You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak 26.0.2启动报错:Infinispan String Property Replacer异常

Keycloak 26.0.2启动失败:JGroups S3_PING配置问题修复

错误日志

WARN  [org.infinispan.commons.util.StringPropertyReplacer] (Thread-6) ISPN000901: Property jgroups.s3.bucket_name could not be replaced as intended!
 ERROR [org.infinispan.CONFIG] (Thread-6) ISPN000660: DefaultCacheManager start failed, stopping any running components: org.infinispan.commons.CacheConfigurationException: ISPN000541: Error while trying to create a channel using the specified configuration '[TCP(bundler.max_size=64000, sock_conn_timeout=300, linger=-1, thread_pool.keep_alive_time=60000, diag.enabled=false, bind_port=7800, thread_naming_pattern=pl, non_blocking_sends=false, thread_pool.thread_dumps_threshold=10000, send_buf_size=640k, thread_pool.max_threads=200, use_virtual_threads=false, bundler_type=transfer-queue, bind_addr=SITE_LOCAL, thread_pool.min_threads=0), RED(), aws.S3_PING(num_discovery_runs=3), MERGE3(max_interval=30000, min_interval=10000), FD_SOCK2(offset=50000), FD_ALL3(), VERIFY_SUSPECT2(timeout=1000), pbcast.NAKACK2(xmit_table_num_rows=50, use_mcast_xmit=false, xmit_table_msgs_per_row=1024, xmit_table_max_compaction_time=30000, xmit_interval=200, resend_last_seqno=true), UNICAST3(conn_close_timeout=5000, xmit_interval=200, xmit_table_num_rows=50, xmit_table_msgs_per_row=1024, xmit_table_max_compaction_time=30000), pbcast.STABLE(desired_avg_gossip=5000, max_bytes=1M), pbcast.GMS(join_timeout=2000, print_local_addr=false), UFC(min_threshold=0.40, max_credits=4m), MFC(min_threshold=0.40, max_credits=4m), FRAG4(frag_size=60000)]'

尝试过的配置方案

方案一:在keycloak.conf中使用JAVA_OPTS_APPEND

# Database configuration
db=postgres
db-url=jdbc:postgresql://boxview-test-keycloak.cluster-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/keycloak
db-username=postgres
db-password=blahblahblah

# Optional: Configure read replica (for read-only queries)
db-url-replica=jdbc:postgresql://boxview-test-keycloak.cluster-ro-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/keycloak

# Cache and clustering configuration
cache=ispn
cache-stack=ec2
cluster-stack=ec2

# JGroups config
JAVA_OPTS_APPEND=-Djgroups.s3.bucket_name=boxview-keycloak -Djgroups.s3.region_name=us-east-1 -Djgroups.s3.access_key=blahblahkey -Djgroups.s3.secret_access_key=blahblahsecret

# Observability

# If the server should expose healthcheck endpoints.
#health-enabled=true

# If the server should expose metrics endpoints.
#metrics-enabled=true

# HTTP

# The file path to a server certificate or certificate chain in PEM format.
https-certificate-file=${kc.home.dir}/keycloak.crt.pem

# The file path to a private key in PEM format.
https-certificate-key-file=${kc.home.dir}/keycloak.key.pem

# The proxy address forwarding mode if the server is behind a reverse proxy.
#proxy=reencrypt

# Do not attach route to cookies and rely on the session affinity capabilities from reverse proxy
#spi-sticky-session-encoder-infinispan-should-attach-route=false

# Hostname for the Keycloak server.
hostname-strict=false

方案二:在keycloak.conf中直接配置jgroups.s3属性

# Database configuration
db=postgres
db-url=jdbc:postgresql://boxview-test-keycloak.cluster-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/postgres
db-username=postgres
db-password=blahblahblah

# Optional: Configure read replica (for read-only queries)
db-url-replica=jdbc:postgresql://boxview-test-keycloak.cluster-ro-cx048rd0lgej.us-east-1.rds.amazonaws.com:5432/postgres

# Cache and clustering configuration
cache=ispn
cache-stack=ec2
cluster-stack=ec2

# JGroups config
jgroups.s3.bucket_name=boxview-keycloak
jgroups.s3.region_name=us-east-1
jgroups.s3.access_key=blahblahkey
jgroups.s3.secret_access_key=blahblahsecret


# Observability

# If the server should expose healthcheck endpoints.
#health-enabled=true

# If the server should expose metrics endpoints.
#metrics-enabled=true

# HTTP

# The file path to a server certificate or certificate chain in PEM format.
https-certificate-file=${kc.home.dir}conf/keycloak.crt.pem

# The file path to a private key in PEM format.
https-certificate-key-file=${kc.home.dir}conf/keycloak.key.pem

# The proxy address forwarding mode if the server is behind a reverse proxy.
#proxy=reencrypt

# Do not attach route to cookies and rely on the session affinity capabilities from reverse proxy
#spi-sticky-session-encoder-infinispan-should-attach-route=false

# Hostname for the Keycloak server.
hostname-strict=false

修复方案

核心问题

Keycloak的keycloak.conf不支持直接配置jgroups.s3.*属性,且在配置文件中设置JAVA_OPTS_APPEND不会被正确解析,导致JGroups无法获取S3_PING所需的参数,进而引发集群通道创建失败。

有效配置方式

1. 启动命令直接追加JVM参数

启动Keycloak时,在命令行中直接传递JGroups相关的系统属性:

bin/kc.sh start --spi-cluster-jgroups-file-path=ec2 \
-Djgroups.s3.bucket_name=boxview-keycloak \
-Djgroups.s3.region_name=us-east-1 \
-Djgroups.s3.access_key=blahblahkey \
-Djgroups.s3.secret_access_key=blahblahsecret

2. 使用环境变量传递参数

先设置环境变量,再启动Keycloak:

export JAVA_OPTS_APPEND="-Djgroups.s3.bucket_name=boxview-keycloak -Djgroups.s3.region_name=us-east-1 -Djgroups.s3.access_key=blahblahkey -Djgroups.s3.secret_access_key=blahblahsecret"
bin/kc.sh start --spi-cluster-jgroups-file-path=ec2

3. 自定义Infinispan集群配置文件

  • 复制Keycloak自带的EC2缓存栈配置文件(路径:conf/cache-stack/ec2.xml)到自定义路径
  • 修改文件中的aws.S3_PING部分,添加参数:
    <aws.S3_PING
        bucket_name="boxview-keycloak"
        region_name="us-east-1"
        access_key="blahblahkey"
        secret_access_key="blahblahsecret"
        num_discovery_runs="3"
    />
    
  • 启动时指定自定义配置文件:
    bin/kc.sh start --spi-cluster-jgroups-file-path=/path/to/custom-ec2.xml
    

额外检查项

  • 证书路径修正:第二个配置中https-certificate-file=${kc.home.dir}conf/keycloak.crt.pem缺少斜杠,应改为${kc.home.dir}/conf/keycloak.crt.pem,避免证书文件找不到
  • 数据库一致性:确保配置中指定的数据库(keycloak或postgres)已存在且可访问
  • IAM权限优化:如果EC2实例使用IAM角色,可移除access_key和secret_access_key参数,确保角色拥有S3的ListBucket、PutObject、DeleteObject权限

内容的提问来源于stack exchange,提问作者Steve D'Agostino

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 17:17:03