OAuth2 Proxy作为Sidecar时登录按钮跳转路径错误问题求助
问题描述
将OAuth2 Proxy配置为外部应用的Sidecar容器,应用部署在https://my-domain.com/subpath。点击OAuth2 Proxy默认的提供商按钮(见下图绿色按钮)时,系统会重定向到https://my-domain.com/oauth2,而非预期的https://my-domain.com/subpath/oauth2。
设置--skip-provider-button=false时可部分实现功能,但这种方式不够优雅——例如当CSRF令牌过期后,仍希望通过点击按钮导航至正确URL。
请问如何使所有OAuth2 Proxy模板按钮(如登录按钮)正常工作?

当前使用的Kubernetes配置如下:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress annotations: kubernetes.io/ingress.class: nginx nginx.ingress.kubernetes.io/use-regex: "true" nginx.ingress.kubernetes.io/rewrite-target: /$2 nginx.ingress.kubernetes.io/configuration-snippet: | proxy_set_header 'X-Forwarded-Uri' $request_uri; proxy_set_header 'X-Auth-Request-Redirect' $request_uri; spec: rules: - host: my-domain.com http: paths: - path: /subpath(/|$)(.*) pathType: Prefix backend: service: name: service port: name: http --- apiVersion: v1 kind: Service metadata: name: service spec: ports: - name: http port: 8080 protocol: TCP targetPort: http selector: select: deployment type: ClusterIP --- # sidecar in deployment: [...] containers: - name: app image: nodered/node-red ports: - containerPort: 1880 protocol: TCP name: http-intern resources: {} - name: oauth2-proxy image: quay.io/oauth2-proxy/oauth2-proxy:v7.4.0 args: - --client-id=xxx - --client-secret=xxx - --cookie-secret=xxx - --http-address=0.0.0.0:8809 - --cookie-domain=my-domain.com #- --proxy-prefix=/oauth2 - --cookie-httponly=true - --cookie-name=xxx.token - --cookie-samesite=lax - --cookie-secure=true - --oidc-issuer-url=https://xxx/auth/realms/xxx - --provider=oidc - --redirect-url=https://my-domain.com/subpath/oauth2/callback - --request-logging - --reverse-proxy=true - --upstream=http://127.0.0.1:1880 - --skip-provider-button=true - --session-cookie-minimal=true - --silence-ping-logging=true - --whitelist-domain=my-domain.com - --email-domain=* ports: - containerPort: 8809 protocol: TCP name: http resources: {} [...]
已知OAuth2 Proxy模板会使用--proxy-prefix参数,但配置后未达到预期效果,需排查配置错误点。
解决方法
要让OAuth2 Proxy的模板按钮正确指向/subpath/oauth2路径,需从Ingress和OAuth2 Proxy两个层面调整配置:
1. 调整Ingress配置,保留完整请求上下文
当前Ingress的rewrite-target会截断/subpath前缀,导致OAuth2 Proxy无法识别外部访问的路径上下文。需修改Ingress规则,取消路径重写,同时添加请求头告知OAuth2 Proxy前缀路径:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress annotations: kubernetes.io/ingress.class: nginx nginx.ingress.kubernetes.io/configuration-snippet: | proxy_set_header 'X-Forwarded-Uri' $request_uri; proxy_set_header 'X-Forwarded-Prefix' /subpath; # 传递外部访问前缀给OAuth2 Proxy spec: rules: - host: my-domain.com http: paths: - path: /subpath pathType: Prefix backend: service: name: service port: name: http
2. 正确配置OAuth2 Proxy的路径参数
取消注释--proxy-prefix并设置为完整路径,同时调整上游转发路径,确保应用收到正确请求:
# OAuth2 Proxy sidecar args调整部分 args: - --client-id=xxx - --client-secret=xxx - --cookie-secret=xxx - --http-address=0.0.0.0:8809 - --cookie-domain=my-domain.com - --proxy-prefix=/subpath/oauth2 # 设置完整的代理前缀,用于生成模板按钮链接 - --cookie-httponly=true - --cookie-name=xxx.token - --cookie-samesite=lax - --cookie-secure=true - --oidc-issuer-url=https://xxx/auth/realms/xxx - --provider=oidc - --redirect-url=https://my-domain.com/subpath/oauth2/callback # 保持回调路径一致 - --request-logging - --reverse-proxy=true - --upstream=http://127.0.0.1:1880/subpath # 转发请求给应用时添加前缀 - --skip-provider-button=false # 重新启用提供商按钮 - --session-cookie-minimal=true - --silence-ping-logging=true - --whitelist-domain=my-domain.com - --email-domain=*
3. 关键配置说明
--proxy-prefix:OAuth2 Proxy会基于该值生成模板中的按钮跳转链接,必须设置为/subpath/oauth2才能让按钮指向正确端点。X-Forwarded-Prefix:Ingress传递该请求头后,OAuth2 Proxy能识别外部访问的前缀路径,生成正确的回调和跳转URL。- 上游路径调整:因为Ingress不再重写路径,OAuth2 Proxy转发请求时需添加
/subpath前缀,确保后端应用能正确处理请求路径。
内容的提问来源于stack exchange,提问作者Yannic Hamann
相关产品推荐
相关产品推荐

