---
title: Spring Boot hybrid access with VPN and central firewall
description: "Reference architecture for Spring Boot on STACKIT with hybrid enterprise connectivity with VPN and central firewall inspection in a hub-and-spoke model."
sidebar:
  badge:
    text: "STACKIT"
    variant: success
scfAsset:
  managed: false
  category: 'blueprint'
  external: false
  tags: ["design-and-mobilize", "design", "target-architecture", "rehost", "spring-boot", "vpn", "firewall", "network-area"]
  maintainers:
    - user: "lukas.weberruss"
      role: true
      website: true
source_url: "https://framework.stackit.cloud/migration/assetcontainer/stackit/architecture-spring-boot-hybrid-vpn-central-firewall/"
source_file: "docs/migration/assetcontainer/stackit/architecture-spring-boot-hybrid-vpn-central-firewall.mdx"
---

## Overview

This pattern is used when workloads on STACKIT must stay connected to central enterprise networks.
It combines workload hosting with explicit network governance through VPN and centralized firewall controls.

## Typical use case

- **Hybrid dependency landscape**: application integrations still depend on on-premises systems.
- **Central inspection requirement**: traffic must pass enterprise-approved firewall controls.
- **Controlled project communication**: east-west traffic between projects should be policy-driven.

## Architecture diagram

```d2
vars: {
  d2-config: {
    pad: 32
  }
}

style.font-size: 22

direction: down

User: "User" {
  icon: ../../../../../../public/stackit-icons/networking/ip.svg
}

Admin: "Admin" {
  icon: ../../../../../../public/stackit-icons/networking/ip.svg
}

Spoke: "Application Project (spoke)" {
  AppVM: "Spring Boot VM" {
    icon: ../../../../../../public/stackit-icons/computing/virtual-machine.svg
    link: https://docs.stackit.cloud/products/compute-engine/server/
  }
  AppLB: "Application Load Balancer" {
    icon: ../../../../../../public/stackit-icons/networking/application-load-balancer.svg
    link: https://docs.stackit.cloud/products/network/load-balancing-and-content-delivery/application-load-balancer/
  }
}

SNA: "Shared Network Area" {
  Routing: "Routing Tables" {
    icon: ../../../../../../public/stackit-icons/networking/network.svg
    link: https://docs.stackit.cloud/products/network/core-networking/network-area/basics/routing-tables/
  }
}

Hub: "Hub Project" {
  FW: "Central Firewall" {
    icon: ../../../../../../public/stackit-icons/networking/firewall.svg
    link: https://docs.stackit.cloud/products/network/network-security/unified-firewall/
  }
  VPN: "VPN Gateway" {
    icon: ../../../../../../public/stackit-icons/networking/vpn.svg
    link: https://docs.stackit.cloud/products/network/connectivity-hybrid-multi-cloud/vpn/
  }
}

OnPrem: "On-Premises" {
  icon: ../../../../../../public/stackit-icons/networking/network.svg
}

Internet: "Internet" {
  icon: ../../../../../../public/stackit-icons/networking/ip.svg
}

Spoke -> SNA: "peering"
SNA -> Hub.FW: "next hop"
Hub.FW -> Hub.VPN: "hybrid path"
Hub.VPN -> Internet: "IPsec tunnel"
Internet -> OnPrem: "IPsec tunnel"
Hub.FW -> Internet: "controlled egress"
User -> Internet: "public access"
Internet -> Spoke.AppLB: "web ingress"
Admin -> OnPrem: "corporate access"
OnPrem -> Internet: "VPN endpoint"
Internet -> Hub.VPN: "VPN endpoint"
Hub.VPN -> Hub.FW: "admin path"
Hub.FW -> SNA: "admin route"
SNA -> Spoke.AppVM: "admin access"
Spoke.AppLB -> Spoke.AppVM: "app traffic"
```

## Design best practices

- **Route all hybrid traffic through one policy point**: keep the central firewall as mandatory next hop.
- **Keep routing ownership explicit**: document who controls route tables and firewall rules per change window.
- **Segment integration paths by criticality**: separate business-critical from non-critical hybrid flows.
- **Validate failover behavior**: include VPN and firewall outage scenarios in architecture acceptance checks.

## Related connectivity asset

- <LinkChip href="/migration/assetcontainer/stackit/pfsense-firewall-connectivity-pattern/">pfSense Firewall Connectivity Pattern</LinkChip>

## Repository usage and required settings

Workload provisioning in this pattern is covered by the VM Rehost repository:

<LinkCard
  title="STACKIT CMF Rehost Spring Boot repository"
  href="https://github.com/stackitcloud/stackit-cmf-rehost-springboot"
/>

Use these settings for the spoke workload VM:

```hcl
create_project              = true
target_project_name         = "cmf-rehost-springboot"
target_project_owner_email  = "owner@sa.stackit.cloud"
parent_container_id         = "cmf-parent-container-id"
service_account_key_path    = "/path/to/stackit-sa-key.json"

enable_observability        = true
enable_node_exporter        = true
enable_local_postgresql     = false
enable_local_load_generator = false
```

Common CMF feature flags:

```dotenv
setup_project=true
setup_observability=true
setup_database=false
setup_workload=true
setup_loadgen=false
setup_dns=false
```

Scope note: VPN gateway, central firewall policies, and shared network area routes are design requirements in this asset and must be configured with the corresponding network/security setup in addition to the workload repository.
