Spring Boot Actuator + Kubernetes + Authentication

Viewed 351

Firstly, let me give you some info about the app:

I have some Spring Boot services backed by Keycloak for authentication/authorization. The app is going to be deployed on kubernetes. I want to add Spring Boot Actuator to all of my Spring Boot apps to have health checks/monitoring capabilities.

When deployed to a k8s environment, actuator gives readinessProbe and livenessProbe endpoints out-of-the-box, see this blog post. I want all actuator endpoints to be secured by keycloak. That means that k8s would hit 401s when attempting to fetch status for my probes. How could I tackle with this ?

I have some solutions that could work:

  • Retrieve a bearer token with curl and put it as a header in httpGet (too slow in my opinion).
  • Restrict /actuator in ingress so that external users cannot access the endpoints and let endpoints unsecured (better but not an ideal solution).

But I'm almost certain that there has to be a better way. Any ideas ?

0 Answers
Related