You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak配置AdminURL后出现无限重定向循环问题(Nginx代理场景)

Keycloak Admin Console Infinite Redirect When Using Separate adminUrl and frontendUrl

我之前成功配置过Keycloak这种内外网分离访问的环境,但在新实例上复刻配置时却遇到了棘手的问题。目前使用的是standalone-ha模式,切换为standalone模式后问题依然存在。

仅配置frontendUrl为https://example.com时,前端页面及管理控制台均可正常访问;但在hostname的SPI配置段添加adminUrl为https://intra.example.com后,管理控制台彻底无法正常使用。

当前Keycloak Hostname SPI配置

<spi name="hostname">
  <default-provider>default</default-provider>
  <provider name="default" enabled="true">
    <properties>
      <property name="frontendUrl" value="https://example.com/auth/"/>
      <property name="adminUrl" value="https://intra.example.com/auth"/>
      <property name="forceBackendUrlToFrontendUrl" value="false"/>
    </properties>
  </provider>
</spi>

具体问题现象

无论是通过欢迎页面链接还是直接访问管理控制台,都会先跳转到https://example.com/auth的登录页面。使用有效凭据登录后,页面会重定向到https://intra.example.com/auth/admin/master/console/,随后立即跳转到带state、session_state和code参数的长链接:

https://intra.example.com/auth/admin/master/console/#state=4626eb82-6993-4fff-8c11-399a05cb8c66&session_state=3198da2f-f6eb-45be-aa87-ae7d52e22068&code=fd73f80a-fe43-4996-b245-efa42efb7b44.3198da2f-f6eb-45be-aa87-ae7d52e22068.e794bdbc-6497-4fc3-8502-e0afedb67492

之后又跳转回https://intra.example.com/auth/admin/master/console/,如此反复形成无限重定向循环。

Nginx代理配置

Keycloak实例部署在Nginx代理之后,已配置必要的请求头,具体配置如下:

server {
 listen 192.168.0.115:443 ssl http2;
 server_name intra.example.com;
 ssl_certificate <valid cert>;
 ssl_certificate_key <key>;
 location /auth {
 proxy_pass https://192.168.0.115:8843/auth;
 proxy_ssl_verify off;
 proxy_set_header Host $host;
 proxy_set_header X-Real-IP $remote_addr;
 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
 proxy_set_header X-Forwarded-Host $host;
 proxy_set_header X-Forwarded-Server $host;
 proxy_set_header X-Forwarded-Port $server_port;
 proxy_set_header X-Forwarded-Proto https;
 }
}
server {
 listen <public IPv4>:443 ssl http2;
 listen [<public IPv6]:443 ssl http2;
 server_name example.com;
 ssl_certificate <valid cert>;
 ssl_certificate_key <key>;
 location /auth {
 proxy_pass https://192.168.0.115:8843/auth;
 proxy_ssl_verify off;
 proxy_set_header Host $host;
 proxy_set_header X-Real-IP $remote_addr;
 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
 proxy_set_header X-Forwarded-Host $host;
 proxy_set_header X-Forwarded-Server $host;
 proxy_set_header X-Forwarded-Port $server_port;
 proxy_set_header X-Forwarded-Proto https;
 }
}

已尝试的解决方案

我调研了相关讨论,尝试了多种配置组合,但均未解决问题:

  • 将Nginx代理路径从/auth改为根路径/
  • 代理到HTTP而非HTTPS
  • 在Keycloak的HTTP/HTTPS监听器中添加proxy-address-forwarding配置:
    <https-listener name="https" socket-binding="https" security-realm="ApplicationRealm" enable-http2="true" proxy-address-forwarding="true"/>
    
  • 添加代理监听器并配合socket绑定:
    <http-listener name="default" socket-binding="http" redirect-socket="proxy-https" enable-http2="true" proxy-address-forwarding="true"/>
    <socket-binding name="proxy-https" port="443"/>
    
  • 临时在数据库中将有效重定向URI设置为*

这些方案覆盖了现有讨论中的主要解决思路,但现有讨论多针对Docker环境,而我使用的是原生实例。此前这套配置曾成功运行,甚至直接复制了之前可用的Nginx配置,因此初步排除Nginx配置问题,但也不排除该可能性。另外,重定向过程中即使使用--debug模式启动Keycloak,也未生成任何相关日志,排查难度较大。

恳请各位提供其他可行的排查方向或解决思路。

内容的提问来源于stack exchange,提问作者gecko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 06:23:14