Minikube+Keycloak Operator部署Keycloak 22.0.1时Admin UI无限加载
Keycloak Operator部署实例未就绪问题排查解决思路
问题场景
通过Minikube+OLM+Keycloak Operator部署Keycloak实例,CR配置如下:
apiVersion: k8s.keycloak.org/v2alpha1 kind: Keycloak metadata: name: example-keycloak namespace: my-keycloak-operator labels: app: sso spec: instances: 1 image: bsctzz/dockerhub:groupaccess hostname: hostname: keycloak.local ingress: enabled: false http: httpEnabled: false tlsSecret: root-secret
启动后Pod状态为Running但未就绪,Admin页面无限加载,容器日志停留在添加admin用户阶段:
2023-08-07 09:07:21,064 INFO [io.quarkus] (main) Installed features: [agroal, cdi, hibernate-orm, jdbc-h2, jdbc-mariadb, jdbc-mssql, jdbc-mysql, jdbc-oracle, jdbc-postgresql, keycloak, logging-gelf, micrometer, narayana-jta, reactive-routes, resteasy, resteasy-jackson, smallrye-context-propagation, smallrye-health, vertx] 2023-08-07 09:07:21,200 INFO [org.keycloak.services] (main) KC-SERVICES0009: Added user 'admin' to realm 'master'
Pod详情显示就绪/存活探针均返回404:
Name: example-keycloak-0 Namespace: my-keycloak-operator Priority: 0 Node: minikube/192.168.49.2 Start Time: Mon, 07 Aug 2023 11:31:02 +0200 Labels: app=keycloak app.kubernetes.io/instance=example-keycloak app.kubernetes.io/managed-by=keycloak-operator controller-revision-hash=example-keycloak-dc5544cf9 statefulset.kubernetes.io/pod-name=example-keycloak-0 Annotations: <none> Status: Running IP: 10.244.1.232 IPs: IP: 10.244.1.232 Controlled By: StatefulSet/example-keycloak Containers: keycloak: Container ID: docker://6bf8d1dcc7df0db016904905d8a073430924f881caae50b0ce58b78c1b66f2a2 Image: bsctzz/dockerhub:groupaccess Image ID: docker-pullable://bsctzz/dockerhub@sha256:e3c3d4c99a26ed1b8fb54432194f939e0d86a87561bd949b14df22f745fe281c Ports: 8443/TCP, 8080/TCP Host Ports: 0/TCP, 0/TCP Args: start --optimized State: Running Started: Mon, 07 Aug 2023 11:31:05 +0200 Ready: False Restart Count: 0 Liveness: http-get https://:8443/health/live delay=20s timeout=1s period=2s #success=1 #failure=150 Readiness: http-get https://:8443/health/ready delay=20s timeout=1s period=2s #success=1 #failure=250 Environment: KC_HOSTNAME: localhost KC_HTTP_ENABLED: false KC_HTTP_PORT: 8080 KC_HTTPS_PORT: 8443 KC_HTTPS_CERTIFICATE_FILE: /mnt/certificates/tls.crt KC_HTTPS_CERTIFICATE_KEY_FILE: /mnt/certificates/tls.key KC_HEALTH_ENABLED: true KC_CACHE: ispn KC_CACHE_STACK: kubernetes KC_PROXY: passthrough KEYCLOAK_ADMIN: <set to the key 'username' in secret 'example-keycloak-initial-admin'> Optional: false KEYCLOAK_ADMIN_PASSWORD: <set to the key 'password' in secret 'example-keycloak-initial-admin'> Optional: false jgroups.dns.query: example-keycloak-discovery.my-keycloak-operator Mounts: /mnt/certificates from keycloak-tls-certificates (rw) /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-fwxnx (ro) Conditions: Type Status Initialized True Ready False ContainersReady False PodScheduled True Volumes: keycloak-tls-certificates: Type: Secret (a volume populated by a Secret) SecretName: root-secret Optional: false kube-api-access-fwxnx: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt ConfigMapOptional: <nil> DownwardAPI: true QoS Class: BestEffort Node-Selectors: <none> Tolerations: node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal Scheduled 43s default-scheduler Successfully assigned my-keycloak-operator/example-keycloak-0 to minikube Normal Pulling 43s kubelet Pulling image "bsctzz/dockerhub:groupaccess" Normal Pulled 42s kubelet Successfully pulled image "bsctzz/dockerhub:groupaccess" in 1.301906831s (1.301917466s including waiting) Normal Created 42s kubelet Created container keycloak Normal Started 41s kubelet Started container keycloak Warning Unhealthy 2s (x10 over 19s) kubelet Readiness probe failed: HTTP probe failed with statuscode: 404 Warning Unhealthy 2s (x10 over 19s) kubelet Liveness probe failed: HTTP probe failed with statuscode: 404
解决思路
1. 修正健康检查端点路径
Quarkus版本的Keycloak健康端点默认路径为/q/health/live和/q/health/ready,而非当前探针配置的/health/live。需修改StatefulSet的探针配置:
livenessProbe: httpGet: path: /q/health/live port: 8443 scheme: HTTPS initialDelaySeconds: 60 timeoutSeconds: 5 periodSeconds: 10 readinessProbe: httpGet: path: /q/health/ready port: 8443 scheme: HTTPS initialDelaySeconds: 60 timeoutSeconds: 5 periodSeconds: 10
若通过Operator管理,可在Keycloak CR中添加探针自定义配置,或临时编辑StatefulSet测试。
2. 排除自定义镜像问题
当前使用的bsctzz/dockerhub:groupaccess为自定义镜像,可能存在配置篡改或缺失。先替换为官方Keycloak镜像测试:
修改CR的spec.image为:
image: quay.io/keycloak/keycloak:22.0.5
重新部署后观察是否能正常就绪,排除镜像本身的问题。
3. 检查TLS证书有效性
自签名证书可能导致kubelet探针验证失败,或证书格式/路径错误:
- 临时启用HTTP测试:修改CR的
spec.http.httpEnabled: true,调整探针为HTTP协议,路径改为/q/health/live和/q/health/ready,端口8080,观察探针是否通过。 - 验证证书:进入Pod内部检查证书文件是否存在且格式正确:
kubectl exec -it example-keycloak-0 -n my-keycloak-operator -- bash ls /mnt/certificates/ openssl x509 -in /mnt/certificates/tls.crt -text -noout
- 探针添加证书跳过验证:在探针配置中加入
insecureSkipTLSVerify: true,避免kubelet因证书不信任返回404。
4. 统一Hostname配置
CR中设置的hostname: keycloak.local与Pod环境变量KC_HOSTNAME: localhost存在冲突,可能导致内部服务路由异常:
- 修改CR的hostname配置为
localhost,或将Pod的KC_HOSTNAME环境变量改为keycloak.local,同时在本地hosts文件添加192.168.49.2 keycloak.local(Minikube节点IP)。
5. 调整探针启动延迟
Keycloak启动需要加载大量资源,当前20秒的初始延迟可能不足,将initialDelaySeconds调整为60秒以上,给实例足够的启动时间。
内容的提问来源于stack exchange,提问作者Dyn amo
相关产品推荐
相关产品推荐

