Spring Cloud Configuration Server - Spring Cloud Azure KeyVault

Spring Cloud Configuration Server is able to use Microsoft Azure’s KeyVault Secrets to locate properties and settings. Support is provided via the following dependency in the WAR overlay:

1
2
3
4
5
<dependency>
    <groupId>org.apereo.cas</groupId>
    <artifactId>cas-server-support-configuration-cloud-azure-keyvault</artifactId>
    <version>${cas.version}</version>
</dependency>
1
implementation "org.apereo.cas:cas-server-support-configuration-cloud-azure-keyvault:${project.'cas.version'}"
1
2
3
4
5
6
7
8
9
dependencyManagement {
    imports {
        mavenBom "org.apereo.cas:cas-server-support-bom:${project.'cas.version'}"
    }
}

dependencies {
    implementation "org.apereo.cas:cas-server-support-configuration-cloud-azure-keyvault"
}
1
2
3
4
5
6
7
8
9
10
dependencies {
    /*
        The following platform references are included automatically and are listed for reference only.

        implementation enforcedPlatform("org.apereo.cas:cas-server-support-bom:${project.'cas.version'}")
        implementation platform(org.springframework.boot.gradle.plugin.SpringBootPlugin.BOM_COORDINATES)
        
    */
    implementation "org.apereo.cas:cas-server-support-configuration-cloud-azure-keyvault"
}

IMPORTANT: The allowed name pattern in Azure Key Vault is ^[0-9a-zA-Z-]+$. For properties that contain . in the name (i.e. cas.some.property), replace . with - when you store the setting in Azure Key Vault (i.e. cas-some-property). The module will handle the transformation for you.

:information_source: Usage

The configuration modules provided here may also be used verbatim inside a CAS server overlay and do not exclusively belong to a Spring Cloud Configuration server. While this module is primarily useful when inside the Spring Cloud Configuration server, it nonetheless may also be used inside a CAS server overlay directly to fetch settings from a source.

The following settings and properties are available from the CAS configuration catalog:

spring.cloud.azure.keyvault.secret.challenge-resource-verification-enabledWhether to enable the Azure Key Vault challenge resource verification, default: true.
true
Third party

Whether to enable the Azure Key Vault challenge resource verification, default: true. Calls the disableChallengeResourceVerification method of the Azure Key Vault Client Builder when set to false.

Type
Boolean
Default
true
Defined by
AzureKeyVaultSecretProperties
spring.cloud.azure.keyvault.secret.client.application-idRepresents current application and is used for telemetry/monitoring purposes.
no default
Third party

Represents current application and is used for telemetry/monitoring purposes.

Type
String
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.client.connect-timeoutAmount of time(Duration) the request attempts to connect to the remote host and the connection is resolved.
no default
Third party

Amount of time(Duration) the request attempts to connect to the remote host and the connection is resolved.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.client.connection-idle-timeoutAmount of time(Duration) before an idle connection.
no default
Third party

Amount of time(Duration) before an idle connection.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.client.headersList of headers applied to each request sent with client.
no default
Third party

List of headers applied to each request sent with client. For instance, '"myCustomHeader", "myStaticValue"'.

Type
List<HeaderProperties>
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.client.headers[0].nameThe name of the header.
no default
Third party

The name of the header.

Type
String
Default
none
Defined by
HeaderProperties
spring.cloud.azure.keyvault.secret.client.headers[0].valuesList of values of the header.
no default
Third party

List of values of the header.

Type
List<String>
Default
none
Defined by
HeaderProperties
spring.cloud.azure.keyvault.secret.client.logging.allowed-header-namesComma-delimited list of allowlist headers that should be logged.
no default
Third party

Comma-delimited list of allowlist headers that should be logged. The default value is `"x-ms-request-id","x-ms-client-request-id","x-ms-return-client-request-id","traceparent","MS-CV","Accept","Cache-Control","Connection","Content-Length","Content-Type","Date","ETag","Expires","If-Match","If-Modified-Since","If-None-Match","If-Unmodified-Since","Last-Modified","Pragma","Request-Id","Retry-After","Server","Transfer-Encoding","User-Agent","WWW-Authenticate"`.

Type
Set<String>
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.client.logging.allowed-query-param-namesComma-delimited list of allowlist query parameters.
no default
Third party

Comma-delimited list of allowlist query parameters. The default value is `"api-version"`.

Type
Set<String>
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.client.logging.levelThe level of detail to log on HTTP messages.
no default
Third party

The level of detail to log on HTTP messages. Supported types are: NONE, BASIC, HEADERS, BODY, BODY_AND_HEADERS. The default value is `NONE`.

Type
HttpLogDetailLevel
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.client.logging.pretty-print-bodyWhether to pretty print the message bodies.
no default
Third party

Whether to pretty print the message bodies. The default value is `false`.

Type
Boolean
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.client.maximum-connection-pool-sizeMaximum connection pool size used by the underlying HTTP client.
no default
Third party

Maximum connection pool size used by the underlying HTTP client.

Type
Integer
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.client.read-timeoutAmount of time(Duration) used when reading the server response.
no default
Third party

Amount of time(Duration) used when reading the server response.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.client.response-timeoutAmount of time(Duration) used when waiting for a server to reply.
no default
Third party

Amount of time(Duration) used when waiting for a server to reply.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.client.write-timeoutAmount of time(Duration) each request being sent over the wire.
no default
Third party

Amount of time(Duration) each request being sent over the wire.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.client-certificate-passwordPassword of the certificate file.
no default
Third party

Password of the certificate file.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.client-certificate-pathPath of a PEM certificate file to use when performing service principal authentication with Azure.
no default
Third party

Path of a PEM certificate file to use when performing service principal authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.client-idClient ID to use when performing service principal authentication with Azure.
no default
Third party

Client ID to use when performing service principal authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.client-secretClient secret to use when performing service principal authentication with Azure.
no default
Third party

Client secret to use when performing service principal authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.managed-identity-enabledWhether to enable managed identity to authenticate with Azure.
false
Third party

Whether to enable managed identity to authenticate with Azure. If true and the client-id is set, will use the client ID as user assigned managed identity client ID.

Type
Boolean
Default
false
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.passwordPassword to use when performing username/password authentication with Azure.
no default
Third party

Password to use when performing username/password authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.token-credential-bean-nameThe bean name of type 'com.azure.core.credential.TokenCredential' to use when performing authentication with Azure.
no default
Third party

The bean name of type 'com.azure.core.credential.TokenCredential' to use when performing authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.credential.usernameUsername to use when performing username/password authentication with Azure.
no default
Third party

Username to use when performing username/password authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.enabledWhether an Azure Service is enabled.
true
Third party

Whether an Azure Service is enabled.

Type
Boolean
Default
true
Defined by
AzureKeyVaultSecretProperties
spring.cloud.azure.keyvault.secret.endpointAzure Key Vault endpoint.
no default
Third party

Azure Key Vault endpoint. For instance, 'https://{your-unique-keyvault-name}.vault.azure.net/'.

Type
String
Default
none
Defined by
AzureKeyVaultSecretProperties
spring.cloud.azure.keyvault.secret.profile.cloud-typeName of the Azure cloud to connect to.
no default
Third party

Name of the Azure cloud to connect to. Supported types are: 'AZURE', 'AZURE_CHINA', 'AZURE_US_GOVERNMENT', 'OTHER'. The default value is 'AZURE'.

Type
AzureProfileOptionsProvider.CloudType
Default
none
Defined by
AzureProfileConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.active-directory-endpointThe Microsoft Entra endpoint to connect to.
no default
Third party

The Microsoft Entra endpoint to connect to.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.active-directory-graph-api-versionThe Azure Active Directory Graph API version.
no default
Third party

The Azure Active Directory Graph API version.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.active-directory-graph-endpointThe Azure Active Directory Graph endpoint.
no default
Third party

The Azure Active Directory Graph endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.active-directory-resource-idThe Microsoft Entra resource ID.
no default
Third party

The Microsoft Entra resource ID.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.azure-application-insights-endpointThe Azure Application Insights endpoint.
no default
Third party

The Azure Application Insights endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.azure-data-lake-analytics-catalog-and-job-endpoint-suffixThe Data Lake analytics catalog and job endpoint suffix.
no default
Third party

The Data Lake analytics catalog and job endpoint suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.azure-data-lake-store-file-system-endpoint-suffixThe Data Lake storage file system endpoint suffix.
no default
Third party

The Data Lake storage file system endpoint suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.azure-log-analytics-endpointThe Azure Log Analytics endpoint.
no default
Third party

The Azure Log Analytics endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.data-lake-endpoint-resource-idThe Data Lake endpoint.
no default
Third party

The Data Lake endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.gallery-endpointThe gallery endpoint.
no default
Third party

The gallery endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.key-vault-dns-suffixThe Key Vault DNS suffix.
no default
Third party

The Key Vault DNS suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.management-endpointThe management service endpoint.
no default
Third party

The management service endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.microsoft-graph-endpointThe Microsoft Graph endpoint.
no default
Third party

The Microsoft Graph endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.portalThe management portal URL.
no default
Third party

The management portal URL.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.publishing-profileThe publishing settings file URL.
no default
Third party

The publishing settings file URL.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.resource-manager-endpointThe resource management endpoint.
no default
Third party

The resource management endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.service-bus-domain-nameThe domain name for Service Bus.
no default
Third party

The domain name for Service Bus.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.sql-management-endpointThe SQL management endpoint.
no default
Third party

The SQL management endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.sql-server-hostname-suffixThe SQL Server hostname suffix.
no default
Third party

The SQL Server hostname suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.environment.storage-endpoint-suffixThe Storage endpoint suffix.
no default
Third party

The Storage endpoint suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.subscription-idSubscription ID to use when connecting to Azure resources.
no default
Third party

Subscription ID to use when connecting to Azure resources.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties
spring.cloud.azure.keyvault.secret.profile.tenant-idTenant ID for Azure resources.
no default
Third party

Tenant ID for Azure resources. The values allowed for 'tenant-id' are: 'common', 'organizations', 'consumers', or the tenant ID.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties
spring.cloud.azure.keyvault.secret.property-source-enabledWhether to enable the Key Vault property source.
true
Third party

Whether to enable the Key Vault property source.

Type
Boolean
Default
true
Defined by
AzureKeyVaultSecretProperties
spring.cloud.azure.keyvault.secret.property-sourcesList of Azure Key Vault property sources.
no default
Third party

List of Azure Key Vault property sources. For instance, ' property-sources[0].name=key-vault-property-source-1, property-sources[0].endpoint={ENDPOINT_1}, property-sources[1].name=key-vault-property-source-2, property-sources[1].endpoint={ENDPOINT_2} '.

Type
List<AzureKeyVaultPropertySourceProperties>
Default
none
Defined by
AzureKeyVaultSecretProperties
spring.cloud.azure.keyvault.secret.property-sources[0].case-sensitiveWhether to enable case-sensitive for secret keys.
no default
Third party

Whether to enable case-sensitive for secret keys. The default value is `false`.

Type
Boolean
Default
none
Defined by
AzureKeyVaultPropertySourceProperties
spring.cloud.azure.keyvault.secret.property-sources[0].challenge-resource-verification-enabledWhether to enable the Azure Key Vault challenge resource verification, default: true.
true
Third party

Whether to enable the Azure Key Vault challenge resource verification, default: true. Calls the disableChallengeResourceVerification method of the Azure Key Vault Client Builder when set to false.

Type
Boolean
Default
true
Defined by
AzureKeyVaultPropertySourceProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.application-idRepresents current application and is used for telemetry/monitoring purposes.
no default
Third party

Represents current application and is used for telemetry/monitoring purposes.

Type
String
Default
none
Defined by
ClientConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.connect-timeoutAmount of time(Duration) the request attempts to connect to the remote host and the connection is resolved.
no default
Third party

Amount of time(Duration) the request attempts to connect to the remote host and the connection is resolved.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.connection-idle-timeoutAmount of time(Duration) before an idle connection.
no default
Third party

Amount of time(Duration) before an idle connection.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.headers[0].nameThe name of the header.
no default
Third party

The name of the header.

Type
String
Default
none
Defined by
HeaderProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.headers[0].valuesList of values of the header.
no default
Third party

List of values of the header.

Type
List<String>
Default
none
Defined by
HeaderProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.logging.allowed-header-namesComma-delimited list of allowlist headers that should be logged.
no default
Third party

Comma-delimited list of allowlist headers that should be logged. The default value is `'x-ms-request-id','x-ms-client-request-id','x-ms-return-client-request-id','traceparent','MS-CV','Accept','Cache-Control','Connection','Content-Length','Content-Type','Date','ETag','Expires','If-Match','If-Modified-Since','If-None-Match','If-Unmodified-Since','Last-Modified','Pragma','Request-Id','Retry-After','Server','Transfer-Encoding','User-Agent','WWW-Authenticate'`.

Type
Set<String>
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.logging.allowed-query-param-namesComma-delimited list of allowlist query parameters.
no default
Third party

Comma-delimited list of allowlist query parameters. The default value is `'api-version'`.

Type
Set<String>
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.logging.levelThe level of detail to log on HTTP messages.
no default
Third party

The level of detail to log on HTTP messages. Supported types are: NONE, BASIC, HEADERS, BODY, BODY_AND_HEADERS. The default value is `NONE`.

Type
HttpLogDetailLevel
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.logging.pretty-print-bodyWhether to pretty print the message bodies.
no default
Third party

Whether to pretty print the message bodies. The default value is `false`.

Type
Boolean
Default
none
Defined by
HttpLoggingConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.maximum-connection-pool-sizeMaximum connection pool size used by the underlying HTTP client.
no default
Third party

Maximum connection pool size used by the underlying HTTP client.

Type
Integer
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.read-timeoutAmount of time(Duration) used when reading the server response.
no default
Third party

Amount of time(Duration) used when reading the server response.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.response-timeoutAmount of time(Duration) used when waiting for a server to reply.
no default
Third party

Amount of time(Duration) used when waiting for a server to reply.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].client.write-timeoutAmount of time(Duration) each request being sent over the wire.
no default
Third party

Amount of time(Duration) each request being sent over the wire.

Type
Duration
Default
none
Defined by
HttpClientConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].credential.client-certificate-passwordPassword of the certificate file.
no default
Third party

Password of the certificate file.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].credential.client-certificate-pathPath of a PEM certificate file to use when performing service principal authentication with Azure.
no default
Third party

Path of a PEM certificate file to use when performing service principal authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].credential.client-idClient ID to use when performing service principal authentication with Azure.
no default
Third party

Client ID to use when performing service principal authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].credential.client-secretClient secret to use when performing service principal authentication with Azure.
no default
Third party

Client secret to use when performing service principal authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].credential.managed-identity-enabledWhether to enable managed identity to authenticate with Azure.
false
Third party

Whether to enable managed identity to authenticate with Azure. If true and the client-id is set, will use the client ID as user assigned managed identity client ID.

Type
Boolean
Default
false
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].credential.passwordPassword to use when performing username/password authentication with Azure.
no default
Third party

Password to use when performing username/password authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].credential.usernameUsername to use when performing username/password authentication with Azure.
no default
Third party

Username to use when performing username/password authentication with Azure.

Type
String
Default
none
Defined by
TokenCredentialConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].enabledWhether an Azure Service is enabled.
true
Third party

Whether an Azure Service is enabled.

Type
Boolean
Default
true
Defined by
AbstractAzureServiceConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].endpointAzure Key Vault endpoint.
no default
Third party

Azure Key Vault endpoint. For instance, 'https://{your-unique-keyvault-name}.vault.azure.net/'.

Type
String
Default
none
Defined by
AzureKeyVaultPropertySourceProperties
spring.cloud.azure.keyvault.secret.property-sources[0].nameName of this property source.
no default
Third party

Name of this property source.

Type
String
Default
none
Defined by
AzureKeyVaultPropertySourceProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.cloud-typeName of the Azure cloud to connect to.
no default
Third party

Name of the Azure cloud to connect to. Supported types are: AZURE, AZURE_CHINA, AZURE_US_GOVERNMENT, OTHER. The default value is `AZURE`.

Type
AzureProfileOptionsProvider.CloudType
Default
none
Defined by
AzureProfileConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.active-directory-endpointThe Microsoft Entra endpoint to connect to.
no default
Third party

The Microsoft Entra endpoint to connect to.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.active-directory-graph-api-versionThe Azure Active Directory Graph API version.
no default
Third party

The Azure Active Directory Graph API version.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.active-directory-graph-endpointThe Azure Active Directory Graph endpoint.
no default
Third party

The Azure Active Directory Graph endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.active-directory-resource-idThe Microsoft Entra resource ID.
no default
Third party

The Microsoft Entra resource ID.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.azure-application-insights-endpointThe Azure Application Insights endpoint.
no default
Third party

The Azure Application Insights endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.azure-data-lake-analytics-catalog-and-job-endpoint-suffixThe Data Lake analytics catalog and job endpoint suffix.
no default
Third party

The Data Lake analytics catalog and job endpoint suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.azure-data-lake-store-file-system-endpoint-suffixThe Data Lake storage file system endpoint suffix.
no default
Third party

The Data Lake storage file system endpoint suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.azure-log-analytics-endpointThe Azure Log Analytics endpoint.
no default
Third party

The Azure Log Analytics endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.data-lake-endpoint-resource-idThe Data Lake endpoint.
no default
Third party

The Data Lake endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.gallery-endpointThe gallery endpoint.
no default
Third party

The gallery endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.key-vault-dns-suffixThe Key Vault DNS suffix.
no default
Third party

The Key Vault DNS suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.management-endpointThe management service endpoint.
no default
Third party

The management service endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.microsoft-graph-endpointThe Microsoft Graph endpoint.
no default
Third party

The Microsoft Graph endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.portalThe management portal URL.
no default
Third party

The management portal URL.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.publishing-profileThe publishing settings file URL.
no default
Third party

The publishing settings file URL.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.resource-manager-endpointThe resource management endpoint.
no default
Third party

The resource management endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.sql-management-endpointThe SQL management endpoint.
no default
Third party

The SQL management endpoint.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.sql-server-hostname-suffixThe SQL Server hostname suffix.
no default
Third party

The SQL Server hostname suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.environment.storage-endpoint-suffixThe Storage endpoint suffix.
no default
Third party

The Storage endpoint suffix.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties$AzureEnvironmentConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.subscription-idSubscription ID to use when connecting to Azure resources.
no default
Third party

Subscription ID to use when connecting to Azure resources.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].profile.tenant-idTenant ID for Azure resources.
no default
Third party

Tenant ID for Azure resources. The values allowed for 'tenant-id' are: 'common', 'organizations', 'consumers', or the tenant ID.

Type
String
Default
none
Defined by
AzureProfileConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].proxy.hostnameThe host of the proxy.
no default
Third party

The host of the proxy.

Type
String
Default
none
Defined by
ProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].proxy.non-proxy-hostsA list of hosts or CIDR to not use proxy HTTP/HTTPS connections through.
no default
Third party

A list of hosts or CIDR to not use proxy HTTP/HTTPS connections through.

Type
String
Default
none
Defined by
HttpProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].proxy.passwordPassword used to authenticate with the proxy.
no default
Third party

Password used to authenticate with the proxy.

Type
String
Default
none
Defined by
ProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].proxy.portThe port of the proxy.
no default
Third party

The port of the proxy.

Type
Integer
Default
none
Defined by
ProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].proxy.typeThe type of the proxy.
no default
Third party

The type of the proxy. For instance of http, 'http', 'socks4', 'socks5'. For instance of amqp, 'http', 'socks'.

Type
String
Default
none
Defined by
ProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].proxy.usernameUsername used to authenticate with the proxy.
no default
Third party

Username used to authenticate with the proxy.

Type
String
Default
none
Defined by
ProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].resource.regionThe region of an Azure resource.
no default
Third party

The region of an Azure resource. For instance, '"eastus"'.

Type
String
Default
none
Defined by
AzureResourceMetadataConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].resource.resource-groupThe resource group holds an Azure resource.
no default
Third party

The resource group holds an Azure resource.

Type
String
Default
none
Defined by
AzureResourceMetadataConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].resource.resource-idID of an Azure resource.
no default
Third party

ID of an Azure resource.

Type
String
Default
none
Defined by
AzureResourceMetadataConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].retry.exponential.base-delayAmount of time(Duration) to wait between retry attempts.
no default
Third party

Amount of time(Duration) to wait between retry attempts.

Type
Duration
Default
none
Defined by
ExponentialRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].retry.exponential.max-delayMaximum permissible amount of time(duration) between retry attempts.
no default
Third party

Maximum permissible amount of time(duration) between retry attempts.

Type
Duration
Default
none
Defined by
ExponentialRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].retry.exponential.max-retriesThe maximum number of attempts.
no default
Third party

The maximum number of attempts.

Type
Integer
Default
none
Defined by
ExponentialRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].retry.fixed.delayAmount of time(Duration) to wait between retry attempts.
no default
Third party

Amount of time(Duration) to wait between retry attempts.

Type
Duration
Default
none
Defined by
FixedRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].retry.fixed.max-retriesThe maximum number of attempts.
no default
Third party

The maximum number of attempts.

Type
Integer
Default
none
Defined by
FixedRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].retry.modeThe retry backoff mode when retrying.
no default
Third party

The retry backoff mode when retrying. Supported types are: FIXED, EXPONENTIAL.

Type
RetryOptionsProvider.RetryMode
Default
none
Defined by
RetryConfigurationProperties
spring.cloud.azure.keyvault.secret.property-sources[0].secret-keysThe configured secret keys will be loaded from Azure Key Vaults secret, if configured nothing, then load all the secrets.
no default
Third party

The configured secret keys will be loaded from Azure Key Vaults secret, if configured nothing, then load all the secrets. Only support exact value for secret names, For example, if you configured secret key name `SecretKey1` in Key Vaults secret, you should configure 'SecretKey1' here.

Type
List<String>
Default
none
Defined by
AzureKeyVaultPropertySourceProperties
spring.cloud.azure.keyvault.secret.property-sources[0].service-versionSecret service version used when making API requests.
no default
Third party

Secret service version used when making API requests.

Type
SecretServiceVersion
Default
none
Defined by
AzureKeyVaultPropertySourceProperties
spring.cloud.azure.keyvault.secret.proxy.hostnameThe host of the proxy.
no default
Third party

The host of the proxy.

Type
String
Default
none
Defined by
HttpProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.proxy.non-proxy-hostsA list of hosts or CIDR to not use proxy HTTP/HTTPS connections through.
no default
Third party

A list of hosts or CIDR to not use proxy HTTP/HTTPS connections through.

Type
String
Default
none
Defined by
HttpProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.proxy.passwordPassword used to authenticate with the proxy.
no default
Third party

Password used to authenticate with the proxy.

Type
String
Default
none
Defined by
HttpProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.proxy.portThe port of the proxy.
no default
Third party

The port of the proxy.

Type
Integer
Default
none
Defined by
HttpProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.proxy.typeThe type of the proxy.
no default
Third party

The type of the proxy. For instance of http, 'http', 'socks4', 'socks5'. For instance of amqp, 'http', 'socks'.

Type
String
Default
none
Defined by
HttpProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.proxy.usernameUsername used to authenticate with the proxy.
no default
Third party

Username used to authenticate with the proxy.

Type
String
Default
none
Defined by
HttpProxyConfigurationProperties
spring.cloud.azure.keyvault.secret.resource.regionThe region of an Azure resource.
no default
Third party

The region of an Azure resource. For instance, '"eastus"'.

Type
String
Default
none
Defined by
AzureResourceMetadataConfigurationProperties
spring.cloud.azure.keyvault.secret.resource.resource-groupThe resource group holds an Azure resource.
no default
Third party

The resource group holds an Azure resource.

Type
String
Default
none
Defined by
AzureResourceMetadataConfigurationProperties
spring.cloud.azure.keyvault.secret.resource.resource-idID of an Azure resource.
no default
Third party

ID of an Azure resource.

Type
String
Default
none
Defined by
AzureResourceMetadataConfigurationProperties
spring.cloud.azure.keyvault.secret.retry.exponential.base-delayAmount of time(Duration) to wait between retry attempts.
no default
Third party

Amount of time(Duration) to wait between retry attempts.

Type
Duration
Default
none
Defined by
ExponentialRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.retry.exponential.max-delayMaximum permissible amount of time(duration) between retry attempts.
no default
Third party

Maximum permissible amount of time(duration) between retry attempts.

Type
Duration
Default
none
Defined by
ExponentialRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.retry.exponential.max-retriesThe maximum number of attempts.
no default
Third party

The maximum number of attempts.

Type
Integer
Default
none
Defined by
ExponentialRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.retry.fixed.delayAmount of time(Duration) to wait between retry attempts.
no default
Third party

Amount of time(Duration) to wait between retry attempts.

Type
Duration
Default
none
Defined by
FixedRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.retry.fixed.max-retriesThe maximum number of attempts.
no default
Third party

The maximum number of attempts.

Type
Integer
Default
none
Defined by
FixedRetryConfigurationProperties
spring.cloud.azure.keyvault.secret.retry.modeThe retry backoff mode when retrying.
no default
Third party

The retry backoff mode when retrying. Supported types are: FIXED, EXPONENTIAL.

Type
RetryOptionsProvider.RetryMode
Default
none
Defined by
RetryConfigurationProperties
spring.cloud.azure.keyvault.secret.service-versionSecret service version used when making API requests.
no default
Third party

Secret service version used when making API requests.

Type
SecretServiceVersion
Default
none
Defined by
AzureKeyVaultSecretProperties

Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

Groovy scripting

CAS takes advantage of Apache Groovy in forms of either embedded or external scripts that allow one to, by default, dynamically build constructs, attributes, access strategies and a lot more. To activate the functionality described here, you may need to prepare CAS to support and integrate with Apache Groovy.

Please review this guide to configure your build.

Notes on configuration

Configuration Metadata

The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

Be Selective

This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

YAGNI

Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

Naming Convention

Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

:information_source: Note

When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

Validation

Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

Indexed Settings

CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.