OpenShift中Oauth2-proxy Pod无法接收/重定向流量求助
问题描述
在OpenShift(Kubernetes)环境中,我在Nginx Pod部署了一个简单的静态HTML网站,想通过oauth2-proxy搭配Keycloak作为SSO提供者做访问保护。但访问网站时显示**“该端点当前未处理请求”**,且查看oauth2-proxy容器日志没有任何请求记录,日志内容如下:
[oauthproxy.go:166] OAuthProxy configured for Keycloak Client ID: documentation [oauthproxy.go:172] Cookie settings: name:_oauth2_proxy secure(https):true httponly:true expiry:168h0m0s domains: path:/ samesite: refresh:disabled
我已经卡了一周,怀疑是忽略了某个简单配置问题。以下是我的相关配置:
Deployment配置
apiVersion: apps/v1 kind: Deployment metadata: name: oauth-documentation namespace: documentation labels: name: oauth-documentation spec: replicas: 1 selector: matchLabels: name: documentation template: metadata: labels: name: documentation spec: containers: - name: documentation-page image: de.icr.io/moddsp/documentation_page ports: - name: doc-auth containerPort: 8080 - name: oauth-proxy image: quay.io/oauth2-proxy/oauth2-proxy:latest args: - --provider=keycloak - --client-id=documentation - --client-secret= - --login-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/auth - --keycloak-group=admins - --session-store-type=cookie - --cookie-secure=true - --cookie-secret= - --http-address=0.0.0.0:4180 - --email-domain=bla.bla ports: - name: oauth-proxy containerPort: 4180 protocol: TCP
Route配置
kind: Route apiVersion: route.openshift.io/v1 metadata: name: documentation-authenticated namespace: documentation labels: name: oauth-documentation spec: host: >- documentation-authenticated.bla.bla to: kind: Service name: oauth-documentation port: targetPort: proxy tls: termination: reencrypt insecureEdgeTerminationPolicy: Redirect
Service配置
apiVersion: v1 kind: Service metadata: name: oauth-documentation namespace: documentation annotations: service.alpha.openshift.io/serving-cert-secret-name: documentation-tls spec: ports: - name: proxy port: 4180 protocol: TCP targetPort: oauth-proxy - name: documentation-page port: 8080 protocol: TCP targetPort: documentation selector: name: documentation sessionAffinity: None type: ClusterIP
我怀疑问题可能出在以下几点,但没找到具体错误:
- Route未正确指向Service
- Service未正确指向
oauth2-proxyDeployment oauth-proxy部署配置有误
恳请帮忙修复配置,让oauth服务正常访问。
解决方案
1. 补全oauth2-proxy上游服务配置
oauth2-proxy核心作用是代理认证后的请求到后端服务,你的配置中缺失了上游服务地址,导致它不知道要转发请求到哪里。在Deployment的oauth-proxy args中添加:
- --upstream=http://localhost:8080
由于两个容器在同一个Pod内,可直接通过localhost:8080访问Nginx服务。
2. 填充必填的密钥配置
你的--client-secret和--cookie-secret为空,这两个是必填项:
--client-secret:从Keycloak客户端配置页面获取对应的客户端密钥--cookie-secret:用命令openssl rand -hex 16生成随机16进制字符串,用于加密会话Cookie
3. 补充Keycloak Token兑换与验证地址
对接Keycloak需要完整的OpenID Connect端点配置,添加以下参数到oauth-proxy args:
- --redeem-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/token - --validate-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/userinfo
4. 修复Service端口映射错误
Service中documentation-page端口的targetPort设为documentation,但Deployment里Nginx容器的端口名称是doc-auth,虽然这不是当前认证失效的直接原因,但会导致Service无法直接访问Nginx,建议修正为:
- name: documentation-page port: 8080 protocol: TCP targetPort: doc-auth
修改后的完整oauth-proxy args示例
args: - --provider=keycloak - --client-id=documentation - --client-secret=YOUR_KEYCLOAK_CLIENT_SECRET - --login-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/auth - --redeem-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/token - --validate-url=https://keycloak.bla.bla/auth/realms/dsp/protocol/openid-connect/userinfo - --keycloak-group=admins - --session-store-type=cookie - --cookie-secure=true - --cookie-secret=YOUR_GENERATED_COOKIE_SECRET - --http-address=0.0.0.0:4180 - --email-domain=bla.bla - --upstream=http://localhost:8080
验证步骤
- 重新部署:
oc apply -f deployment.yaml -n documentation - 检查Pod状态:
oc get pods -n documentation,确保两个容器均为Running状态 - 查看oauth2-proxy日志,确认无启动报错
- 访问Route地址,验证是否跳转到Keycloak登录页,登录成功后可正常访问静态网站
内容的提问来源于stack exchange,提问作者Herman
相关产品推荐
相关产品推荐

