You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker部署Guacamole首次启动MySQL连接异常求助

解决Guacamole Docker部署首次启动时的MySQL连接异常问题

问题背景

在OCI的Oracle Linux 8环境中通过Docker部署Guacamole,使用的docker-compose.yaml配置如下:

# import .env file from volt
# Generate ./initdb.sql : $ mkdir initdb && docker run --rm guacamole/guacamole /opt/guacamole/bin/initdb.sh --mysql > ./initdb/initdb.sql

# networks
# create a network 'guacamole_net' in mode 'bridged'
networks:
  guac-net:
    driver: bridge
  haproxy_net:
    external: true

# services
services:
  # guacd
  guacd:
    container_name: guac-guacd
    image: guacamole/guacd
    networks:
      - guac-net
    restart: always

  # mysql
  mysql:
    container_name: guac-mysql
    environment:
      MYSQL_ROOT_PASSWORD: '${MYSQL_ROOT_PASSWORD}'
      MYSQL_DATABASE: '${MYSQL_DATABASE}'
      MYSQL_USER: '${MYSQL_USER}'
      MYSQL_PASSWORD: '${MYSQL_PASSWORD}'
    image: mysql:oraclelinux8
    networks:
      - guac-net
    restart: always
    volumes:
      - ./initdb:/docker-entrypoint-initdb.d

  # guacamole
  guacamole:
    container_name: guac-guacamole
    depends_on:
      - guacd
      - mysql
    environment:
      GUACD_HOSTNAME: guacd
      MYSQL_HOSTNAME: mysql
      MYSQL_DATABASE: '${MYSQL_DATABASE}'
      MYSQL_USER: '${MYSQL_NAME}'
      MYSQL_PASSWORD: '${MYSQL_PASSWORD}'
      MYSQL_SSL_MODE: disabled
    image: guacamole/guacamole
    ports:
      - "8080:8080"
    links:
      - guacd
    networks:
      - guac-net
    restart: always

首次执行docker compose up时页面报错:

An error has occurred and this action cannot be completed. If the problem persists, please notify your system administrator or check your system logs.

容器日志显示核心错误:

guac-guacamole  | Loading class `com.mysql.jdbc.Driver'. This is deprecated. The new driver class is `com.mysql.cj.jdbc.Driver'. The driver is automatically registered via the SPI and manual loading of the driver class is generally unnecessary.
guac-guacamole  | 21:17:00.399 [http-nio-8080-exec-7] WARN  o.a.g.e.AuthenticationProviderFacade - The "mysql" authentication provider has encountered an internal error which will halt the authentication process. If this is unexpected or you are the developer of this authentication provider, you may wish to enable debug-level logging. If this is expected and you wish to ignore such failures in the future, please set "skip-if-unavailable: mysql" within your guacamole.properties.
guac-guacamole  | 21:17:00.404 [http-nio-8080-exec-7] ERROR o.a.g.rest.RESTExceptionMapper - Unexpected internal error:
guac-guacamole  | ### Error querying database.  Cause: java.sql.SQLNonTransientConnectionException: Public Key Retrieval is not allowed
guac-guacamole  | ### The error may exist in org/apache/guacamole/auth/jdbc/user/UserMapper.xml
guac-guacamole  | ### The error may involve org.apache.guacamole.auth.jdbc.user.UserMapper.selectOne
guac-guacamole  | ### The error occurred while executing a query
guac-guacamole  | ### Cause: java.sql.SQLNonTransientConnectionException: Public Key Retrieval is not allowed

手动登录MySQL容器后(执行以下命令),Guacamole即可正常访问:

$ docker exec -it guac-mysql bash
# mysql -u guacamole guacamoledb -p

解决方案

方案1:修改MySQL容器配置,允许公钥检索

在docker-compose.yaml的mysql服务中添加command参数,开启允许公钥检索:

mysql:
  container_name: guac-mysql
  environment:
    MYSQL_ROOT_PASSWORD: '${MYSQL_ROOT_PASSWORD}'
    MYSQL_DATABASE: '${MYSQL_DATABASE}'
    MYSQL_USER: '${MYSQL_USER}'
    MYSQL_PASSWORD: '${MYSQL_PASSWORD}'
  image: mysql:oraclelinux8
  networks:
    - guac-net
  restart: always
  volumes:
    - ./initdb:/docker-entrypoint-initdb.d
  command: --allowPublicKeyRetrieval=TRUE

方案2:调整Guacamole的MySQL连接参数

在Guacamole服务的环境变量中添加MYSQL_ADDITIONAL_PARAMETERS,指定允许公钥检索:

guacamole:
  container_name: guac-guacamole
  depends_on:
    - guacd
    - mysql
  environment:
    GUACD_HOSTNAME: guacd
    MYSQL_HOSTNAME: mysql
    MYSQL_DATABASE: '${MYSQL_DATABASE}'
    MYSQL_USER: '${MYSQL_NAME}'
    MYSQL_PASSWORD: '${MYSQL_PASSWORD}'
    MYSQL_SSL_MODE: disabled
    MYSQL_ADDITIONAL_PARAMETERS: allowPublicKeyRetrieval=true
  image: guacamole/guacamole
  ports:
    - "8080:8080"
  links:
    - guacd
  networks:
    - guac-net
  restart: always

方案3:修复环境变量匹配错误

注意到Guacamole服务中MYSQL_USER引用的是${MYSQL_NAME},但MySQL服务对应的环境变量是${MYSQL_USER},这会导致用户名不匹配,建议修正为:

MYSQL_USER: '${MYSQL_USER}'

验证步骤

  1. 停止并删除现有容器:docker compose down
  2. 应用修改后的docker-compose.yaml配置
  3. 重新启动服务:docker compose up -d
  4. 访问Guacamole页面,确认首次启动不再出现连接错误

内容的提问来源于stack exchange,提问作者TimyShark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 22:42:05