WSO2 API Manager v2.2.0用户与角色备份问题咨询
Got it, let's tackle your user and role backup issue with WSO2 API Manager v2.2.0. Since the api-import-export tool only handles APIs, here are a few reliable approaches you can use:
WSO2 APIM exposes SCIM-compliant REST APIs that let you fetch and manage users/roles directly. You can use these to build a simple backup script:
- Fetch all roles:
curl -k -u admin:admin https://<YOUR_APIM_HOST>:9443/wso2/scim/Roles - Fetch all users:
curl -k -u admin:admin https://<YOUR_APIM_HOST>:9443/wso2/scim/Users - Fetch users in a specific role:
curl -k -u admin:admin https://<YOUR_APIM_HOST>:9443/wso2/scim/Roles/<ROLE_NAME>/Users
Save the JSON responses to files for backup. To restore, use the POST API for creating users/roles, or PUT for updating. Note: Passwords are stored as hashes in the responses—you can reuse these hashes during restoration to keep existing passwords intact.
All user and role data lives in WSO2 APIM's user store database (default is H2, but you’re probably using MySQL/Oracle in production). Target these core tables for backup:
- User data:
UM_USER,UM_USER_ATTRIBUTE - Role data:
UM_ROLE,UM_ROLE_ATTRIBUTE,UM_USER_ROLE
Backup steps:
- Stop your APIM server to ensure data consistency (or use a database snapshot tool if you can’t take downtime).
- Use your database’s native backup tool. For example, with MySQL:
mysqldump -u <DB_USER> -p <APIM_DB_NAME> UM_USER UM_USER_ATTRIBUTE UM_ROLE UM_ROLE_ATTRIBUTE UM_USER_ROLE > user_role_backup.sql - Store the
.sqlfile securely.
Restore steps:
- Ensure the target database has the same schema structure.
- Run the backup script to import data:
mysql -u <DB_USER> -p <APIM_DB_NAME> < user_role_backup.sql - Restart your APIM server.
If you want to backup the entire user store configuration + data in one go, use WSO2’s cApp export feature via the management console:
- Log into the APIM Carbon console (
https://<YOUR_APIM_HOST>:9443/carbon) - Navigate to Main > Identity > Users and Roles > User Stores
- Select your primary user store (usually named
PRIMARY) - Click Export as Carbon Application
- Download the generated
.carfile
To restore, go to Main > Carbon Applications > Add, upload the .car file, and deploy it. This method is great for migrating user data between environments.
For more control, you can use WSO2’s underlying Admin SOAP Services (like UserAdmin and RoleAdmin). These let you call methods like getAllRoles, getUserListOfRole, addRole, and updateUserListOfRole. You can use tools like SoapUI or write a Python/Shell script with a SOAP client to automate export/import.
Quick tip:
For most use cases, the REST API approach is the simplest to automate, while database backups are the most reliable for production environments. The cApp method is perfect if you need to move user stores between APIM instances.
内容的提问来源于stack exchange,提问作者unknown

