Skip to content
Beta

Spring Boot hybrid access with VPN and central firewall

Last updated on

This pattern is used when workloads on STACKIT must stay connected to central enterprise networks. It combines workload hosting with explicit network governance through VPN and centralized firewall controls.

  • Hybrid dependency landscape: application integrations still depend on on-premises systems.
  • Central inspection requirement: traffic must pass enterprise-approved firewall controls.
  • Controlled project communication: east-west traffic between projects should be policy-driven.
UserAdminApplication Project (spoke)Shared Network AreaHub ProjectOn-PremisesInternetSpring Boot VMApplication Load BalancerRouting TablesCentral FirewallVPN Gateway peeringnext hophybrid pathIPsec tunnelIPsec tunnelcontrolled egresspublic accessweb ingresscorporate accessVPN endpointVPN endpointadmin pathadmin routeadmin accessapp traffic
  • Route all hybrid traffic through one policy point: keep the central firewall as mandatory next hop.
  • Keep routing ownership explicit: document who controls route tables and firewall rules per change window.
  • Segment integration paths by criticality: separate business-critical from non-critical hybrid flows.
  • Validate failover behavior: include VPN and firewall outage scenarios in architecture acceptance checks.

Workload provisioning in this pattern is covered by the VM Rehost repository:

Code & registry github.com STACKIT CMF Rehost Spring Boot repository Open the repository

Use these settings for the spoke workload VM:

create_project = true
target_project_name = "cmf-rehost-springboot"
target_project_owner_email = "owner@sa.stackit.cloud"
parent_container_id = "cmf-parent-container-id"
service_account_key_path = "/path/to/stackit-sa-key.json"
enable_observability = true
enable_node_exporter = true
enable_local_postgresql = false
enable_local_load_generator = false

Common CMF feature flags:

setup_project=true
setup_observability=true
setup_database=false
setup_workload=true
setup_loadgen=false
setup_dns=false

Scope note: VPN gateway, central firewall policies, and shared network area routes are design requirements in this asset and must be configured with the corresponding network/security setup in addition to the workload repository.

Asset historyActive 4 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
Maintainers
TMTobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172LWLukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwnerActive 10 of the last 12 weeks · 47 updatesSTACKITwww.linkedin.com/in/lukas-weberruß-a360b081Contributed in STACKIT
Show full history (3 more)