Camunda Platform 8自托管对接外部Keycloak 20.0.3认证失败求助
Camunda Platform 8 对接外部Keycloak(>20.0.3)认证失败求助
我正尝试配置Camunda Platform 8自托管版,希望使用已有的Keycloak实例,但Identity服务无法通过Keycloak认证,Keycloak事件日志显示invalid_user_credentials错误。恳请成功对接过Keycloak>20.0.3外部实例的用户分享操作步骤。
我的Camunda-Platform Helm配置
kind-values.yaml global: identity: keycloak: url: protocol: "http" host: "auth.local.growd.io" port: "80" contextPath: "/" auth: adminUser: "identity-admin" existingSecret: "keycloak-secret" existingSecretKey: "password" auth: enabled: false publicIssuerUrl: "https://auth.local.growd.io/realms/camunda-platform" operate: redirectUrl: "https://operate.camunda.local.growd.io" tasklist: redirectUrl: "https://taasklist.camunda.local.growd.io" optimize: redirectUrl: "https://optimize.camunda.local.growd.io" identity: env: - name: KEYCLOAK_SETUP_CLIENT_ID value: identity_admin_cli - name: IDENTITY_LOG_LEVEL value: DEBUG keycloak: legacy: false enabled: false httpRelativePath: / optimize: enabled: false zeebe: clusterSize: 1 partitionCount: 1 replicationFactor: 1 pvcSize: 10Gi zeebe-gateway: replicas: 1 elasticsearch: imageTag: 7.17.3 replicas: 1 minimumMasterNodes: 1 clusterHealthCheckParams: "wait_for_status=yellow&timeout=1s" resources: requests: cpu: "100m" memory: "512M" limits: cpu: "1000m" memory: "512M" volumeClaimTemplate: accessModes: ["ReadWriteOnce"] storageClass: "microk8s-hostpath" resources: requests: storage: 15Gi
已排查内容
- 已确认密钥中的密码正确,进入identity容器查看
KEYCLOAK_SETUP_PASSWORD符合预期。
Keycloak认证错误日志
2023-02-28 00:15:21,812 WARN [org.keycloak.events] (executor-thread-81) type=LOGIN_ERROR, realmId=5d304d58-2aa5-4aa1-aecd-d643db489a76, clientId=identity_admin_cli, userId=9e29d31a-9047-40fc-9e72-61fa1c7ce4eb, ipAddress=127.0.0.6, error=invalid_user_credentials, auth_method=openid-connect, grant_type=password, client_auth_method=client-secret, username=identity-admin, authSessionParentId=f86ce961-02e1-44cf-b918-60bc337e7294, authSessionTabId=95kqFzX1Zb0
版本信息
- Camunda Platform: 8.1.6
- Keycloak: 20.0.3
内容的提问来源于stack exchange,提问作者Robert
相关产品推荐
相关产品推荐

