Docker部署的Apache Guacamole无法通过MySQL认证求助
Guacamole容器连接MySQL认证失败(Communications link failure)
已部署guacd、guacamole和MySQL三个独立容器并完成关联,通过Ubuntu测试容器安装mysql-client可成功连接到MySQL容器:
PS > docker exec -it ubuntu bash root@f31a3436f297:/# mysql -h test-mysql -u guacamole_user -p Enter password: Welcome to the MySQL monitor. Commands end with ; or \g. Your MySQL connection id is 22 Server version: 8.0.32 MySQL Community Server - GPL Copyright (c) 2000, 2023, Oracle and/or its affiliates. Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners. Type 'help;' or '\h' for help. Type '\c' to clear the current input statement. mysql> use guacamole_db; Reading table information for completion of table and column names You can turn off this feature to get a quicker startup with -A Database changed mysql> show tables; +---------------------------------------+ | Tables_in_guacamole_db | +---------------------------------------+ | guacamole_connection | | guacamole_connection_attribute | | guacamole_connection_group | | guacamole_connection_group_attribute | | guacamole_connection_group_permission | | guacamole_connection_history | | guacamole_connection_parameter | | guacamole_connection_permission | | guacamole_entity | | guacamole_sharing_profile | | guacamole_sharing_profile_attribute | | guacamole_sharing_profile_parameter | | guacamole_sharing_profile_permission | | guacamole_system_permission | | guacamole_user | | guacamole_user_attribute | | guacamole_user_group | | guacamole_user_group_attribute | | guacamole_user_group_member | | guacamole_user_group_permission | | guacamole_user_history | | guacamole_user_password_history | | guacamole_user_permission | +---------------------------------------+ 23 rows in set (0.00 sec) mysql>
但访问localhost:8080/guacamole时出现认证错误:
guacamole容器日志报错如下:
2023-03-16 16:42:29 16:42:29.866 [http-nio-8080-exec-6] WARN o.a.g.e.AuthenticationProviderFacade - The "mysql" authentication provider has encountered an internal error which will halt the authentication process. If this is unexpected or you are the developer of this authentication provider, you may wish to enable debug-level logging. If this is expected and you wish to ignore such failures in the future, please set "skip-if-unavailable: mysql" within your guacamole.properties. 2023-03-16 16:42:29 16:42:29.869 [http-nio-8080-exec-6] ERROR o.a.g.rest.RESTExceptionMapper - Unexpected internal error: 2023-03-16 16:42:29 ### Error querying database. Cause: com.mysql.jdbc.exceptions.jdbc4.CommunicationsException: Communications link failure 2023-03-16 16:42:29 2023-03-16 16:42:29 The last packet successfully received from the server was 63 milliseconds ago. The last packet sent successfully to the server was 62 milliseconds ago. 2023-03-16 16:42:29 ### The error may exist in org/apache/guacamole/auth/jdbc/user/UserMapper.xml 2023-03-16 16:42:29 ### The error may involve org.apache.guacamole.auth.jdbc.user.UserMapper.selectOne 2023-03-16 16:42:29 ### The error occurred while executing a query 2023-03-16 16:42:29 ### Cause: com.mysql.jdbc.exceptions.jdbc4.CommunicationsException: Communications link failure 2023-03-16 16:42:29 2023-03-16 16:42:29 The last packet successfully received from the server was 63 milliseconds ago. The last packet sent successfully to the server was 62 milliseconds ago.
已尝试以下方法未解决:
- 改用mysql:5.7镜像
- 为guacamole_user设置
WITH mysql_native_password
进一步排查与解决方案
1. 直接验证Guacamole容器到MySQL的连通性
进入Guacamole容器内部测试MySQL连接,排除网络层面问题:
# 替换为你的Guacamole容器ID/名称 docker exec -it <guacamole-container-id> bash # 若容器无mysql-client,先安装(Debian/Ubuntu基础镜像) apt update && apt install -y mysql-client # 测试连接,替换为你的MySQL容器名称/IP mysql -h <mysql-container-name> -u guacamole_user -p
如果连接失败:
- 确认所有容器处于同一Docker网络(自定义网络或默认桥接网络)
- 检查MySQL容器的网络别名是否正确,Guacamole需用容器名而非
localhost(容器内localhost指向自身)
2. 修正MySQL用户权限配置
确保guacamole_user允许从Guacamole容器的地址访问:
# 进入MySQL容器执行 GRANT ALL PRIVILEGES ON guacamole_db.* TO 'guacamole_user'@'%' IDENTIFIED BY 'your-password'; FLUSH PRIVILEGES;
注:%允许任意地址访问,生产环境可限制为Guacamole所在网段,优先用此配置测试。
3. 核对Guacamole数据库配置参数
确认guacamole.properties或Docker环境变量的MySQL配置无误:
# guacamole.properties示例 mysql-hostname: <mysql-container-name> mysql-port: 3306 mysql-database: guacamole_db mysql-username: guacamole_user mysql-password: your-password
Docker启动时需通过环境变量传递:
docker run ... \ -e MYSQL_HOST=<mysql-container-name> \ -e MYSQL_DATABASE=guacamole_db \ -e MYSQL_USER=guacamole_user \ -e MYSQL_PASSWORD=your-password
4. 关闭MySQL SSL强制(针对8.0+版本)
MySQL 8.0默认开启SSL,Guacamole JDBC驱动未配置SSL会导致连接中断:
- 临时测试:在MySQL配置文件添加
skip_ssl后重启容器 - 永久适配:在Guacamole配置中添加SSL禁用参数,Docker环境可加:
-e MYSQL_DRIVER_PROPERTIES=useSSL=false
5. 开启调试日志获取细节
按日志提示开启Guacamole debug级日志,定位更具体的错误:
Docker启动时添加环境变量:
-e LOG_LEVEL=DEBUG
重启容器后重新查看日志,获取更详细的连接失败原因。
内容的提问来源于stack exchange,提问作者dsl101
相关产品推荐
相关产品推荐

