forked from Hithomelabs/CFTunnels
Hithomelabs/CFTunnels#122: Add trust-all SSL RestTemplate for prod profile
Extract trust-all SSL logic into buildTrustAllRestTemplate() helper.
Add @Profile("prod") bean that also trusts self-signed certs.
Change @Profile("!local") to @Profile("!local & !prod") so standard
strict SSL is only used for CI/test profiles.
Rename portainerRestTemplate() to portainerRestTemplateDefault().
This commit is contained in:
parent
3bffa43d6a
commit
52f40e3d92
@ -22,12 +22,11 @@ import java.security.cert.X509Certificate;
|
|||||||
public class PortainerClientConfig {
|
public class PortainerClientConfig {
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Trust-all SSL RestTemplate for the "local" profile.
|
* Builds a RestTemplate that trusts all SSL certificates.
|
||||||
* Used when connecting via Cloudflare Tunnel (self-signed certs).
|
* Used when connecting via Cloudflare Tunnel (self-signed certs)
|
||||||
|
* or to the prod Portainer instance (also self-signed).
|
||||||
*/
|
*/
|
||||||
@Profile("local")
|
private static RestTemplate buildTrustAllRestTemplate() throws Exception {
|
||||||
@Bean(name = "portainerRestTemplate")
|
|
||||||
public RestTemplate portainerRestTemplateLocal() throws Exception {
|
|
||||||
TrustManager[] trustAllCerts = new TrustManager[]{
|
TrustManager[] trustAllCerts = new TrustManager[]{
|
||||||
new X509TrustManager() {
|
new X509TrustManager() {
|
||||||
public X509Certificate[] getAcceptedIssuers() { return new X509Certificate[0]; }
|
public X509Certificate[] getAcceptedIssuers() { return new X509Certificate[0]; }
|
||||||
@ -47,12 +46,32 @@ public class PortainerClientConfig {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Standard validating SSL RestTemplate for non-local profiles
|
* Trust-all SSL RestTemplate for the "local" profile.
|
||||||
* (CI, test, prod — internal Docker network).
|
* Used when connecting via Cloudflare Tunnel (self-signed certs).
|
||||||
*/
|
*/
|
||||||
@Profile("!local")
|
@Profile("local")
|
||||||
@Bean(name = "portainerRestTemplate")
|
@Bean(name = "portainerRestTemplate")
|
||||||
public RestTemplate portainerRestTemplate() {
|
public RestTemplate portainerRestTemplateLocal() throws Exception {
|
||||||
|
return buildTrustAllRestTemplate();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Trust-all SSL RestTemplate for the "prod" profile.
|
||||||
|
* Prod Portainer at https://192.168.0.100:9443 uses a self-signed certificate.
|
||||||
|
*/
|
||||||
|
@Profile("prod")
|
||||||
|
@Bean(name = "portainerRestTemplate")
|
||||||
|
public RestTemplate portainerRestTemplateProd() throws Exception {
|
||||||
|
return buildTrustAllRestTemplate();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Standard validating SSL RestTemplate for profiles other than local and prod
|
||||||
|
* (CI, test — internal Docker network with valid certs).
|
||||||
|
*/
|
||||||
|
@Profile("!local & !prod")
|
||||||
|
@Bean(name = "portainerRestTemplate")
|
||||||
|
public RestTemplate portainerRestTemplateDefault() {
|
||||||
return new RestTemplate();
|
return new RestTemplate();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user