---
title: Aspire Configuration Example
description: Explore experimental Aspire publish-time configuration generation.
moved_from:
  - foundry/aspire-config.md
---

# Aspire Configuration Example

Demonstrates Aspire publish-time configuration generation for security and infrastructure settings.

## 📋 Overview

This example shows how to:

- Define security permissions and business roles in C# code
- Configure upstream API dependencies with required permissions
- Generate YAML configuration files during `aspire publish`

## 🏗️ Architecture

```mermaid
flowchart TB
    subgraph AppHost["AspireConfig.AppHost"]
        direction TB
        Auth["Auth/<br/>Permissions.cs<br/>BusinessRoles.cs"]
        Config["AppHost.cs<br/>AddSaifEnvironment()"]
    end

    subgraph Resources["Resource Model"]
        SaifEnv["SaifEnvironmentResource"]
        Security["SecurityResource<br/>(child)"]
        Upstream["UpstreamApiResource"]
        SaifEnv --> Security
    end

    subgraph Publish["aspire publish"]
        Generator["SecurityResource<br/>Pipeline Step"]
    end

    subgraph Output["Generated YAML"]
        API["infra/api/config.yml"]
        Corp["infra/auth/corp/config.yml"]
        ExtUser["infra/auth/ext/user/<br/>business-role-app-role.yml"]
        ExtApp["infra/auth/ext/app/<br/>authorized-apps.yml"]
    end

    AppHost --> Resources
    Security --> Generator
    Upstream --> Generator
    Generator --> Output
```

## 🔑 Key Features

- **Composite Resource Pattern** - `SaifEnvironmentResource` aggregates child resources like `SecurityResource`
- **Typed security configuration** - the example uses the `SAIF.Platform.Aspire.Hosting` security APIs; see [Aspire Security Configuration](../identity/configuration/aspire-security-configuration.md#overview) for their benefits and the step-by-step guide

## 📂 Project Structure

```
foundry/dotnet/aspire-config/
├── AspireConfig.sln
├── src/
│   ├── AspireConfig.AppHost/
│   │   ├── Auth/
│   │   │   ├── Permissions.cs        # App roles and scopes
│   │   │   ├── BusinessRoles.cs      # Business role definitions
│   │   │   └── AppRoleAssignments.cs # Business role to app role mapping
│   │   ├── AppHost.cs                # Security configuration
│   │   └── ResourceBuilders/         # Generated API builder
│   ├── AspireConfig/                 # API project
│   ├── AspireConfig.UnitTests/
│   └── AspireConfig.IntegrationTests/
└── infra/                            # Infrastructure config
```

## 🚀 Getting Started

### Prerequisites

- .NET 10.0 SDK
- Aspire 13.x

### Running the Example

```bash
cd foundry/dotnet/aspire-config
dotnet run --project src/AspireConfig.AppHost
```

### Publishing Configuration

To generate the security YAML files:

```bash
dotnet run --project src/AspireConfig.AppHost -- publish
```

## 📝 What the Example Configures

The example follows the steps in the [Aspire Security Configuration guide](../identity/configuration/aspire-security-configuration.md), which explains each type and extension method and shows the generated YAML. The example-specific choices are:

| File | What it declares |
| ---- | ---------------- |
| `Auth/Permissions.cs` | App roles `Claims.Read`, `Claims.Write`, `Policy.Read`, and `App.Admin`; upstream scopes `Orders.Read` and `Orders.Write`; upstream app role `Orders.App.Read` |
| `Auth/BusinessRoles.cs` | Corporate roles `Claims Adjuster`, `Policy Viewer`, and `Administrator`; external roles `Injured Worker` and `Employer Representative` |
| `Auth/AppRoleAssignments.cs` | Pairs each business role with its app roles |
| `AppHost.cs` | Calls `AddSaifEnvironment()`, registers the corporate and external assignments with `AddSecurity()`, and declares the `it-api-proc-orders` upstream API |

Publishing writes the four files shown in the architecture diagram. Compare them with the guide's [generated files](../identity/configuration/aspire-security-configuration.md#generated-files) to see how each declaration maps to YAML.

## 🔗 Related Documentation

- [Aspire Security Configuration Guide](../identity/configuration/aspire-security-configuration.md)
- [Business Roles](../identity/configuration/business-roles.md)
- [User Permissions](../identity/configuration/user-permissions.md)

## 📍 Source Code

**Location:** [`foundry/dotnet/aspire-config/`](https://dev.azure.com/SAIFCorporation/Platform/_git/forge?path=/foundry/dotnet/aspire-config)
