Skip to content

Apiml modulith start script does not consume components.apiml.* properties #4770

Description

@balhar-jakub

The apiml-package/src/main/resources/bin/start.sh was derived from the gateway start script, but most configuration variable references still use ZWE_components_gateway_* instead of ZWE_components_apiml_*. Users cannot independently configure the modulith via components.apiml.* in zowe.yaml — they must use components.gateway.*.

Already fixed (2 properties)

  • debug (line 143)
  • spring.profiles.active (lines 144-145)

Still missing — 68 lines across 55 properties

All use the pattern ${ZWE_components_gateway_<prop>:-<default>} which should become ${ZWE_components_apiml_<prop>:-${ZWE_components_gateway_<prop>:-<default>}}.

Heap & Port

  • line 220: heap.init, heap.max (-Xms / -Xmx)
  • line 319: port (also embedded in 4 URL defaults: lines 283, 289, 301, 302, 309)

Server & WebSocket

  • line 169, 352: server.ssl.enabled
  • line 348: server.maxConnectionsPerRoute
  • line 349: server.maxTotalConnections
  • line 362: server.webSocket.asyncWriteTimeout
  • line 363: server.webSocket.connectTimeout
  • line 364: server.webSocket.maxIdleTimeout
  • line 365: server.webSocket.requestBufferSize

Connection Pool

  • line 240: connection.idleConnectionTimeoutSeconds
  • line 241: connection.timeout
  • line 242: connection.timeToLive

Discovery

  • line 244: discovery.password
  • line 247: discovery.userid

Gateway Routing & Rate Limiting

  • line 248: gateway.cachePeriodSec
  • line 250: gateway.maxSimultaneousRequests
  • line 251: gateway.rateLimiterCapacity
  • line 252: gateway.rateLimiterRefillDuration
  • line 253: gateway.rateLimiterTokens
  • line 254: gateway.refresh-interval-ms
  • line 255: gateway.registry.enabled
  • line 256: gateway.registry.metadata-key-allow-list
  • line 257: gateway.servicesToDisableRetry
  • line 258: gateway.servicesToLimitRequestRate

Health

  • line 259: health.protected

Security — Auth Core

  • line 151: security.auth.uniqueCookie
  • line 274: security.allowTokenRefresh
  • line 276: security.auth.jwt.customAuthHeader
  • line 277: security.auth.passticket.customAuthHeader
  • line 278: security.auth.passticket.customUserHeader
  • line 279: security.auth.provider
  • line 280: security.auth.zosmf.jwtAutoconfiguration
  • line 281: security.auth.zosmf.serviceId

Security — OIDC

  • line 288: security.oidc.enabled
  • line 289: security.oidc.identityMapperUrl
  • line 290: security.oidc.identityMapperUser
  • line 291: security.oidc.jwks.refreshInternalHours
  • line 292: security.oidc.jwks.uri
  • line 293: security.oidc.registry
  • line 294: security.oidc.userIdField
  • line 295: security.oidc.userInfo.uri
  • line 296: security.oidc.validationType

Security — X.509

  • line 306: security.x509.acceptForwardedCert
  • line 307: security.x509.certificatesUrls, security.x509.certificatesUrl
  • line 308, 317: security.x509.enabled
  • line 309: security.x509.externalMapperUrl
  • line 310: security.x509.externalMapperUser
  • line 311: security.x509.registry.allowedUsers

Security — Authorization

  • line 282: security.authorization.endpoint.enabled
  • line 283: security.authorization.endpoint.url
  • line 284: security.authorization.provider
  • line 285: security.authorization.resourceClass
  • line 286: security.authorization.resourceNamePrefix

Security — SAF

  • line 300: security.saf.provider
  • line 301: security.saf.urls.authenticate
  • line 302: security.saf.urls.verify

Security — PAT, Rauditx & Other

  • line 287: security.jwtInitializerTimeout
  • line 297: security.personalAccessToken.enabled
  • line 298: security.rauditx.oidcSourceUserPaths
  • line 299: security.rauditx.onOidcUserIsMapped
  • line 305: security.useInternalMapper

Service Config

  • line 313: service.allowEncodedSlashes
  • line 314: service.apimlId
  • line 315: service.corsAllowedMethods
  • line 316: service.corsEnabled
  • line 317: service.forwardClientCertEnabled

SSL Debug

  • line 332: sslDebug

Acceptance Criteria

  • All 68 listed references are updated to accept ZWE_components_apiml_* as primary with ZWE_components_gateway_* fallback
  • components.apiml.heap.init / components.apiml.heap.max work via zowe.yaml
  • components.apiml.port works via zowe.yaml
  • All other components.apiml.* properties work via zowe.yaml
  • Existing configurations using components.gateway.* continue to work (backward compatible)

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions