You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Minikube+Keycloak Operator部署Keycloak 22.0.1时Admin UI无限加载

Keycloak Operator部署实例未就绪问题排查解决思路

问题场景

通过Minikube+OLM+Keycloak Operator部署Keycloak实例,CR配置如下:

apiVersion: k8s.keycloak.org/v2alpha1
kind: Keycloak
metadata:
  name: example-keycloak
  namespace: my-keycloak-operator
  labels:
    app: sso
spec:
  instances: 1
  image: bsctzz/dockerhub:groupaccess
  hostname:
    hostname: keycloak.local
  ingress:
    enabled: false
  http:
    httpEnabled: false
    tlsSecret: root-secret

启动后Pod状态为Running但未就绪,Admin页面无限加载,容器日志停留在添加admin用户阶段:

2023-08-07 09:07:21,064 INFO  [io.quarkus] (main) Installed features: [agroal, cdi, hibernate-orm, jdbc-h2, jdbc-mariadb, jdbc-mssql, jdbc-mysql, jdbc-oracle, jdbc-postgresql, keycloak, logging-gelf, micrometer, narayana-jta, reactive-routes, resteasy, resteasy-jackson, smallrye-context-propagation, smallrye-health, vertx]
2023-08-07 09:07:21,200 INFO  [org.keycloak.services] (main) KC-SERVICES0009: Added user 'admin' to realm 'master'

Pod详情显示就绪/存活探针均返回404:

Name:         example-keycloak-0
Namespace:    my-keycloak-operator
Priority:     0
Node:         minikube/192.168.49.2
Start Time:   Mon, 07 Aug 2023 11:31:02 +0200
Labels:       app=keycloak
              app.kubernetes.io/instance=example-keycloak
              app.kubernetes.io/managed-by=keycloak-operator
              controller-revision-hash=example-keycloak-dc5544cf9
              statefulset.kubernetes.io/pod-name=example-keycloak-0
Annotations:  <none>
Status:       Running
IP:           10.244.1.232
IPs:
  IP:           10.244.1.232
Controlled By:  StatefulSet/example-keycloak
Containers:
  keycloak:
    Container ID:  docker://6bf8d1dcc7df0db016904905d8a073430924f881caae50b0ce58b78c1b66f2a2
    Image:         bsctzz/dockerhub:groupaccess
    Image ID:      docker-pullable://bsctzz/dockerhub@sha256:e3c3d4c99a26ed1b8fb54432194f939e0d86a87561bd949b14df22f745fe281c
    Ports:         8443/TCP, 8080/TCP
    Host Ports:    0/TCP, 0/TCP
    Args:
      start
      --optimized
    State:          Running
      Started:      Mon, 07 Aug 2023 11:31:05 +0200
    Ready:          False
    Restart Count:  0
    Liveness:       http-get https://:8443/health/live delay=20s timeout=1s period=2s #success=1 #failure=150
    Readiness:      http-get https://:8443/health/ready delay=20s timeout=1s period=2s #success=1 #failure=250
    Environment:
      KC_HOSTNAME:                    localhost
      KC_HTTP_ENABLED:                false
      KC_HTTP_PORT:                   8080
      KC_HTTPS_PORT:                  8443
      KC_HTTPS_CERTIFICATE_FILE:      /mnt/certificates/tls.crt
      KC_HTTPS_CERTIFICATE_KEY_FILE:  /mnt/certificates/tls.key
      KC_HEALTH_ENABLED:              true
      KC_CACHE:                       ispn
      KC_CACHE_STACK:                 kubernetes
      KC_PROXY:                       passthrough
      KEYCLOAK_ADMIN:                 <set to the key 'username' in secret 'example-keycloak-initial-admin'>  Optional: false
      KEYCLOAK_ADMIN_PASSWORD:        <set to the key 'password' in secret 'example-keycloak-initial-admin'>  Optional: false
      jgroups.dns.query:              example-keycloak-discovery.my-keycloak-operator
    Mounts:
      /mnt/certificates from keycloak-tls-certificates (rw)
      /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-fwxnx (ro)
Conditions:
  Type              Status
  Initialized       True 
  Ready             False 
  ContainersReady   False 
  PodScheduled      True 
Volumes:
  keycloak-tls-certificates:
    Type:        Secret (a volume populated by a Secret)
    SecretName:  root-secret
    Optional:    false
  kube-api-access-fwxnx:
    Type:                    Projected (a volume that contains injected data from multiple sources)
    TokenExpirationSeconds:  3607
    ConfigMapName:           kube-root-ca.crt
    ConfigMapOptional:       <nil>
    DownwardAPI:             true
QoS Class:                   BestEffort
Node-Selectors:              <none>
Tolerations:                 node.kubernetes.io/not-ready:NoExecute op=Exists for 300s
                             node.kubernetes.io/unreachable:NoExecute op=Exists for 300s
Events:
  Type     Reason     Age                From               Message
  ----     ------     ----               ----               -------
  Normal   Scheduled  43s                default-scheduler  Successfully assigned my-keycloak-operator/example-keycloak-0 to minikube
  Normal   Pulling    43s                kubelet            Pulling image "bsctzz/dockerhub:groupaccess"
  Normal   Pulled     42s                kubelet            Successfully pulled image "bsctzz/dockerhub:groupaccess" in 1.301906831s (1.301917466s including waiting)
  Normal   Created    42s                kubelet            Created container keycloak
  Normal   Started    41s                kubelet            Started container keycloak
  Warning  Unhealthy  2s (x10 over 19s)  kubelet            Readiness probe failed: HTTP probe failed with statuscode: 404
  Warning  Unhealthy  2s (x10 over 19s)  kubelet            Liveness probe failed: HTTP probe failed with statuscode: 404

解决思路

1. 修正健康检查端点路径

Quarkus版本的Keycloak健康端点默认路径为/q/health/live和/q/health/ready,而非当前探针配置的/health/live。需修改StatefulSet的探针配置:

livenessProbe:
  httpGet:
    path: /q/health/live
    port: 8443
    scheme: HTTPS
  initialDelaySeconds: 60
  timeoutSeconds: 5
  periodSeconds: 10
readinessProbe:
  httpGet:
    path: /q/health/ready
    port: 8443
    scheme: HTTPS
  initialDelaySeconds: 60
  timeoutSeconds: 5
  periodSeconds: 10

若通过Operator管理,可在Keycloak CR中添加探针自定义配置,或临时编辑StatefulSet测试。

2. 排除自定义镜像问题

当前使用的bsctzz/dockerhub:groupaccess为自定义镜像,可能存在配置篡改或缺失。先替换为官方Keycloak镜像测试:
修改CR的spec.image为:

image: quay.io/keycloak/keycloak:22.0.5

重新部署后观察是否能正常就绪,排除镜像本身的问题。

3. 检查TLS证书有效性

自签名证书可能导致kubelet探针验证失败,或证书格式/路径错误:

  • 临时启用HTTP测试:修改CR的spec.http.httpEnabled: true,调整探针为HTTP协议,路径改为/q/health/live和/q/health/ready,端口8080,观察探针是否通过。
  • 验证证书:进入Pod内部检查证书文件是否存在且格式正确:
kubectl exec -it example-keycloak-0 -n my-keycloak-operator -- bash
ls /mnt/certificates/
openssl x509 -in /mnt/certificates/tls.crt -text -noout
  • 探针添加证书跳过验证:在探针配置中加入insecureSkipTLSVerify: true,避免kubelet因证书不信任返回404。

4. 统一Hostname配置

CR中设置的hostname: keycloak.local与Pod环境变量KC_HOSTNAME: localhost存在冲突,可能导致内部服务路由异常:

  • 修改CR的hostname配置为localhost,或将Pod的KC_HOSTNAME环境变量改为keycloak.local,同时在本地hosts文件添加192.168.49.2 keycloak.local(Minikube节点IP)。

5. 调整探针启动延迟

Keycloak启动需要加载大量资源,当前20秒的初始延迟可能不足,将initialDelaySeconds调整为60秒以上,给实例足够的启动时间。

内容的提问来源于stack exchange,提问作者Dyn amo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 07:53:10