You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

APISIX与Keycloak集成异常:路由重叠引发OIDC发现超时

APISIX集成Keycloak OIDC时500错误排查解决

问题场景

使用Keycloak作为OIDC身份提供商,在APISIX中配置两条路由:

  • /auth相关API转发至Keycloak
  • /*其他API转发至traefik whoami
    访问foo.example.com时返回500错误,预期应跳转至Keycloak登录页面。

路由配置

# Keycloak转发路由(路由ID:2)
curl -XPUT localhost:xxxx/apisix/admin/routes/2 -H "X-API-KEY: xxx" -d '{
    "uris": ["/auth/*", "/auth/"],
    "service_id": "1",
    "hosts": ["*.example.com"],
    "methods": ["GET","POST","PUT","DELETE"],
    "priority": 999
}'

# 应用转发路由(路由ID:1)
curl -XPUT localhost:xxxx/apisix/admin/routes/1 -H "X-API-KEY: xxxx" -d '{
    "uri":"/*",
    "service_id": "2",
    "hosts": ["foo.example.com"],
    "methods": ["GET","POST","PUT","DELETE"],
    "priority": 10,
    "plugins":{
        "openid-connect":{
            "client_id": "foo",
            "client_secret": "ATfWp96az8uTStNSr7qYKSrlXpFqm35b",
            "discovery": "http://foo.example.com/auth/realms/foo/.well-known/openid-configuration",
            "scope": "openid profile",
            "bearer_only": false,
            "realm": "foo",
            "introspection_endpoint_auth_method": "client_secret_post",
            "redirect_uri": "http://foo.example.com/",
            "logout_path": "/logout",
            "set_refresh_token_header":true,
            "post_logout_redirect_uri":"http://foo.example.com/"
        }
    }
}'

错误日志

[lua] openidc.lua:573: openidc_discover(): accessing discovery url (http://foo.example.com/auth/realms/foo/.well-known/openid-configuration) failed: timeout, client: 172.19.0.7, server: _, request: "GET /auth/realms/foo/.well-known/openid-configuration HTTP/1.1", host: "foo.example.com"

排查与解决方案

核心原因

APISIX的openid-connect插件在初始化时,会直接从APISIX节点发起HTTP请求到配置的discovery地址,不会经过APISIX自身的路由转发。当前配置的http://foo.example.com是外部访问域名,APISIX内部(如容器环境)可能无法解析或访问该地址,导致请求超时。

解决步骤

  1. 替换Discovery地址为Keycloak内部可访问地址
    将openid-connect插件的discovery字段修改为Keycloak的内部服务地址,比如:

    • 若使用Docker Compose部署,使用服务名:http://keycloak:8080/auth/realms/foo/.well-known/openid-configuration
    • 若为虚拟机部署,使用Keycloak节点的内部IP+端口:http://192.168.x.x:8080/auth/realms/foo/.well-known/openid-configuration
  2. 验证内部连通性
    在APISIX节点/容器内执行curl命令,测试Discovery地址是否能正常返回内容:

    curl http://keycloak:8080/auth/realms/foo/.well-known/openid-configuration
    

    确保返回包含OIDC端点信息的JSON数据。

  3. 检查Keycloak服务状态
    确认Keycloak服务正常运行,且/auth/realms/foo/.well-known/openid-configuration接口可正常访问。

  4. 可选:调整插件超时配置
    若网络延迟较高,可在openid-connect插件中添加超时参数:

    "plugins":{
        "openid-connect":{
            // 其他配置...
            "timeout": 5000, // 单位:毫秒
            "ssl_verify": false // 若内部服务使用自签证书,可关闭SSL验证
        }
    }
    

内容的提问来源于stack exchange,提问作者Shanmugapriya.N

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 00:36:12