Skip to content

Install the plugin

Warning

the plugins geofence-server and geofence are about two different architectural configurations. Please install either one according to your setup.

It is recommended to not install both of them at the same time.

geofence-server will run the GeoFence engine internally, and you won't need an external GeoFence webapp.

Download the plugin

  1. Login, and navigate to About & Status > About GeoServer and check Build Information to determine the exact version of GeoServer you are running.

  2. Visit the website download page, change the Archive tab, and locate your release.

    From the list of Security extensions download GeoFence Server:

    Make sure to match the plugin version (e.g. 3.1.0 above) to the version of the GeoServer instance.

Install the files

  1. Extract the files in this archive to the WEB-INF/lib directory of your GeoServer installation.
  2. Configure the plugin
  3. Restart GeoServer

Known incompatibilities

The embedded engine brings its own versions of two libraries that the base GeoServer install also uses, and neither pair can coexist on one classpath:

  • Jiffle raster band-math stops working. GeoFence's persistence layer needs antlr4-runtime-4.13.x, while Eclipse Imagen's Jiffle support needs 4.7.1. The plugin ships an empty antlr4-runtime-4.7.1.jar that overwrites the base install's copy during step 1, so the conflict cannot arise even in an unattended install.

  • Cloud Optimized GeoTIFF (COG) is unsupported in a build that also enables the embedded engine. COG uses org.ehcache:ehcache, which clashes with the ehcache:jakarta variant GeoFence's persistence layer requires. This only affects custom builds combining the cog and geofence-server profiles; the official plugin does not enable COG.

Both affect the embedded engine only: the geofence client plugin, talking to a standalone GeoFence server, is unaffected.

Configure the plugin

You need a properties file containing the information to connect to the DB where GeoFence will store its data.

If the file is not present, the problem will be logged out to the GeoServer log:

01 set 17:24:13 WARN   [config.GeofencePersistenceConfig] - GeoFence embedded engine will be unavailable until this is fixed
java.lang.IllegalStateException: No geofence datasource configuration found. Checked:
  - <your geoserver data dir>/data/geofence/geofence-datasource.properties
  - <container working dir>/geofence-datasource.properties
Wrote a sample file to <your geoserver data dir>/data/geofence/geofence-datasource.properties.sample - copy it to geofence-datasource.properties in the same directory and fill in real credentials.
    at org.geofence.core.db.config.DatasourcePropertiesLoader.load(DatasourcePropertiesLoader.java:79)
    at org.geofence.core.db.config.DatasourcePropertiesLoader.load(DatasourcePropertiesLoader.java:57)
    at org.geofence.core.db.config.GeofencePersistenceConfig.<init>(GeofencePersistenceConfig.java:48)
    <long stacktrace here>

and, as reported in the log, a sample file will be created for you. You need to copy the sample into the file <DATADIR>/geofence/geofence-datasource.properties and edit it with the real info.

This is the sample file content:

# Sample GeoFence datasource configuration.
#
# Copy this file to the same name without the ".sample" suffix, in the same directory, and
# fill in real credentials. All four properties are required; there is no built-in default.

geofence.datasource.url=jdbc:postgresql://localhost:5432/geofence
geofence.datasource.username=geofence
# Plain text here. When GeoFence runs embedded in GeoServer, the value may instead be encrypted with
# GeoServer's config-password encryption (same scheme as store connection passwords) and is decrypted
# transparently on startup. To have a clear-text password encrypted at rest, prefix it with 'plain:'
# (e.g. plain:mysecret): on next startup GeoFence encrypts it and rewrites this line with the result.
geofence.datasource.password=geofence
geofence.datasource.driver=org.postgresql.Driver

# Optional: any geofence.hibernate.* property is passed through to Hibernate/JPA, with the
# prefix stripped, e.g.:
# geofence.hibernate.hbm2ddl.auto=validate
# geofence.hibernate.default_schema=public

# Optional: any geofence.datasource.hikari.* property is passed through to the connection pool
# (HikariCP), with the prefix stripped - must be a real Hikari property name, an unrecognized one
# fails fast at startup. keepaliveTime periodically pings idle pooled connections so a dead one
# (e.g. after a DB restart) is detected and evicted instead of causing a transaction failure later.
# geofence.datasource.hikari.keepaliveTime=30000

Note

By default GeoFence will create the initial schema or update the DB schema by itself when needed. In case you want to manage the schema by yourself, you may want to use the SQL file located here

Also, you need to set this property to validate (default value is update).

geofence.hibernate.hbm2ddl.auto=validate

Other info

You may found other info about configuration in this GeoFence wiki page .