You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Rancher API遇401未授权错误:需认证,求解决方案

Rancher API调用返回Unauthorized 401: must authenticate问题排查

调用Rancher API时,无论尝试哪种参数组合,始终返回Unauthorized 401: must authenticate错误。试过多种Project ID组合、官方已过时的Python库,结果一致,怀疑Rancher端存在额外配置但未找到相关信息,求解决思路。

复现步骤

  • 创建Rancher API密钥(access key)和密钥密码(secret key)
  • 编写脚本尝试部署测试工作负载,脚本代码如下:
import requests

api_url = "https://myrancherurl.com/v3/project/c-m-qh7tkqn4/jobs"
access_key = "token-zmdpqs"
secret_key = "fr9v6z9xxfqdgmjv2k9z44zvx6mlrandomtoke"
token=access_key+":"+secret_key

# Set the API token
headers = { "Authorization": "Bearer "+token }

# Set the payload for the API request
payload = {
    "name": "my-job",
    "jobConfig": {
        "image": "nginx:latest",
        "command": ["nginx", "-g", "daemon off;"],
        "restartPolicy": {
            "name": "Never"
        }
    }
}

# Send the API request to create the job
response = requests.post(api_url, json=payload, headers=headers)

# Print the API response
print(response.json())

解决思路

1. 修正认证方式

Rancher v3 API不支持直接用Bearer access_key:secret_key的认证格式,有两种正确方式:

  • Basic认证:将access_key:secret_key做Base64编码,然后在请求头中使用:
    import base64
    auth_str = f"{access_key}:{secret_key}"
    auth_bytes = auth_str.encode('utf-8')
    auth_base64 = base64.b64encode(auth_bytes).decode('utf-8')
    headers = { "Authorization": f"Basic {auth_base64}" }
    
  • 获取Bearer Token:先调用登录接口获取有效token,再用Bearer认证:
    login_url = "https://myrancherurl.com/v3-public/localProviders/local?action=login"
    login_payload = {"username": access_key, "password": secret_key}
    login_response = requests.post(login_url, json=login_payload)
    token = login_response.json()['token']
    headers = { "Authorization": f"Bearer {token}" }
    

2. 确认正确的Project ID与API路径

你的脚本中API路径存在两处错误:

  • 路径中的project需改为projects,Rancher v3 API的正确路径格式为/v3/projects/<完整Project ID>/jobs
  • 完整Project ID格式是集群ID:项目ID,比如c-m-qh7tkqn4:p-abc123。可在Rancher控制台获取:进入目标集群→选择对应项目→查看页面URL,URL中会包含projects/c-m-xxx:p-xxx,其中p-xxx就是项目ID,拼接后替换路径中的集群ID部分。

3. 检查API密钥权限

创建API密钥时,需确保密钥拥有对应项目的操作权限:

  • 若为全局密钥,需授予Manage Projects或更高权限;
  • 若为项目级密钥,需确保绑定到目标项目并拥有Create Jobs等相关权限。

4. 验证API版本兼容性

确认Rancher版本与API路径匹配:如果使用Rancher v2.x,v3 API是稳定版本;若为更旧版本,需对应调整API路径与认证方式。

内容的提问来源于stack exchange,提问作者WillX0r

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 22:50:23