Jfrog Xray服务运行正常但JFrog UI无显示及配置异常咨询
JFrog Xray 启动与UI访问问题
问题背景
在独立服务器上安装JFrog Xray后,启动服务时出现失败,后续服务虽运行但UI访问异常,具体报错如下:
1. systemd启动失败日志
● xray.service - Xray service Loaded: loaded (/usr/lib/systemd/system/xray.service; enabled; vendor preset: disabled) Active: failed (Result: exit-code) since Sat 2022-12-03 12:36:50 IST; 1min 17s ago Process: 1217 ExecStart=/opt/jfrog/xray/app/bin/xray.sh start (code=exited, status=1/FAILURE) Main PID: 1217 (code=exited, status=1/FAILURE)
2. systemDiagnostics.log报错
提示system.yaml不存在但文件实际存在,同时存在ulimit过低问题:
[WARN ] Error while initializing File resolver : Config file does not exists : /opt/jfrog/xray/var/etc/system.yaml [INFO ] Router external port (8082) is open [INFO ] Router internal port (8046) is open [INFO ] Router traefik port (8049) is open [INFO ] Router grpc port (8047) is open [INFO ] XrayServer port (8000) is open [INFO ] XrayAnalysis port (7000) is open [INFO ] XrayIndexer port (7002) is open [INFO ] XrayPersist port (7003) is open [INFO ] Ulimit level for processes is satisfactory--no change required ulimit value(4096) is below expected value(100000) [ERROR] Ulimit level for open files is less than the recommended minimum 100000 [INFO ] Router external port (8082) is not blocked by firewall [INFO ] Router internal port (8046) is not blocked by firewall [INFO ] Router grpc port (8047) is not blocked by firewall [INFO ] Router traefik port (8049) is not blocked by firewall [INFO ] XrayServer port (8000) is not blocked by firewall [INFO ] XrayAnalysis port (7000) is not blocked by firewall [INFO ] XrayIndexer port (7002) is not blocked by firewall [INFO ] XrayPersist port (7003) is not blocked by firewall [INFO ] Router external port (8082) is not blocked by iptables [INFO ] Router internal port (8046) is not blocked by iptables [INFO ] Router grpc port (8047) is not blocked by iptables [INFO ] Router traefik port (8049) is not blocked by iptables [INFO ] XrayServer port (8000) is not blocked by iptables [INFO ] XrayAnalysis port (7000) is not blocked by iptables [INFO ] XrayIndexer port (7002) is not blocked by iptables [INFO ] XrayPersist port (7003) is not blocked by iptables [INFO ] Router external port (8082) is not blocked by ip6tables
3. console.log报错
提示master.key不存在但文件实际存在,同时join.key缺失:
[INFO ] JFrog Observability (jfob) service initialization started. Version: 1.11.0 (revision: 38bcc4c00d, build date: 2022-09-16T11:08:32Z) PID: 5922 Home: /opt/jfrog/xray [DEBUG] Resolved system configuration file path: /opt/jfrog/xray/var/etc/system.yaml Logging configuration has both console=true and filepath='router-service.log'; ignoring console. 2022-12-03T07:05:40.342Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:77 ] [main ] [] - Router (jfrou) service initialization started. Version: 7.51.0-1 Revision: fd36933e55dfc526ec51ec35f5face80a80debac PID: 5895 Home: /opt/jfrog/xray 2022-12-03T07:05:40.342Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:80 ] [main ] [] - JFrog Router IP: 192.168.71.30 2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [49203c85e5fdf6fe] [run_main:351 ] [main ] Loading config, service name: analysis 2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [49203c85e5fdf6fe] [start_xray_server:288 ] [main ] Xray Analysis (analysis) service initialization started 2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [ ] [fileutil:73 ] [main ] no master key found, cause: failed resolving 'shared.security.masterKey' key; file does not exist: /opt/jfrog/xray/var/etc/security/master.key 2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [ ] [connection_pool_holder:94 ] [main ] connecting to postgresql attempt #1 2022-12-03T07:05:41.343Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:130 ] [main ] [] - System configuration encryption report: shared.database.password: encrypted successfully shared.multiTenant.tenantRegistryClient.clientCertKey: does not exist in the config file shared.newrelic.licenseKey: does not exist in the config file shared.rabbitMq.password: encrypted successfully shared.security.joinKey: encrypted successfully shared.security.joinKeyFile: file '/opt/jfrog/xray/var/etc/security/join.key' - open /opt/jfrog/xray/var/etc/security/join.key: no such file or directory 2022-12-03T07:05:41.344Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:85 ] [main ] [] - JFrog Router Service ID: jfrou@0abcdefgh 2022-12-03T07:05:41.344Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:86
4. 后续运行异常
- 点击JFrog UI中的Xray标签无反应,系统日志报错:
Forbidden UI REST: Xray is not configured on the repo 'libs-release-local' or file 'db2jcc4/db2jcc4/10.5.0.5/db2jcc4-10.5.0.5.jar' is not handled by Xray
- Xray console.log持续报错无法连接本地router:
2022-12-04T02:28:38.441Z ^[[33m[jfxr ]^[[0m ^[[34m[INFO ]^[[0m [ ] [access_client_bootstrap:182 ] [main ] (--wrapper--)Cluster join: Retry 85: Service registry ping failed, will retry. Error: Error while trying to connect to local router at address 'http://localhost:8046/access': Get "http://localhost:8046/access/api/v1/system/ping": dial tcp [::1]:8046: connect: connection refused
2022-12-04T19:55:11.997Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [ ] [access_client_bootstrap:182 ] [main ] (--wrapper--)Cluster join: Retry 165: Service registry ping failed, will retry. Error: Error while trying to connect to local router at address 'http://localhost:8046/access': Get "http://localhost:8046/access/api/v1/system/ping": dial tcp [::1]:8046: connect: connection refused
问题:是否需要在JFrog UI中进行手动配置以启用Xray功能?
解决方案
先处理底层连接与权限问题,再进行UI配置:
1. 修复文件权限问题
日志中提示存在文件找不到但实际存在的情况,大概率是Xray运行用户没有文件访问权限:
- 确认Xray运行用户(通常是
jfrog)对/opt/jfrog/xray/var/etc/目录及下属文件有读权限:chown -R jfrog:jfrog /opt/jfrog/xray/var/etc/ chmod -R 750 /opt/jfrog/xray/var/etc/
2. 修复ulimit过低问题
日志提示open files的ulimit仅4096,远低于推荐的100000:
- 临时生效:
ulimit -n 100000 - 永久生效:编辑
/etc/security/limits.conf,添加:
重启Xray服务。jfrog soft nofile 100000 jfrog hard nofile 100000
3. 处理join.key缺失问题
日志显示join.key不存在,需生成该文件:
- 进入Xray安装目录,执行生成命令:
生成后确认文件存在于cd /opt/jfrog/xray/app/bin ./xray.sh generate-join-key/opt/jfrog/xray/var/etc/security/join.key,并确保权限正确。
4. 修复Router连接问题
日志显示Xray服务无法连接localhost:8046,可能是绑定地址问题:
- 检查
system.yaml中Router的绑定地址,确保不是仅绑定了IPv4而服务尝试用IPv6连接:
修改/opt/jfrog/xray/var/etc/system.yaml中的router.internalPort配置,绑定到服务器实际IP而非localhost:router: internalPort: 8046 internalHost: 192.168.71.30 # 替换为你的服务器IP - 重启Xray服务,确认Router服务正常运行:
systemctl restart xray.service systemctl status xray.service
5. UI中启用Xray配置
当底层服务恢复正常后,需要在JFrog UI中完成Xray的配置:
- 登录JFrog Platform UI,进入Admin > Xray > Settings;
- 按照向导完成Xray与Platform的关联配置,包括授权、仓库关联等;
- 针对报错的
libs-release-local仓库,进入仓库设置页面,启用Xray扫描:- 进入Repositories > Repositories List,找到
libs-release-local; - 点击仓库名称进入设置,在Xray标签页勾选Enable Xray Scan;
- 保存设置后,重新尝试访问Xray标签页。
- 进入Repositories > Repositories List,找到
完成以上步骤后,Xray服务应能正常连接并在UI中正常显示,仓库的Xray扫描也会生效。
内容的提问来源于stack exchange,提问作者Ramesh Thiyagarajan
相关产品推荐
相关产品推荐

