You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

同Kubernetes集群内Pod请求时,openid-configuration能否返回HTTP URL?

IdentityServer4在Kubernetes集群中返回HTTPS内部URL导致服务间请求超时问题

我有一个托管前端、身份服务及多个应用服务的Kubernetes(OpenShift)集群,身份服务器采用IdentityServer4,可被外部客户端或集群内Pod访问。集群内所有Pod(含身份服务)仅暴露HTTP端口,HTTPS流量由Ingress统一处理。

当前遇到的问题:ApplicationA配置为使用http://identity.yyy.svc.cluster.local访问身份服务,它通过该HTTP地址获取/.well-known/openid-configuration,但返回的配置文件中所有端点均为HTTPS格式的URL(如https://identity.yyy.svc.cluster.local/connect/token)。ApplicationA后续会使用这些HTTPS地址发起请求,可身份服务并未监听HTTPS端口,直接导致请求超时。

已知openid-configuration是动态生成的,URL协议应与请求协议保持一致,但实际表现为:

  • 当外部请求https://example.com/Identity/.well-known/openid-configuration时,返回HTTPS格式的URL,符合预期;
  • 当集群内部请求http://identity.yyy.svc.cluster.local/.well-known/openid-configuration时,仍返回HTTPS格式的URL,不符合需求。

我希望针对来自*.cluster.local的内部请求,让IdentityServer4返回HTTP格式的URL,且希望在身份服务端进行配置修改,而非逐个调整应用配置。请问该如何操作?是否需要重新配置集群?


编辑说明

访问http://identity.yyy.svc.cluster.local/.well-known/openid-configuration得到的格式化配置内容如下:

{
  "issuer":"https://identity.yyy.svc.cluster.local",
  "jwks_uri":"https://identity.yyy.svc.cluster.local/.well-known/openid-configuration/jwks",
  "authorization_endpoint":"https://identity.yyy.svc.cluster.local/connect/authorize",
  "token_endpoint":"https://identity.yyy.svc.cluster.local/connect/token",
  "userinfo_endpoint":"https://identity.yyy.svc.cluster.local/connect/userinfo",
  [省略其他内容]
}

解决方案

问题源于代码中存在一个不规范的中间件,该中间件强制将所有请求的协议设置为HTTPS。修复该中间件并正确配置UseForwardedHeaders()中间件后,IdentityServer4即可根据请求协议返回对应格式的URL。


内容的提问来源于stack exchange,提问作者Simone

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 08:52:29