在内部Cloud Foundry部署Spring Cloud Dataflow 1.4.0.RELEASE的配置疑问
I’ve tackled this exact scenario when setting up SCDF 1.4.x on PCF where Vault is used for secret management instead of relying on CUPS. Here’s how you can configure your deployment to get Spring Cloud Tasks connected to the tracking database without CUPS:
Core Context
The PCF docs recommend using a User-Provided Service (CUPS) to set SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_SERVICES=my_mysql, which tells SCDF to bind the my_mysql service to deployed tasks. But since your org stores secrets in Vault, CUPS isn’t feasible (it would expose or require hardcoding sensitive credentials). We have two solid workarounds:
Solution 1: Bind the CF Database Service + Override Credentials via Vault
This approach keeps SCDF’s service binding behavior but ensures tasks use Vault-stored credentials instead of the ones from CF service binding:
- Keep setting
SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_SERVICES=my_mysqlin your SCDF manifest. This tells SCDF to bind the existingmy_mysqlCF database service to every deployed task. - Configure your Spring Cloud Task applications to use Spring Cloud Vault and prioritize Vault-stored database credentials over those from
VCAP_SERVICES. This way, even though the service is bound, the task will use the secure credentials from Vault.
Solution 2: Skip Service Binding, Pass Vault Config Directly to Tasks
If you don’t want to rely on CF service bindings at all, you can inject Vault connection details and database credentials directly into tasks via SCDF’s deployment defaults:
- Remove the
SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_SERVICESvariable from your manifest. - Add environment variables to your SCDF manifest that pass Vault configuration to all deployed tasks. These variables will be inherited by every task SCDF deploys.
Example SCDF Manifest (Solution 2)
Here’s a complete manifest that configures SCDF to pass Vault settings to tasks, using CF’s variable interpolation to pull secrets from Vault/CredHub:
applications: - name: scdf-server memory: 2G instances: 1 path: spring-cloud-dataflow-server-cloudfoundry-1.4.0.RELEASE.jar env: SPRING_PROFILES_ACTIVE: cloud # SCDF Server's own Vault configuration (for its internal database) SPRING_CLOUD_VAULT_ENABLED: true SPRING_CLOUD_VAULT_HOST: vault.your-org.com SPRING_CLOUD_VAULT_PORT: 443 SPRING_CLOUD_VAULT_SCHEME: https SPRING_CLOUD_VAULT_AUTHENTICATION: token SPRING_CLOUD_VAULT_TOKEN: ((scdf-server-vault-token)) # Default Vault config for ALL deployed tasks SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_CLOUD_VAULT_ENABLED: true SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_CLOUD_VAULT_HOST: vault.your-org.com SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_CLOUD_VAULT_PORT: 443 SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_CLOUD_VAULT_SCHEME: https SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_CLOUD_VAULT_AUTHENTICATION: token SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_CLOUD_VAULT_TOKEN: ((task-vault-token)) # Optional: If you want to pass direct DB config instead of pulling from Vault # SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_DATASOURCE_URL: jdbc:mysql://your-db-host:3306/task_db?useSSL=true # SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_DATASOURCE_USERNAME: ((db-username)) # SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_ENVIRONMENT_VARIABLES_SPRING_DATASOURCE_PASSWORD: ((db-password))
Key Notes
- Ensure all your Spring Cloud Task applications include the Spring Cloud Vault Starter dependency and are configured to pull the correct database credentials from Vault.
- The
((variable-name))syntax relies on your PCF environment being integrated with Vault or CredHub to resolve secrets securely—no hardcoded values here. - For SCDF 1.4.0, the
SPRING_CLOUD_DEPLOYER_CLOUDFOUNDRY_TASK_*prefix is valid for setting default task deployment properties.
内容的提问来源于stack exchange,提问作者Israel Fernández

