APISIX与Keycloak集成异常:路由重叠引发OIDC发现超时
问题场景
使用Keycloak作为OIDC身份提供商,在APISIX中配置两条路由:
/auth相关API转发至Keycloak/*其他API转发至traefik whoami
访问foo.example.com时返回500错误,预期应跳转至Keycloak登录页面。
路由配置
# Keycloak转发路由(路由ID:2) curl -XPUT localhost:xxxx/apisix/admin/routes/2 -H "X-API-KEY: xxx" -d '{ "uris": ["/auth/*", "/auth/"], "service_id": "1", "hosts": ["*.example.com"], "methods": ["GET","POST","PUT","DELETE"], "priority": 999 }' # 应用转发路由(路由ID:1) curl -XPUT localhost:xxxx/apisix/admin/routes/1 -H "X-API-KEY: xxxx" -d '{ "uri":"/*", "service_id": "2", "hosts": ["foo.example.com"], "methods": ["GET","POST","PUT","DELETE"], "priority": 10, "plugins":{ "openid-connect":{ "client_id": "foo", "client_secret": "ATfWp96az8uTStNSr7qYKSrlXpFqm35b", "discovery": "http://foo.example.com/auth/realms/foo/.well-known/openid-configuration", "scope": "openid profile", "bearer_only": false, "realm": "foo", "introspection_endpoint_auth_method": "client_secret_post", "redirect_uri": "http://foo.example.com/", "logout_path": "/logout", "set_refresh_token_header":true, "post_logout_redirect_uri":"http://foo.example.com/" } } }'
错误日志
[lua] openidc.lua:573: openidc_discover(): accessing discovery url (http://foo.example.com/auth/realms/foo/.well-known/openid-configuration) failed: timeout, client: 172.19.0.7, server: _, request: "GET /auth/realms/foo/.well-known/openid-configuration HTTP/1.1", host: "foo.example.com"
排查与解决方案
核心原因
APISIX的openid-connect插件在初始化时,会直接从APISIX节点发起HTTP请求到配置的discovery地址,不会经过APISIX自身的路由转发。当前配置的http://foo.example.com是外部访问域名,APISIX内部(如容器环境)可能无法解析或访问该地址,导致请求超时。
解决步骤
替换Discovery地址为Keycloak内部可访问地址
将openid-connect插件的discovery字段修改为Keycloak的内部服务地址,比如:- 若使用Docker Compose部署,使用服务名:
http://keycloak:8080/auth/realms/foo/.well-known/openid-configuration - 若为虚拟机部署,使用Keycloak节点的内部IP+端口:
http://192.168.x.x:8080/auth/realms/foo/.well-known/openid-configuration
- 若使用Docker Compose部署,使用服务名:
验证内部连通性
在APISIX节点/容器内执行curl命令,测试Discovery地址是否能正常返回内容:curl http://keycloak:8080/auth/realms/foo/.well-known/openid-configuration确保返回包含OIDC端点信息的JSON数据。
检查Keycloak服务状态
确认Keycloak服务正常运行,且/auth/realms/foo/.well-known/openid-configuration接口可正常访问。可选:调整插件超时配置
若网络延迟较高,可在openid-connect插件中添加超时参数:"plugins":{ "openid-connect":{ // 其他配置... "timeout": 5000, // 单位:毫秒 "ssl_verify": false // 若内部服务使用自签证书,可关闭SSL验证 } }
内容的提问来源于stack exchange,提问作者Shanmugapriya.N

