You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenShift中Oauth2-proxy Pod无法接收/重定向流量求助

问题描述

在OpenShift(Kubernetes)环境中,我在Nginx Pod部署了一个简单的静态HTML网站,想通过oauth2-proxy搭配Keycloak作为SSO提供者做访问保护。但访问网站时显示**“该端点当前未处理请求”**,且查看oauth2-proxy容器日志没有任何请求记录,日志内容如下:

[oauthproxy.go:166] OAuthProxy configured for Keycloak Client ID: documentation
[oauthproxy.go:172] Cookie settings: name:_oauth2_proxy secure(https):true httponly:true expiry:168h0m0s domains: path:/ samesite: refresh:disabled

我已经卡了一周,怀疑是忽略了某个简单配置问题。以下是我的相关配置:


Deployment配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: oauth-documentation
  namespace: documentation
  labels:
    name: oauth-documentation
spec:
  replicas: 1
  selector:
    matchLabels:
      name: documentation
  template:
    metadata:
      labels:
        name: documentation
    spec:
      containers:
        - name: documentation-page
          image: de.icr.io/moddsp/documentation_page
          ports:
            - name: doc-auth
              containerPort: 8080

        - name: oauth-proxy
          image: quay.io/oauth2-proxy/oauth2-proxy:latest
          args:
            - --provider=keycloak
            - --client-id=documentation
            - --client-secret=
            - --login-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/auth
            - --keycloak-group=admins
            - --session-store-type=cookie
            - --cookie-secure=true
            - --cookie-secret=
            - --http-address=0.0.0.0:4180
            - --email-domain=bla.bla
          ports:
            - name: oauth-proxy
              containerPort: 4180
              protocol: TCP

Route配置

kind: Route
apiVersion: route.openshift.io/v1
metadata:
  name: documentation-authenticated
  namespace: documentation
  labels:
    name: oauth-documentation
spec:
  host: >-
    documentation-authenticated.bla.bla
  to:
    kind: Service
    name: oauth-documentation
  port:
    targetPort: proxy
  tls:
    termination: reencrypt
    insecureEdgeTerminationPolicy: Redirect

Service配置

apiVersion: v1
kind: Service
metadata:
  name: oauth-documentation
  namespace: documentation
  annotations:
    service.alpha.openshift.io/serving-cert-secret-name: documentation-tls
spec:
  ports:
    - name: proxy
      port: 4180
      protocol: TCP
      targetPort: oauth-proxy
    - name: documentation-page
      port: 8080
      protocol: TCP
      targetPort: documentation
  selector:
    name: documentation
  sessionAffinity: None
  type: ClusterIP

我怀疑问题可能出在以下几点,但没找到具体错误:

  • Route未正确指向Service
  • Service未正确指向oauth2-proxy Deployment
  • oauth-proxy部署配置有误

恳请帮忙修复配置,让oauth服务正常访问。


解决方案

1. 补全oauth2-proxy上游服务配置

oauth2-proxy核心作用是代理认证后的请求到后端服务,你的配置中缺失了上游服务地址,导致它不知道要转发请求到哪里。在Deployment的oauth-proxy args中添加:

- --upstream=http://localhost:8080

由于两个容器在同一个Pod内,可直接通过localhost:8080访问Nginx服务。

2. 填充必填的密钥配置

你的--client-secret和--cookie-secret为空,这两个是必填项:

  • --client-secret:从Keycloak客户端配置页面获取对应的客户端密钥
  • --cookie-secret:用命令openssl rand -hex 16生成随机16进制字符串,用于加密会话Cookie

3. 补充Keycloak Token兑换与验证地址

对接Keycloak需要完整的OpenID Connect端点配置,添加以下参数到oauth-proxy args:

- --redeem-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/token
- --validate-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/userinfo

4. 修复Service端口映射错误

Service中documentation-page端口的targetPort设为documentation,但Deployment里Nginx容器的端口名称是doc-auth,虽然这不是当前认证失效的直接原因,但会导致Service无法直接访问Nginx,建议修正为:

- name: documentation-page
  port: 8080
  protocol: TCP
  targetPort: doc-auth

修改后的完整oauth-proxy args示例

args:
  - --provider=keycloak
  - --client-id=documentation
  - --client-secret=YOUR_KEYCLOAK_CLIENT_SECRET
  - --login-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/auth
  - --redeem-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/token
  - --validate-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/userinfo
  - --keycloak-group=admins
  - --session-store-type=cookie
  - --cookie-secure=true
  - --cookie-secret=YOUR_GENERATED_COOKIE_SECRET
  - --http-address=0.0.0.0:4180
  - --email-domain=bla.bla
  - --upstream=http://localhost:8080

验证步骤

  1. 重新部署:oc apply -f deployment.yaml -n documentation
  2. 检查Pod状态:oc get pods -n documentation,确保两个容器均为Running状态
  3. 查看oauth2-proxy日志,确认无启动报错
  4. 访问Route地址,验证是否跳转到Keycloak登录页,登录成功后可正常访问静态网站

内容的提问来源于stack exchange,提问作者Herman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 08:35:16