You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

添加认证配置后Apache Druid Kubernetes Operator出现故障

Druid 29.0.0 + K8s Operator 安全配置后组件启动报错解决方案

问题描述

在Druid 29.0.0版本中,将官方提供的Basic安全配置添加到common.properties后,使用Kubernetes Operator部署时,除Coordinator外的所有Pod均报以下错误:

com.fasterxml.jackson.core.JsonParseException: Input does not start with Smile format header (first byte = 0x3c) and parser has REQUIRE_HEADER enabled: can not parse

添加的安全配置示例:

# Druid basic security
druid.auth.authenticatorChain=["MyBasicMetadataAuthenticator"]
druid.auth.authenticator.MyBasicMetadataAuthenticator.type=basic

# Default password for 'admin' user, should be changed for production.
druid.auth.authenticator.MyBasicMetadataAuthenticator.initialAdminPassword=password1

# Default password for internal 'druid_system' user, should be changed for production.
druid.auth.authenticator.MyBasicMetadataAuthenticator.initialInternalClientPassword=password2

# Uses the metadata store for storing users.
# You can use the authentication API to create new users and grant permissions
druid.auth.authenticator.MyBasicMetadataAuthenticator.credentialsValidator.type=metadata

# If true and if the request credential doesn't exist in this credentials store,
# the request will proceed to next Authenticator in the chain.
druid.auth.authenticator.MyBasicMetadataAuthenticator.skipOnFailure=false

druid.auth.authenticator.MyBasicMetadataAuthenticator.authorizerName=MyBasicMetadataAuthorizer

# Escalator
druid.escalator.type=basic
druid.escalator.internalClientUsername=druid_system
druid.escalator.internalClientPassword=password2
druid.escalator.authorizerName=MyBasicMetadataAuthorizer

druid.auth.authorizers=["MyBasicMetadataAuthorizer"]

druid.auth.authorizer.MyBasicMetadataAuthorizer.type=basic

错误原因

这个错误本质是Druid内部组件间通信默认使用Smile二进制JSON格式,但启用Basic认证后,未配置认证凭据的组件在向Coordinator等组件发起请求时,被返回了HTML格式的401未授权页面(0x3c是HTML标签<的ASCII码),导致解析Smile格式失败。

解决方案

  • 确保安全配置全局生效:检查Kubernetes Operator的DruidCluster自定义资源,确认common.runtime.properties已将所有安全配置(包括druid.escalator相关)应用到所有组件,而非仅Coordinator。Operator可能存在默认只给Coordinator加载完整配置的情况,需手动确认全局配置覆盖。
  • 添加内部客户端认证配置:在common.properties中补充以下配置,确保所有内部组件的客户端请求自动带上认证凭据:
    druid.client.auth.enabled=true
    druid.client.auth.username=druid_system
    druid.client.auth.password=password2
    
  • 排查组件配置覆盖问题:检查是否有组件的单独配置(如Broker、Historical的专属properties)覆盖了common.properties中的认证链、授权器或 escalator 配置,导致认证逻辑失效。
  • 定位具体通信故障:查看报错Pod的完整日志,找到触发错误的请求URL,确认是哪两个组件之间的通信未携带认证头,针对性调整该组件的配置。

内容的提问来源于stack exchange,提问作者DISCO

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 06:43:12