You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ory Kratos/Oathkeeper对接Starburst遇401认证失败求助

Ory Oathkeeper代理Starburst UI返回401未授权问题排查请求

架构与目标

已部署Ory Kratos、Ory Oathkeeper、Starburst及Apache Ranger,期望实现:

  • 用户通过Ory Kratos完成账号创建与认证
  • 访问https://proxy.oathkeeper.mydomain.com/starburst/时,Ory Oathkeeper生成可通过指定jwks.json验证的JWT,携带该令牌进入Starburst UI
  • 由Apache Ranger基于当前登录用户身份应用数据访问策略

相关组件地址

  • Kratos UI:https://kratos.mydomain.com
  • Kratos公网服务:https://public.kratos.mydomain.com
  • Kratos管理服务:https://admin.kratos.mydomain.com
  • jwks.json:https://auth.mydomain.com/assets/well-known/jwks.json
  • Ory Oathkeeper代理:https://proxy.oathkeeper.mydomain.com
  • Ory Oathkeeper API:https://api.oathkeeper.mydomain.com

当前状态与问题

已完成Ory Kratos、Ory Oathkeeper、Starburst的基础配置:

  1. 登录Kratos后,浏览器生成有效的csrf cookie和ory_kratos_session cookie,但未生成JWT令牌
  2. 访问https://proxy.oathkeeper.mydomain.com/foobar返回预期404,说明代理路由功能正常
  3. 访问https://proxy.oathkeeper.mydomain.com/starburst/时返回401未授权:
    • Ory Oathkeeper Pod日志显示"Access credentials are invalid"
    • Starburst侧无Authorization: Bearer <JWT...>相关请求日志

不确定是遗漏配置还是配置有误,请求帮忙审核配置并指明排查方向。

内容的提问来源于stack exchange,提问作者Bagaboo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 15:10:19