Dubbo作为一个分布式服务框架,提供了多种安全机制来确保服务调用的安全性。以下是Dubbo的主要安全机制:
我们将创建一个简单的项目结构,包含一个服务提供者和一个服务消费者:
dubbo-demo
├── dubbo-api
│ └── src/main/java/com/example/dubbo/api
│ └── MyService.java
├── dubbo-provider
│ └── src/main/java/com/example/dubbo/provider
│ └── MyServiceImpl.java
│ └── DubboProviderApplication.java
├── dubbo-consumer
│ └── src/main/java/com/example/dubbo/consumer
│ └── MyServiceConsumer.java
│ └── DubboConsumerApplication.java
└── pom.xml
服务接口模块 dubbo-api
定义了服务接口。
pom.xml
在 dubbo-api
模块中创建 pom.xml
文件:
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://www.w3.org/2001/04/xmldsig-more#">
<modelVersion>4.0.0modelVersion>
<groupId>com.examplegroupId>
<artifactId>dubbo-apiartifactId>
<version>1.0-SNAPSHOTversion>
<packaging>jarpackaging>
<dependencies>
<dependency>
<groupId>org.apache.dubbogroupId>
<artifactId>dubboartifactId>
<version>2.7.8version>
dependency>
dependencies>
project>
在 dubbo-api/src/main/java/com/example/dubbo/api
目录下创建 MyService
接口:
package com.example.dubbo.api;
public interface MyService {
String sayHello(String name);
}
服务提供者模块 dubbo-provider
实现了服务接口并提供服务。
pom.xml
在 dubbo-provider
模块中创建 pom.xml
文件:
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://www.w3.org/2001/04/xmldsig-more#">
<parent>
<groupId>com.examplegroupId>
<artifactId>dubbo-demoartifactId>
<version>1.0-SNAPSHOTversion>
<relativePath>../pom.xmlrelativePath>
parent>
<artifactId>dubbo-providerartifactId>
<dependencies>
<dependency>
<groupId>com.examplegroupId>
<artifactId>dubbo-apiartifactId>
<version>1.0-SNAPSHOTversion>
dependency>
<dependency>
<groupId>org.apache.dubbogroupId>
<artifactId>dubbo-spring-boot-starterartifactId>
<version>2.7.8version>
dependency>
<dependency>
<groupId>org.springframework.bootgroupId>
<artifactId>spring-boot-starterartifactId>
dependency>
dependencies>
project>
在 dubbo-provider/src/main/java/com/example/dubbo/provider
目录下创建 MyServiceImpl
类:
package com.example.dubbo.provider;
import com.example.dubbo.api.MyService;
import org.apache.dubbo.config.annotation.DubboService;
@DubboService(token = "123456") // 使用Token进行服务认证
public class MyServiceImpl implements MyService {
@Override
public String sayHello(String name) {
return "Hello, " + name;
}
}
在 dubbo-provider/src/main/java/com/example/dubbo/provider
目录下创建 DubboProviderApplication
类:
package com.example.dubbo.provider;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
@SpringBootApplication
public class DubboProviderApplication {
public static void main(String[] args) {
SpringApplication.run(DubboProviderApplication.class, args);
}
}
在 dubbo-provider/src/main/resources
目录下创建 application.yml
配置文件:
spring:
application:
name: dubbo-provider
main:
web-application-type: none
dubbo:
application:
name: dubbo-provider
registry:
address: zookeeper://localhost:2181
protocol:
name: dubbo
port: 20880
provider:
token: 123456 # 设置Token认证
scan:
base-packages: com.example.dubbo.provider
服务消费者模块 dubbo-consumer
调用服务提供者提供的服务。
pom.xml
在 dubbo-consumer
模块中创建 pom.xml
文件:
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://www.w3.org/2001/04/xmldsig-more#">
<parent>
<groupId>com.examplegroupId>
<artifactId>dubbo-demoartifactId>
<version>1.0-SNAPSHOTversion>
<relativePath>../pom.xmlrelativePath>
parent>
<artifactId>dubbo-consumerartifactId>
<dependencies>
<dependency>
<groupId>com.examplegroupId>
<artifactId>dubbo-apiartifactId>
<version>1.0-SNAPSHOTversion>
dependency>
<dependency>
<groupId>org.apache.dubbogroupId>
<artifactId>dubbo-spring-boot-starterartifactId>
<version>2.7.8version>
dependency>
<dependency>
<groupId>org.springframework.bootgroupId>
<artifactId>spring-boot-starter-webartifactId>
dependency>
dependencies>
project>
在 dubbo-consumer/src/main/java/com/example/dubbo/consumer
目录下创建 MyServiceConsumer
类:
package com.example.dubbo.consumer;
import com.example.dubbo.api.MyService;
import org.apache.dubbo.config.annotation.DubboReference;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
@RestController
public class MyServiceConsumer {
@DubboReference(token = "123456") // 使用Token进行服务认证
private MyService myService;
@GetMapping("/sayHello")
public String sayHello(@RequestParam String name) {
return myService.sayHello(name);
}
}
在 dubbo-consumer/src/main/java/com/example/dubbo/consumer
目录下创建 DubboConsumerApplication
类:
package com.example.dubbo.consumer;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
@SpringBootApplication
public class DubboConsumerApplication {
public static void main(String[] args) {
SpringApplication.run(DubboConsumerApplication.class, args);
}
}
在 dubbo-consumer/src/main/resources
目录下创建 application.yml
配置文件:
spring:
application:
name: dubbo-consumer
dubbo:
application:
name: dubbo-consumer
registry:
address: zookeeper://localhost:2181
protocol:
name: dubbo
consumer:
token: 123456 # 设置Token认证
scan:
base-packages: com.example.dubbo.consumer
pom.xml
在根项目 dubbo-demo
中创建 pom.xml
文件,定义模块和依赖管理:
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.w3.org/POM/4.0.0 http://www.w3.org/2001/04/xmldsig-more#">
<modelVersion>4.0.0modelVersion>
<groupId>com.examplegroupId>
<artifactId>dubbo-demoartifactId>
<version>1.0-SNAPSHOTversion>
<packaging>pompackaging>
<modules>
<module>dubbo-apimodule>
<module>dubbo-providermodule>
<module>dubbo-consumermodule>
modules>
<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.apache.dubbogroupId>
<artifactId>dubboartifactId>
<version>2.7.8version>
dependency>
<dependency>
<groupId>org.apache.dubbogroupId>
<artifactId>dubbo-spring-boot-starterartifactId>
<version>2.7.8version>
dependency>
dependencies>
dependencyManagement>
<build>
<pluginManagement>
<plugins>
<plugin>
<groupId>org.apache.maven.pluginsgroupId>
<artifactId>maven-compiler-pluginartifactId>
<version>3.8.1version>
<configuration>
<source>1.8source>
<target>1.8target>
configuration>
plugin>
<plugin>
<groupId>org.springframework.bootgroupId>
<artifactId>spring-boot-maven-pluginartifactId>
<version>2.3.4.RELEASEversion>
plugin>
plugins>
pluginManagement>
build>
project>
确保Zookeeper在本地运行,默认端口为 2181
。可以通过下载Zookeeper并运行以下命令启动Zookeeper:
bin/zkServer.sh start
DubboProviderApplication
类。DubboConsumerApplication
类。Dubbo支持使用Token机制来认证客户端。通过在服务提供者和消费者的配置中设置相同的Token,可以实现服务认证。
@DubboService(token = "123456")
public class MyServiceImpl implements MyService {
@Override
public String sayHello(String name) {
return "Hello, " + name;
}
}
@DubboReference(token = "123456")
private MyService myService;
可以使用SSL/TLS加密通信,确保数据在传输过程中不会被窃取或篡改。
在 application.yml
中进行配置:
dubbo:
protocol:
name: dubbo
port: 20880
server: netty
ssl: true
ssl:
enabled: true
keystore: classpath:/keystore.jks
keystore-password: your_keystore_password
truststore: classpath:/truststore.jks
truststore-password: your_truststore_password
通过配置文件设置允许或禁止的IP地址,确保只有特定IP地址的客户端才能访问服务。
在 application.yml
中进行配置:
dubbo:
provider:
allowed: 192.168.1.100,192.168.1.101 # 允许访问的IP地址列表
denied: 192.168.1.102 # 禁止访问的IP地址列表
使用限流和熔断机制保护服务,防止服务过载。
在 application.yml
中进行配置:
dubbo:
consumer:
timeout: 3000 # 设置超时时间
retries: 2 # 设置重试次数
loadbalance: roundrobin # 设置负载均衡策略
以下是一个简单的Dubbo服务提供者和消费者的代码示例,展示了Dubbo的安全机制。
在 dubbo-api/src/main/java/com/example/dubbo/api
目录下创建 MyService
接口:
package com.example.dubbo.api;
public interface MyService {
String sayHello(String name);
}
在 dubbo-provider/src/main/java/com/example/dubbo/provider
目录下创建 MyServiceImpl
类:
package com.example.dubbo.provider;
import com.example.dubbo.api.MyService;
import org.apache.dubbo.config.annotation.DubboService;
@DubboService(token = "123456") // 使用Token进行服务认证
public class MyServiceImpl implements MyService {
@Override
public String sayHello(String name) {
return "Hello, " + name;
}
}
在 dubbo-consumer/src/main/java/com/example/dubbo/consumer
目录下创建 MyServiceConsumer
类:
package com.example.dubbo.consumer;
import com.example.dubbo.api.MyService;
import org.apache.dubbo.config.annotation.DubboReference;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
@RestController
public class MyServiceConsumer {
@DubboReference(token = "123456") // 使用Token进行服务认证
private MyService myService;
@GetMapping("/sayHello")
public String sayHello(@RequestParam String name) {
return myService.sayHello(name);
}
}
通过以上步骤,我们详细展示了Dubbo的安全机制,包括服务认证、数据加密、访问控制和限流熔断等。以下是关键步骤的总结:
pom.xml
中定义模块和依赖管理。通过这些步骤,可以深入理解Dubbo的安全机制,确保系统的高效和安全运行。