You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Trino Coordinator认证错误求助:JWT签名不匹配问题排查

解决Trino内部认证JWT签名不匹配错误

错误信息

"2023-10-30T06:01:59.321Z ERROR http-worker-117
io.trino.server.InternalAuthenticationManager Internal
authentication failed io.jsonwebtoken.security.SignatureException: JWT
signature does not match locally computed signature. JWT validity
cannot be asserted and should not be trusted."

排查与解决步骤

  • 确认共享密钥完全一致:
    尽管配置中internal-communication.shared-secret均为Testing@123,仍需仔细检查:
    • 密钥是否存在大小写、空格、特殊字符的细微差异,比如Worker端配置是否有隐藏空格或拼写错误
    • 修改配置后需重启所有Trino节点,确保新配置生效
  • 校准Discovery URI配置:
    Coordinator的discovery.uri使用http://0.0.0.0:8080,Worker端指向域名http://XXXXXXXXXXXXX.XXXXX.com:8080,需确认:
    • Worker能通过该域名正常访问Coordinator服务,域名解析结果正确
    • 建议将Coordinator的discovery.uri替换为Worker可访问的实际IP或域名,与Worker端配置保持一致
  • 同步节点系统时间:
    JWT签名验证依赖时间戳,Coordinator与Worker的系统时间差过大也会触发该错误,确保所有节点开启NTP服务,时间误差控制在3秒以内
  • 清理重复配置项:
    Coordinator配置中重复出现discovery-server.enabled=true,虽不直接引发签名问题,但建议删除重复项,避免潜在配置冲突

提供的配置文件

Coordinator config.properties

coordinator=true
node-scheduler.include-coordinator=false
http-server.http.port=8080
query.max-memory=5GB
query.max-memory-per-node=2GB
discovery-server.enabled=true
discovery.uri=http://0.0.0.0:8080
internal-communication.https.required=false
internal-communication.shared-secret=Testing@123

Worker config.properties

coordinator=false
http-server.http.port=8080
query.max-memory=5GB
query.max-memory-per-node=1GB
discovery.uri=http://XXXXXXXXXXXXX.XXXXX.com:8080
internal-communication.https.required=false
internal-communication.shared-secret=Testing@123

内容的提问来源于stack exchange,提问作者Harikrishna Ezhumalai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 16:27:25