Skip to content

Configure Solr Basic Authentication

Apache Solr stores audit records that Audit Server sends and that Privacera Portal displays. Basic authentication protects Solr with a username and password. When basic authentication is enabled, Privacera services that connect to Solr use the configured credentials automatically.

Note

Solr basic authentication is different from Audit Server authentication. The SOLR_BASIC_AUTH_* variables protect connections to Solr. The AUDITSERVER_AUTH_* variables protect connections to Audit Server.

Enable Solr basic authentication

  1. Copy the Solr authentication sample file to config/custom-vars.

    Bash
    cd ~/privacera/privacera-manager
    cp -n config/sample-vars/vars.solr.auth.yml config/custom-vars/
    
  2. Edit config/custom-vars/vars.solr.auth.yml.

    YAML
    1
    2
    3
    SOLR_BASIC_AUTH_ENABLED: "true"
    SOLR_BASIC_AUTH_USER: "<solr-user>"
    SOLR_BASIC_AUTH_PASSWORD: "<strong-password>"
    
    Variable Description
    SOLR_BASIC_AUTH_ENABLED Set to true to require basic authentication for Solr.
    SOLR_BASIC_AUTH_USER Specifies the username that Privacera services use to connect to Solr.
    SOLR_BASIC_AUTH_PASSWORD Specifies the password that Privacera services use to connect to Solr.
  3. To avoid storing the password as plain text, store SOLR_BASIC_AUTH_PASSWORD in Privacera Manager Vault:

    1. Run the following command:

      Bash
      cd ~/privacera/privacera-manager
      ./privacera-manager.sh vault
      
    2. Select the option to edit common Privacera vault secrets.

    3. Add the following entry with the same password:

      YAML
      SOLR_BASIC_AUTH_PASSWORD: "<strong-password>"
      
    4. Remove or comment out SOLR_BASIC_AUTH_PASSWORD in config/custom-vars/vars.solr.auth.yml.

    For more information, see Enable Vault in Privacera Manager.

  4. Apply the configuration:

    Bash
    1
    2
    3
    4
    cd ~/privacera/privacera-manager
    ./privacera-manager.sh setup
    ./pm_with_helm.sh upgrade
    ./privacera-manager.sh post-install
    

Rotate the Solr password

Use the following steps to change the Solr password without losing audits. During the rolling upgrade, new audits may be delayed until the Audit Server pods finish restarting.

  1. Set the new value for SOLR_BASIC_AUTH_PASSWORD:

    • If the password is stored in config/custom-vars/vars.solr.auth.yml, replace its current value.
    • If Privacera Manager Vault is enabled, run ./privacera-manager.sh vault, edit the common Privacera vault secrets, and replace the value there. Keep the password removed or commented out in vars.solr.auth.yml.
  2. Run the Privacera Manager setup and upgrade commands:

    Bash
    1
    2
    3
    cd ~/privacera/privacera-manager
    ./privacera-manager.sh setup
    ./pm_with_helm.sh upgrade
    

    Note

    While the upgrade is going on, you might see a temporary disturbance in audits. There is no data loss.

    The upgrade applies the new password to Solr and redeploys dependent services, including Audit Server. Audit Server gets the new Solr password automatically so it can continue writing audits.

  3. Run the post-installation step:

    Bash
    ./privacera-manager.sh post-install
    
  4. Confirm that the Solr and Audit Server pods are running, and then verify that new audits appear in Privacera Portal.

Warning

Do not update only Solr. Audit Server and Privacera Portal must use the same password as Solr. If Audit Server continues to use the old password, it cannot write new audits to Solr. If Privacera Portal continues to use the old password, it cannot read audits from Solr and the audit pages return no records.