EKS环境下Kubernetes Dashboard结合oauth2-proxy与Keycloak认证遇未授权问题
已实现oauth2-proxy向Kubernetes Dashboard转发Authorization请求头,但Dashboard仍提示unauthorized。经排查发现,Dashboard期望请求头中包含id_token字段,但当前Keycloak返回的Token里没有这个字段,不确定是Keycloak配置问题,还是其他环节存在错误。
部署配置
通过Helm部署oauth2-proxy和Kubernetes Dashboard的配置如下:
kubernetes-dashboard: app: ingress: enabled: true ingressClassName: nginx issuer: name: letsencrypt scope: cluster paths: web: / api: /api annotations: external-dns.alpha.kubernetes.io/hostname: kubernetes-dashboard.example.com nginx.ingress.kubernetes.io/proxy-buffer-size: "64k" nginx.ingress.kubernetes.io/backend-protocol: HTTP nginx.ingress.kubernetes.io/auth-signin: 'https://kubernetes-dashboard.example.com/oauth2/start?rd=$escaped_request_uri' nginx.ingress.kubernetes.io/auth-url: 'https://kubernetes-dashboard.example.com/oauth2/auth' nginx.ingress.kubernetes.io/auth-response-headers: "Authorization" hosts: - kubernetes-dashboard.example.com nginx: enabled: false cert-manager: enabled: false installCRDs: false metrics-server: enabled: false oauth2-proxy: config: existingSecret: "kubernetes-dashboard-oidc-secret" configFile: | provider="keycloak-oidc" provider_display_name="Keycloak" redirect_url="https://kubernetes-dashboard.example.com/oauth2/callback" email_domains = [ "*" ] oidc_issuer_url="https://keycloak.example.com/realms/myrealm" scope = "openid email groups" upstreams = [ "https://kubernetes-dashboard.example.com" ] cookie_secure = true set_authorization_header = true metrics: enabled: false ingress: enabled: true path: /oauth2 className: nginx annotations: nginx.ingress.kubernetes.io/proxy-buffer-size: "64k" hosts: - kubernetes-dashboard.example.com tls: - secretName: kubernetes-dashboard-tls hosts: - "kubernetes-dashboard.example.com" sessionStorage: type: redis redis: password: "" redis: enabled: true architecture: standalone
版本信息
- oauth2-proxy:Helm 6.16.1(应用版本7.4.0)
- Kubernetes Dashboard:Helm 7.0.3(应用版本v3.0.0-alpha0)
- Keycloak:21.1.1
- EKS版本:1.26
相关配置说明
- EKS OIDC配置:

- Keycloak配置:

注:当前使用的Keycloak客户端与kubelogin通过OIDC认证时所用客户端相同,且该客户端在kubelogin场景下可正常工作。
日志与Token情况
- Dashboard错误日志:
(日志内容不够清晰) - JWT Token情况:访问
https://kubernetes-dashboard.example.com/oauth2/callback时,可看到Authorization请求头,但其中不包含id_token:
登录后页面可正常加载,但所有资源都无法显示。推测是因为传递的Authorization Token中缺少id_token,导致API服务器报错,但尝试多种方法均无法将id_token加入请求头,恳请提供帮助。
内容的提问来源于stack exchange,提问作者geoffo-dev
相关产品推荐
相关产品推荐

