You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Application Load Balancer(ALB)后端配置Grafana使用Google OAuth2?

解决ALB后端Grafana的Google OAuth2配置问题

你的推测完全准确,问题核心出在Grafana外部URL配置错误和Google OAuth回调地址不匹配这两点上,下面是具体的修复步骤:

1. 修正Grafana的grafana.ini配置

由于Grafana运行在ALB之后,外部用户通过HTTPS的443端口访问(ALB负责处理SSL加密),ALB再将请求转发到EC2实例的3000端口(HTTP)。因此Grafana必须知晓自己的外部访问URL,而不是直接使用自身的HTTP+3000端口配置。

修改grafana.ini中的以下关键项:

protocol = http
http_port = 3000
domain = grafana.acme-live.co.uk
# 核心修改:root_url要设置为用户实际访问的HTTPS地址,不需要带3000端口
root_url = https://%(domain)s/
# OAuth相关配置保留,注意allowed_domains需对应你的Google账号域名
enabled = true
client_id = acme.apps.googleusercontent.com
client_secret = acme-ACME
scopes = https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/userinfo.email
auth_url = https://accounts.google.com/o/oauth2/auth
token_url = https://accounts.google.com/o/oauth2/token
allowed_domains = acme.com  # 这里建议改为你的Google账号所属域名,而非Grafana域名
allow_sign_up = true

解释:root_url是Grafana生成OAuth回调地址的核心参数,必须与外部用户访问的URL完全一致(即ALB的HTTPS地址)。

2. 更新Google Cloud Console的OAuth配置

Google OAuth要求回调地址必须与Grafana生成的地址完全匹配,因此需要调整以下配置:

  • Authorized JavaScript origins:保留https://grafana.acme-live.co.uk(当前配置正确)
  • Authorized redirect URIs:修改为https://grafana.acme-live.co.uk/login/google(移除末尾的:3000,因为外部访问无需指定该端口,ALB会自动转发到EC2的3000端口)

3. 确认ALB转发规则

确保你的ALB配置了正确的监听与转发逻辑:

  • ALB监听443端口(HTTPS),并绑定你的SSL证书
  • 将HTTPS请求转发至EC2实例的3000端口(HTTP)
  • 安全组配置:允许ALB的安全组访问EC2的3000端口,同时允许外部流量访问ALB的443端口

4. 重启Grafana服务

修改完配置后,重启Grafana使新配置生效:

# 以systemd服务为例,根据你的安装方式调整命令
sudo systemctl restart grafana-server

完成以上步骤后,再次尝试点击“Login using google”按钮,即可正常完成OAuth认证流程。

内容的提问来源于stack exchange,提问作者Bluz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 20:27:34