You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ambassador Edge Stack JWT过滤器验证Firebase令牌失败排查

问题:Ambassador Edge Stack验证Firebase JWT令牌失败

我正尝试使用Ambassador Edge Stack(datawire/edge-stack 3.3.0版本)的Filter验证Firebase生成的JWT令牌。

令牌生成方式

Firebase令牌通过邮箱/密码认证机制生成,Python代码示例:

email=input("Enter email: ")
password=input("Enter password: ")
user = authentication.sign_in_with_email_and_password(email, password)
custom_token = auth.create_custom_token(user["localId"], additional_claims)
print("JWT Token :")
print(custom_token)

请求与错误返回

生成令牌后,执行curl请求:

curl -H "Authorization: Bearer $TOKEN" https://ambassador-ip.nip.io/hello-world/

返回401错误:

{
    "message": "Token validation error: token is invalid: errorFlags=0x00000002=(ValidationErrorUnverifiable) wrappedError=(KeyID=\"50***redacted***1\": JWK not found)",
    "status_code": 401
}

当前Ambassador配置

Filter配置(v2版本API)

apiVersion: getambassador.io/v2
kind: Filter
metadata:
  name: "firebase-filter"
  namespace: ${kubernetes_namespace.hello_world.metadata[0].name}
spec:
  JWT:
    jwksURI:  "https://www.googleapis.com/service_accounts/v1/metadata/x509/securetoken@system.gserviceaccount.com"
    audience: "${local.project_id}"
    issuer:   "https://securetoken.google.com/${local.project_id}"

FilterPolicy配置(v3alpha1版本API)

apiVersion: getambassador.io/v3alpha1
kind: FilterPolicy
metadata:
  name: "firebase-filter-policy"
  namespace: ${kubernetes_namespace.hello_world.metadata[0].name}
spec:
  rules:
  - host: "*"
    path: "/hello-world/"
    filters:                    
    - name: "firebase-filter"
      namespace: "${kubernetes_namespace.hello_world.metadata[0].name}"

备注

相同令牌在Cloud Run服务搭配GCP API网关时可正常工作,网关配置如下:

swagger: '2.0'
info:
  title: Example Firebase auth Gateway
  description: API Gateway with firebase auth
  version: 1.0.0
schemes:
  - https
produces:
  - application/json
securityDefinitions:
  firebase:
    authorizationUrl: ''
    flow: implicit
    type: oauth2
    x-google-issuer: "https://securetoken.google.com/${project_id}"
    x-google-jwks_uri: "https://www.googleapis.com/service_accounts/v1/metadata/x509/securetoken@system.gserviceaccount.com"
    x-google-audiences: "${project_id}"
paths:
  /v1/hello:
    get:
      security:
        - firebase: []
      description: Hello
      operationId: hello
      responses:
        '200':
          description: Success
      x-google-backend:
        address: 'https://hello-redacted-ew.a.run.app'

请问Ambassador过滤器的配置哪里出错了?


问题分析与解决

核心问题:JWKS格式不兼容

当前配置的jwksURI返回的是X.509证书元数据,而Ambassador的JWT Filter仅支持标准JWKS(JSON Web Key Set)格式数据。GCP API网关可自动处理X.509格式,但Ambassador无法直接解析,导致找不到对应KeyID的JWK。

修正方案

将Filter中的jwksURI替换为Firebase标准JWKS端点:

apiVersion: getambassador.io/v2
kind: Filter
metadata:
  name: "firebase-filter"
  namespace: ${kubernetes_namespace.hello_world.metadata[0].name}
spec:
  JWT:
    # 替换为Firebase标准JWKS端点
    jwksURI:  "https://www.googleapis.com/service_accounts/v1/jwk/securetoken@system.gserviceaccount.com"
    audience: "${local.project_id}"
    issuer:   "https://securetoken.google.com/${local.project_id}"

额外验证点

  1. API版本统一:Filter用v2版本API,FilterPolicy用v3alpha1,在Ambassador 3.3.0中虽兼容,但建议统一使用v3alpha1版本Filter以避免潜在问题:
apiVersion: getambassador.io/v3alpha1
kind: Filter
metadata:
  name: "firebase-filter"
  namespace: ${kubernetes_namespace.hello_world.metadata[0].name}
spec:
  JWT:
    jwksURI:  "https://www.googleapis.com/service_accounts/v1/jwk/securetoken@system.gserviceaccount.com"
    audience: "${local.project_id}"
    issuer:   "https://securetoken.google.com/${local.project_id}"
  1. 令牌类型修正:create_custom_token生成的是自定义令牌,需先通过Firebase Auth端点交换为ID Token才能用于API验证:
# 交换自定义令牌为ID Token
import requests

id_token_response = requests.post(
    "https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken",
    json={"token": custom_token, "returnSecureToken": True},
    params={"key": "你的Firebase Web API密钥"}
)
id_token = id_token_response.json()["idToken"]

使用此id_token作为请求的Bearer Token,才能被Ambassador正确验证。

内容的提问来源于stack exchange,提问作者ThomasVI

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 18:01:14