You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx反向代理后独立KASM服务无法访问:WebSocket错误排查

解决KASM Desktop通过Nginx Proxy Manager代理的WebSocket认证与连接问题

问题概述

使用KASM Desktop镜像(独立模式)部署Web桌面环境,直接访问https://server-host:6901可正常使用,但通过Nginx Proxy Manager(NPM)代理后,出现WebSocket认证失败或连接无效的问题,最终目标是实现带Authentik反向代理认证的Linux桌面Web沙箱。

现有部署配置

Docker Compose配置

services:
  kasmweb:
    image: kasmweb/desktop:1.15.0-rolling-weekly
    container_name: kasmweb
    ports:
        - 6901:6901
    stdin_open: true
    tty: true
    shm_size: '2gb'
    volumes:
      - /etc/localtime:/etc/localtime:ro
      - /etc/timezone:/etc/timezone:ro
    devices:
      - /dev/dri:/dev/dri
    env_file: /dockerfiles/kasmweb.env
    networks:
      - public

networks:
  public:
    external: true

其中kasmweb.env配置了VNC_PW实现HTTP基础认证,默认凭据:

  • 用户名:kasm_user
  • 密码:password

错误现象与排查过程

  1. 首次代理错误:启用NPM的WebSocket功能后,输入凭据仍报错,KASM日志显示未收到认证信息:
2024-10-17 10:41:04,174 [INFO] websocket 8: got client connection from 172.19.0.15
2024-10-17 10:41:04,186 [DEBUG] websocket 8: using SSL socket
2024-10-17 10:41:04,195 [DEBUG] websocket 8: X-Forwarded-For ip '192.168.20.59'
2024-10-17 10:41:04,195 [INFO] websocket 8: Authentication attempt failed, BasicAuth required, but client didn't send any
2024-10-17 10:41:04,195 [INFO] websocket 8: 172.19.0.15 192.168.20.59 - "GET / HTTP/1.1" 401 158
2024-10-17 10:41:04,195 [DEBUG] websocket 8: No connection after handshake
2024-10-17 10:41:04,195 [DEBUG] websocket 8: handler exit
  1. 添加硬编码认证头后:NPM自定义配置中添加固定Authorization头,认证通过但出现WebSocket请求无效:
2024-10-17 13:44:45,623 [INFO] websocket 56: got client connection from 172.19.0.15
2024-10-17 13:44:45,634 [DEBUG] websocket 56: using SSL socket
2024-10-17 13:44:45,634 [DEBUG] websocket 56: X-Forwarded-For ip '192.168.20.59'
2024-10-17 13:44:45,639 [DEBUG] websocket 56: BasicAuth matched
2024-10-17 13:44:45,639 [DEBUG] websocket 56: Invalid WS request, maybe a HTTP one
2024-10-17 13:44:45,639 [DEBUG] websocket 56: Requested file '/index.html'
2024-10-17 13:44:45,640 [INFO] websocket 56: 172.19.0.15 192.168.20.59 kasm_user "GET /index.html HTTP/1.1" 200 24135
2024-10-17 13:44:45,640 [DEBUG] websocket 56: No connection after handshake
2024-10-17 13:44:45,640 [DEBUG] websocket 56: handler exit
  1. 添加WebSocket代理头后:补充Upgrade、Connection等头配置,问题依旧。

解决方案

步骤1:修正NPM代理配置,区分HTTP与WebSocket请求

KASM的WebSocket连接路径为/websockify,需单独配置该路径的代理规则,避免HTTP请求与WebSocket请求混淆。在NPM的自定义配置中替换为:

location / {
    proxy_pass https://kasmweb:6901;
    # 转发客户端的认证头,而非硬编码
    proxy_set_header Authorization $http_authorization;
    proxy_pass_header Authorization;
    
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}

location /websockify {
    proxy_pass https://kasmweb:6901;
    proxy_set_header Authorization $http_authorization;
    proxy_pass_header Authorization;
    
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    
    # WebSocket专属配置
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    proxy_read_timeout 86400;
}

步骤2:关闭KASM自身的基础认证,交由Authentik处理

既然目标是使用Authentik做反向代理认证,无需保留KASM的VNC_PW认证,避免双重认证冲突:

  1. 从kasmweb.env中移除VNC_PW变量
  2. 重启KASM容器:docker-compose restart kasmweb

步骤3:配置Authentik与NPM的集成

  1. 在Authentik中创建对应的应用与认证策略
  2. 在NPM的代理主机设置中,启用Authentik认证,配置对应的Authentik代理地址与凭据
  3. 确保NPM的代理主机已启用WebSockets Support选项

验证方法

  1. 访问NPM代理的KASM域名,会先跳转到Authentik认证页面
  2. 认证通过后,正常加载KASM桌面环境,查看KASM容器日志无错误:
    • 日志中应显示WebSocket连接成功的信息
    • 无Invalid WS request类错误

内容的提问来源于stack exchange,提问作者Asem Khen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 04:27:02