Integration with Apache Tomcat
This section describes how to configure Apache Tomcat to use the Kron PAM JDBC Proxy Driver for secure and dynamic database authentication. After configuration, Tomcat retrieves database credentials directly from Kron PAM Vault at runtime, eliminating the need for static passwords in configuration files.
Prerequisites
Before starting the integration, ensure the following components are available:
- Kron PAM Server: A running Kron PAM instance with network access from the Tomcat host.
- Access Token: A valid API token generated from Kron PAM for the service account that will retrieve database credentials.
- Kron PAM Proxy Driver: com.kron.jdbc-1.0.0.jar
- Database JDBC Driver: The native JDBC driver corresponding to your target database (PostgreSQL, MySQL, Oracle, SQL Server).
- Apache Tomcat Version: Apache Tomcat 8.5 or later.
General Configuration Steps
- Copy the JAR Files: Place both the Kron PAM Proxy Driver (com.kron.jdbc-1.0.0.jar) and the native JDBC driver (e.g., postgresql-42.7.3.jar) into the Tomcat library directory. ($CATALINA_HOME/lib)
- Modify the Context Definition: Edit the data source configuration in either:
- $CATALINA_BASE/conf/context.xml, or
- META-INF/context.xml inside your application.
- Replace the Driver and URL:
- Set driverClassName to com.kron.jdbc.ProxyDriver.
- Update the JDBC URL to use the jdbc:kron: prefix and add Kron PAM parameters.
- Restart Tomcat: Restart the Tomcat service for configuration changes to take effect.
PostgreSQL Configuration Example
The following is an example context.xml configuration for connecting to a PostgreSQL database via a credential fetched from Kron PAM.
<Resource
name="jdbc/PostgreSQLDS"
auth="Container"
type="javax.sql.DataSource"
driverClassName="com.kron.jdbc.ProxyDriver"
url="jdbc:kron:postgresql://postgresql.example.com:5432/employee_db?baseUrl=https://example.kronpam.com&acc_token=3aa0b9f5-cab4-4a3d-b410-1df18328079d&acc_name=webapp_user&acc_path=/VaultFolder&agentHost=localhost&agentPort=6396"
maxTotal="20"
maxIdle="10"
maxWaitMillis="-1"
/>Parameter Descriptions
Parameter | Description |
|---|---|
driverClassName | Instructs Tomcat to load the Kron Proxy Driver. |
url | Combines database connection info with Kron PAM Vault parameters |
baseUrl | URL of the Kron PAM server |
acc_token | Access token for Kron PAM API authentication |
acc_name | Name of the managed database account |
acc_path | Vault path of the account |
agentHost (Optional) | Kron PAM Secrets Manager Agent IP Address/hostname |
agentPort (Optional) | Kron PAM Secrets Manager Agent Port Number |
- Driver Component: PostgreSQL JDBC Driver 42.7.3
- Supported Versions: PostgreSQL 9.4 and later (tested up to v15)
MySQL Configuration Example
The following is an example context.xml configuration for connecting to a MySQL database via a credential fetched from Kron PAM.
<Resource
name="jdbc/MySQLDS"
auth="Container"
type="javax.sql.DataSource"
driverClassName="com.kron.jdbc.ProxyDriver"
url="jdbc:kron:mysql://mysql-host:3306/appdb?baseUrl=https://example.kronpam.com&acc_token=6adcb6af-b84c-4a4c-bfe3-e1d97d633f2b&acc_name=mysql_app_user&acc_path=/DBs/MySQL"
maxTotal="20"
maxIdle="10"
maxWaitMillis="-1"
/>- Driver Component: MySQL Connector/J 8.2.
- Supported Versions: MySQL 5.7 and 8.0 (compatible with Java 8 and above)
Oracle Database Configuration Example
The following is an example context.xml configuration for connecting to an Oracle database via a credential fetched from Kron PAM.
<Resource
name="jdbc/OracleDS"
auth="Container"
type="javax.sql.DataSource"
driverClassName="com.kron.jdbc.ProxyDriver"
url="jdbc:kron:oracle:thin:@//oracle-host:1521/orclpdb?baseUrl=https://example.kronpam.com&acc_token=6adcb6af-b84c-4a4c-bfe3-e1d97d633f2b&acc_name=c##jdbcuser&acc_path=/DBs"
maxTotal="20"
maxIdle="10"
maxWaitMillis="-1"
/>- Driver Component: Oracle JDBC Driver (ojdbc8-21.5.0.0.jar
- Supported Versions: Oracle 11g R2 through 21c
Microsoft SQL Server Configuration Example
The following is an example context.xml configuration for connecting to an MsSQL database via a credential fetched from Kron PAM.
<Resource
name="jdbc/SQLServerDS"
auth="Container"
type="javax.sql.DataSource"
driverClassName="com.kron.jdbc.ProxyDriver"
url="jdbc:kron:sqlserver://sql-host:1433;databaseName=AppDB?baseUrl=https://example.kronpam.com&acc_token=6adcb6af-b84c-4a4c-bfe3-e1d97d633f2b&acc_name=sql_app_user&acc_path=/DBs/SQLServer"
maxTotal="20"
maxIdle="10"
maxWaitMillis="-1"
/>- Driver Component: Microsoft JDBC Driver for SQL Serve
- Supported Versions: SQL Server 2012 – 2022 (compatible with Java 8, 11, 17+)
Verification
After Tomcat is restarted:
- Verify that the application can successfully establish a database connection.
- Check Tomcat logs (catalina.out) for any proxy or connectivity messages.
- Confirm from the Kron PAM Vault Audit Logs that credentials were retrieved through the API at runtime.