You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何部署仅暴露非安全端口的所有Hono组件?

背景说明

我们已有上层安全机制,基于证书的部署反而增加了基础设施复杂度,因此希望部署所有Hono组件时仅暴露非安全端口。

使用官方Hono Helm部署包(设备注册中心为Hono MongoDB Device Registry的派生版本)将Hono部署到GCP Kubernetes(GKE)。此前通过extraVolumes和extraVolumeMounts挂载自有PKI证书,并通过tenantSpec、deviceRegistrationSpec和credentialsSpec配置相关参数,已在minikube上成功完成部署。

当前目标是让各组件通过非安全端口正常通信,仅使用自有PKI证书保护适配器。

问题描述

能否部署所有通过非安全端口互相通信的Hono组件?目前command-router与device-registry通信时出现SASL handshake failed due to a transient error错误,暂未明确根本原因。

已尝试多种配置调整,以下是最接近目标的配置:主机地址确认无误,但Hono Helm Chart似乎未部署带非安全端口的Service(仅绑定amqps-5671)。

相关配置

device-registry配置

hono:
  auth:
    host: hono-service-auth
    port: 5672
    hostnameVerificationRequired: false
    supportedSaslMechanisms: PLAIN
    connectTimeout: 2000
  registry:
    http:
      authenticationRequired: false
      insecurePortEnabled: true
      insecurePortBindAddress: 0.0.0.0
    amqp:
      insecurePort: 5672
      insecurePortEnabled: true
      insecurePortBindAddress: 0.0.0.0

适配器全局配置(访问tenant/device/credentials APIs)

adapters:
  tenantSpec:
    credentialsPath: /opt/hono/config/adapter.credentials
    host: device-registry-chart-service-device-registry
    port: 5672
    tlsEnabled: false
    hostnameVerificationRequired: false
  deviceRegistrationSpec:
    credentialsPath: /opt/hono/config/adapter.credentials
    host: device-registry-chart-service-device-registry
    port: 5672
    tlsEnabled: false
    hostnameVerificationRequired: false
  credentialsSpec:
    credentialsPath: /opt/hono/config/adapter.credentials
    host: device-registry-chart-service-device-registry
    port: 5672
    tlsEnabled: false
    hostnameVerificationRequired: false

auth-server配置

hono:
  auth:
    amqp:
      insecurePortEnabled: true
      insecurePortBindAddress: 0.0.0.0
      bindAddress: 0.0.0.0
    svc:
      permissionsPath: "file:///mnt/permissions/permissions.json"
      supportedSaslMechanisms: "PLAIN"
      # auth-server不配置签名材料无法启动,尝试在客户端验证证书但无效果
      signing:
        keyPath: /mnt/cert/tls.key
        certPath: /mnt/cert/tls.crt

解决方案

1. 确认Hono支持全非安全端口部署

Hono完全支持组件间通过非加密AMQP端口(5672)通信,核心是确保每个组件的非安全端口启用,且对应的Kubernetes Service暴露该端口。

2. 修复Service未暴露非安全端口的问题

Helm Chart默认仅暴露安全AMQP端口(5671),需要在values.yaml中为每个组件开启非安全端口的Service映射:

  • device-registry:添加service.amqp.insecurePort.enabled: true,确保Service绑定5672端口
  • auth-server:添加service.amqp.insecurePort.enabled: true
  • command-router:同理配置其Service暴露非安全端口

示例(device-registry的Helm配置):

deviceRegistry:
  service:
    amqp:
      insecurePort:
        enabled: true
        port: 5672
        targetPort: 5672

3. 解决SASL握手失败问题

  • 验证SASL机制一致性:确保所有组件的supportedSaslMechanisms统一为PLAIN,同时确认adapter.credentials文件中的凭证(用户名/密码)在auth-server中已注册,且拥有访问device-registry的权限。
  • 检查auth-server权限配置:permissions.json需允许command-router的身份访问device-registry的AMQP API,例如添加对应角色的权限规则。
  • auth-server签名材料:该配置用于签发JWT令牌,和组件间的AMQP SASL通信无关,保留当前配置即可,不影响非安全端口通信。

4. 额外验证步骤

  • 进入command-router Pod,使用nc测试device-registry的5672端口是否可达:nc -zv device-registry-chart-service-device-registry 5672
  • 查看command-router和device-registry的日志,确认握手失败的具体细节(比如凭证错误、权限不足)

内容的提问来源于stack exchange,提问作者MichalJ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 00:57:15