[
https://issues.apache.org/jira/browse/SOLR-14216?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17071277#comment-17071277
]
Jan Høydahl commented on SOLR-14216:
------------------------------------
What about a new env.var to handle this:
{noformat}
# Skip authentication for certain handlers. Allowed values are: health, metrics
(separate by comma). Default=none
# SOLR_AUTH_SKIP=none
{noformat}
bin/solr will then transfer this as e.g. {{-Dsolr.auth.skip=health,metrics}}
and only these values are allowed. In Solr we then create a static Util method
{{public static Set<String> skipAuthPaths()}} which returns what paths to skip
auth for, and use this call from all three locations mentioned above. The
response will always include {{["/admin/info/key", "/", "/solr/"]}} and will
also check the new sysprop and return v1 and v2 paths for health and/or metrics
if configured.
> Exclude HealthCheck from authentication
> ---------------------------------------
>
> Key: SOLR-14216
> URL: https://issues.apache.org/jira/browse/SOLR-14216
> Project: Solr
> Issue Type: Improvement
> Security Level: Public(Default Security Level. Issues are Public)
> Components: Authentication
> Reporter: Jan Høydahl
> Assignee: Jan Høydahl
> Priority: Major
> Time Spent: 10m
> Remaining Estimate: 0h
>
> The {{HealthCheckHandler}} on {{/api/node/health}} and
> {{/solr/admin/info/health}} should by default not be subject to
> authentication, but be open for all. This allows for load balancers and
> various monitoring to probe Solr's health without having to support the auth
> scheme in place. I can't see any reason we need auth on the health endpoint.
> It is possible to achieve the same by setting blockUnknown=false and
> configuring three RBAC permissions: One for v1 endpoint, one for v2 endpoint
> and one "all" catch all at the end of the chain. But this is cumbersome so
> better have this ootb.
> An alternative solution is to create a separate HttpServer for health check,
> listening on a different port, just like embedded ZK and JMX.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]