启用分布式缓存的Keycloak HA集群出现Expired_Code等错误求助
问题背景
在Azure Container Apps部署3个Keycloak节点,搭配Infinispan分布式缓存,先后遇到两类登录相关错误,重启容器实例后问题均解决,怀疑与分布式缓存有关,请求分析具体原因。
第一次错误:管理后台登录失败
尝试登录Web管理后台时持续失败,触发如下警告日志:
2025-02-18T13:10:59.3949172Z stdout F 2025-02-18 13:10:59,394 WARN [org.keycloak.events] (executor-thread-10) type="LOGIN_ERROR", realmId="a1d39a9f-95b4-4fd6-9538-171ed94bead6", realmName="master", clientId="security-admin-console", userId="null", ipAddress="xx.xx.xx.xx", error="expired_code", restart_after_timeout="true"
重启Azure Container App后问题解决。
第二次错误:授权码兑换令牌失败
几天后出现授权码换取令牌失败的情况,错误日志如下:
2025-02-24T07:31:47.2906574Z stdout F 2025-02-24 07:31:47,290 WARN [org.keycloak.events] (executor-thread-30) type="CODE_TO_TOKEN_ERROR", realmId="5f626112-b788-4c16-8e15-c3be1a3910b6", realmName="TEST", clientId="TestWeb", userId="null", sessionId="cee35b2b-cc88-44cd-81cc-792708b48ec2", ipAddress="xx.xx.xx.xx", error="invalid_code", grant_type="authorization_code", code_id="cee35b2b-cc88-44cd-81cc-792708b48ec2", client_auth_method="client-secret"
重启全部3个容器实例后问题解决,推测是重启重置分布式缓存导致问题消除。
当前Infinispan缓存配置(默认配置)
<cache-container name="keycloak"> <transport lock-timeout="60000" stack="jdbc-ping"/> <local-cache name="realms" simple-cache="true"> <encoding> <key media-type="application/x-java-object"/> <value media-type="application/x-java-object"/> </encoding> <memory max-count="10000"/> </local-cache> <local-cache name="users" simple-cache="true"> <encoding> <key media-type="application/x-java-object"/> <value media-type="application/x-java-object"/> </encoding> <memory max-count="10000"/> </local-cache> <local-cache name="authorization" simple-cache="true"> <encoding> <key media-type="application/x-java-object"/> <value media-type="application/x-java-object"/> </encoding> <memory max-count="10000"/> </local-cache> <local-cache name="keys" simple-cache="true"> <encoding> <key media-type="application/x-java-object"/> <value media-type="application/x-java-object"/> </encoding> <expiration max-idle="3600000"/> <memory max-count="1000"/> </local-cache> <distributed-cache name="sessions" owners="2"> <expiration lifespan="-1"/> </distributed-cache> <distributed-cache name="authenticationSessions" owners="2"> <expiration lifespan="-1"/> </distributed-cache> <distributed-cache name="offlineSessions" owners="2"> <expiration lifespan="-1"/> </distributed-cache> <distributed-cache name="clientSessions" owners="2"> <expiration lifespan="-1"/> </distributed-cache> <distributed-cache name="offlineClientSessions" owners="2"> <expiration lifespan="-1"/> </distributed-cache> <distributed-cache name="loginFailures" owners="2"> <expiration lifespan="-1"/> </distributed-cache> <distributed-cache name="actionTokens" owners="2"> <encoding> <key media-type="application/x-java-object"/> <value media-type="application/x-java-object"/> </encoding> <expiration max-idle="-1" lifespan="-1" interval="300000"/> <memory max-count="-1"/> </distributed-cache> <replicated-cache name="work"> <expiration lifespan="-1"/> </replicated-cache> </cache-container>
需求说明
已认定默认配置存在问题并计划更新,但希望进一步分析出现这两类错误的具体原因。
内容的提问来源于stack exchange,提问作者Enricosoft

