Grafana配置AWS Cognito认证遇redirect_mismatch错误求助
我在AWS环境中有两台部署在ALB后的Grafana EC2实例,需要配置AWS Cognito实现访问认证。已按如下内容配置grafana.ini文件:
[server] protocol = http #domain = grafana.mydomain.com root_url = https://grafana.mydomain.com serve_from_sub_path = true [auth.generic_oauth] enabled = true allow_sign_up = true auto_login = false client_id = xxxxxxxxxxxxxxxxxxxxxxxxxxx client_secret = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx user_pool_id = eu-west-1_xxxxxxxxx auth_url = https://myapp.auth.eu-west-1.amazoncognito.com/auth2/authorize token_url = https://myapp.auth.eu-west-1.amazoncognito.com/oauth2/token region = eu-west-1 allow_sign_up = false allowed_groups = "arn:aws:cognito:eu-west-1:000000000000:userpool/eu-west-1_xxxxxxxx:group/grafana-read", "arn:aws:cognito:eu-west-1:000000000000:userpool/eu-west-1_xxxxxxxx:group/grafana-admin" role_attribute_path = contains(info.roles[*], 'grafana-admin') && 'Admin' || contains(info.roles[*], 'grafana-read') && 'Editor' || 'Viewer'
但通过浏览器访问https://grafana.mydomain.com/generic_oauth/login时,收到错误:
https://myapp.auth.eu-west-1.amazoncognito.com/error?error=redirect_mismatch&client_id=xxxxxxxxxxxxxxxxxxxxxxxxxxx
redirect_mismatch错误的核心原因是Cognito客户端配置的回调URL与Grafana实际跳转的URL不匹配,按以下步骤排查修正:
修正回调URL格式
Grafana Generic OAuth的标准回调URL为{root_url}/login/generic_oauth,结合你的配置,正确地址应为https://grafana.mydomain.com/login/generic_oauth,而非你访问的https://grafana.mydomain.com/generic_oauth/login。在Cognito控制台配置正确的回调URL
登录AWS控制台进入目标用户池eu-west-1_xxxxxxxxx,打开应用客户端设置,在允许的重定向URI列表中添加https://grafana.mydomain.com/login/generic_oauth,保存配置。修正Grafana的Auth URL拼写错误
你配置的auth_url中auth2是错误的,正确的Cognito授权端点应为https://myapp.auth.eu-west-1.amazoncognito.com/oauth2/authorize(将auth2改为oauth2)。验证root_url与ALB配置一致性
确保ALB的域名grafana.mydomain.com配置正确,Grafana的root_url完全匹配ALB的访问地址,避免协议、路径不一致。重启Grafana服务
修改grafana.ini后,重启两台EC2上的Grafana服务,确保配置生效。
内容的提问来源于stack exchange,提问作者Marco Ferrara

