You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Thorntail WildFly服务器中最简方式添加应用用户?是否有类似add-user.sh -a的方法?

Answer to Your Thorntail WildFly User Management Questions

Great question! Thorntail (now often referenced as WildFly Bootable Jar) doesn’t ship with the exact same tooling as the full WildFly server distribution, but there are straightforward ways to add application users—including a lightweight alternative to the add-user.sh -a workflow you’re familiar with.

The Simplest Method: Property File User Store

If you want to skip complex external user storage setups, using a property file-based user store is your best bet. It’s lightweight, easy to maintain, and avoids overcomplicating your configuration:

  1. Create user/role property files

    • Make two plain-text files: application-users.properties (stores usernames and encrypted passwords) and application-roles.properties (maps users to their roles).
    • To generate encrypted passwords, use the Elytron Tool from a full WildFly distribution (this is the same tool add-user.sh uses under the hood):
      # Navigate to your full WildFly bin directory
      $WILDFLY_HOME/bin/elytron-tool.sh encrypt --password=your-secure-password
      
    • Add entries to your files like this:
      # application-users.properties
      jdoe=ENC(your-encrypted-password-here)
      
      # application-roles.properties
      jdoe=admin,app-user
      
  2. Configure Thorntail to use these files
    Add the following to your Thorntail config file (e.g., project-defaults.yml or thorntail.yml) to wire up a security domain pointing to your property files:

    thorntail:
      security:
        security-domains:
          app-security-domain:
            classic-authentication:
              login-modules:
                - code: Properties
                  flag: required
                  module-options:
                    usersProperties: "application-users.properties"
                    rolesProperties: "application-roles.properties"
                    hashAlgorithm: "PBKDF2WithHmacSHA256" # Match the encryption algorithm you used
                    hashEncoding: "base64"
    

Adding new users is as simple as adding lines to these property files—no fancy setup required.

Can You Use an add-user.sh-Style Script?

Unfortunately, Thorntail doesn’t include the add-user.sh script out of the box (it’s designed as a self-contained, lightweight bootable jar). However, you can replicate the runtime user-addition functionality using WildFly’s remote CLI:

  1. Enable the management interface in Thorntail
    Add this to your config to open up the management port for CLI access:

    thorntail:
      management:
        http-interface:
          security-realm: ManagementRealm
          socket-binding: management-http
      socket-bindings:
        default-sockets:
          socket-binding:
            management-http:
              port: 9990
    
  2. Connect with WildFly CLI
    Use the jboss-cli.sh from a full WildFly distribution to connect to your running Thorntail instance:

    ./jboss-cli.sh --controller=localhost:9990 --connect
    
  3. Add users via CLI commands
    Once connected, you can create a filesystem-based realm and add users to it (mirroring add-user.sh's behavior):

    # Create a filesystem realm to store users
    /subsystem=elytron/filesystem-realm=app-realm:add(path=app-user-store)
    # Add a new user identity
    /subsystem=elytron/filesystem-realm=app-realm:add-identity(identity=jsmith)
    # Set the user's password (use a secure password in production!)
    /subsystem=elytron/filesystem-realm=app-realm:set-password(identity=jsmith, clear={password=secure-pass-123})
    # Link the realm to your application security domain
    /subsystem=elytron/security-domain=app-security-domain:add(realms=[{realm=app-realm, role-decoder=groups-to-roles}], default-realm=app-realm)
    

This gives you the same runtime user-addition capability as add-user.sh, though it requires having the full WildFly CLI tooling available.


内容的提问来源于stack exchange,提问作者Francesco Marchioni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:49:01