You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OAuth2 Proxy作为Sidecar时登录按钮跳转路径错误问题求助

问题描述

将OAuth2 Proxy配置为外部应用的Sidecar容器,应用部署在https://my-domain.com/subpath。点击OAuth2 Proxy默认的提供商按钮(见下图绿色按钮)时,系统会重定向到https://my-domain.com/oauth2,而非预期的https://my-domain.com/subpath/oauth2。

设置--skip-provider-button=false时可部分实现功能,但这种方式不够优雅——例如当CSRF令牌过期后,仍希望通过点击按钮导航至正确URL。

请问如何使所有OAuth2 Proxy模板按钮(如登录按钮)正常工作?

OAuth2 Proxy登录按钮重定向错误

当前使用的Kubernetes配置如下:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ingress
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/use-regex: "true"
    nginx.ingress.kubernetes.io/rewrite-target: /$2
    nginx.ingress.kubernetes.io/configuration-snippet: |
       proxy_set_header 'X-Forwarded-Uri' $request_uri;
       proxy_set_header 'X-Auth-Request-Redirect' $request_uri;
spec:
  rules:
    - host: my-domain.com
      http:
        paths:
          - path: /subpath(/|$)(.*)
            pathType: Prefix
            backend:
              service:
                name: service
                port:
                  name: http
---
apiVersion: v1
kind: Service
metadata:    
  name: service
spec: 
  ports:
    - name: http
      port: 8080
      protocol: TCP
      targetPort: http  
  selector:
    select: deployment
  type: ClusterIP
---
# sidecar in deployment:
[...]
containers:
  - name: app
    image: nodered/node-red
    ports:
    - containerPort: 1880
      protocol: TCP
      name: http-intern
    resources: {}
  - name: oauth2-proxy
    image: quay.io/oauth2-proxy/oauth2-proxy:v7.4.0
    args:
    - --client-id=xxx
    - --client-secret=xxx
    - --cookie-secret=xxx
    - --http-address=0.0.0.0:8809
    - --cookie-domain=my-domain.com
    #- --proxy-prefix=/oauth2
    - --cookie-httponly=true
    - --cookie-name=xxx.token
    - --cookie-samesite=lax
    - --cookie-secure=true
    - --oidc-issuer-url=https://xxx/auth/realms/xxx
    - --provider=oidc
    - --redirect-url=https://my-domain.com/subpath/oauth2/callback
    - --request-logging
    - --reverse-proxy=true
    - --upstream=http://127.0.0.1:1880
    - --skip-provider-button=true
    - --session-cookie-minimal=true
    - --silence-ping-logging=true
    - --whitelist-domain=my-domain.com
    - --email-domain=*
    ports:
    - containerPort: 8809
      protocol: TCP
      name: http
    resources: {}
[...]

已知OAuth2 Proxy模板会使用--proxy-prefix参数,但配置后未达到预期效果,需排查配置错误点。

解决方法

要让OAuth2 Proxy的模板按钮正确指向/subpath/oauth2路径,需从Ingress和OAuth2 Proxy两个层面调整配置:

1. 调整Ingress配置,保留完整请求上下文

当前Ingress的rewrite-target会截断/subpath前缀,导致OAuth2 Proxy无法识别外部访问的路径上下文。需修改Ingress规则,取消路径重写,同时添加请求头告知OAuth2 Proxy前缀路径:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ingress
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/configuration-snippet: |
       proxy_set_header 'X-Forwarded-Uri' $request_uri;
       proxy_set_header 'X-Forwarded-Prefix' /subpath; # 传递外部访问前缀给OAuth2 Proxy
spec:
  rules:
    - host: my-domain.com
      http:
        paths:
          - path: /subpath
            pathType: Prefix
            backend:
              service:
                name: service
                port:
                  name: http

2. 正确配置OAuth2 Proxy的路径参数

取消注释--proxy-prefix并设置为完整路径,同时调整上游转发路径,确保应用收到正确请求:

# OAuth2 Proxy sidecar args调整部分
args:
- --client-id=xxx
- --client-secret=xxx
- --cookie-secret=xxx
- --http-address=0.0.0.0:8809
- --cookie-domain=my-domain.com
- --proxy-prefix=/subpath/oauth2 # 设置完整的代理前缀,用于生成模板按钮链接
- --cookie-httponly=true
- --cookie-name=xxx.token
- --cookie-samesite=lax
- --cookie-secure=true
- --oidc-issuer-url=https://xxx/auth/realms/xxx
- --provider=oidc
- --redirect-url=https://my-domain.com/subpath/oauth2/callback # 保持回调路径一致
- --request-logging
- --reverse-proxy=true
- --upstream=http://127.0.0.1:1880/subpath # 转发请求给应用时添加前缀
- --skip-provider-button=false # 重新启用提供商按钮
- --session-cookie-minimal=true
- --silence-ping-logging=true
- --whitelist-domain=my-domain.com
- --email-domain=*

3. 关键配置说明

  • --proxy-prefix:OAuth2 Proxy会基于该值生成模板中的按钮跳转链接,必须设置为/subpath/oauth2才能让按钮指向正确端点。
  • X-Forwarded-Prefix:Ingress传递该请求头后,OAuth2 Proxy能识别外部访问的前缀路径,生成正确的回调和跳转URL。
  • 上游路径调整:因为Ingress不再重写路径,OAuth2 Proxy转发请求时需添加/subpath前缀,确保后端应用能正确处理请求路径。

内容的提问来源于stack exchange,提问作者Yannic Hamann

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 11:02:57