Skip to content

Aspire Configuration Example

Demonstrates Aspire publish-time configuration generation for security and infrastructure settings.

📋 Overview

This example shows how to:

  • Define security permissions and business roles in C# code
  • Configure upstream API dependencies with required permissions
  • Generate YAML configuration files during aspire publish

🏗️ Architecture

flowchart TB
    subgraph AppHost["AspireConfig.AppHost"]
        direction TB
        Auth["Auth/<br/>Permissions.cs<br/>BusinessRoles.cs"]
        Config["AppHost.cs<br/>AddSaifEnvironment()"]
    end

    subgraph Resources["Resource Model"]
        SaifEnv["SaifEnvironmentResource"]
        Security["SecurityResource<br/>(child)"]
        Upstream["UpstreamApiResource"]
        SaifEnv --> Security
    end

    subgraph Publish["aspire publish"]
        Generator["SecurityResource<br/>Pipeline Step"]
    end

    subgraph Output["Generated YAML"]
        API["infra/api/config.yml"]
        Corp["infra/auth/corp/config.yml"]
        ExtUser["infra/auth/ext/user/<br/>business-role-app-role.yml"]
        ExtApp["infra/auth/ext/app/<br/>authorized-apps.yml"]
    end

    AppHost --> Resources
    Security --> Generator
    Upstream --> Generator
    Generator --> Output

🔑 Key Features

  • Composite Resource Pattern - SaifEnvironmentResource aggregates child resources like SecurityResource
  • Typed security configuration - the example uses the SAIF.Platform.Aspire.Hosting security APIs; see Aspire Security Configuration for their benefits and the step-by-step guide

📂 Project Structure

foundry/dotnet/aspire-config/
├── AspireConfig.sln
├── src/
│   ├── AspireConfig.AppHost/
│   │   ├── Auth/
│   │   │   ├── Permissions.cs        # App roles and scopes
│   │   │   ├── BusinessRoles.cs      # Business role definitions
│   │   │   └── AppRoleAssignments.cs # Business role to app role mapping
│   │   ├── AppHost.cs                # Security configuration
│   │   └── ResourceBuilders/         # Generated API builder
│   ├── AspireConfig/                 # API project
│   ├── AspireConfig.UnitTests/
│   └── AspireConfig.IntegrationTests/
└── infra/                            # Infrastructure config

🚀 Getting Started

Prerequisites

  • .NET 10.0 SDK
  • Aspire 13.x

Running the Example

cd foundry/dotnet/aspire-config
dotnet run --project src/AspireConfig.AppHost

Publishing Configuration

To generate the security YAML files:

dotnet run --project src/AspireConfig.AppHost -- publish

📝 What the Example Configures

The example follows the steps in the Aspire Security Configuration guide, which explains each type and extension method and shows the generated YAML. The example-specific choices are:

File What it declares
Auth/Permissions.cs App roles Claims.Read, Claims.Write, Policy.Read, and App.Admin; upstream scopes Orders.Read and Orders.Write; upstream app role Orders.App.Read
Auth/BusinessRoles.cs Corporate roles Claims Adjuster, Policy Viewer, and Administrator; external roles Injured Worker and Employer Representative
Auth/AppRoleAssignments.cs Pairs each business role with its app roles
AppHost.cs Calls AddSaifEnvironment(), registers the corporate and external assignments with AddSecurity(), and declares the it-api-proc-orders upstream API

Publishing writes the four files shown in the architecture diagram. Compare them with the guide's generated files to see how each declaration maps to YAML.

📍 Source Code

Location: foundry/dotnet/aspire-config/