当前位置: 代码网 > it编程>编程语言>Asp.net > Nacos2.2.2开启鉴权配置

Nacos2.2.2开启鉴权配置

2026年08月19日 Asp.net 我要评论
前言最近公司开启了一个新的电商项目,项目中用到了naocs作为注册中心和配置中心,在将nacos服务器启动后,发现是直接可以访问nacos的后台不用登录,看了一下官方的介绍,开启登录的的话需要开启鉴权

前言

最近公司开启了一个新的电商项目,项目中用到了naocs作为注册中心和配置中心,在将nacos服务器启动后,发现是直接可以访问nacos的后台不用登录,看了一下官方的介绍,开启登录的的话需要开启鉴权,那么将我实测后的配置记录一下!

一、更改application.properties中的配置

路径:你的nacos的位置下confg/application.properties

二、修改配置

开启鉴权之前,application.properties中的配置信息为:

### if turn on auth system:
nacos.core.auth.enabled=false

开启鉴权之后,application.properties中的配置信息为:

### if turn on auth system:
nacos.core.auth.system.type=nacos
nacos.core.auth.enabled=true

在2.2.0.1版本后,社区发布版本将移除以文档如下值作为默认值,需要自行填充,否则无法启动节点。

### the default token(base64 string):
nacos.core.auth.default.token.secret.key=secretkey012345678901234567890123456789012345678901234567890123456789

### 2.1.0 版本后
nacos.core.auth.plugin.nacos.token.secret.key=secretkey012345678901234567890123456789012345678901234567890123456789

自定义密钥时,推荐将配置项设置为base64编码的字符串,且原始密钥长度不得低于32字符

### the default token(base64 string):
nacos.core.auth.default.token.secret.key=vghpc0lztxlddxn0b21tzwnyzxrlzxkwmtizndu2nzg=

### 2.1.0 版本后
nacos.core.auth.plugin.nacos.token.secret.key=vghpc0lztxlddxn0b21tzwnyzxrlzxkwmtizndu2nzg=

nacos.core.auth.server.identity.key和nacos.core.auth.server.identity.value必须要有值

nacos.core.auth.server.identity.key=example
nacos.core.auth.server.identity.value=example

那么我的全部配置如下:

#
# copyright 1999-2021 alibaba group holding ltd.
#
# licensed under the apache license, version 2.0 (the "license");
# you may not use this file except in compliance with the license.
# you may obtain a copy of the license at
#
#      http://www.apache.org/licenses/license-2.0
#
# unless required by applicable law or agreed to in writing, software
# distributed under the license is distributed on an "as is" basis,
# without warranties or conditions of any kind, either express or implied.
# see the license for the specific language governing permissions and
# limitations under the license.
#

#*************** spring boot related configurations ***************#
### default web context path:
server.servlet.contextpath=/nacos
### include message field
server.error.include-message=always
### default web server port:
server.port=8848

#*************** network related configurations ***************#
### if prefer hostname over ip for nacos server addresses in cluster.conf:
# nacos.inetutils.prefer-hostname-over-ip=false

### specify local server's ip:
# nacos.inetutils.ip-address=


#*************** config module related configurations ***************#
### if use mysql as datasource:
### deprecated configuration property, it is recommended to use `spring.sql.init.platform` replaced.
 spring.datasource.platform=mysql
# spring.sql.init.platform=mysql

### count of db:
 db.num=1

### connect url of db:
 db.url.0=jdbc:mysql://127.0.0.1:3306/nacos?characterencoding=utf8&connecttimeout=1000&sockettimeout=3000&autoreconnect=true&useunicode=true&usessl=false&servertimezone=utc
 db.user.0=root
 db.password.0=123456

### connection pool configuration: hikaricp
db.pool.config.connectiontimeout=30000
db.pool.config.validationtimeout=10000
db.pool.config.maximumpoolsize=20
db.pool.config.minimumidle=2

#*************** naming module related configurations ***************#

### if enable data warmup. if set to false, the server would accept request without local data preparation:
# nacos.naming.data.warmup=true

### if enable the instance auto expiration, kind like of health check of instance:
# nacos.naming.expireinstance=true

### add in 2.0.0
### the interval to clean empty service, unit: milliseconds.
# nacos.naming.clean.empty-service.interval=60000

### the expired time to clean empty service, unit: milliseconds.
# nacos.naming.clean.empty-service.expired-time=60000

### the interval to clean expired metadata, unit: milliseconds.
# nacos.naming.clean.expired-metadata.interval=5000

### the expired time to clean metadata, unit: milliseconds.
# nacos.naming.clean.expired-metadata.expired-time=60000

### the delay time before push task to execute from service changed, unit: milliseconds.
# nacos.naming.push.pushtaskdelay=500

### the timeout for push task execute, unit: milliseconds.
# nacos.naming.push.pushtasktimeout=5000

### the delay time for retrying failed push task, unit: milliseconds.
# nacos.naming.push.pushtaskretrydelay=1000

### since 2.0.3
### the expired time for inactive client, unit: milliseconds.
# nacos.naming.client.expired.time=180000

#*************** cmdb module related configurations ***************#
### the interval to dump external cmdb in seconds:
# nacos.cmdb.dumptaskinterval=3600

### the interval of polling data change event in seconds:
# nacos.cmdb.eventtaskinterval=10

### the interval of loading labels in seconds:
# nacos.cmdb.labeltaskinterval=300

### if turn on data loading task:
# nacos.cmdb.loaddataatstart=false


#*************** metrics related configurations ***************#
### metrics for prometheus
#management.endpoints.web.exposure.include=*

### metrics for elastic search
management.metrics.export.elastic.enabled=false
#management.metrics.export.elastic.host=http://localhost:9200

### metrics for influx
management.metrics.export.influx.enabled=false
#management.metrics.export.influx.db=springboot
#management.metrics.export.influx.uri=http://localhost:8086
#management.metrics.export.influx.auto-create-db=true
#management.metrics.export.influx.consistency=one
#management.metrics.export.influx.compressed=true

#*************** access log related configurations ***************#
### if turn on the access log:
server.tomcat.accesslog.enabled=true

### the access log pattern:
server.tomcat.accesslog.pattern=%h %l %u %t "%r" %s %b %d %{user-agent}i %{request-source}i

### the directory of access log:
server.tomcat.basedir=file:.

#*************** access control related configurations ***************#
### if enable spring security, this option is deprecated in 1.2.0:
#spring.security.enabled=false

### the ignore urls of auth
nacos.security.ignore.urls=/,/error,/**/*.css,/**/*.js,/**/*.html,/**/*.map,/**/*.svg,/**/*.png,/**/*.ico,/console-ui/public/**,/v1/auth/**,/v1/console/health/**,/actuator/**,/v1/console/server/**

### the auth system to use, currently only 'nacos' and 'ldap' is supported:
nacos.core.auth.system.type=nacos

### if turn on auth system:
nacos.core.auth.enabled=true

### turn on/off caching of auth information. by turning on this switch, the update of auth information would have a 15 seconds delay.
nacos.core.auth.caching.enabled=true

### since 1.4.1, turn on/off white auth for user-agent: nacos-server, only for upgrade from old version.
nacos.core.auth.enable.useragentauthwhite=false

### since 1.4.1, worked when nacos.core.auth.enabled=true and nacos.core.auth.enable.useragentauthwhite=false.
### the two properties is the white list for auth and used by identity the request from other server.
nacos.core.auth.server.identity.key=example
nacos.core.auth.server.identity.value=example

### worked when nacos.core.auth.system.type=nacos
### the token expiration in seconds:
nacos.core.auth.plugin.nacos.token.cache.enable=false
nacos.core.auth.plugin.nacos.token.expire.seconds=18000
### the default token (base64 string):
nacos.core.auth.plugin.nacos.token.secret.key=vghpc0lztxlddxn0b21tzwnyzxrlzxkwmtizndu2nzg=

### worked when nacos.core.auth.system.type=ldap,{0} is placeholder,replace login username
#nacos.core.auth.ldap.url=ldap://localhost:389
#nacos.core.auth.ldap.basedc=dc=example,dc=org
#nacos.core.auth.ldap.userdn=cn=admin,${nacos.core.auth.ldap.basedc}
#nacos.core.auth.ldap.password=admin
#nacos.core.auth.ldap.userdn=cn={0},dc=example,dc=org
#nacos.core.auth.ldap.filter.prefix=uid
#nacos.core.auth.ldap.case.sensitive=true


#*************** istio related configurations ***************#
### if turn on the mcp server:
nacos.istio.mcp.server.enabled=false

#*************** core related configurations ***************#

### set the workerid manually
# nacos.core.snowflake.worker-id=

### member-metadata
# nacos.core.member.meta.site=
# nacos.core.member.meta.adweight=
# nacos.core.member.meta.weight=

### memberlookup
### addressing pattern category, if set, the priority is highest
# nacos.core.member.lookup.type=[file,address-server]
## set the cluster list with a configuration file or command-line argument
# nacos.member.list=192.168.16.101:8847?raft_port=8807,192.168.16.101?raft_port=8808,192.168.16.101:8849?raft_port=8809
## for addressservermemberlookup
# maximum number of retries to query the address server upon initialization
# nacos.core.address-server.retry=5
## server domain name address of [address-server] mode
# address.server.domain=jmenv.tbsite.net
## server port of [address-server] mode
# address.server.port=8080
## request address of [address-server] mode
# address.server.url=/nacos/serverlist

#*************** jraft related configurations ***************#

### sets the raft cluster election timeout, default value is 5 second
# nacos.core.protocol.raft.data.election_timeout_ms=5000
### sets the amount of time the raft snapshot will execute periodically, default is 30 minute
# nacos.core.protocol.raft.data.snapshot_interval_secs=30
### raft internal worker threads
# nacos.core.protocol.raft.data.core_thread_num=8
### number of threads required for raft business request processing
# nacos.core.protocol.raft.data.cli_service_thread_num=4
### raft linear read strategy. safe linear reads are used by default, that is, the leader tenure is confirmed by heartbeat
# nacos.core.protocol.raft.data.read_index_type=readonlysafe
### rpc request timeout, default 5 seconds
# nacos.core.protocol.raft.data.rpc_request_timeout_ms=5000

#*************** distro related configurations ***************#

### distro data sync delay time, when sync task delayed, task will be merged for same data key. default 1 second.
# nacos.core.protocol.distro.data.sync.delayms=1000

### distro data sync timeout for one sync data, default 3 seconds.
# nacos.core.protocol.distro.data.sync.timeoutms=3000

### distro data sync retry delay time when sync data failed or timeout, same behavior with delayms, default 3 seconds.
# nacos.core.protocol.distro.data.sync.retrydelayms=3000

### distro data verify interval time, verify synced data whether expired for a interval. default 5 seconds.
# nacos.core.protocol.distro.data.verify.intervalms=5000

### distro data verify timeout for one verify, default 3 seconds.
# nacos.core.protocol.distro.data.verify.timeoutms=3000

### distro data load retry delay when load snapshot data failed, default 30 seconds.
# nacos.core.protocol.distro.data.load.retrydelayms=30000

### enable to support prometheus service discovery
#nacos.prometheus.metrics.enabled=true

### since 2.3
#*************** grpc configurations ***************#

## sdk grpc(between nacos server and client) configuration
## sets the maximum message size allowed to be received on the server.
#nacos.remote.server.grpc.sdk.max-inbound-message-size=10485760

## sets the time(milliseconds) without read activity before sending a keepalive ping. the typical default is two hours.
#nacos.remote.server.grpc.sdk.keep-alive-time=7200000

## sets a time(milliseconds) waiting for read activity after sending a keepalive ping. defaults to 20 seconds.
#nacos.remote.server.grpc.sdk.keep-alive-timeout=20000


## sets a time(milliseconds) that specify the most aggressive keep-alive time clients are permitted to configure. the typical default is 5 minutes
#nacos.remote.server.grpc.sdk.permit-keep-alive-time=300000

## cluster grpc(inside the nacos server) configuration
#nacos.remote.server.grpc.cluster.max-inbound-message-size=10485760

## sets the time(milliseconds) without read activity before sending a keepalive ping. the typical default is two hours.
#nacos.remote.server.grpc.cluster.keep-alive-time=7200000

## sets a time(milliseconds) waiting for read activity after sending a keepalive ping. defaults to 20 seconds.
#nacos.remote.server.grpc.cluster.keep-alive-timeout=20000

## sets a time(milliseconds) that specify the most aggressive keep-alive time clients are permitted to configure. the typical default is 5 minutes
#nacos.remote.server.grpc.cluster.permit-keep-alive-time=300000

配置完成后就可以在/bin cmd

输入命令 startup.cmd -m standalone 运行就可以了

总结

以上为个人经验,希望能给大家一个参考,也希望大家多多支持代码网。

(0)

相关文章:

版权声明:本文内容由互联网用户贡献,该文观点仅代表作者本人。本站仅提供信息存储服务,不拥有所有权,不承担相关法律责任。 如发现本站有涉嫌抄袭侵权/违法违规的内容, 请发送邮件至 2386932994@qq.com 举报,一经查实将立刻删除。

发表评论

验证码:
Copyright © 2017-2026  代码网 保留所有权利. 粤ICP备2024248653号
站长QQ:2386932994 | 联系邮箱:2386932994@qq.com