You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rundeck跨项目调度API Token授权失败及永不过期Token创建咨询

Rundeck API权限错误排查与永不过期Token创建

问题描述

在项目A中配置了一个Rundeck任务,用于启用/禁用项目B中某任务的调度规则,正常运行一个月后抛出以下错误:

{"error":true,"apiversion":47,"errorCode":"unauthorized","message":"(Token:G74m****) is not authorized for: /api/21/job/job-id/schedule/enable"}

任务定义如下:

- defaultTab: nodes
  description: This job can be used to disable and enable the releases schedule.
  executionEnabled: true
  group: Releases
  id: 
  loglevel: INFO
  name: Disable-Enable Schedules
  nodeFilterEditable: false
  options:
  - hidden: true
    name: RUNDECK_AUTH_TOKEN
    secure: true
    storagePath: keys/project/developer-tools/RUNDECK_AUTH_TOKEN
    valueExposed: true
  - enforced: true
    label: Release Schedule Action
    name: ReleaseScheduleAction
    required: true
    values:
    - Disable
    - Enable
    valuesListDelimiter: ','
  plugins:
    ExecutionLifecycle: {}
  scheduleEnabled: true
  sequence:
    commands:
    - description: Disable and/or Enable Schedules
      script: |-
        #!/bin/bash

        if [ $RD_OPTION_RELEASESCHEDULEACTION == "Disable" ]
        then
            curl --location --request POST 'https://rundeck.xxx.dev/api/21/job/job-id/schedule/disable' \
            --header 'Accept: application/json' \
            --header 'X-Rundeck-Auth-Token: @option.RUNDECK_AUTH_TOKEN@' \
            --header 'Content-Type: application/json' \
            --data ''
        else
            curl --location --request POST 'https://rundeck.xxx.dev/api/21/job/job-id/schedule/enable' \
            --header 'Accept: application/json' \
            --header 'X-Rundeck-Auth-Token: @option.RUNDECK_AUTH_TOKEN@' \
            --header 'Content-Type: application/json' \
            --data ''
        fi
    keepgoing: false
    pluginConfig:
      LogFilter:
      - config:
          color: yellow
          replacement: '[SECURE]'
        type: mask-passwords
    strategy: node-first
  uuid: 

解答

1. 该错误是否意味着Token已过期?

不一定。这个unauthorized错误核心指向Token对应的用户无权限执行目标操作,而非Token过期:

  • 若Token过期,Rundeck通常会返回明确的过期提示(如token expired类信息);
  • 触发该错误的常见原因包括:
    • Token所属用户的权限被修改,丢失了项目B中目标任务的调度编辑权限;
    • 目标任务的ID或路径变更,导致API请求的资源路径无效;
    • Token被撤销或重置;
    • 项目B的权限策略更新,限制了跨项目API操作。

可先验证Token有效性:用该Token调用基础API接口(如/api/21/system/info),若能正常返回数据,说明Token未过期,问题出在权限配置上。

2. 如何创建永不过期的Rundeck API Token?

创建永不过期的Token需在生成时将过期时间设为never,具体操作如下:

通过Web UI创建

  • 登录Rundeck控制台,点击右上角用户头像,选择Profile;
  • 左侧菜单选API Tokens,点击Create Token;
  • 弹出窗口中:
    • 填写Token描述;
    • Expiration选项选择Never;
    • 配置Token关联的项目权限(需包含项目B的任务调度编辑权限);
    • 点击Generate,保存生成的Token。

通过CLI创建

使用rd命令行工具执行(替换占位符为实际信息):

rd tokens create --user <用户名> --role <关联角色> --expiration never --description "永不过期的跨项目调度操作Token"

注:执行该命令需拥有Rundeck管理员权限,且提前配置好CLI认证信息。

额外注意事项

  • 永不过期Token存在安全风险,建议仅分配最小必要权限(如仅项目B的任务调度编辑权限),并妥善存储在Rundeck密钥存储中(如现有配置的storagePath方式);
  • 定期审计Token使用情况,规避泄露风险。

内容的提问来源于stack exchange,提问作者skp15

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 15:43:15