MDM Web App Application Properties
This article is intended to serve as a reference point for MDM Web App configuration.
As such, it provides an overview of the available properties and, when applicable, refers users to more comprehensive sources.
The properties described here are defined in the mdm/etc/application.properties file.
For each property, you will find information about the required data type, its default value, and a short description.
The Mandatory column specifies whether a property is required for the application to run and function as expected.
For certain features (such as SSL), several properties must be configured at the same time for the feature to work.
Refer to the property descriptions for details.
MDM Web App
Use these properties to specify details about the MDM Web App URLs. For an overview of all ports used by MDM components and how to change them, see Default ports.
| Name | Data Type | Default Value | Mandatory | Description |
|---|---|---|---|---|
|
Number |
|
Yes |
The number of the port where MDM Web App is running. |
|
Number |
|
No |
The number of the HTTP port for the management endpoint for actuators. |
|
Number |
|
Yes |
The maximum number of simultaneously opened HTTP connections between the web server (embedded Tomcat in the Springboot) and MDM Web App. |
MDM Server connectivity
Use these properties to specify details about the MDM Server location, adjustments of MDM Web App URLs, and connectivity settings.
| In this section, the term MDM Server refers specifically to the MDM Web App backend component. It always runs within the MDM Server context, so the URLs for both are the same. |
| Name | Data Type | Default Value | Mandatory | Description |
|---|---|---|---|---|
|
String |
|
Yes |
The URL of the server where MDM Server is running. Only used when the private and public URLs specified below are not defined. |
|
String |
|
No |
The private URL of the server where MDM Server is running. Used for communication between MDM Web App and the MDM backend. |
|
String |
|
No |
The public URL of the server where MDM Server is running. Used for communication between React-based SPAs (like the Admin Center) and the MDM backend. |
|
String |
|
Yes |
The URL of MDM Server for HA read-only requests. |
|
String |
|
No |
Specifies the URL of MDM Server to perform health checks of its availability. |
|
String |
|
Yes |
The URL of the Server Manager GraphQL endpoint, which provides the Server Dashboard in the MDM Admin Center.
Set it to Unlike the other properties in this section, this URL does not point to the MDM Server HTTP port ( The Admin Center calls this endpoint directly from the user’s browser, and the URL is included in the |
MDM features
| Name | Data Type | Default Value | Mandatory | Description |
|---|---|---|---|---|
|
Boolean |
|
Yes |
Enables the possibility to reset the environment from the new Admin Center (for user roles defined by the |
|
Boolean |
|
No |
Enables Git operations in MDM Web App Admin Center. Shows the Clone config repository option on the Server Dashboard. |
|
String |
|
No |
Specifies the endpoint filter for excluding the Keycloak authentication error page from security checks. |
|
Boolean |
|
No |
Enables the use of trailing slashes in API URLs for the MDM Web App. |
Keycloak
The following properties configure Keycloak. See Encrypt Passwords for information on how to encrypt passwords.
| Name | Data Type | Default Value | Mandatory | Description | ||
|---|---|---|---|---|---|---|
|
String |
|
Yes |
The URL of the server where Keycloak is running. |
||
|
String |
|
Yes |
The name of the Keycloak realm. |
||
|
String |
|
Yes |
The client identifier. Used to verify a user authorization token and to log in a user. |
||
|
String |
|
Yes |
Keycloak public client ID for web application browsing. |
||
|
String |
|
Yes |
Specifies the issuer of the JWT token. Typically, Keycloak uses the URL of the realm as the token issuer. |
||
|
Boolean |
|
No |
Enables access to Keycloak API with admin rights to perform health checks.
|
||
|
String |
|
Yes |
The public key of the client. |
Request header is too large error when logging in
If you encounter an HTTP 400 Bad Request response with Request header is too large error when logging in with a user that has many roles assigned (>100), increase the maximum HTTP header size.
This prevents the authentication token from exceeding header limits.
Add or edit the following property:
server.max-http-request-header-size=32768
| Name | Data type | Default value | Mandatory | Description |
|---|---|---|---|---|
|
String |
|
No |
Set the maximum size of the request header in Spring Boot. |
SSL
Use these properties to make MDM Web App serve HTTPS instead of HTTP on server.port.
By default, MDM Web App serves plain HTTP and none of the server.ssl.* properties is present in application.properties.
To enable HTTPS, set the server.ssl.enabled property to true and configure a keystore using server.ssl.key-store.
If you enable HTTPS without providing a keystore, MDM Web App fails on startup with the SSL is enabled but no trust material is configured error.
server.ssl.enabled=true
server.ssl.key-store=/opt/ataccama/mdm-web-server/etc/mdm-web-app.p12
server.ssl.key-store-password=<keystore_password>
server.ssl.key-store-type=PKCS12
For all supported options, refer to the official Spring Boot documentation.
| Name | Data Type | Default Value | Mandatory | Description |
|---|---|---|---|---|
|
Boolean |
|
No |
Enables HTTPS.
To use HTTPS, set the property to |
|
String |
/ |
No |
The full path to the keystore that contains the server certificate and its private key.
To switch MDM Web App from HTTP to HTTPS, ensure |
|
String |
/ |
No |
The password for the keystore. Required if the keystore is password-protected. |
|
String |
/ |
No |
The keystore type, for example |
|
String |
/ |
No |
The password of the private key inside the keystore. Set it only if the key is protected by a different password than the keystore. |
|
String |
/ |
No |
The full path to the truststore with the certificates of trusted clients.
Not needed for standard HTTPS.
Used only when clients authenticate with certificates ( |
|
String |
/ |
No |
The password for the truststore. |
Logging
The following properties configure logging.
| Name | Data Type | Default Value | Mandatory | Description |
|---|---|---|---|---|
|
String |
|
No |
The root logging level.
Available values are |
|
String |
|
No |
The logging level for |
|
String |
|
No |
Logging level for MDM Web App packages. |
|
Boolean |
|
No |
If set to |
|
Boolean |
|
No |
If set to |
|
Boolean |
|
No |
If set to |
|
Boolean |
|
No |
If set to |
Endpoints for monitoring
The following properties configure monitoring. For more information, see Monitoring Configuration.
| Name | Data Type | Default Value | Mandatory | Description |
|---|---|---|---|---|
|
Boolean |
|
No |
Enables all actuator endpoints.
If set to |
|
Boolean |
|
No |
Enables |
|
Boolean |
|
No |
Enables |
|
Boolean |
|
No |
Enables |
|
String |
|
No |
A comma-separated list of exposed actuator endpoints that should provide information about the application. These endpoints track the following:
|
|
String |
|
No |
Specifies how much information is provided by the
|
|
String |
|
No |
Specifies how much detail the
|
|
String |
|
No |
A comma-separated list that determines how the |
|
String |
|
No |
Configures how much information the |
|
Boolean |
|
No |
Enables |
|
String |
|
No |
Defines which components are covered by the liveness probe.
These components are a subset of |
|
String |
|
No |
Defines which components are covered by the readiness probe.
These components are a subset of |
|
String |
|
No |
Allows access to the endpoint defined in the |
|
String |
|
No |
A comma-separated list of user roles allowed to access the Prometheus endpoint. |
|
Boolean |
|
No |
Enables recording metrics for all Spring MVC requests. |
|
Boolean |
|
No |
Timing metrics to all Spring endpoints. |
|
String |
|
No |
Specifies the URL for performing health checks between MDM Web App and MDM Server. |
Client security headers
You can configure MDM Web App security by adding response headers (security headers) to HTTP responses from the web application.
| We recommend setting security headers to help protect your web application against potential security threats. |
| Name | Data Type | Default value | Mandatory | Desription |
|---|---|---|---|---|
|
String |
|
No |
Specifies allowed connections. We strongly recommend using the default value. |
|
String |
|
No |
Specifies allowed script sources. We strongly recommend using the default value. |
|
String |
|
No |
Specifies allowed image sources. We strongly recommend using the default value. |
|
String |
|
No |
Protects against clickjacking.
If set to |
|
String |
|
No |
Specifies if cross-domain requests from Flash and PDF documents are allowed. |
|
String |
|
No |
Defines how much referrer information (sent with the Referer header) should be included with requests.
If set to |
|
String |
|
No |
Protects against cross-site scripting attacks.
If set to |
|
String |
|
No |
Protects against MIME sniffing. |
Retry connection functionality
Use the following properties to configure repeated attempts for initial connection to critical components.
MDM-gRPC retry setup
| Name | Data Type | Default value | Mandatory | Desription |
|---|---|---|---|---|
|
Number |
|
Yes |
The maximum number of attempts (including the initial call as the first attempt). |
`resilience4j.retry.configs.mdm-grpc.waitDuration |
Number |
|
Yes |
A fixed wait duration between retry attempts (in milliseconds). |
|
String |
|
Yes |
Configures a list of Throwable classes that are recorded as a failure and thus are retried. |
Environment banner in MDM Web App Admin Center
| Available from 16.3.1. |
| Name | Data Type | Default value | Mandatory | Desription |
|---|---|---|---|---|
|
String |
No |
Sets the environment name used in the environment banner in the MDM Web App Admin Center. Available from 16.3.1. The banner displays the message: This is a If not set, no banner is shown. |
|
|
String |
|
No |
Sets the background color of the environment banner.
Only applies when Supported values:
Defaults to |
Was this page useful?