Istio AuthorizationPolicy在OAuth2-Proxy+Dex登录后返回403求助
环境信息
- Istio版本:1.18.2
- 部署环境:AKS
现象描述
访问应用端点httpbin.example.com时,可正常重定向到Dex完成登录,OAuth2-Proxy日志输出[AuthSuccess],但返回应用后浏览器收到403错误,提示RBAC: Access Denied,该错误来自Istio AuthorizationPolicy。
- httpbin pod的envoy-proxy日志、Ingress Gateway日志均无异常
- 部署Istio官方extauthz示例并配置AuthorizationPolicy,功能正常,排除AuthorizationPolicy本身问题,推测OAuth2-Proxy返回结果不符合Istio的成功判定要求
相关配置
1. AuthorizationPolicy配置
apiVersion: security.istio.io/v1beta1 kind: AuthorizationPolicy metadata: name: oauth-policy namespace: istio-system spec: selector: matchLabels: istio: ingressgateway action: CUSTOM provider: name: "oauth2-proxy" rules: # The rules specify when to trigger the external authorizer. - to: - operation: hosts: - "httpbin.example.com"
2. Istio自定义扩展提供者配置
meshConfig: extensionProviders: - name: "oauth2-proxy" envoyExtAuthzHttp: service: "oauth2-proxy.demo.svc.cluster.local" port: "80" headersToDownstreamOnDeny: - content-type - set-cookie headersToUpstreamOnAllow: - authorization - cookie - path - x-auth-request-access-token - x-forwarded-access-token includeHeadersInCheck: - "cookie" - "x-forwarded-access-token" - "x-forwarded-user" - "x-forwarded-email" - "authorization" - "x-forwarded-proto" - "proxy-authorization" - "user-agent" - "x-forwarded-host" - "from" - "x-forwarded-for" - "accept" includeAdditionalHeadersInCheck: authorization: '%REQ(x-auth-request-access-token)%'
3. OAuth2-Proxy配置
# Oauth client configuration specifics config: # OAuth client ID clientID: "oauth2-proxy" # OAuth client secret clientSecret: "ZXhhbXBsZS1hcHAtc2VjcmV0" cookieSecure: true cookieSecret: "b311562c684c75e497b4fb3f08c3deea" # The name of the cookie that oauth2-proxy will create # If left empty, it will default to the release name cookieName: "_oauth2_proxy" configFile: |- email_domains = [ "*" ] upstreams = [ "static://200" ] provider = "oidc" cookie_refresh = "5m" cookie_expire = "4h" cookie_domains = [ "httpbin.example.com" ] cookie_samesite = "lax" set_xauthrequest = true set_authorization_header = true pass_authorization_header = true pass_host_header = true pass_access_token = true skip_jwt_bearer_tokens = true reverse_proxy = true skip_provider_button = true http_address = "0.0.0.0:4180" silence_ping_logging = true oidc_issuer_url = "http://dex.example.com" scope = "openid" oidc_email_claim = "sub" real_client_ip_header = "X-Forwarded-For"
排查思路与解决方案
核心问题定位
最明显的错误是端口不匹配:Istio扩展提供者配置中指定OAuth2-Proxy的端口为80,但OAuth2-Proxy配置的监听端口是4180,导致Istio无法正确连接到OAuth2-Proxy完成授权校验,最终返回403。
具体解决方案
修正端口配置
修改Istio自定义扩展提供者配置中的port字段,从"80"改为"4180",确保与OAuth2-Proxy的监听端口一致:envoyExtAuthzHttp: service: "oauth2-proxy.demo.svc.cluster.local" port: "4180" # 修正为4180验证OAuth2-Proxy响应状态
当前OAuth2-Proxy配置upstreams = [ "static://200" ]是正确的,该配置会让OAuth2-Proxy在认证成功后返回200状态码,符合Istio extauthz的成功判定要求(Istio期望授权成功时返回200,非200会被判定为拒绝)。开启OAuth2-Proxy debug日志排查
在OAuth2-Proxy的configFile中添加log_level = "debug",查看详细的请求交互日志,确认Istio发送的授权请求是否被正确处理,以及返回给Istio的响应头和状态码是否符合要求:configFile: |- log_level = "debug" # 添加此行 email_domains = [ "*" ] # 其他配置保持不变检查头传递配置
当前Istio的includeAdditionalHeadersInCheck配置中,将x-auth-request-access-token赋值给authorization头,需确保OAuth2-Proxy能正确识别该头进行校验。若存在问题,可暂时注释该配置,测试基础授权流程是否正常。
内容的提问来源于stack exchange,提问作者mindcrime

