,提问作者Francesco Marchioni

