How to configure SpringSecurity oAuth2 and Basic

Viewed 44

I'm writting microservice for some business logic, that connected to authentication microservice for auth. For now I try to congigure prometheus with name/passord to get info from my service(dont want to do it permitAll()). But, unfortunatelly, it works perfect only when use permitAll() for "/actuator/**". If I change it to smth like hasRole('ACTUATOR ADMIN') I revieve BadCredential.

application.yml:

application:
  clientId: newApp
server: 
  port: 8081
  
spring:
  security:
    name: prom
    password: prom
    roles: ACTUATOR_ADMIN
    
#prometheus
management:
  endpoint:
    metrics:
      enabled: true
    prometheus:
      enabled: true
  endpoints:
    web:
      exposure:
        include: '*'
  metrics:
    export:
      prometheus:
        enabled: true

prometheus.yml

scrape_configs:
  - job_name: 'spring-actuator'
    metrics_path: '/actuator/prometheus'
    basic_auth:
      username: "prom"
      password: "prom"
    scrape_interval: 5s
    static_configs:
    - targets: ['192.168.1.187:8081']

and ResourceServerConfig:

 @Configuration
@EnableResourceServer
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class ResourceServerConfiguration extends ResourceServerConfigurerAdapter {

    @Override
    public void configure(HttpSecurity http) throws Exception {

        http
        .csrf().disable()
        .authorizeRequests()
                .antMatchers("/v2/api-docs", "/configuration/ui", "/swagger-resources", "/configuration/security",
                        "/swagger-ui.html", "/webjars/**", "/swagger-resources/configuration/ui",
                        "/swagger-resources/configuration/security").permitAll()
                .antMatchers("/**").authenticated();
}

How to fix it?

Thanks in advance.

0 Answers
Related