Keycloak 26.0.2启动报错:Infinispan String Property Replacer异常
Keycloak 26.0.2启动失败:JGroups S3_PING配置问题修复
错误日志
WARN [org.infinispan.commons.util.StringPropertyReplacer] (Thread-6) ISPN000901: Property jgroups.s3.bucket_name could not be replaced as intended! ERROR [org.infinispan.CONFIG] (Thread-6) ISPN000660: DefaultCacheManager start failed, stopping any running components: org.infinispan.commons.CacheConfigurationException: ISPN000541: Error while trying to create a channel using the specified configuration '[TCP(bundler.max_size=64000, sock_conn_timeout=300, linger=-1, thread_pool.keep_alive_time=60000, diag.enabled=false, bind_port=7800, thread_naming_pattern=pl, non_blocking_sends=false, thread_pool.thread_dumps_threshold=10000, send_buf_size=640k, thread_pool.max_threads=200, use_virtual_threads=false, bundler_type=transfer-queue, bind_addr=SITE_LOCAL, thread_pool.min_threads=0), RED(), aws.S3_PING(num_discovery_runs=3), MERGE3(max_interval=30000, min_interval=10000), FD_SOCK2(offset=50000), FD_ALL3(), VERIFY_SUSPECT2(timeout=1000), pbcast.NAKACK2(xmit_table_num_rows=50, use_mcast_xmit=false, xmit_table_msgs_per_row=1024, xmit_table_max_compaction_time=30000, xmit_interval=200, resend_last_seqno=true), UNICAST3(conn_close_timeout=5000, xmit_interval=200, xmit_table_num_rows=50, xmit_table_msgs_per_row=1024, xmit_table_max_compaction_time=30000), pbcast.STABLE(desired_avg_gossip=5000, max_bytes=1M), pbcast.GMS(join_timeout=2000, print_local_addr=false), UFC(min_threshold=0.40, max_credits=4m), MFC(min_threshold=0.40, max_credits=4m), FRAG4(frag_size=60000)]'
尝试过的配置方案
方案一:在keycloak.conf中使用JAVA_OPTS_APPEND
# Database configuration db=postgres db-url=jdbc:postgresql://boxview-test-keycloak.cluster-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/keycloak db-username=postgres db-password=blahblahblah # Optional: Configure read replica (for read-only queries) db-url-replica=jdbc:postgresql://boxview-test-keycloak.cluster-ro-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/keycloak # Cache and clustering configuration cache=ispn cache-stack=ec2 cluster-stack=ec2 # JGroups config JAVA_OPTS_APPEND=-Djgroups.s3.bucket_name=boxview-keycloak -Djgroups.s3.region_name=us-east-1 -Djgroups.s3.access_key=blahblahkey -Djgroups.s3.secret_access_key=blahblahsecret # Observability # If the server should expose healthcheck endpoints. #health-enabled=true # If the server should expose metrics endpoints. #metrics-enabled=true # HTTP # The file path to a server certificate or certificate chain in PEM format. https-certificate-file=${kc.home.dir}/keycloak.crt.pem # The file path to a private key in PEM format. https-certificate-key-file=${kc.home.dir}/keycloak.key.pem # The proxy address forwarding mode if the server is behind a reverse proxy. #proxy=reencrypt # Do not attach route to cookies and rely on the session affinity capabilities from reverse proxy #spi-sticky-session-encoder-infinispan-should-attach-route=false # Hostname for the Keycloak server. hostname-strict=false
方案二:在keycloak.conf中直接配置jgroups.s3属性
# Database configuration db=postgres db-url=jdbc:postgresql://boxview-test-keycloak.cluster-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/postgres db-username=postgres db-password=blahblahblah # Optional: Configure read replica (for read-only queries) db-url-replica=jdbc:postgresql://boxview-test-keycloak.cluster-ro-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/postgres # Cache and clustering configuration cache=ispn cache-stack=ec2 cluster-stack=ec2 # JGroups config jgroups.s3.bucket_name=boxview-keycloak jgroups.s3.region_name=us-east-1 jgroups.s3.access_key=blahblahkey jgroups.s3.secret_access_key=blahblahsecret # Observability # If the server should expose healthcheck endpoints. #health-enabled=true # If the server should expose metrics endpoints. #metrics-enabled=true # HTTP # The file path to a server certificate or certificate chain in PEM format. https-certificate-file=${kc.home.dir}conf/keycloak.crt.pem # The file path to a private key in PEM format. https-certificate-key-file=${kc.home.dir}conf/keycloak.key.pem # The proxy address forwarding mode if the server is behind a reverse proxy. #proxy=reencrypt # Do not attach route to cookies and rely on the session affinity capabilities from reverse proxy #spi-sticky-session-encoder-infinispan-should-attach-route=false # Hostname for the Keycloak server. hostname-strict=false
修复方案
核心问题
Keycloak的keycloak.conf不支持直接配置jgroups.s3.*属性,且在配置文件中设置JAVA_OPTS_APPEND不会被正确解析,导致JGroups无法获取S3_PING所需的参数,进而引发集群通道创建失败。
有效配置方式
1. 启动命令直接追加JVM参数
启动Keycloak时,在命令行中直接传递JGroups相关的系统属性:
bin/kc.sh start --spi-cluster-jgroups-file-path=ec2 \ -Djgroups.s3.bucket_name=boxview-keycloak \ -Djgroups.s3.region_name=us-east-1 \ -Djgroups.s3.access_key=blahblahkey \ -Djgroups.s3.secret_access_key=blahblahsecret
2. 使用环境变量传递参数
先设置环境变量,再启动Keycloak:
export JAVA_OPTS_APPEND="-Djgroups.s3.bucket_name=boxview-keycloak -Djgroups.s3.region_name=us-east-1 -Djgroups.s3.access_key=blahblahkey -Djgroups.s3.secret_access_key=blahblahsecret" bin/kc.sh start --spi-cluster-jgroups-file-path=ec2
3. 自定义Infinispan集群配置文件
- 复制Keycloak自带的EC2缓存栈配置文件(路径:
conf/cache-stack/ec2.xml)到自定义路径 - 修改文件中的
aws.S3_PING部分,添加参数:<aws.S3_PING bucket_name="boxview-keycloak" region_name="us-east-1" access_key="blahblahkey" secret_access_key="blahblahsecret" num_discovery_runs="3" /> - 启动时指定自定义配置文件:
bin/kc.sh start --spi-cluster-jgroups-file-path=/path/to/custom-ec2.xml
额外检查项
- 证书路径修正:第二个配置中
https-certificate-file=${kc.home.dir}conf/keycloak.crt.pem缺少斜杠,应改为${kc.home.dir}/conf/keycloak.crt.pem,避免证书文件找不到 - 数据库一致性:确保配置中指定的数据库(
keycloak或postgres)已存在且可访问 - IAM权限优化:如果EC2实例使用IAM角色,可移除
access_key和secret_access_key参数,确保角色拥有S3的ListBucket、PutObject、DeleteObject权限
内容的提问来源于stack exchange,提问作者Steve D'Agostino
相关产品推荐
相关产品推荐

