请求协助配置Envoy实现Keycloak JWT认证跳转Swagger UI
针对Swagger UI的Envoy + Keycloak认证跳转配置方案
以下是适配你现有环境的可靠Envoy配置,解决Swagger UI访问时的JWT校验与Keycloak认证跳转需求,同时避免过滤器报错崩溃问题:
完整Envoy配置片段
static_resources: listeners: - name: listener_0 address: socket_address: { address: 0.0.0.0, port_value: 80 } filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager stat_prefix: ingress_http codec_type: AUTO route_config: name: local_route virtual_hosts: - name: service_host domains: ["*"] routes: # 放行Keycloak认证回调路径,避免循环拦截 - match: { prefix: "/oauth2/callback" } route: { cluster: keycloak_cluster } # 匹配Swagger UI全路径,强制JWT校验 - match: { prefix: "/swagger-ui" } route: { cluster: swagger_cluster } typed_per_filter_config: envoy.filters.http.jwt_authn: "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.PerRouteConfig require: { requires_any: { requirements: [{ jwt_requirement_name: "keycloak_jwt" }] } } # 保留现有Spring Security API路由 - match: { prefix: "/api" } route: { cluster: spring_api_cluster } http_filters: # JWT认证过滤器:必须放在router过滤器之前 - name: envoy.filters.http.jwt_authn typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication providers: keycloak_jwt: # 替换为你的Keycloak Realm地址 issuer: "http://IP:8080/realms/你的Realm名称" # Keycloak公钥获取地址 jwks_uri: "http://IP:8080/realms/你的Realm名称/protocol/openid-connect/certs" # 全局认证规则:仅对Swagger路径生效 rules: - match: { prefix: "/swagger-ui" } requires: requires_any: requirements: - jwt_requirement_name: "keycloak_jwt" # Token缺失/无效时重定向到Keycloak认证页 failure_action: redirect: uri: "http://IP:8080/realms/你的Realm名称/protocol/openid-connect/auth?client_id=你的客户端ID&redirect_uri=http://Envoy对外地址/swagger-ui/index.html&response_type=code&scope=openid" # 路由转发过滤器 - name: envoy.filters.http.router typed_config: {} # 集群配置:替换为你的实际服务IP clusters: - name: keycloak_cluster connect_timeout: 0.25s type: STRICT_DNS lb_policy: ROUND_ROBIN load_assignment: cluster_name: keycloak_cluster endpoints: - lb_endpoints: - endpoint: address: socket_address: { address: IP, port_value: 8080 } - name: swagger_cluster connect_timeout: 0.25s type: STRICT_DNS lb_policy: ROUND_ROBIN load_assignment: cluster_name: swagger_cluster endpoints: - lb_endpoints: - endpoint: address: socket_address: { address: IP, port_value: 9081 } - name: spring_api_cluster connect_timeout: 0.25s type: STRICT_DNS lb_policy: ROUND_ROBIN load_assignment: cluster_name: spring_api_cluster endpoints: - lb_endpoints: - endpoint: address: socket_address: { address: IP, port_value: 9084 }
关键配置说明
- 过滤器顺序:
jwt_authn过滤器必须放在router过滤器之前,这是避免过滤器崩溃的核心——Envoy按过滤器顺序执行逻辑,顺序错误会导致认证逻辑无法触发或抛出异常。 - JWT Provider配置:
issuer和jwks_uri必须与Keycloak Realm的实际信息一致,确保Envoy能获取有效公钥校验JWT。 - 重定向参数:
client_id替换为Keycloak中创建的客户端IDredirect_uri设置为Envoy对外暴露的Swagger UI地址(如http://192.168.1.100/swagger-ui/index.html),且必须在Keycloak客户端的Valid Redirect URIs列表中添加该地址,否则Keycloak会拒绝认证请求。
- 回调路径放行:
/oauth2/callback是Keycloak认证成功后的回调路径,必须跳过JWT校验,否则会出现循环重定向。
报错排查要点
- 若仍出现过滤器崩溃,检查Envoy版本是否为1.18+(v3版本的
jwt_authn过滤器需要该版本支持) - 通过
envoy --config-path your_config.yaml --log-level debug查看详细日志,定位具体的配置错误或连接问题 - 确保Keycloak服务正常,Envoy能访问到Keycloak的
jwks_uri地址
内容的提问来源于stack exchange,提问作者Yaroslav Malein
相关产品推荐
相关产品推荐

