From 52f40e3d927aacef838414b0e3822223b6fc4f73 Mon Sep 17 00:00:00 2001 From: hitanshu310 Date: Fri, 10 Jul 2026 02:24:23 +0530 Subject: [PATCH] Hithomelabs/CFTunnels#122: Add trust-all SSL RestTemplate for prod profile Extract trust-all SSL logic into buildTrustAllRestTemplate() helper. Add @Profile("prod") bean that also trusts self-signed certs. Change @Profile("!local") to @Profile("!local & !prod") so standard strict SSL is only used for CI/test profiles. Rename portainerRestTemplate() to portainerRestTemplateDefault(). --- .../config/PortainerClientConfig.java | 37 ++++++++++++++----- 1 file changed, 28 insertions(+), 9 deletions(-) diff --git a/portainer-automation/src/main/java/com/hithomelabs/portainer/config/PortainerClientConfig.java b/portainer-automation/src/main/java/com/hithomelabs/portainer/config/PortainerClientConfig.java index a1eb364..6d98a75 100644 --- a/portainer-automation/src/main/java/com/hithomelabs/portainer/config/PortainerClientConfig.java +++ b/portainer-automation/src/main/java/com/hithomelabs/portainer/config/PortainerClientConfig.java @@ -22,12 +22,11 @@ import java.security.cert.X509Certificate; public class PortainerClientConfig { /** - * Trust-all SSL RestTemplate for the "local" profile. - * Used when connecting via Cloudflare Tunnel (self-signed certs). + * Builds a RestTemplate that trusts all SSL certificates. + * Used when connecting via Cloudflare Tunnel (self-signed certs) + * or to the prod Portainer instance (also self-signed). */ - @Profile("local") - @Bean(name = "portainerRestTemplate") - public RestTemplate portainerRestTemplateLocal() throws Exception { + private static RestTemplate buildTrustAllRestTemplate() throws Exception { TrustManager[] trustAllCerts = new TrustManager[]{ new X509TrustManager() { public X509Certificate[] getAcceptedIssuers() { return new X509Certificate[0]; } @@ -47,12 +46,32 @@ public class PortainerClientConfig { } /** - * Standard validating SSL RestTemplate for non-local profiles - * (CI, test, prod — internal Docker network). + * Trust-all SSL RestTemplate for the "local" profile. + * Used when connecting via Cloudflare Tunnel (self-signed certs). */ - @Profile("!local") + @Profile("local") @Bean(name = "portainerRestTemplate") - public RestTemplate portainerRestTemplate() { + public RestTemplate portainerRestTemplateLocal() throws Exception { + return buildTrustAllRestTemplate(); + } + + /** + * Trust-all SSL RestTemplate for the "prod" profile. + * Prod Portainer at https://192.168.0.100:9443 uses a self-signed certificate. + */ + @Profile("prod") + @Bean(name = "portainerRestTemplate") + public RestTemplate portainerRestTemplateProd() throws Exception { + return buildTrustAllRestTemplate(); + } + + /** + * Standard validating SSL RestTemplate for profiles other than local and prod + * (CI, test — internal Docker network with valid certs). + */ + @Profile("!local & !prod") + @Bean(name = "portainerRestTemplate") + public RestTemplate portainerRestTemplateDefault() { return new RestTemplate(); }