Uploaded image for project: 'Thorntail'
  1. Thorntail
  2. THORN-1876

Microprofile Health - Warn security

    Details

      Description

      There's a security warning at startup for this fraction.

      There's no way to set up the application to remove this warning.

      2018-03-03 11:25:11,936 WARN  [org.wildfly.swarm.microprofile.health] (MSC service thread 1-2) You are running the monitoring endpoints without any security realm configuration!
      

      From Heiko Braun :
      Unfortunately It's not possible without a custom main() and that's deprecated (See org.wildfly.swarm.microprofile.health.HealthFraction). I can see two ways forward this:

      • Ignore the warning: It should be fin to the the health checks unsecured as long as you don't expose any sensitive information in the health response payload
      • Provide patch to make make the security realm setting in that fraction configurable.

      Even if you decide to ignore it, it would be good to file an issue request the later change.

      Regards, Heiko

        Gliffy Diagrams

          Attachments

            Activity

              People

              • Assignee:
                sbiarozk Sergey Beryozkin
                Reporter:
                jonleyo Jonathan Laterreur
              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: