添加认证配置后Apache Druid Kubernetes Operator出现故障
Druid 29.0.0 + K8s Operator 安全配置后组件启动报错解决方案
问题描述
在Druid 29.0.0版本中,将官方提供的Basic安全配置添加到common.properties后,使用Kubernetes Operator部署时,除Coordinator外的所有Pod均报以下错误:
com.fasterxml.jackson.core.JsonParseException: Input does not start with Smile format header (first byte = 0x3c) and parser has REQUIRE_HEADER enabled: can not parse
添加的安全配置示例:
# Druid basic security druid.auth.authenticatorChain=["MyBasicMetadataAuthenticator"] druid.auth.authenticator.MyBasicMetadataAuthenticator.type=basic # Default password for 'admin' user, should be changed for production. druid.auth.authenticator.MyBasicMetadataAuthenticator.initialAdminPassword=password1 # Default password for internal 'druid_system' user, should be changed for production. druid.auth.authenticator.MyBasicMetadataAuthenticator.initialInternalClientPassword=password2 # Uses the metadata store for storing users. # You can use the authentication API to create new users and grant permissions druid.auth.authenticator.MyBasicMetadataAuthenticator.credentialsValidator.type=metadata # If true and if the request credential doesn't exist in this credentials store, # the request will proceed to next Authenticator in the chain. druid.auth.authenticator.MyBasicMetadataAuthenticator.skipOnFailure=false druid.auth.authenticator.MyBasicMetadataAuthenticator.authorizerName=MyBasicMetadataAuthorizer # Escalator druid.escalator.type=basic druid.escalator.internalClientUsername=druid_system druid.escalator.internalClientPassword=password2 druid.escalator.authorizerName=MyBasicMetadataAuthorizer druid.auth.authorizers=["MyBasicMetadataAuthorizer"] druid.auth.authorizer.MyBasicMetadataAuthorizer.type=basic
错误原因
这个错误本质是Druid内部组件间通信默认使用Smile二进制JSON格式,但启用Basic认证后,未配置认证凭据的组件在向Coordinator等组件发起请求时,被返回了HTML格式的401未授权页面(0x3c是HTML标签<的ASCII码),导致解析Smile格式失败。
解决方案
- 确保安全配置全局生效:检查Kubernetes Operator的DruidCluster自定义资源,确认
common.runtime.properties已将所有安全配置(包括druid.escalator相关)应用到所有组件,而非仅Coordinator。Operator可能存在默认只给Coordinator加载完整配置的情况,需手动确认全局配置覆盖。 - 添加内部客户端认证配置:在
common.properties中补充以下配置,确保所有内部组件的客户端请求自动带上认证凭据:druid.client.auth.enabled=true druid.client.auth.username=druid_system druid.client.auth.password=password2 - 排查组件配置覆盖问题:检查是否有组件的单独配置(如Broker、Historical的专属properties)覆盖了
common.properties中的认证链、授权器或 escalator 配置,导致认证逻辑失效。 - 定位具体通信故障:查看报错Pod的完整日志,找到触发错误的请求URL,确认是哪两个组件之间的通信未携带认证头,针对性调整该组件的配置。
内容的提问来源于stack exchange,提问作者DISCO
相关产品推荐
相关产品推荐

