Install the plugin¶
Warning
the plugins geofence-server and geofence are about two different architectural configurations.
Please install either one according to your setup.
It is recommended to not install both of them at the same time.
geofence-server will run the GeoFence engine internally, and you won't need an external GeoFence webapp.
Download the plugin¶
-
Login, and navigate to About & Status > About GeoServer and check Build Information to determine the exact version of GeoServer you are running.
-
Visit the website download page, change the Archive tab, and locate your release.
From the list of Security extensions download GeoFence Server:
- 3.1.0: geoserver-3.1.0-geofence-server-plugin.zip
- 3.1.0-SNAPSHOT: geoserver-3.1.0-SNAPSHOT-geofence-server-plugin.zip
Make sure to match the plugin version (e.g. 3.1.0 above) to the version of the GeoServer instance.
Install the files¶
- Extract the files in this archive to the
WEB-INF/libdirectory of your GeoServer installation. - Configure the plugin
- Restart GeoServer
Known incompatibilities¶
The embedded engine brings its own versions of two libraries that the base GeoServer install also uses, and neither pair can coexist on one classpath:
-
Jiffle raster band-math stops working. GeoFence's persistence layer needs
antlr4-runtime-4.13.x, while Eclipse Imagen's Jiffle support needs4.7.1. The plugin ships an emptyantlr4-runtime-4.7.1.jarthat overwrites the base install's copy during step 1, so the conflict cannot arise even in an unattended install. -
Cloud Optimized GeoTIFF (COG) is unsupported in a build that also enables the embedded engine. COG uses
org.ehcache:ehcache, which clashes with theehcache:jakartavariant GeoFence's persistence layer requires. This only affects custom builds combining thecogandgeofence-serverprofiles; the official plugin does not enable COG.
Both affect the embedded engine only: the geofence client plugin, talking to a standalone GeoFence server, is unaffected.
Configure the plugin¶
You need a properties file containing the information to connect to the DB where GeoFence will store its data.
If the file is not present, the problem will be logged out to the GeoServer log:
01 set 17:24:13 WARN [config.GeofencePersistenceConfig] - GeoFence embedded engine will be unavailable until this is fixed
java.lang.IllegalStateException: No geofence datasource configuration found. Checked:
- <your geoserver data dir>/data/geofence/geofence-datasource.properties
- <container working dir>/geofence-datasource.properties
Wrote a sample file to <your geoserver data dir>/data/geofence/geofence-datasource.properties.sample - copy it to geofence-datasource.properties in the same directory and fill in real credentials.
at org.geofence.core.db.config.DatasourcePropertiesLoader.load(DatasourcePropertiesLoader.java:79)
at org.geofence.core.db.config.DatasourcePropertiesLoader.load(DatasourcePropertiesLoader.java:57)
at org.geofence.core.db.config.GeofencePersistenceConfig.<init>(GeofencePersistenceConfig.java:48)
<long stacktrace here>
and, as reported in the log, a sample file will be created for you. You need to copy the sample into the file <DATADIR>/geofence/geofence-datasource.properties and edit it with the real info.
This is the sample file content:
# Sample GeoFence datasource configuration.
#
# Copy this file to the same name without the ".sample" suffix, in the same directory, and
# fill in real credentials. All four properties are required; there is no built-in default.
geofence.datasource.url=jdbc:postgresql://localhost:5432/geofence
geofence.datasource.username=geofence
# Plain text here. When GeoFence runs embedded in GeoServer, the value may instead be encrypted with
# GeoServer's config-password encryption (same scheme as store connection passwords) and is decrypted
# transparently on startup. To have a clear-text password encrypted at rest, prefix it with 'plain:'
# (e.g. plain:mysecret): on next startup GeoFence encrypts it and rewrites this line with the result.
geofence.datasource.password=geofence
geofence.datasource.driver=org.postgresql.Driver
# Optional: any geofence.hibernate.* property is passed through to Hibernate/JPA, with the
# prefix stripped, e.g.:
# geofence.hibernate.hbm2ddl.auto=validate
# geofence.hibernate.default_schema=public
# Optional: any geofence.datasource.hikari.* property is passed through to the connection pool
# (HikariCP), with the prefix stripped - must be a real Hikari property name, an unrecognized one
# fails fast at startup. keepaliveTime periodically pings idle pooled connections so a dead one
# (e.g. after a DB restart) is detected and evicted instead of causing a transaction failure later.
# geofence.datasource.hikari.keepaliveTime=30000
Note
By default GeoFence will create the initial schema or update the DB schema by itself when needed. In case you want to manage the schema by yourself, you may want to use the SQL file located here
Also, you need to set this property to validate (default value is update).
Other info¶
You may found other info about configuration in this GeoFence wiki page .