迁移至EKS并升级Rundeck 5.x.x后页面加载正常但无法登录
Rundeck 5.x迁移至EKS后登录失败排查方案
问题背景
- 原部署:ECS运行Rundeck社区版4.x,自定义ECR镜像(含实用工具),通过
realm.properties管理用户凭证,数据库密钥存储在Secrets Manager,运行正常。 - 当前状态:迁移至EKS,升级镜像至5.x,同集群命名空间创建密钥后,页面加载正常,但无法登录(
realm.properties定义的用户及默认admin/admin均失效)。 - 关键报错:
Chrome控制台显示:Refused to send form data to 'https://rundeck.xx.dev/j_security_check' because it violates the following Content Security Policy directive: "form-action 'self'." - 容器日志仅记录GET请求:
INFO web.requests "GET /user/login" 10.x.x.x http form 2 ? [] (Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome INFO web.requests "GET /static/images/favicon.ico" 10.x.x.x http form 1 ? [image/x-icon] (Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit - 自定义Dockerfile:
ARG RUNDECK_IMAGE FROM ${RUNDECK_IMAGE} COPY data/realm.properties /home/rundeck/server/config COPY data/plugins/. /home/rundeck/libext RUN sudo apt-get update && sudo apt-get install -y \ gnupg2 \ jq \ iputils-ping \ sharutils \ telnet \ unzip \ vim RUN curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" \ && unzip awscliv2.zip \ && sudo ./aws/install
解决建议
修正Content Security Policy(CSP)配置
Rundeck 5.x调整了默认CSP策略,需在rundeck-config.properties中添加允许域名的form-action规则:framework.security.contentSecurityPolicy.formAction = 'self' https://rundeck.xx.dev若使用反向代理(如ALB、Nginx),检查代理是否额外添加了CSP头导致覆盖Rundeck配置,确保代理传递的CSP包含允许的域名。
验证
realm.properties的权限与格式- 检查容器内文件权限,确保rundeck用户(UID 1000)可读取:
kubectl exec -it <rundeck-pod-name> -- ls -l /home/rundeck/server/config/realm.properties - 对比4.x版本的文件格式,确认5.x未对用户条目格式(如加密方式、角色字段)做变更,确保内容符合要求。
- 检查容器内文件权限,确保rundeck用户(UID 1000)可读取:
检查EKS Ingress/服务配置
- 确认Ingress规则允许POST请求到
/j_security_check路径,部分Ingress控制器默认会限制特定路径或请求方法。 - 验证服务端口映射正确,Rundeck默认端口为4440(HTTP)或4443(HTTPS),确保Ingress指向正确端口。
- 确认Ingress规则允许POST请求到
确认Rundeck 5.x认证配置
在rundeck-config.properties中明确启用file realm认证:security.provider.name=file security.file.realm.path=/home/rundeck/server/config/realm.properties5.x可能默认启用其他认证方式(如OIDC),需手动指定file realm为默认认证源。
查看详细认证日志
调整log4j2.properties提升日志级别,获取认证失败细节:logger.org.springframework.security.level = DEBUG logger.com.dtolabs.rundeck.level = DEBUG重启Pod后查看完整日志,定位是否存在用户不存在、密码不匹配或配置错误等问题。
检查默认admin账号状态
若realm.properties中未定义admin用户,需手动添加符合格式的条目:admin:admin,user,admin确保密码为明文(默认加密方式)或正确的加密字符串。
内容的提问来源于stack exchange,提问作者skp15
相关产品推荐
相关产品推荐

