Aspire Configuration Example¶
Demonstrates Aspire publish-time configuration generation for security and infrastructure settings.
📋 Overview¶
This example shows how to:
- Define security permissions and business roles in C# code
- Configure upstream API dependencies with required permissions
- Generate YAML configuration files during
aspire publish
🏗️ Architecture¶
flowchart TB
subgraph AppHost["AspireConfig.AppHost"]
direction TB
Auth["Auth/<br/>Permissions.cs<br/>BusinessRoles.cs"]
Config["AppHost.cs<br/>AddSaifEnvironment()"]
end
subgraph Resources["Resource Model"]
SaifEnv["SaifEnvironmentResource"]
Security["SecurityResource<br/>(child)"]
Upstream["UpstreamApiResource"]
SaifEnv --> Security
end
subgraph Publish["aspire publish"]
Generator["SecurityResource<br/>Pipeline Step"]
end
subgraph Output["Generated YAML"]
API["infra/api/config.yml"]
Corp["infra/auth/corp/config.yml"]
ExtUser["infra/auth/ext/user/<br/>business-role-app-role.yml"]
ExtApp["infra/auth/ext/app/<br/>authorized-apps.yml"]
end
AppHost --> Resources
Security --> Generator
Upstream --> Generator
Generator --> Output
🔑 Key Features¶
- Composite Resource Pattern -
SaifEnvironmentResourceaggregates child resources likeSecurityResource - Typed security configuration - the example uses the
SAIF.Platform.Aspire.Hostingsecurity APIs; see Aspire Security Configuration for their benefits and the step-by-step guide
📂 Project Structure¶
foundry/dotnet/aspire-config/
├── AspireConfig.sln
├── src/
│ ├── AspireConfig.AppHost/
│ │ ├── Auth/
│ │ │ ├── Permissions.cs # App roles and scopes
│ │ │ ├── BusinessRoles.cs # Business role definitions
│ │ │ └── AppRoleAssignments.cs # Business role to app role mapping
│ │ ├── AppHost.cs # Security configuration
│ │ └── ResourceBuilders/ # Generated API builder
│ ├── AspireConfig/ # API project
│ ├── AspireConfig.UnitTests/
│ └── AspireConfig.IntegrationTests/
└── infra/ # Infrastructure config
🚀 Getting Started¶
Prerequisites¶
- .NET 10.0 SDK
- Aspire 13.x
Running the Example¶
Publishing Configuration¶
To generate the security YAML files:
📝 What the Example Configures¶
The example follows the steps in the Aspire Security Configuration guide, which explains each type and extension method and shows the generated YAML. The example-specific choices are:
| File | What it declares |
|---|---|
Auth/Permissions.cs |
App roles Claims.Read, Claims.Write, Policy.Read, and App.Admin; upstream scopes Orders.Read and Orders.Write; upstream app role Orders.App.Read |
Auth/BusinessRoles.cs |
Corporate roles Claims Adjuster, Policy Viewer, and Administrator; external roles Injured Worker and Employer Representative |
Auth/AppRoleAssignments.cs |
Pairs each business role with its app roles |
AppHost.cs |
Calls AddSaifEnvironment(), registers the corporate and external assignments with AddSecurity(), and declares the it-api-proc-orders upstream API |
Publishing writes the four files shown in the architecture diagram. Compare them with the guide's generated files to see how each declaration maps to YAML.
🔗 Related Documentation¶
📍 Source Code¶
Location: foundry/dotnet/aspire-config/