Project Flotta与yggdrasil设备注册401未授权错误求助
Project Flotta设备worker启动失败:Flotta Edge API返回401未授权
问题现象
按官方文档测试Project Flotta贡献代码时,设备worker无法启动,核心原因是Flotta Edge API返回401未授权响应。
服务端日志
2023-06-22T19:15:22.072Z INFO httpapi/main.go:165 cannot verify request {"authType": 0, "method": "GET", "url": "/api/flotta-management/v1/data/b069bb0ae2c649c5a99b195db96bebd2/in", "err": "cannot use register certificate on this resource"}
客户端执行命令
在RedHatInsights/yggdrasil仓库执行以下命令:
sudo ./yggd --log-level trace --protocol http --path-prefix api/flotta-management/v1 --client-id $(cat /etc/machine-id)\ --cert-file /tmp/cert.pem --key-file /tmp/key.pem --ca-root /tmp/ca.pem --socket-addr @yggd --server 127.0.0.1:8043
客户端报错日志
[yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/http/client.go:44: request: &{GET https://127.0.0.1:8043/api/flotta-management/v1/data/b069bb0ae2c649c5a99b195db96bebd2/in HTTP/1.1 1 1 map[User-Agent:[yggdrasil/0.2.98]] <nil> <nil> 0 [] false 127.0.0.1:8043 map[] map[] <nil> map[] <nil> <nil> <nil> 0xc0000280c0} [yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/http/client.go:56: received HTTP 401 Unauthorized: [yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/http/client.go:56: received HTTP 401 Unauthorized: [yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/transport/http.go:70: cannot get HTTP request: unexpected response: 401 - Unauthorized [yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/transport/http.go:54: cannot get HTTP request: unexpected response: 401 - Unauthorized
现有yggdrasil配置文件(/etc/yggdrasil/config.toml)
log-level = "info" cert-file = "/etc/pki/consumer/cert.pem" key-file = "/etc/pki/consumer/key.pem" ca-root = "/etc/pki/consumer/ca.pem" path-prefix = "api/flotta-management/v1" protocol = "http" server = "127.0.0.1:8043"
排查方向
- 证书权限与用途不匹配:服务端日志明确提示
cannot use register certificate on this resource,说明当前使用的证书仅用于设备注册,无法访问/data/.../in这类数据交互接口。需确认证书的X.509扩展字段(如Extended Key Usage)是否包含数据交互所需权限,或是否应为设备worker使用专用操作证书而非注册证书。 - 证书路径不一致:客户端启动命令指定证书路径为
/tmp/目录,但配置文件中路径为/etc/pki/consumer/。需确保启动命令或配置文件使用的是同一套有效证书,且yggd进程具备证书文件的读取权限。 - 设备注册状态:预期返回208响应说明设备可能已注册,但当前请求使用的证书未关联到已注册的设备ID。需验证
--client-id对应的machine-id是否已在Flotta服务端完成注册,且证书与该设备ID绑定。 - API端点权限配置:检查Flotta服务端的API权限规则,确认
/api/flotta-management/v1/data/{deviceId}/in端点是否允许当前证书的认证类型(authType=0)访问,是否存在配置错误导致权限拦截。
内容的提问来源于stack exchange,提问作者VtI
相关产品推荐
相关产品推荐

