You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes Nginx Ingress多主机配置Azure OAuth2遇CORS错误求助

解决AKS中Nginx Ingress多主机OAuth2认证下的CORS预检重定向问题

问题场景

在AKS环境中为dev.example.com和api.dev.example.com配置Nginx Ingress+Azure OAuth2认证,Azure AD应用配置完成后登录流程正常,但主应用访问https://api.dev.example.com/identity/.well-known/openid-configuration时触发CORS错误:预检请求的响应包含重定向,不符合CORS策略。

现有配置

应用Ingress配置

kind: Ingress
apiVersion: networking.k8s.io/v1
metadata:
  name: dev-ingress
  annotations:
    cert-manager.io/issuer: letsencrypt-cert
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/auth-signin: https://$host/oauth2/start?rd=$escaped_request_uri
    nginx.ingress.kubernetes.io/auth-url: https://$host/oauth2/auth
    nginx.ingress.kubernetes.io/ssl-redirect: 'false'
    nginx.ingress.kubernetes.io/use-regex: 'true'
spec:
  tls:
    - hosts:
        - dev.example.com
        - api.dev.example.com
      secretName: letsencrypt-cert
  rules:
    - host: dev.example.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: dev-service
                port:
                  number: 80
    - host: api.dev.example.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: api-service
                port:
                  number: 80

OAuth2 Proxy配置

apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    k8s-app: oauth2-proxy
  name: oauth2-proxy
  namespace: dev
spec:
  replicas: 1
  selector:
    matchLabels:
      k8s-app: oauth2-proxy
  template:
    metadata:
      labels:
        k8s-app: oauth2-proxy
    spec:
      containers:
      - args:
        - --provider=oidc
        #- --provider=azure
        - --azure-tenant=xxxxxxxxxxxxxx
        - --skip-jwt-bearer-tokens=true
        - --skip-auth-preflight=true        
        - --email-domain=*
        - --http-address=0.0.0.0:4180
        - --cookie-domain=.example.com
        - --whitelist-domain=.example.com
        - --oidc-issuer-url=https://login.microsoftonline.com/xxxxxxxx/v2.0
        env:
        - name: OAUTH2_PROXY_CLIENT_ID
          valueFrom:
            secretKeyRef:
              name: client-id
              key: oauth2_proxy_client_id
        - name: OAUTH2_PROXY_CLIENT_SECRET
          valueFrom:
            secretKeyRef:
              name: client-secret
              key: oauth2_proxy_client_secret
        - name: OAUTH2_PROXY_COOKIE_SECRET
          valueFrom:
            secretKeyRef:
              name: cookie-secret
              key: oauth2_proxy_cookie_secret
        image: quay.io/oauth2-proxy/oauth2-proxy:latest
        imagePullPolicy: Always
        name: oauth2-proxy
        ports:
        - containerPort: 4180
          protocol: TCP
---
apiVersion: v1
kind: Service
metadata:
  labels:
    k8s-app: oauth2-proxy
  name: oauth2-proxy
  namespace: dev
spec:
  ports:
  - name: http
    port: 4180
    protocol: TCP
    targetPort: 4180
  selector:
    k8s-app: oauth2-proxy
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: oauth2-proxy
  namespace: dev
spec:
  ingressClassName: nginx
  rules:
  - host: dev.example.com
    http:
      paths:
      - path: /oauth2
        pathType: Prefix
        backend:
          service:
            name: oauth2-proxy
            port:
              number: 4180
  - host: api.dev.example.com
    http:
      paths:
      - path: /oauth2
        pathType: Prefix
        backend:
          service:
            name: oauth2-proxy
            port:
              number: 4180

问题原因与解决方案

核心原因

当前Ingress为整个api.dev.example.com配置了全局OAuth2认证,包括/identity/.well-known/openid-configuration端点。浏览器发送的OPTIONS预检请求被Ingress转发到OAuth2 Proxy认证,而认证流程会触发重定向,违反CORS规则(预检请求不允许重定向)。

具体修复步骤

  1. 修改应用Ingress,豁免特定端点的认证并配置CORS
    在dev-ingress的annotations中添加认证豁免规则和CORS相关配置,更新后的metadata.annotations如下:

    metadata:
      name: dev-ingress
      annotations:
        cert-manager.io/issuer: letsencrypt-cert
        kubernetes.io/ingress.class: nginx
        nginx.ingress.kubernetes.io/auth-signin: https://$host/oauth2/start?rd=$escaped_request_uri
        nginx.ingress.kubernetes.io/auth-url: https://$host/oauth2/auth
        nginx.ingress.kubernetes.io/ssl-redirect: 'false'
        nginx.ingress.kubernetes.io/use-regex: 'true'
        # 豁免OpenID配置端点的认证
        nginx.ingress.kubernetes.io/auth-except: /identity/.well-known/openid-configuration
        # 启用CORS并允许主域跨域请求
        nginx.ingress.kubernetes.io/enable-cors: "true"
        nginx.ingress.kubernetes.io/cors-allow-origin: "https://dev.example.com"
        nginx.ingress.kubernetes.io/cors-allow-methods: "GET, OPTIONS"
        nginx.ingress.kubernetes.io/cors-allow-credentials: "true"
    
  2. 确认OAuth2 Proxy的预检请求跳过配置
    现有配置中已包含--skip-auth-preflight=true参数,该参数会让OAuth2 Proxy直接放行OPTIONS预检请求,需确保此配置未被修改。

  3. 重新应用Ingress配置
    执行命令更新Ingress资源:

    kubectl apply -f dev-ingress.yaml -n dev
    

额外说明

  • 若api.dev.example.com还有其他需跨域的端点,可在auth-except中用逗号分隔添加,例如/identity/.well-known/openid-configuration,/api/public/*
  • CORS规则需根据实际业务调整,比如允许的Origin、HTTP方法等
  • 确保后端api-service能正确处理OPTIONS请求,返回合法的CORS响应头

内容的提问来源于stack exchange,提问作者Trav Erse

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 02:45:18