使用Traefik搭配Authelia做认证器无登录界面问题排查
问题:Authelia+Traefik保护Kibana时未弹出登录界面直接返回401
环境配置
- 一台Docker主机,运行Kibana/Elasticsearch、Traefik和Authelia容器
- 采用无标签配置(后续计划将反向代理配置用于非Docker环境)
- 拆分两个Docker Compose文件(本次仅提供Traefik/Authelia的配置文件,排除Kibana访问性问题)
预期效果
- 用户访问
https://dockerhost.company.local:5601/ - 弹出Authelia登录窗口
- 完成单因素认证后进入Kibana
实际问题
启用Authelia中间件后,访问上述URL时浏览器直接返回401未授权:
- Traefik日志:
Remote error "http://authelia:9091/api/verify". StatusCode: 401" middlewareName=auth@file middlewareType=ForwardedAuthType
- Authelia日志:
"Access to "https://dockerhost.company.local:5601/" (method GET) is not authorized to user <anonymous>, responding with status code 401" method=GET path=/api/verify remote_ip=10.2.120.251
匿名用户未授权符合逻辑,但未触发登录界面跳转。
已排查操作
- 禁用Authelia中间件后,可通过Traefik正常访问Kibana
- 直接访问Authelia容器的9091端口可正常完成认证
问题分析
核心原因是Authelia的登录页面未通过Traefik暴露给外部客户端,且Traefik中间件未正确传递Authelia返回的重定向Header。当用户未认证时,Authelia返回302重定向到自身登录页,但该地址是容器内部域名(authelia:9091),客户端无法解析,因此浏览器只能收到401错误,无法跳转至登录界面。
解决方案
1. 在Traefik中配置Authelia路由
修改Traefik动态配置dynamic.toml,添加Authelia的路由规则,让客户端能通过外部域名访问Authelia的登录页面:
[http.routers] [http.routers.kibana] entryPoints = ["kibana-entrypoint"] rule = "Host(`dockerhost.company.local`)" service = "kibana-service" middlewares = ["auth@file"] [http.routers.kibana.tls] # 新增Authelia路由 [http.routers.authelia] entryPoints = ["kibana-entrypoint"] rule = "Host(`dockerhost.company.local`) && PathPrefix(`/authelia`)" service = "authelia-service" [http.routers.authelia.tls] [http.services] [http.services.kibana-service] [[http.services.kibana-service.loadBalancer.servers]] url = "http://kibana:5601/" # 新增Authelia服务配置 [http.services.authelia-service] [[http.services.authelia-service.loadBalancer.servers]] url = "http://authelia:9091/" [http.middlewares] [http.middlewares.auth.forwardAuth] address = "http://authelia:9091/authelia/api/verify" # 调整为带path_prefix的验证地址 trustForwardHeader = true passHostHeader = true # 传递主机头给Authelia authResponseHeaders = ["Remote-User", "Remote-Groups", "Remote-Name", "Remote-Email", "Location"] # 传递重定向Location头
2. 调整Authelia配置
修改Authelia的configuration.yml,添加路径前缀和信任Traefik的转发Header:
server: port: 9091 path_prefix: /authelia # 与Traefik路由的PathPrefix匹配 forwarded_headers: trusted_proxies: - 10.2.120.0/24 # 替换为Traefik所在的容器子网(根据实际环境调整) log.level: debug jwt_secret: insecure_secret authentication_backend: ldap: implementation: activedirectory url: ldap://ldapserver.company.local timeout: 5s start_tls: false base_dn: DC=company,DC=local # additional_users_dn: OU=Users,OU=COMPANY users_filter: (&(|({username_attribute}={input})({mail_attribute}={input}))(objectCategory=person)(objectClass=user)(!userAccountControl:1.2.840.113556.1.4.803:=2)(!pwdLastSet=0)) username_attribute: sAMAccountName mail_attribute: mail display_name_attribute: displayName groups_filter: (&(member:1.2.840.113556.1.4.1941:={dn})(objectClass=group)(objectCategory=group)) group_name_attribute: cn permit_referrals: false permit_unauthenticated_bind: false user: CN=dockeruser_sa,OU=ServiceAccounts,OU=Users,OU=COMPANY,DC=company,DC=local password: <password> totp: disable: true session: name: authelia_session domain: company.local same_site: lax secret: unsecure_session_secret expiration: 1h inactivity: 5m remember_me_duration: 1M storage: encryption_key: a_very_important_secret local: path: /config/db.sqlite3 access_control: default_policy: one_factor rules: - domain: dockerhost.company.local policy: one_factor # 允许未认证访问Authelia的登录路径 - domain: dockerhost.company.local path: /authelia/* policy: bypass notifier: filesystem: filename: /var/lib/authelia/emails.txt
3. 重启容器
重启Traefik和Authelia容器,让配置生效:
docker-compose down && docker-compose up -d
验证
访问https://dockerhost.company.local:5601/,此时应该会自动跳转到https://dockerhost.company.local:5601/authelia/login,完成单因素认证后即可正常访问Kibana。
内容的提问来源于stack exchange,提问作者Isegrimm
相关产品推荐
相关产品推荐

