You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JBOSS EAP向Red Hat DataGrid写入数据时遇ISPN006017认证错误求助

ISPN006017: Operation 'EXEC' requires authentication错误解决方案

问题描述

我正在使用JBOSS EAP(7.4.2)和Red Hat DataGrid(8.3.1)部署Java应用,两者容器处于同一网络中。但当EAP尝试向DataGrid写入数据时,出现ISPN006017: Operation 'EXEC' requires authentication错误,恳请各位提供解决方案。以下是相关配置信息:

获取RemoteCache代码

private static RemoteCache<String, Object> getCache() {
    if (remoteCacheManager == null) {
        Configuration configuration = new ConfigurationBuilder().withProperties(HotrodClientProperty.getProperites()).build();
        remoteCacheManager = new RemoteCacheManager(configuration);
    }

    return remoteCacheManager.getCache(CacheProperty.jdgCacheName());
}

属性配置

infinispan.client.hotrod.server_list=datagrid-usersession:11222
infinispan.client.hotrod.cache.default.configuration=\ <distributed-cache name="default" mode="ASYNC"><encoding media-type="application/x-jboss-marshalling"/><memory storage="OFF_HEAP"/></distributed-cache> 
infinispan.client.hotrod.marshaller=org.infinispan.jboss.marshalling.commons.GenericJBossMarshaller
infinispan.client.hotrod.socket_timeout=30000 infinispan.client.hotrod.connect_timeout=3000
infinispan.client.hotrod.max_retries=2 infinispan.client.hotrod.connection_pool.max_wait=3000
infinispan.client.hotrod.connection_pool.min_idle=1
infinispan.client.hotrod.connection_pool.min_evictable_idle_time=60000

Docker命令

RHDG="datagrid-usersession"
docker run -e HOTROD_AUTHENTICATION_ENABLED=false \
           -e HOTROD_AUTHORIZATION_ENABLED=false \
           -e HOTROD_ENCRYPTION_ENABLED=false \
-d --name=${RHDG} --network=${NW} ${DGIMG}

EAP="${SERVICE}"
docker run -d --name=${EAP} --network=${NW} \
        -v ${PJTDIR}/App:/app:ro \
        -v ${BUILDDIR}/app:/builddir:ro \
        ${APIMG}

需求:通过HotRod客户端将EAP中的会话数据写入DataGrid。


解决方案

1. 验证DataGrid的认证/授权禁用配置

尽管启动时设置了HOTROD_AUTHENTICATION_ENABLED=false和HOTROD_AUTHORIZATION_ENABLED=false,仍需确认配置实际生效:

  • 查看DataGrid容器启动日志,搜索hotrod关键词,确认认证与授权已被禁用;
  • 进入容器检查核心配置文件(如standalone.xml),确保hotrod-connector节点配置如下:
    <hotrod-connector socket-binding="hotrod" cache-container="default">
      <authentication enabled="false"/>
      <authorization enabled="false"/>
    </hotrod-connector>
    
  • 若环境变量未生效,可在启动命令中添加JVM参数强制覆盖:
    docker run -e HOTROD_AUTHENTICATION_ENABLED=false \
               -e HOTROD_AUTHORIZATION_ENABLED=false \
               -e HOTROD_ENCRYPTION_ENABLED=false \
               -d --name=${RHDG} --network=${NW} ${DGIMG} \
               /opt/infinispan/bin/server.sh -c standalone.xml -Dhotrod.authentication.enabled=false -Dhotrod.authorization.enabled=false
    

2. 排查客户端隐式认证参数

  • 检查HotrodClientProperty.getProperites()返回的属性集合,确认没有意外包含infinispan.client.hotrod.auth_username、infinispan.client.hotrod.auth_password等认证相关配置;
  • 检查EAP的standalone.xml或系统属性,确认没有全局注入认证信息导致客户端触发认证流程。

3. 定位EXEC操作的触发逻辑

ISPN006017错误由EXEC操作触发,该操作通常对应远程脚本执行或特定缓存API调用:

  • 检查EAP会话存储的实现代码,确认是否调用了Cache.execute()等会触发EXEC操作的方法;
  • 若会话存储依赖默认EXEC操作,需确保DataGrid完全禁用权限校验,或在启用认证的场景下为客户端分配对应操作权限。

4. 开启调试日志追踪细节

在EAP的standalone.xml中添加HotRod客户端调试日志,明确连接过程中的认证交互:

<logger category="org.infinispan.client.hotrod">
  <level name="DEBUG"/>
</logger>

通过日志可确认客户端是否收到服务器的认证要求,以及触发错误的具体操作类型。


内容的提问来源于stack exchange,提问作者Ketan Lotake

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 17:15:43