Spring Cloud Configuration Server - Spring Cloud Default

The Spring Cloud Configuration Server is able to handle git or svn based repositories that host CAS configuration. Such repositories can either be local to the deployment, or they could be on the cloud in form of GitHub/Bitbucket. Access to cloud-based repositories can either be in form of a username/password, or via SSH so as long the appropriate keys are configured in the CAS deployment environment which is really no different than how one would normally access a git repository via SSH.

The following settings and properties are available from the CAS configuration catalog:

spring.cloud.config.server.git.azure.identity.client-idClient ID of the Azure managed identity used for Azure DevOps authentication.
no default
Third party

Client ID of the Azure managed identity used for Azure DevOps authentication.

Type
String
Default
none
Defined by
JGitEnvironmentProperties$AzureProperties$Identity
spring.cloud.config.server.git.azure.identity.managed-identity-enabledWhether managed identity authentication is enabled for Azure DevOps repositories.
false
Third party

Whether managed identity authentication is enabled for Azure DevOps repositories.

Type
Boolean
Default
false
Defined by
JGitEnvironmentProperties$AzureProperties$Identity
spring.cloud.config.server.git.basedirBase directory for local working copy of repository.
no default
Third party

Base directory for local working copy of repository.

Type
File
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.clone-on-startFlag to indicate that the repository should be cloned on startup (not on demand).
false
Third party

Flag to indicate that the repository should be cloned on startup (not on demand). Generally leads to slower startup but faster first query.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.clone-submodulesFlag to indicate that the submodules in the repository should be cloned.
false
Third party

Flag to indicate that the submodules in the repository should be cloned.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.continue-on-multiple-label-failureFlag to indicate whether to continue on multiple label failure.
false
Third party

Flag to indicate whether to continue on multiple label failure. Defaults to false.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.default-labelThe default label to be used with the remote repository.
no default
Third party

The default label to be used with the remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.delete-untracked-branchesFlag to indicate that the branch should be deleted locally if it's origin tracked branch was removed.
false
Third party

Flag to indicate that the branch should be deleted locally if it's origin tracked branch was removed.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.force-pullFlag to indicate that the repository should force pull.
false
Third party

Flag to indicate that the repository should force pull. If true discard any local changes and take from remote repository.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.host-keyValid SSH host key.
no default
Third party

Valid SSH host key. Must be set if hostKeyAlgorithm is also set.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.host-key-algorithmOne of ssh-dss, ssh-rsa, ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, or ecdsa-sha2-nistp521.
no default
Third party

One of ssh-dss, ssh-rsa, ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, or ecdsa-sha2-nistp521. Must be set if hostKey is also set.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.ignore-local-ssh-settingsIf true, use property-based instead of file-based SSH config.
false
Third party

If true, use property-based instead of file-based SSH config.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.known-hosts-fileLocation of custom .known_hosts file.
no default
Third party

Location of custom .known_hosts file.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.orderThe order of the environment repository.
no default
Third party

The order of the environment repository.

Type
Integer
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.passphrasePassphrase for unlocking your ssh private key.
no default
Third party

Passphrase for unlocking your ssh private key.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.passwordPassword for authentication with remote repository.
no default
Third party

Password for authentication with remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.preferred-authenticationsOverride server authentication method order.
no default
Third party

Override server authentication method order. This should allow for evading login prompts if server has keyboard-interactive authentication before the publickey method.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.private-keyValid SSH private key.
no default
Third party

Valid SSH private key. Must be set if ignoreLocalSshSettings is true and Git URI is SSH format.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.proxyHTTP proxy configuration.
no default
Third party

HTTP proxy configuration.

Type
Map<ProxyHostProperties.ProxyForScheme,ProxyHostProperties>
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.refresh-rateTime (in seconds) between refresh of the git repository.
0
Third party

Time (in seconds) between refresh of the git repository.

Type
Integer
Default
0
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.reposMap of repository identifier to location and other properties.
no default
Third party

Map of repository identifier to location and other properties.

Type
Map<String,MultipleJGitEnvironmentProperties.PatternMatchingJGitEnvironmentProperties>
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.search-pathsSearch paths to use within local working copy.
no default
Third party

Search paths to use within local working copy. By default searches only the root.

Type
String[]
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.skip-ssl-validationFlag to indicate that SSL certificate validation should be bypassed when communicating with a repository served over an HTTPS connection.
false
Third party

Flag to indicate that SSL certificate validation should be bypassed when communicating with a repository served over an HTTPS connection.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.strict-host-key-checkingIf false, ignore errors with host key.
true
Third party

If false, ignore errors with host key.

Type
Boolean
Default
true
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.timeoutTimeout (in seconds) for obtaining HTTP or SSH connection (if applicable), defaults to 5 seconds.
5
Third party

Timeout (in seconds) for obtaining HTTP or SSH connection (if applicable), defaults to 5 seconds.

Type
Integer
Default
5
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.try-master-branchTo maintain compatibility we will try the master branch in addition to main when we try to fetch the default branch.
true
Third party

To maintain compatibility we will try the master branch in addition to main when we try to fetch the default branch.

Type
Boolean
Default
true
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.uriURI of remote repository.
no default
Third party

URI of remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.usernameUsername for authentication with remote repository.
no default
Third party

Username for authentication with remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.svn.basedirBase directory for local working copy of repository.
no default
Third party

Base directory for local working copy of repository.

Type
File
Default
none
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.continue-on-multiple-label-failureFlag to indicate whether to continue on multiple label failure.
false
Third party

Flag to indicate whether to continue on multiple label failure. Defaults to false.

Type
Boolean
Default
false
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.default-labelThe default label to be used with the remote repository.
no default
Third party

The default label to be used with the remote repository.

Type
String
Default
none
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.orderThe order of the environment repository.
no default
Third party

The order of the environment repository.

Type
Integer
Default
none
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.passphrasePassphrase for unlocking your ssh private key.
no default
Third party

Passphrase for unlocking your ssh private key.

Type
String
Default
none
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.passwordPassword for authentication with remote repository.
no default
Third party

Password for authentication with remote repository.

Type
String
Default
none
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.search-pathsSearch paths to use within local working copy.
no default
Third party

Search paths to use within local working copy. By default searches only the root.

Type
String[]
Default
none
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.strict-host-key-checkingReject incoming SSH host keys from remote servers not in the known host list.
true
Third party

Reject incoming SSH host keys from remote servers not in the known host list.

Type
Boolean
Default
true
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.uriURI of remote repository.
no default
Third party

URI of remote repository.

Type
String
Default
none
Defined by
SvnKitEnvironmentProperties
spring.cloud.config.server.svn.usernameUsername for authentication with remote repository.
no default
Third party

Username for authentication with remote repository.

Type
String
Default
none
Defined by
SvnKitEnvironmentProperties

Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

Notes on configuration

Configuration Metadata

The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

Be Selective

This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

YAGNI

Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

Naming Convention

Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

:information_source: Note

When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

Validation

Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

Indexed Settings

CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.

:information_source: Usage

The configuration modules provided here may also be used verbatim inside a CAS server overlay and do not exclusively belong to a Spring Cloud Configuration server. While this module is primarily useful when inside the Spring Cloud Configuration server, it nonetheless may also be used inside a CAS server overlay directly to fetch settings from a source.

Needless to say, the repositories could use both YAML and properties syntax to host configuration files. The default profile is activated using spring.profiles.active=default.

:information_source: Keep What You Need!

Again, in all of the above strategies, an adopter is encouraged to only keep and maintain properties needed for their particular deployment. It is UNNECESSARY to grab a copy of all CAS settings and move them to an external location. Settings that are defined by the external configuration location or repository are able to override what is provided by CAS as a default.

Load settings from external properties/yaml configuration files.

The following settings and properties are available from the CAS configuration catalog:

spring.cloud.config.server.default-application-nameDefault application name when incoming requests do not have a specific one.
application
Third party

Default application name when incoming requests do not have a specific one.

Type
String
Default
application
Defined by
ConfigServerProperties
spring.cloud.config.server.default-labelDefault repository label when incoming requests do not have a specific label.
no default
Third party

Default repository label when incoming requests do not have a specific label.

Type
String
Default
none
Defined by
ConfigServerProperties
spring.cloud.config.server.default-profileDefault application profile when incoming requests do not have a specific one.
default
Third party

Default application profile when incoming requests do not have a specific one.

Type
String
Default
default
Defined by
ConfigServerProperties
spring.profiles.activeComma-separated list of active profiles.
no default
Third party

Comma-separated list of active profiles. Can be overridden by a command line switch.

Type
List<String>
Default
none
Defined by
Profiles

Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

Notes on configuration

Configuration Metadata

The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

Be Selective

This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

YAGNI

Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

Naming Convention

Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

:information_source: Note

When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

Validation

Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

Indexed Settings

CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.

Git Repository

Allow the CAS Spring Cloud configuration server to load settings from an internal/external Git repository. This then allows CAS to become a client of the configuration server, consuming settings over HTTP where needed.

The following settings and properties are available from the CAS configuration catalog:

spring.cloud.config.server.git.azure.identity.client-idClient ID of the Azure managed identity used for Azure DevOps authentication.
no default
Third party

Client ID of the Azure managed identity used for Azure DevOps authentication.

Type
String
Default
none
Defined by
JGitEnvironmentProperties$AzureProperties$Identity
spring.cloud.config.server.git.azure.identity.managed-identity-enabledWhether managed identity authentication is enabled for Azure DevOps repositories.
false
Third party

Whether managed identity authentication is enabled for Azure DevOps repositories.

Type
Boolean
Default
false
Defined by
JGitEnvironmentProperties$AzureProperties$Identity
spring.cloud.config.server.git.basedirBase directory for local working copy of repository.
no default
Third party

Base directory for local working copy of repository.

Type
File
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.clone-on-startFlag to indicate that the repository should be cloned on startup (not on demand).
false
Third party

Flag to indicate that the repository should be cloned on startup (not on demand). Generally leads to slower startup but faster first query.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.clone-submodulesFlag to indicate that the submodules in the repository should be cloned.
false
Third party

Flag to indicate that the submodules in the repository should be cloned.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.continue-on-multiple-label-failureFlag to indicate whether to continue on multiple label failure.
false
Third party

Flag to indicate whether to continue on multiple label failure. Defaults to false.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.default-labelThe default label to be used with the remote repository.
no default
Third party

The default label to be used with the remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.delete-untracked-branchesFlag to indicate that the branch should be deleted locally if it's origin tracked branch was removed.
false
Third party

Flag to indicate that the branch should be deleted locally if it's origin tracked branch was removed.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.force-pullFlag to indicate that the repository should force pull.
false
Third party

Flag to indicate that the repository should force pull. If true discard any local changes and take from remote repository.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.host-keyValid SSH host key.
no default
Third party

Valid SSH host key. Must be set if hostKeyAlgorithm is also set.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.host-key-algorithmOne of ssh-dss, ssh-rsa, ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, or ecdsa-sha2-nistp521.
no default
Third party

One of ssh-dss, ssh-rsa, ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, or ecdsa-sha2-nistp521. Must be set if hostKey is also set.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.ignore-local-ssh-settingsIf true, use property-based instead of file-based SSH config.
false
Third party

If true, use property-based instead of file-based SSH config.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.known-hosts-fileLocation of custom .known_hosts file.
no default
Third party

Location of custom .known_hosts file.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.orderThe order of the environment repository.
no default
Third party

The order of the environment repository.

Type
Integer
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.passphrasePassphrase for unlocking your ssh private key.
no default
Third party

Passphrase for unlocking your ssh private key.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.passwordPassword for authentication with remote repository.
no default
Third party

Password for authentication with remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.preferred-authenticationsOverride server authentication method order.
no default
Third party

Override server authentication method order. This should allow for evading login prompts if server has keyboard-interactive authentication before the publickey method.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.private-keyValid SSH private key.
no default
Third party

Valid SSH private key. Must be set if ignoreLocalSshSettings is true and Git URI is SSH format.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.proxyHTTP proxy configuration.
no default
Third party

HTTP proxy configuration.

Type
Map<ProxyHostProperties.ProxyForScheme,ProxyHostProperties>
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.refresh-rateTime (in seconds) between refresh of the git repository.
0
Third party

Time (in seconds) between refresh of the git repository.

Type
Integer
Default
0
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.reposMap of repository identifier to location and other properties.
no default
Third party

Map of repository identifier to location and other properties.

Type
Map<String,MultipleJGitEnvironmentProperties.PatternMatchingJGitEnvironmentProperties>
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.search-pathsSearch paths to use within local working copy.
no default
Third party

Search paths to use within local working copy. By default searches only the root.

Type
String[]
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.skip-ssl-validationFlag to indicate that SSL certificate validation should be bypassed when communicating with a repository served over an HTTPS connection.
false
Third party

Flag to indicate that SSL certificate validation should be bypassed when communicating with a repository served over an HTTPS connection.

Type
Boolean
Default
false
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.strict-host-key-checkingIf false, ignore errors with host key.
true
Third party

If false, ignore errors with host key.

Type
Boolean
Default
true
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.timeoutTimeout (in seconds) for obtaining HTTP or SSH connection (if applicable), defaults to 5 seconds.
5
Third party

Timeout (in seconds) for obtaining HTTP or SSH connection (if applicable), defaults to 5 seconds.

Type
Integer
Default
5
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.try-master-branchTo maintain compatibility we will try the master branch in addition to main when we try to fetch the default branch.
true
Third party

To maintain compatibility we will try the master branch in addition to main when we try to fetch the default branch.

Type
Boolean
Default
true
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.uriURI of remote repository.
no default
Third party

URI of remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.cloud.config.server.git.usernameUsername for authentication with remote repository.
no default
Third party

Username for authentication with remote repository.

Type
String
Default
none
Defined by
MultipleJGitEnvironmentProperties
spring.profiles.activeComma-separated list of active profiles.
no default
Third party

Comma-separated list of active profiles. Can be overridden by a command line switch.

Type
List<String>
Default
none
Defined by
Profiles

Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

Notes on configuration

Configuration Metadata

The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

Be Selective

This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

YAGNI

Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

Naming Convention

Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

:information_source: Note

When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

Validation

Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

Indexed Settings

CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.

The above configuration also applies to online git-based repositories such as GitHub, Bitbucket, etc.