You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地部署OpenShift集群UI认证失败排查求助

OpenShift UI认证页面无法访问(Application is not available)排查方案

问题场景

本地部署的OpenShift集群,命令行可正常访问,但访问控制台URL https://console-openshift-console.apps.myapp-name.com/ 时,重定向到OAuth认证页面后提示Application is not available,已确认openshift-authentication命名空间下的Pod和Service状态正常。

排查方向与解决步骤

1. 检查OAuth路由配置

  • 查看oauth-openshift路由的状态与配置:
    oc get route oauth-openshift -n openshift-authentication -o wide
    
  • 确认路由的HOST/PORT是否为oauth-openshift.apps.myapp-name.com,TLS字段显示的证书是否有效、域名匹配。
  • 若路由异常,删除后由Authentication Operator自动重建:
    oc delete route oauth-openshift -n openshift-authentication
    
    等待1-2分钟后重新检查路由状态。

2. 验证DNS解析

  • 在访问UI的客户端机器上,测试OAuth域名的解析:
    nslookup oauth-openshift.apps.myapp-name.com
    # 或使用dig
    dig oauth-openshift.apps.myapp-name.com
    
  • 若解析失败,确认集群Ingress域名apps.myapp-name.com的DNS记录已正确指向Ingress Controller的外部IP/负载均衡器。

3. 检查Ingress Controller状态

  • 查看openshift-ingress命名空间下的Router Pod状态:
    oc get pods -n openshift-ingress
    
  • 确认Router Service的外部IP分配:
    oc get svc router-default -n openshift-ingress
    
  • 查看Router日志,排查转发错误:
    oc logs deployment/router-default -n openshift-ingress
    

4. 修复OAuth回调URL不匹配问题

注意到重定向URL中的回调地址域名与控制台域名不一致(控制台为myapp-name.com,回调地址为sasi-molsheim.biocontinuum-innovation.com):

  • 查看控制台OAuth客户端配置:
    oc get oauthclient console -o yaml
    
  • 更新回调URL为正确的控制台域名:
    oc patch oauthclient console --type=json -p '[{"op": "replace", "path": "/redirectURIs", "value": ["https://console-openshift-console.apps.myapp-name.com/auth/callback"]}]'
    

5. 排查集群内部网络连通性

  • 进入Ingress Pod,测试与oauth-openshift Service的内部连通性:
    # 替换<router-pod-name>为实际的Router Pod名称
    oc exec -n openshift-ingress <router-pod-name> -- bash -c "curl -v https://oauth-openshift.openshift-authentication.svc:443/oauth/authorize"
    
  • 检查是否有NetworkPolicy阻止流量:
    oc get networkpolicy -n openshift-authentication
    
    确保存在允许openshift-ingress命名空间访问oauth-openshift服务的规则,若不存在可添加:
    oc apply -n openshift-authentication -f - <<EOF
    apiVersion: networking.k8s.io/v1
    kind: NetworkPolicy
    metadata:
      name: allow-ingress-access
    spec:
      podSelector:
        matchLabels:
          app: oauth-openshift
      ingress:
      - from:
        - namespaceSelector:
            matchLabels:
              name: openshift-ingress
        ports:
        - protocol: TCP
          port: 443
    EOF
    

6. 客户端证书信任配置

若集群使用自签名证书,客户端浏览器可能拒绝加载认证页面:

  • 导出集群CA证书:
    oc get configmap -n openshift-config-managed trusted-ca -o jsonpath='{.data.ca-bundle\.crt}' > cluster-ca.crt
    
  • 将导出的cluster-ca.crt导入到客户端浏览器的信任根证书存储中。

内容的提问来源于stack exchange,提问作者mazembo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 17:45:55