You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot Admin Server启动连接Kubernetes API时出现未授权错误

Kubernetes Discovery 未自动使用Service Account Token导致401认证失败

场景与配置

将Spring Boot监控应用部署在Kubernetes集群中,目标是监控集群内所有应用,当前application.yml配置如下:

spring:
  application:
    name: springbootmonitoring-app
  cloud:
    kubernetes:
      discovery:
        enabled: true
        all-namespaces: false  # Optional: Set to true if you need to discover services across all namespaces
        discovery-server-url: https://kubernetes.default.svc.cluster.local

启动报错日志

应用启动失败,报错日志如下:

2025-01-31 13:40:56.566 DEBUG [o.s.web.client.RestTemplate,,main] HTTP GET https://kubernetes.default.svc.cluster.local/apps
2025-01-31 13:40:56.661 DEBUG [o.s.web.client.RestTemplate,,main] Accept=[application/json, application/*+json]
2025-01-31 13:40:57.268 DEBUG [o.s.web.client.RestTemplate,,main] Response 401 UNAUTHORIZED
2025-01-31 13:40:57.448 ERROR [o.s.boot.SpringApplication,,main] Application run failed
2025-01-31T11:40:57.451618044Z org.springframework.web.client.HttpClientErrorException$Unauthorized: 401 Unauthorized: "{"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"Unauthorized","reason":"Unauthorized","code":401}<EOL>"

已排查情况

  • 从日志可见,请求Kubernetes API时缺少Bearer token,返回401未授权
  • 在Spring Boot Admin Pod内执行以下curl命令可正常访问API:
curl --cacert /var/run/secrets/kubernetes.io/serviceaccount/ca.crt -H "Authorization: Bearer $(cat /var/run/secrets/kubernetes.io/serviceaccount/token)" https://kubernetes.default.svc.cluster.local/apps

这说明:

  • Service Account Token已正确挂载到Pod中
  • 对应的Role和RoleBinding权限配置无误

疑问

  1. 为何Spring Cloud Kubernetes Discovery未自动使用挂载的Service Account Token发起API请求?
  2. 是否有强制让它使用该Token的配置方法?

内容的提问来源于stack exchange,提问作者Abhishek Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 17:15:02