You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes中Keycloak容器无法连接Postgres容器问题求助

Kubernetes中Keycloak无法连接同Pod内Postgres的解决方案

问题诊断

从错误日志java.net.UnknownHostException: postgres-client1可以明确,Keycloak无法解析Postgres容器的主机名。虽然同一Pod内的容器理论上可以通过容器名通信,但更可靠的方式是利用同一Pod共享网络命名空间的特性直接访问。此外你的配置还存在几个潜在问题:

  • Deployment副本数设为2会导致每个Pod运行独立的Postgres实例,数据无法共享,不符合生产场景
  • Service的selector与Pod标签不匹配,导致Keycloak服务无法被外部访问
  • 使用emptyDir存储Postgres数据,Pod重启后数据会丢失

解决方案步骤

  • 修正Keycloak数据库连接地址:将Keycloak的DB_ADDR环境变量改为localhost,同一Pod内的容器共享网络栈,Postgres的5432端口直接绑定在localhost上。
  • 调整Deployment副本数(推荐):测试环境先将replicas改为1;生产环境需将Postgres单独部署为StatefulSet并通过Service暴露,避免多Keycloak实例对应独立数据库。
  • 修复Service的Selector匹配:将Service的selector.app改为与Pod标签一致的keycloak-postgres-client1。
  • 替换为持久化存储(推荐):将emptyDir替换为PersistentVolumeClaim,确保Postgres数据持久化。

修改后的完整配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: keycloak-postgres-deployment-client1
spec:
  replicas: 1 # 测试环境先设为1,生产环境需分离Postgres
  selector:
    matchLabels:
      app: keycloak-postgres-client1
  template:
    metadata:
      labels:
        app: keycloak-postgres-client1
    spec:
      containers:
      - name: keycloak-client1
        image: jboss/keycloak
        env:
        - name: DB_VENDOR
          value: POSTGRES
        - name: DB_ADDR
          value: localhost # 修改为localhost
        - name: DB_PORT
          value: "5432"
        - name: DB_DATABASE
          value: keycloak-client1
        - name: DB_USER
          valueFrom:
            secretKeyRef:
              name: postgres-credentials-client1
              key: client_db_username
        - name: DB_PASSWORD
          valueFrom:
            secretKeyRef:
              name: postgres-credentials-client1
              key: client_db_password
        - name: KEYCLOAK_USER
          valueFrom:
            secretKeyRef:
              name: keycloak-credentials-client1
              key: client_kc_username
        - name: KEYCLOAK_PASSWORD
          valueFrom:
            secretKeyRef:
              name: keycloak-credentials-client1
              key: client_kc_password
        - name: KC_PROXY
          value: "edge"
        ports:
        - containerPort: 8080
          name: http
        - containerPort: 8443
          name: https
      - name: postgres-client1
        image: postgres:latest
        env:
        - name: POSTGRES_DB
          value: keycloak-client1
        - name: POSTGRES_USER
          valueFrom:
            secretKeyRef:
              name: postgres-credentials-client1
              key: client_db_username
        - name: POSTGRES_PASSWORD
          valueFrom:
            secretKeyRef:
              name: postgres-credentials-client1
              key: client_db_password
        ports:
        - containerPort: 5432
          name: postgres
        volumeMounts:
        - name: postgres-data-client1
          mountPath: /var/lib/postgresql/data
      volumes:
      - name: postgres-data-client1
        # 替换为PersistentVolumeClaim,需提前创建PVC
        # persistentVolumeClaim:
        #   claimName: postgres-pvc-client1
        emptyDir:
          sizeLimit: 500Mi
---
apiVersion: v1
kind: Service
metadata:
  name: keycloak-service-client1
  labels:
    app: keycloak-postgres-client1
spec:
  selector:
    app: keycloak-postgres-client1 # 修正selector与Pod标签一致
  type: LoadBalancer
  ports:
  - name: http
    port: 8080
    targetPort: 8080
  - name: https
    port: 443
    targetPort: 8443

验证步骤

  1. 应用修改后的配置:kubectl apply -f your-config.yaml
  2. 查看Pod状态:kubectl get pods
  3. 进入Keycloak容器测试连接:kubectl exec -it <pod-name> -c keycloak-client1 -- psql -h localhost -U <db-user> -d keycloak-client1

内容的提问来源于stack exchange,提问作者gabriele serafini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 02:50:14