同Kubernetes集群内Pod请求时,openid-configuration能否返回HTTP URL?
我有一个托管前端、身份服务及多个应用服务的Kubernetes(OpenShift)集群,身份服务器采用IdentityServer4,可被外部客户端或集群内Pod访问。集群内所有Pod(含身份服务)仅暴露HTTP端口,HTTPS流量由Ingress统一处理。
当前遇到的问题:ApplicationA配置为使用http://identity.yyy.svc.cluster.local访问身份服务,它通过该HTTP地址获取/.well-known/openid-configuration,但返回的配置文件中所有端点均为HTTPS格式的URL(如https://identity.yyy.svc.cluster.local/connect/token)。ApplicationA后续会使用这些HTTPS地址发起请求,可身份服务并未监听HTTPS端口,直接导致请求超时。
已知openid-configuration是动态生成的,URL协议应与请求协议保持一致,但实际表现为:
- 当外部请求
https://example.com/Identity/.well-known/openid-configuration时,返回HTTPS格式的URL,符合预期; - 当集群内部请求
http://identity.yyy.svc.cluster.local/.well-known/openid-configuration时,仍返回HTTPS格式的URL,不符合需求。
我希望针对来自*.cluster.local的内部请求,让IdentityServer4返回HTTP格式的URL,且希望在身份服务端进行配置修改,而非逐个调整应用配置。请问该如何操作?是否需要重新配置集群?
编辑说明
访问http://identity.yyy.svc.cluster.local/.well-known/openid-configuration得到的格式化配置内容如下:
{ "issuer":"https://identity.yyy.svc.cluster.local", "jwks_uri":"https://identity.yyy.svc.cluster.local/.well-known/openid-configuration/jwks", "authorization_endpoint":"https://identity.yyy.svc.cluster.local/connect/authorize", "token_endpoint":"https://identity.yyy.svc.cluster.local/connect/token", "userinfo_endpoint":"https://identity.yyy.svc.cluster.local/connect/userinfo", [省略其他内容] }
解决方案
问题源于代码中存在一个不规范的中间件,该中间件强制将所有请求的协议设置为HTTPS。修复该中间件并正确配置UseForwardedHeaders()中间件后,IdentityServer4即可根据请求协议返回对应格式的URL。
内容的提问来源于stack exchange,提问作者Simone

