Supplement · Core

Tomcat classloader, deployment, proxy/TLS và production tuning

Tomcat là Servlet container với hierarchy Server, Service, Connector, Engine, Host và Context; embedded Spring Boot che cấu hình XML nhưng không xóa connector, classloader, proxy và lifecycle semantics.

Container architecture

Server chứa Services; mỗi Service nối Connectors với Engine; Engine route Host/Context; request qua Valve pipeline rồi application Filter/Servlet. Connector/Coyote protocol handler quản socket, parsing và executor; Catalina quản container/lifecycle. Embedded Boot tạo và cấu hình hierarchy bằng code/properties thay vì server.xml.

Classloader hierarchy

Bootstrap → System → Common; mỗi webapp có WebappX loader và ưu tiên local trước theo Servlet rules với ngoại lệ Java/Jakarta/XML. Webapps được cô lập nhưng Common libraries chia sẻ. Duplicate API/library ở sai loader gây ClassCastException, LinkageError, version shadowing hoặc memory leak sau redeploy.

Reload/redeploy leaks

Old WebappClassLoader chỉ GC khi không còn reference từ parent/long-lived roots. Threads/executors không dừng, ThreadLocal trên container thread, JDBC driver, timer, logging/JMX/static cache và shutdown hook có thể giữ classloader. Tomcat leak-prevention/clearReferences cảnh báo hoặc mitigate một phần; application vẫn phải close resources. Immutable process/container restart giảm redeploy risk nhưng không thay lifecycle correctness.

Deployment và configuration

WAR, context descriptor và autoDeploy có production trade-offs; parallel deployment cho versioned contexts nhưng session/routing compatibility cần xét. Với embedded executable JAR, deploy whole process/image, externalize config và dùng rolling/canary. Không chỉnh exploded application tại runtime. JNDI resources/global naming và per-context resources cần ownership/cleanup rõ.

Connector capacity

maxConnections giới hạn sockets accepted/processed, acceptCount queue khi max connections reached, executor maxThreadsmaxQueueSize quản request work; OS listen backlog có layer riêng. Keep-alive, connection timeout, header/body limits và swallow limits ảnh hưởng resource/security. Tune từ workload, Little's Law và downstream capacity; tăng threads/connections có thể overload DB.

TLS termination

Tomcat hỗ trợ JSSE hoặc OpenSSL implementations; cấu hình SSLHostConfig gồm certificates, protocols, ciphers và client authentication. Direct TLS tăng key/certificate lifecycle trong app tier; edge proxy termination đơn giản hóa nhưng hop nội bộ/trust/compliance quyết định re-encrypt. Test certificate chain, SNI, rotation, revocation và protocols—not chỉ browser success.

Reverse proxy headers

Application cần biết original scheme/host/client IP cho redirects, secure cookies, links và audit. Chỉ tin Forwarded hoặc X-Forwarded-* từ trusted proxies đã strip/overwrite client headers. Tomcat RemoteIpValve có internal/trusted proxies và protocol header; Spring strategy phải không double-process. Sai trust cho phép spoof IP/scheme hoặc redirect poisoning.

Security và hardening

Giảm exposed apps như manager, host-manager và examples; dùng least OS user/files, read-only image, secret permissions, current Tomcat/JDK, safe error pages, request limits và access-log privacy. AJP chỉ dùng khi cần, bind private và authentication secret đúng. JMX/management endpoints cần network, authentication và TLS.

Graceful lifecycle

Load balancer remove/readiness false → connector pause/stop intake → drain keep-alive/in-flight/async requests → stop application executors/consumers → close pools → process exit trước orchestration deadline. SIGTERM và Boot graceful shutdown phải được test dưới long request, async dispatch và message processing. Liveness restart không thay drain.

Diagnostics và tuning loop

Đo active/current/max threads, connections, accept/error/request rate/duration, executor queue, bytes, sessions, access logs và downstream pools. Thread dumps/JFR map request stacks; connector metrics không đủ nếu work chờ DB. Load test arrival distribution, keep-alive, TLS và request sizes giống production; tune một bottleneck rồi verify SLO và secondary saturation.

Tài liệu: Tomcat Architecture · Class Loader HOW-TO · HTTP Connector · Remote IP Valve · SSL/TLS HOW-TO · Deployment HOW-TO