如何禁用Spring Boot Admin登录并仅用Keycloak作为唯一认证器
解决Spring Boot Admin与Keycloak认证共存问题
已完成受Keycloak保护的应用集成到Spring Boot Admin,但出现SBA自带登录与Keycloak的Spring Security登录共存的情况,以下是禁用SBA登录、将Keycloak设为唯一认证方式的解决方案:
核心思路
通过自定义Spring Security配置,禁用SBA默认的表单登录逻辑,强制所有认证请求走Keycloak的OAuth2登录流程。
具体步骤
1. 自定义Spring Security配置类
创建配置类覆盖默认认证规则,让未授权请求直接跳转到Keycloak登录页:
import de.codecentric.boot.admin.server.config.AdminServerProperties; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint; @Configuration public class SecurityConfig { private final AdminServerProperties adminServerProperties; public SecurityConfig(AdminServerProperties adminServerProperties) { this.adminServerProperties = adminServerProperties; } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { String adminContextPath = adminServerProperties.getContextPath(); http // 配置请求权限规则 .authorizeHttpRequests(auth -> auth // 允许SBA静态资源、实例注册端点无需认证 .requestMatchers( adminContextPath + "/assets/**", adminContextPath + "/instances", adminContextPath + "/actuator/health" ).permitAll() // 其余所有请求必须经过认证 .anyRequest().authenticated() ) // 禁用SBA自带的表单登录 .formLogin(form -> form.disable()) // 配置OAuth2登录,指定Keycloak为认证提供商 .oauth2Login(oauth2 -> oauth2 .loginPage("/oauth2/authorization/keycloak") .defaultSuccessUrl(adminContextPath + "/", true) ) // 配置退出登录,同步销毁Keycloak会话 .logout(logout -> logout .logoutUrl(adminContextPath + "/logout") .logoutSuccessUrl("/") .invalidateHttpSession(true) ) // 未认证请求直接跳转至Keycloak登录页 .exceptionHandling(ex -> ex .authenticationEntryPoint(new LoginUrlAuthenticationEntryPoint("/oauth2/authorization/keycloak")) ); return http.build(); } }
2. 配置Keycloak与SBA参数
在application.yml中填写Keycloak客户端信息及SBA基础配置:
spring: security: oauth2: client: registration: keycloak: client-id: sba-admin-client # 替换为你的Keycloak客户端ID client-secret: your-client-secret # 替换为你的客户端密钥 scope: openid,profile,email authorization-grant-type: authorization_code provider: keycloak: issuer-uri: http://your-keycloak-server:8080/auth/realms/your-realm # 替换为你的Keycloak Realm地址 user-name-attribute: preferred_username spring.boot.admin: context-path: /admin # 自定义SBA访问路径,可按需调整
3. 确认依赖完整性
确保项目引入了必要的依赖(以Maven为例):
<!-- Spring Boot Admin Server --> <dependency> <groupId>de.codecentric</groupId> <artifactId>spring-boot-admin-starter-server</artifactId> <version>3.2.3</version> <!-- 替换为你的SBA版本 --> </dependency> <!-- Spring Boot Admin UI --> <dependency> <groupId>de.codecentric</groupId> <artifactId>spring-boot-admin-starter-ui</artifactId> <version>3.2.3</version> </dependency> <!-- OAuth2 Client 用于Keycloak集成 --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency>
验证效果
启动项目后访问Spring Boot Admin页面,会直接跳转至Keycloak登录界面,不再显示SBA自带的登录表单;登录成功后自动返回SBA控制台,实现Keycloak作为唯一认证方式。
内容的提问来源于stack exchange,提问作者Alfredo Gabriel
相关产品推荐
相关产品推荐

