The Container Security Provider Framework adds a Security Provider to the JVM that automatically includes BOSH trusted certificates and Diego identity certificates and private keys.
| Detection Criterion | Unconditional |
| Tags | container-security-provider=<version> |
For general information on configuring the buildpack, including how to specify configuration values through environment variables, refer to Configuration and Extension.
The framework can be configured by setting the JBP_CONFIG_CONTAINER_SECURITY_PROVIDER environment variable. The value must be valid inline YAML.
| Name | Description |
|---|---|
key_manager_enabled |
Whether the container KeyManager is enabled. Defaults to true. |
trust_manager_enabled |
Whether the container TrustManager is enabled. Defaults to true. |
Disable the KeyManager:
JBP_CONFIG_CONTAINER_SECURITY_PROVIDER: '{key_manager_enabled: false}'Disable the TrustManager:
JBP_CONFIG_CONTAINER_SECURITY_PROVIDER: '{trust_manager_enabled: false}'The security provider added by this framework contributes two types, a TrustManagerFactory and a KeyManagerFactory. The TrustManagerFactory adds an additional new TrustManager after the configured system TrustManager which reads the contents of /etc/ssl/certs/ca-certificates.crt which is where BOSH trusted certificates are placed. The KeyManagerFactory adds an additional KeyManager after the configured system KeyManager which reads the contents of the files specified by $CF_INSTANCE_CERT and $CF_INSTANCE_KEY which are set by Diego to give each container a unique cryptographic identity. These TrustManagers and KeyManagers are used transparently by any networking library that reads standard system SSL configuration and can be used to enable system-wide trust and mutual TLS authentication.
The path read by the TrustManager defaults to /etc/ssl/certs/ca-certificates.crt but can be overridden by setting the CF_CA_CERTS environment variable to an alternate file path.
Note: This is distinct from — but complementary to — Cloud Foundry's Trusted System Certificates feature (
CF_SYSTEM_CERT_PATH,/etc/cf-system-certificates). Diego's executor merges operator-deployed trusted system certificates into/etc/ssl/certs, so they are automatically picked up by theTrustManager's default path without any additional configuration.