You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jfrog Xray服务运行正常但JFrog UI无显示及配置异常咨询

JFrog Xray 启动与UI访问问题

问题背景

在独立服务器上安装JFrog Xray后,启动服务时出现失败,后续服务虽运行但UI访问异常,具体报错如下:

1. systemd启动失败日志

● xray.service - Xray service
   Loaded: loaded (/usr/lib/systemd/system/xray.service; enabled; vendor preset: disabled)
   Active: failed (Result: exit-code) since Sat 2022-12-03 12:36:50 IST; 1min 17s ago
  Process: 1217 ExecStart=/opt/jfrog/xray/app/bin/xray.sh start (code=exited, status=1/FAILURE)
 Main PID: 1217 (code=exited, status=1/FAILURE)

2. systemDiagnostics.log报错

提示system.yaml不存在但文件实际存在,同时存在ulimit过低问题:

[WARN ] Error while initializing File resolver : Config file does not exists : /opt/jfrog/xray/var/etc/system.yaml
[INFO ] Router external port (8082) is open
[INFO ] Router internal port (8046) is open
[INFO ] Router traefik port (8049) is open
[INFO ] Router grpc port (8047) is open
[INFO ] XrayServer port (8000) is open
[INFO ] XrayAnalysis port (7000) is open
[INFO ] XrayIndexer port (7002) is open
[INFO ] XrayPersist port (7003) is open
[INFO ] Ulimit level for processes is satisfactory--no change required
ulimit value(4096) is below expected value(100000)
[ERROR] Ulimit level for open files is less than the recommended minimum 100000
[INFO ] Router external port (8082) is not blocked by firewall
[INFO ] Router internal port (8046) is not blocked by firewall
[INFO ] Router grpc port (8047) is not blocked by firewall
[INFO ] Router traefik port (8049) is not blocked by firewall
[INFO ] XrayServer port (8000) is not blocked by firewall
[INFO ] XrayAnalysis port (7000) is not blocked by firewall
[INFO ] XrayIndexer port (7002) is not blocked by firewall
[INFO ] XrayPersist port (7003) is not blocked by firewall
[INFO ] Router external port (8082) is not blocked by iptables
[INFO ] Router internal port (8046) is not blocked by iptables
[INFO ] Router grpc port (8047) is not blocked by iptables
[INFO ] Router traefik port (8049) is not blocked by iptables
[INFO ] XrayServer port (8000) is not blocked by iptables
[INFO ] XrayAnalysis port (7000) is not blocked by iptables
[INFO ] XrayIndexer port (7002) is not blocked by iptables
[INFO ] XrayPersist port (7003) is not blocked by iptables
[INFO ] Router external port (8082) is not blocked by ip6tables

3. console.log报错

提示master.key不存在但文件实际存在,同时join.key缺失:

[INFO ] JFrog Observability (jfob) service initialization started. Version: 1.11.0 (revision: 38bcc4c00d, build date: 2022-09-16T11:08:32Z) PID: 5922 Home: /opt/jfrog/xray
[DEBUG] Resolved system configuration file path: /opt/jfrog/xray/var/etc/system.yaml
Logging configuration has both console=true and filepath='router-service.log'; ignoring console.
2022-12-03T07:05:40.342Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:77               ] [main                ] [] - Router (jfrou) service initialization started. Version: 7.51.0-1 Revision: fd36933e55dfc526ec51ec35f5face80a80debac PID: 5895 Home: /opt/jfrog/xray
2022-12-03T07:05:40.342Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:80               ] [main                ] [] - JFrog Router IP: 192.168.71.30
2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [49203c85e5fdf6fe] [run_main:351                  ] [main                ] Loading config, service name: analysis
2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [49203c85e5fdf6fe] [start_xray_server:288         ] [main                ] Xray Analysis (analysis) service initialization started
2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [                ] [fileutil:73                   ] [main                ] no master key found, cause: failed resolving 'shared.security.masterKey' key; file does not exist: /opt/jfrog/xray/var/etc/security/master.key
2022-12-03T07:05:40.505Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [                ] [connection_pool_holder:94     ] [main                ] connecting to postgresql attempt #1
2022-12-03T07:05:41.343Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:130              ] [main                ] [] - System configuration encryption report:
shared.database.password: encrypted successfully
shared.multiTenant.tenantRegistryClient.clientCertKey: does not exist in the config file
shared.newrelic.licenseKey: does not exist in the config file
shared.rabbitMq.password: encrypted successfully
shared.security.joinKey: encrypted successfully
shared.security.joinKeyFile: file '/opt/jfrog/xray/var/etc/security/join.key' - open /opt/jfrog/xray/var/etc/security/join.key: no such file or directory
2022-12-03T07:05:41.344Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:85               ] [main                ] [] - JFrog Router Service ID: jfrou@0abcdefgh
2022-12-03T07:05:41.344Z ^[[36m[jfrou]^[[0m ^[[34m[INFO ]^[[0m [7a8ced89c2f6d1db] [bootstrap.go:86  

4. 后续运行异常

  • 点击JFrog UI中的Xray标签无反应,系统日志报错:
Forbidden UI REST: Xray is not configured on the repo 'libs-release-local' or file 'db2jcc4/db2jcc4/10.5.0.5/db2jcc4-10.5.0.5.jar' is not handled by Xray
  • Xray console.log持续报错无法连接本地router:
2022-12-04T02:28:38.441Z ^[[33m[jfxr ]^[[0m ^[[34m[INFO ]^[[0m [                ] [access_client_bootstrap:182   ] [main                ] (--wrapper--)Cluster join: Retry 85: Service registry ping failed, will retry. Error: Error while trying to connect to local router at address 'http://localhost:8046/access': Get "http://localhost:8046/access/api/v1/system/ping": dial tcp [::1]:8046: connect: connection refused
2022-12-04T19:55:11.997Z ^[[33m[jfxan]^[[0m ^[[34m[INFO ]^[[0m [                ] [access_client_bootstrap:182   ] [main                ] (--wrapper--)Cluster join: Retry 165: Service registry ping failed, will retry. Error: Error while trying to connect to local router at address 'http://localhost:8046/access': Get "http://localhost:8046/access/api/v1/system/ping": dial tcp [::1]:8046: connect: connection refused

问题:是否需要在JFrog UI中进行手动配置以启用Xray功能?

解决方案

先处理底层连接与权限问题,再进行UI配置:

1. 修复文件权限问题

日志中提示存在文件找不到但实际存在的情况,大概率是Xray运行用户没有文件访问权限:

  • 确认Xray运行用户(通常是jfrog)对/opt/jfrog/xray/var/etc/目录及下属文件有读权限:
    chown -R jfrog:jfrog /opt/jfrog/xray/var/etc/
    chmod -R 750 /opt/jfrog/xray/var/etc/
    

2. 修复ulimit过低问题

日志提示open files的ulimit仅4096,远低于推荐的100000:

  • 临时生效:
    ulimit -n 100000
    
  • 永久生效:编辑/etc/security/limits.conf,添加:
    jfrog soft nofile 100000
    jfrog hard nofile 100000
    
    重启Xray服务。

3. 处理join.key缺失问题

日志显示join.key不存在,需生成该文件:

  • 进入Xray安装目录,执行生成命令:
    cd /opt/jfrog/xray/app/bin
    ./xray.sh generate-join-key
    
    生成后确认文件存在于/opt/jfrog/xray/var/etc/security/join.key,并确保权限正确。

4. 修复Router连接问题

日志显示Xray服务无法连接localhost:8046,可能是绑定地址问题:

  • 检查system.yaml中Router的绑定地址,确保不是仅绑定了IPv4而服务尝试用IPv6连接:
    修改/opt/jfrog/xray/var/etc/system.yaml中的router.internalPort配置,绑定到服务器实际IP而非localhost:
    router:
      internalPort: 8046
      internalHost: 192.168.71.30 # 替换为你的服务器IP
    
  • 重启Xray服务,确认Router服务正常运行:
    systemctl restart xray.service
    systemctl status xray.service
    

5. UI中启用Xray配置

当底层服务恢复正常后,需要在JFrog UI中完成Xray的配置:

  • 登录JFrog Platform UI,进入Admin > Xray > Settings;
  • 按照向导完成Xray与Platform的关联配置,包括授权、仓库关联等;
  • 针对报错的libs-release-local仓库,进入仓库设置页面,启用Xray扫描:
    1. 进入Repositories > Repositories List,找到libs-release-local;
    2. 点击仓库名称进入设置,在Xray标签页勾选Enable Xray Scan;
    3. 保存设置后,重新尝试访问Xray标签页。

完成以上步骤后,Xray服务应能正常连接并在UI中正常显示,仓库的Xray扫描也会生效。


内容的提问来源于stack exchange,提问作者Ramesh Thiyagarajan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 16:40:27