Skip to main content

Secure ASP.NET Core Health Checks to a specific port

· 2 min read
Mark Burton
Software Engineer & Technical Writer

To secure Health Checks it is possible to make them available on internal addresses only, and on a different port to the publicly served pages/API endpoints.

First we need to make the service available over 2 different ports. This can be achieved by adding a Urls value to appsettings.json.

{
"Logging": {
"IncludeScopes": false,
"LogLevel": {
"Default": "Debug",
"System": "Information",
"Microsoft": "Information"
}
},
"Urls": "http://localhost:1114;http://localhost:1115",
"ManagementPort": "1115",
"ConnectionStrings": {
"LoginServiceDb": "Data Source=.,11433;Initial Catalog=LoginServiceDatabase;Integrated Security=true;"
}
}

This can be done in several ways, and is described in more detail by Andrew Lock in his post 5 ways to set the URLs for an ASP.NET Core app.

Now when you debug the service you should see in the log that it is listening on 2 ports.

info: Microsoft.Hosting.Lifetime[0]  Now listening on: http://localhost:1114
info: Microsoft.Hosting.Lifetime[0] Now listening on: http://localhost:1115
info: Microsoft.Hosting.Lifetime[0] Application started. Press Ctrl+C to shut down.