Spring Boot Admin Server启动连接Kubernetes API时出现未授权错误
Kubernetes Discovery 未自动使用Service Account Token导致401认证失败
场景与配置
将Spring Boot监控应用部署在Kubernetes集群中,目标是监控集群内所有应用,当前application.yml配置如下:
spring: application: name: springbootmonitoring-app cloud: kubernetes: discovery: enabled: true all-namespaces: false # Optional: Set to true if you need to discover services across all namespaces discovery-server-url: https://kubernetes.default.svc.cluster.local
启动报错日志
应用启动失败,报错日志如下:
2025-01-31 13:40:56.566 DEBUG [o.s.web.client.RestTemplate,,main] HTTP GET https://kubernetes.default.svc.cluster.local/apps 2025-01-31 13:40:56.661 DEBUG [o.s.web.client.RestTemplate,,main] Accept=[application/json, application/*+json] 2025-01-31 13:40:57.268 DEBUG [o.s.web.client.RestTemplate,,main] Response 401 UNAUTHORIZED 2025-01-31 13:40:57.448 ERROR [o.s.boot.SpringApplication,,main] Application run failed 2025-01-31T11:40:57.451618044Z org.springframework.web.client.HttpClientErrorException$Unauthorized: 401 Unauthorized: "{"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"Unauthorized","reason":"Unauthorized","code":401}<EOL>"
已排查情况
- 从日志可见,请求Kubernetes API时缺少Bearer token,返回401未授权
- 在Spring Boot Admin Pod内执行以下curl命令可正常访问API:
curl --cacert /var/run/secrets/kubernetes.io/serviceaccount/ca.crt -H "Authorization: Bearer $(cat /var/run/secrets/kubernetes.io/serviceaccount/token)" https://kubernetes.default.svc.cluster.local/apps
这说明:
- Service Account Token已正确挂载到Pod中
- 对应的Role和RoleBinding权限配置无误
疑问
- 为何Spring Cloud Kubernetes Discovery未自动使用挂载的Service Account Token发起API请求?
- 是否有强制让它使用该Token的配置方法?
内容的提问来源于stack exchange,提问作者Abhishek Singh
相关产品推荐
相关产品推荐

