You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NGINX Ingress auth-signin与error_page冲突问题求助

解决NGINX Ingress添加auth-signin后error_page失效问题(无需自定义默认后端)

问题背景

通过Ingress注解配置了自定义错误页跳转,原本功能正常:

nginx.ingress.kubernetes.io/server-snippet: |
        error_page 404 "https://example.com/404";
        error_page 403 "https://example.com/403";

但添加OAuth2Proxy的auth-signin注解后,上述error_page规则完全失效:

nginx.ingress.kubernetes.io/auth-signin: https://$host/oauth2/start?rd=$escaped_request_uri

需求是实现OAuth2Proxy重定向完成后,NGINX仍能识别HTTP状态码并触发自定义错误页跳转,且无需部署自定义默认后端。

已尝试的无效方案:

  • 添加proxy_intercept_errors on;
  • 修改NGINX Pod内的nginx.conf
  • 配置custom-http-errors(不符合需求)

可行解决方案

修改server-snippet注解内容,补充针对auth跳转内部location的错误处理规则,具体配置如下:

nginx.ingress.kubernetes.io/server-snippet: |
        proxy_intercept_errors on;
        # 明确指定跳转状态码,避免默认逻辑覆盖
        error_page 404 =302 https://example.com/404;
        error_page 403 =302 https://example.com/403;
        
        # 覆盖auth-signin生成的内部location,添加错误处理规则
        location @oauth2_signin {
                proxy_intercept_errors on;
                error_page 404 =302 https://example.com/404;
                error_page 403 =302 https://example.com/403;
        }

原理说明

添加auth-signin后,NGINX Ingress会自动生成@oauth2_signin内部location来处理OAuth2跳转逻辑,原server级别的error_page规则不会自动继承到这个内部location中。因此需要显式在@oauth2_signin中重复配置错误处理规则,确保auth流程完成后的请求依然能触发自定义错误页跳转。

另外,使用=302明确指定跳转的状态码,避免NGINX使用默认的错误响应逻辑覆盖自定义跳转规则。

内容的提问来源于stack exchange,提问作者Teo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 11:22:43