You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助配置Envoy实现Keycloak JWT认证跳转Swagger UI

针对Swagger UI的Envoy + Keycloak认证跳转配置方案

以下是适配你现有环境的可靠Envoy配置,解决Swagger UI访问时的JWT校验与Keycloak认证跳转需求,同时避免过滤器报错崩溃问题:

完整Envoy配置片段

static_resources:
  listeners:
  - name: listener_0
    address:
      socket_address: { address: 0.0.0.0, port_value: 80 }
    filter_chains:
    - filters:
      - name: envoy.filters.network.http_connection_manager
        typed_config:
          "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
          stat_prefix: ingress_http
          codec_type: AUTO
          route_config:
            name: local_route
            virtual_hosts:
            - name: service_host
              domains: ["*"]
              routes:
              # 放行Keycloak认证回调路径,避免循环拦截
              - match: { prefix: "/oauth2/callback" }
                route: { cluster: keycloak_cluster }
              # 匹配Swagger UI全路径,强制JWT校验
              - match: { prefix: "/swagger-ui" }
                route: { cluster: swagger_cluster }
                typed_per_filter_config:
                  envoy.filters.http.jwt_authn:
                    "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.PerRouteConfig
                    require: { requires_any: { requirements: [{ jwt_requirement_name: "keycloak_jwt" }] } }
              # 保留现有Spring Security API路由
              - match: { prefix: "/api" }
                route: { cluster: spring_api_cluster }
          http_filters:
          # JWT认证过滤器:必须放在router过滤器之前
          - name: envoy.filters.http.jwt_authn
            typed_config:
              "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication
              providers:
                keycloak_jwt:
                  # 替换为你的Keycloak Realm地址
                  issuer: "http://IP:8080/realms/你的Realm名称"
                  # Keycloak公钥获取地址
                  jwks_uri: "http://IP:8080/realms/你的Realm名称/protocol/openid-connect/certs"
              # 全局认证规则:仅对Swagger路径生效
              rules:
              - match: { prefix: "/swagger-ui" }
                requires:
                  requires_any:
                    requirements:
                    - jwt_requirement_name: "keycloak_jwt"
              # Token缺失/无效时重定向到Keycloak认证页
              failure_action:
                redirect:
                  uri: "http://IP:8080/realms/你的Realm名称/protocol/openid-connect/auth?client_id=你的客户端ID&redirect_uri=http://Envoy对外地址/swagger-ui/index.html&response_type=code&scope=openid"
          # 路由转发过滤器
          - name: envoy.filters.http.router
            typed_config: {}
  # 集群配置:替换为你的实际服务IP
  clusters:
  - name: keycloak_cluster
    connect_timeout: 0.25s
    type: STRICT_DNS
    lb_policy: ROUND_ROBIN
    load_assignment:
      cluster_name: keycloak_cluster
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address: { address: IP, port_value: 8080 }
  - name: swagger_cluster
    connect_timeout: 0.25s
    type: STRICT_DNS
    lb_policy: ROUND_ROBIN
    load_assignment:
      cluster_name: swagger_cluster
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address: { address: IP, port_value: 9081 }
  - name: spring_api_cluster
    connect_timeout: 0.25s
    type: STRICT_DNS
    lb_policy: ROUND_ROBIN
    load_assignment:
      cluster_name: spring_api_cluster
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address: { address: IP, port_value: 9084 }

关键配置说明

  1. 过滤器顺序:jwt_authn过滤器必须放在router过滤器之前,这是避免过滤器崩溃的核心——Envoy按过滤器顺序执行逻辑,顺序错误会导致认证逻辑无法触发或抛出异常。
  2. JWT Provider配置:issuer和jwks_uri必须与Keycloak Realm的实际信息一致,确保Envoy能获取有效公钥校验JWT。
  3. 重定向参数:
    • client_id替换为Keycloak中创建的客户端ID
    • redirect_uri设置为Envoy对外暴露的Swagger UI地址(如http://192.168.1.100/swagger-ui/index.html),且必须在Keycloak客户端的Valid Redirect URIs列表中添加该地址,否则Keycloak会拒绝认证请求。
  4. 回调路径放行:/oauth2/callback是Keycloak认证成功后的回调路径,必须跳过JWT校验,否则会出现循环重定向。

报错排查要点

  • 若仍出现过滤器崩溃,检查Envoy版本是否为1.18+(v3版本的jwt_authn过滤器需要该版本支持)
  • 通过envoy --config-path your_config.yaml --log-level debug查看详细日志,定位具体的配置错误或连接问题
  • 确保Keycloak服务正常,Envoy能访问到Keycloak的jwks_uri地址

内容的提问来源于stack exchange,提问作者Yaroslav Malein

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 13:25:21