You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Cloud Gateway集成Keycloak遇JWKS URL 404错误求助

解决Spring API Gateway访问Keycloak JWKS URL返回404的问题

问题背景

我们采用Spring Boot微服务架构,包含微服务、Spring API Gateway及用于认证授权的Keycloak实例。网关的OAuth2配置如下:

security:
    oauth2:
      client:
        provider:
          keycloak:
            authorization-uri: https://baseurl/auth/realms/realmname/protocol/openid-connect/auth
            jwk-set-uri: https://baseurlauth/realms/realmname/protocol/openid-connect/certs
            token-uri: https://baseurl/auth/realms/cardbyte/protocol/openid-connect/token
            user-name-attribute: preferred_username
            userinfo-uri: https://baseurl/auth/realms/cardbyte/protocol/openid-connect/userinfo
      resourceserver:
        jwt:
          jwk-set-uri: https://baseurlauth/realms/realmname/protocol/openid-connect/certs
          useInsecureTrustManager: true

已在Keycloak中启用JWKS URL设置并配置对应地址,但通过网关访问API时,出现**"HTTP Get JWKS URL Response 404 Not Found"**错误,抛出异常:Java.lang.IllegalStateException: Could not obtain the keys。

问题分析

从配置和错误信息来看,核心问题集中在以下几点:

  1. URL路径拼写错误:配置里的jwk-set-uri写成了https://baseurlauth/...,对比其他正确端点(如authorization-uri),明显缺失了/auth路径(Keycloak旧版本)或路径格式不匹配(Keycloak新版本)。
  2. Realm名称不一致:token-uri和userinfo-uri使用cardbyte realm,而authorization-uri和JWKS配置用realmname,跨realm配置会导致认证逻辑混乱。
  3. Keycloak版本适配问题:Keycloak 17及以后的Quarkus版本去掉了/auth前缀,若仍用旧路径会直接返回404。

解决方案

1. 修正JWKS URL路径

根据Keycloak版本调整正确的JWKS端点:

  • Keycloak 16及更早版本:添加/auth前缀,修正后URL为:
    https://baseurl/auth/realms/realmname/protocol/openid-connect/certs
  • Keycloak 17+版本:去掉/auth前缀,URL为:
    https://baseurl/realms/realmname/protocol/openid-connect/certs

2. 统一Realm名称

将所有配置中的realm名称保持一致,把token-uri和userinfo-uri里的cardbyte改为realmname,确保所有认证端点指向同一realm。

修正后的完整配置示例(Keycloak旧版本):

security:
    oauth2:
      client:
        provider:
          keycloak:
            authorization-uri: https://baseurl/auth/realms/realmname/protocol/openid-connect/auth
            jwk-set-uri: https://baseurl/auth/realms/realmname/protocol/openid-connect/certs
            token-uri: https://baseurl/auth/realms/realmname/protocol/openid-connect/token
            user-name-attribute: preferred_username
            userinfo-uri: https://baseurl/auth/realms/realmname/protocol/openid-connect/userinfo
      resourceserver:
        jwt:
          jwk-set-uri: https://baseurl/auth/realms/realmname/protocol/openid-connect/certs
          useInsecureTrustManager: true

3. 验证JWKS URL可用性

直接通过curl或浏览器访问修正后的JWKS URL,确认能返回JSON格式的密钥集合:

curl https://baseurl/auth/realms/realmname/protocol/openid-connect/certs

如果仍返回404,检查:

  • Keycloak服务是否正常启动
  • 目标realm是否存在且配置正确
  • 网关与Keycloak之间的网络连通性

4. 调整SSL配置(可选)

useInsecureTrustManager: true仅适合测试环境,生产环境建议关闭该配置,并将Keycloak的SSL证书导入网关的信任存储,确保安全的SSL连接。

内容的提问来源于stack exchange,提问作者Dhruv Kapur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 08:26:29