You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kong Ingress Controller资源解析失败及Admin更新异常问题求助

问题排查:Kong Ingress Controller 配置同步失败报错

错误解析

你遇到的两个核心错误指向配置解析和同步的底层问题:

  1. 资源解析失败:could not unmarshal config error: json: cannot unmarshal object into Go struct field ConfigError.flattened_errors of type []sendconfig.FlatEntityError
    该错误说明Kong Admin API返回的错误格式与KIC预期的数组类型不匹配,根源是配置存在非法项导致Kong返回了非预期的错误结构。
  2. Dataplane同步失败:failed posting new config to /config: got status code 400
    400状态码表明提交给Kong Admin的配置不符合校验规则,被直接拒绝。

问题定位

检查你的配置文件后,发现三个关键问题:

1. JWT凭证配置冲突(RS256算法误用secret字段)

在secrets.yaml的JWT Secret中,你为RS256算法添加了secret: empty字段,但RS256是基于RSA公钥/私钥的算法,不需要secret字段——secret仅用于HMAC类算法(如HS256)。同时存在rsa_public_key和secret会导致Kong解析JWT凭证时出现冲突,触发配置校验失败。

2. Consumer用户名重复

consumers.yaml中有两个Consumer的username都设置为user:

  • Admin JWT对应的Consumer
  • 通用Basic Auth对应的Consumer

Kong要求Consumer用户名全局唯一,重复的用户名会导致Consumer创建失败,进而中断整个配置同步流程。

3. 匿名Consumer的插件绑定方式错误

你在anonymous-consumer的metadata.annotations中使用了konghq.com/plugins,但这个注解仅适用于Ingress/HTTPRoute资源,不能直接绑定到KongConsumer。错误的插件绑定会导致配置解析异常。

解决方案

1. 修正JWT Secret配置

删除两个JWT Secret中的secret: empty字段,修改后的JWT Secret示例:

# JWT Credential for Admin
apiVersion: v1
kind: Secret
metadata:
  name: jwt-admin-secret
  labels:
    konghq.com/credential: jwt
type: Opaque
stringData:
  key: admin-issuer
  algorithm: RS256
  rsa_public_key: |
    -----BEGIN PUBLIC KEY-----
    [...]
    -----END PUBLIC KEY-----

2. 修复重复的Consumer用户名

将Basic Auth对应的Consumer用户名改为唯一值,比如user-basic-auth:

# Consumer for generic basic auth user
apiVersion: configuration.konghq.com/v1
kind: KongConsumer
metadata:
 name: generic-basic-auth-consumer
 annotations:
   kubernetes.io/ingress.class: kong
username: user-basic-auth
credentials:
- user-generic-secret

3. 修正匿名Consumer的插件绑定

删除anonymous-consumer中的konghq.com/plugins注解,改用KongPluginBinding将request-termination-anonymous插件绑定到该Consumer:

# 添加到consumers.yaml末尾
apiVersion: configuration.konghq.com/v1
kind: KongPluginBinding
metadata:
  name: anonymous-request-termination-binding
targetRef:
  kind: KongConsumer
  name: anonymous-consumer
plugin: request-termination-anonymous

4. 重新部署配置

先清理现有配置,再重新应用:

kubectl delete -f secrets.yaml -f consumers.yaml -f plugins.yaml -f services.yaml
kubectl apply -f secrets.yaml -f consumers.yaml -f plugins.yaml -f services.yaml

验证

  1. 查看KIC控制器日志,确认同步错误是否消失:
kubectl logs -n kong deployment/kong-kong-ingress-controller -f
  1. 测试各认证路由:
  • Key Auth路由:curl -H "apikey: key" http://<KONG_IP>/foobar/test/auth/key
  • Basic Auth路由:curl -u user:password http://<KONG_IP>/foobar/test/auth/basic
  • JWT路由:使用对应issuer的JWT令牌发起请求
  • 未认证请求:访问任意路由应返回401 Authentication required

内容的提问来源于stack exchange,提问作者mikyll98

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 20:37:03