You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Traefik搭配Authelia做认证器无登录界面问题排查

问题:Authelia+Traefik保护Kibana时未弹出登录界面直接返回401

环境配置

  • 一台Docker主机,运行Kibana/Elasticsearch、Traefik和Authelia容器
  • 采用无标签配置(后续计划将反向代理配置用于非Docker环境)
  • 拆分两个Docker Compose文件(本次仅提供Traefik/Authelia的配置文件,排除Kibana访问性问题)

预期效果

  • 用户访问https://dockerhost.company.local:5601/
  • 弹出Authelia登录窗口
  • 完成单因素认证后进入Kibana

实际问题

启用Authelia中间件后,访问上述URL时浏览器直接返回401未授权:

  • Traefik日志:
Remote error "http://authelia:9091/api/verify". StatusCode: 401" middlewareName=auth@file middlewareType=ForwardedAuthType
  • Authelia日志:
"Access to "https://dockerhost.company.local:5601/" (method GET) is not authorized to user <anonymous>, responding with status code 401" method=GET path=/api/verify remote_ip=10.2.120.251

匿名用户未授权符合逻辑,但未触发登录界面跳转。

已排查操作

  • 禁用Authelia中间件后,可通过Traefik正常访问Kibana
  • 直接访问Authelia容器的9091端口可正常完成认证

问题分析

核心原因是Authelia的登录页面未通过Traefik暴露给外部客户端,且Traefik中间件未正确传递Authelia返回的重定向Header。当用户未认证时,Authelia返回302重定向到自身登录页,但该地址是容器内部域名(authelia:9091),客户端无法解析,因此浏览器只能收到401错误,无法跳转至登录界面。

解决方案

1. 在Traefik中配置Authelia路由

修改Traefik动态配置dynamic.toml,添加Authelia的路由规则,让客户端能通过外部域名访问Authelia的登录页面:

[http.routers]
  [http.routers.kibana]
    entryPoints = ["kibana-entrypoint"]
    rule = "Host(`dockerhost.company.local`)"
    service = "kibana-service"
    middlewares = ["auth@file"]
    [http.routers.kibana.tls]

  # 新增Authelia路由
  [http.routers.authelia]
    entryPoints = ["kibana-entrypoint"]
    rule = "Host(`dockerhost.company.local`) && PathPrefix(`/authelia`)"
    service = "authelia-service"
    [http.routers.authelia.tls]

[http.services]
  [http.services.kibana-service]
    [[http.services.kibana-service.loadBalancer.servers]]
      url = "http://kibana:5601/"

  # 新增Authelia服务配置
  [http.services.authelia-service]
    [[http.services.authelia-service.loadBalancer.servers]]
      url = "http://authelia:9091/"

[http.middlewares]
  [http.middlewares.auth.forwardAuth]
    address = "http://authelia:9091/authelia/api/verify" # 调整为带path_prefix的验证地址
    trustForwardHeader = true
    passHostHeader = true # 传递主机头给Authelia
    authResponseHeaders = ["Remote-User", "Remote-Groups", "Remote-Name", "Remote-Email", "Location"] # 传递重定向Location头

2. 调整Authelia配置

修改Authelia的configuration.yml,添加路径前缀和信任Traefik的转发Header:

server:
  port: 9091
  path_prefix: /authelia # 与Traefik路由的PathPrefix匹配
  forwarded_headers:
    trusted_proxies:
      - 10.2.120.0/24 # 替换为Traefik所在的容器子网(根据实际环境调整)

log.level: debug
jwt_secret: insecure_secret
authentication_backend:
  ldap:
    implementation: activedirectory
    url: ldap://ldapserver.company.local
    timeout: 5s
    start_tls: false
    base_dn: DC=company,DC=local
#    additional_users_dn: OU=Users,OU=COMPANY
    users_filter: (&(|({username_attribute}={input})({mail_attribute}={input}))(objectCategory=person)(objectClass=user)(!userAccountControl:1.2.840.113556.1.4.803:=2)(!pwdLastSet=0))
    username_attribute: sAMAccountName
    mail_attribute: mail
    display_name_attribute: displayName
    groups_filter: (&(member:1.2.840.113556.1.4.1941:={dn})(objectClass=group)(objectCategory=group))
    group_name_attribute: cn
    permit_referrals: false
    permit_unauthenticated_bind: false
    user: CN=dockeruser_sa,OU=ServiceAccounts,OU=Users,OU=COMPANY,DC=company,DC=local
    password: <password>
totp:
  disable: true
session:
  name: authelia_session
  domain: company.local
  same_site: lax
  secret: unsecure_session_secret
  expiration: 1h
  inactivity: 5m
  remember_me_duration:  1M
storage:
  encryption_key: a_very_important_secret
  local:
    path: /config/db.sqlite3
access_control:
  default_policy: one_factor
  rules:
    - domain: dockerhost.company.local
      policy: one_factor
    # 允许未认证访问Authelia的登录路径
    - domain: dockerhost.company.local
      path: /authelia/*
      policy: bypass
notifier:
  filesystem:
    filename: /var/lib/authelia/emails.txt

3. 重启容器

重启Traefik和Authelia容器,让配置生效:

docker-compose down && docker-compose up -d

验证

访问https://dockerhost.company.local:5601/,此时应该会自动跳转到https://dockerhost.company.local:5601/authelia/login,完成单因素认证后即可正常访问Kibana。

内容的提问来源于stack exchange,提问作者Isegrimm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 04:15:02