You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Grafana配置AWS Cognito认证遇redirect_mismatch错误求助

问题描述

我在AWS环境中有两台部署在ALB后的Grafana EC2实例,需要配置AWS Cognito实现访问认证。已按如下内容配置grafana.ini文件:

[server]
protocol = http
#domain = grafana.mydomain.com
root_url = https://grafana.mydomain.com
serve_from_sub_path = true

[auth.generic_oauth]
enabled = true
allow_sign_up = true
auto_login = false
client_id = xxxxxxxxxxxxxxxxxxxxxxxxxxx
client_secret = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
user_pool_id = eu-west-1_xxxxxxxxx
auth_url = https://myapp.auth.eu-west-1.amazoncognito.com/auth2/authorize
token_url = https://myapp.auth.eu-west-1.amazoncognito.com/oauth2/token
region = eu-west-1
allow_sign_up = false
allowed_groups = "arn:aws:cognito:eu-west-1:000000000000:userpool/eu-west-1_xxxxxxxx:group/grafana-read", "arn:aws:cognito:eu-west-1:000000000000:userpool/eu-west-1_xxxxxxxx:group/grafana-admin"
role_attribute_path = contains(info.roles[*], 'grafana-admin') && 'Admin' || contains(info.roles[*], 'grafana-read') && 'Editor' || 'Viewer'

但通过浏览器访问https://grafana.mydomain.com/generic_oauth/login时,收到错误:

https://myapp.auth.eu-west-1.amazoncognito.com/error?error=redirect_mismatch&client_id=xxxxxxxxxxxxxxxxxxxxxxxxxxx
解决方法

redirect_mismatch错误的核心原因是Cognito客户端配置的回调URL与Grafana实际跳转的URL不匹配,按以下步骤排查修正:

  • 修正回调URL格式
    Grafana Generic OAuth的标准回调URL为{root_url}/login/generic_oauth,结合你的配置,正确地址应为https://grafana.mydomain.com/login/generic_oauth,而非你访问的https://grafana.mydomain.com/generic_oauth/login。

  • 在Cognito控制台配置正确的回调URL
    登录AWS控制台进入目标用户池eu-west-1_xxxxxxxxx,打开应用客户端设置,在允许的重定向URI列表中添加https://grafana.mydomain.com/login/generic_oauth,保存配置。

  • 修正Grafana的Auth URL拼写错误
    你配置的auth_url中auth2是错误的,正确的Cognito授权端点应为https://myapp.auth.eu-west-1.amazoncognito.com/oauth2/authorize(将auth2改为oauth2)。

  • 验证root_url与ALB配置一致性
    确保ALB的域名grafana.mydomain.com配置正确,Grafana的root_url完全匹配ALB的访问地址,避免协议、路径不一致。

  • 重启Grafana服务
    修改grafana.ini后,重启两台EC2上的Grafana服务,确保配置生效。

内容的提问来源于stack exchange,提问作者Marco Ferrara

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 04:07:24