You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Project Flotta与yggdrasil设备注册401未授权错误求助

Project Flotta设备worker启动失败:Flotta Edge API返回401未授权

问题现象

按官方文档测试Project Flotta贡献代码时,设备worker无法启动,核心原因是Flotta Edge API返回401未授权响应。

服务端日志

2023-06-22T19:15:22.072Z        INFO    httpapi/main.go:165     cannot verify request   {"authType": 0, "method": "GET", "url": "/api/flotta-management/v1/data/b069bb0ae2c649c5a99b195db96bebd2/in", "err": "cannot use register certificate on this resource"}

客户端执行命令

在RedHatInsights/yggdrasil仓库执行以下命令:

sudo ./yggd   --log-level trace   --protocol http  --path-prefix api/flotta-management/v1  --client-id $(cat /etc/machine-id)\           --cert-file /tmp/cert.pem  --key-file /tmp/key.pem  --ca-root /tmp/ca.pem  --socket-addr @yggd  --server 127.0.0.1:8043

客户端报错日志

[yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/http/client.go:44: request: &{GET https://127.0.0.1:8043/api/flotta-management/v1/data/b069bb0ae2c649c5a99b195db96bebd2/in HTTP/1.1 1 1 map[User-Agent:[yggdrasil/0.2.98]] <nil> <nil> 0 [] false 127.0.0.1:8043 map[] map[] <nil> map[]   <nil> <nil> <nil> 0xc0000280c0}
[yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/http/client.go:56: received HTTP 401 Unauthorized:
[yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/http/client.go:56: received HTTP 401 Unauthorized:
[yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/transport/http.go:70: cannot get HTTP request: unexpected response: 401 - Unauthorized
[yggd] 2023/06/22 19:15:47 /home/daringmouse/go/src/github.com/project-flotta/yggdrasil/internal/transport/http.go:54: cannot get HTTP request: unexpected response: 401 - Unauthorized

现有yggdrasil配置文件(/etc/yggdrasil/config.toml)

log-level = "info"
cert-file = "/etc/pki/consumer/cert.pem"
key-file = "/etc/pki/consumer/key.pem"
ca-root = "/etc/pki/consumer/ca.pem"
path-prefix = "api/flotta-management/v1"
protocol = "http"
server = "127.0.0.1:8043"

排查方向

  • 证书权限与用途不匹配:服务端日志明确提示cannot use register certificate on this resource,说明当前使用的证书仅用于设备注册,无法访问/data/.../in这类数据交互接口。需确认证书的X.509扩展字段(如Extended Key Usage)是否包含数据交互所需权限,或是否应为设备worker使用专用操作证书而非注册证书。
  • 证书路径不一致:客户端启动命令指定证书路径为/tmp/目录,但配置文件中路径为/etc/pki/consumer/。需确保启动命令或配置文件使用的是同一套有效证书,且yggd进程具备证书文件的读取权限。
  • 设备注册状态:预期返回208响应说明设备可能已注册,但当前请求使用的证书未关联到已注册的设备ID。需验证--client-id对应的machine-id是否已在Flotta服务端完成注册,且证书与该设备ID绑定。
  • API端点权限配置:检查Flotta服务端的API权限规则,确认/api/flotta-management/v1/data/{deviceId}/in端点是否允许当前证书的认证类型(authType=0)访问,是否存在配置错误导致权限拦截。

内容的提问来源于stack exchange,提问作者VtI

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 08:23:11