Spring Boot hybrid access with VPN and central firewall
Last updated on
Overview
Section titled “Overview”This pattern is used when workloads on STACKIT must stay connected to central enterprise networks. It combines workload hosting with explicit network governance through VPN and centralized firewall controls.
Typical use case
Section titled “Typical use case”- Hybrid dependency landscape: application integrations still depend on on-premises systems.
- Central inspection requirement: traffic must pass enterprise-approved firewall controls.
- Controlled project communication: east-west traffic between projects should be policy-driven.
Architecture diagram
Section titled “Architecture diagram”Design best practices
Section titled “Design best practices”- Route all hybrid traffic through one policy point: keep the central firewall as mandatory next hop.
- Keep routing ownership explicit: document who controls route tables and firewall rules per change window.
- Segment integration paths by criticality: separate business-critical from non-critical hybrid flows.
- Validate failover behavior: include VPN and firewall outage scenarios in architecture acceptance checks.
Related connectivity asset
Section titled “Related connectivity asset”Repository usage and required settings
Section titled “Repository usage and required settings”Workload provisioning in this pattern is covered by the VM Rehost repository:
STACKIT CMF Rehost Spring Boot repository Open the repositoryUse these settings for the spoke workload VM:
create_project = truetarget_project_name = "cmf-rehost-springboot"target_project_owner_email = "owner@sa.stackit.cloud"parent_container_id = "cmf-parent-container-id"service_account_key_path = "/path/to/stackit-sa-key.json"
enable_observability = trueenable_node_exporter = trueenable_local_postgresql = falseenable_local_load_generator = falseCommon CMF feature flags:
setup_project=truesetup_observability=truesetup_database=falsesetup_workload=truesetup_loadgen=falsesetup_dns=falseScope note: VPN gateway, central firewall policies, and shared network area routes are design requirements in this asset and must be configured with the corresponding network/security setup in addition to the workload repository.
Asset historyActive 4 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
- LWLukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwner
Lukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwnerActive 10 of the last 12 weeks · 47 updateswww.linkedin.com/in/lukas-weberruß-a360b081