You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何绕过KubeFlow的Dex认证,通过curl访问Seldon模型

绕过Dex认证访问Kubeflow中的Seldon模型

问题场景

已完成以下操作:

  • 端口转发暴露Istio网关:kubectl port-forward $(kubectl get pods -l istio=ingressgateway -n istio-system -o jsonpath='{.items[0].metadata.name}') -n istio-system 8005:80
  • 创建并切换至命名空间kubeflow-user-example-com
  • 构建Seldon模型封装器并上传至Docker仓库
  • 部署SeldonDeployment(配置如下):
apiVersion: machinelearning.seldon.io/v1
kind: SeldonDeployment
metadata:
  labels:
    app: seldon
  name: seldon-sentiment
  namespace: kubeflow-user-example-com
spec:
  annotations:
    project_name: NLP Pipeline
    deployment_version: v1
  name: seldon-sentiment
  predictors:
    - componentSpecs:
        - spec:
            containers:
              - image: 'localhost:5000/seldon-sentiment:0.1'
                imagePullPolicy: IfNotPresent
                name: sentiment
                resources:
                  requests:
                    memory: 1Mi
            terminationGracePeriodSeconds: 20
      graph:
        children: []
        endpoint:
          type: REST
        name: sentiment
        type: MODEL
      name: sentiment
      replicas: 1
      annotations:
        predictor_version: v1

执行curl访问时被重定向至Dex认证:

curl -k -O http://localhost:8005/seldon/kubeflow-user-example-com/seldon-sentiment-sentiment-0-sentiment/api/v0.1/predictions -d "{'data': { 'ndarray': ['Hello world this is a test']}}" -H 'Content-Type: application/json'

返回302重定向到Dex登录页面。

解决方案

1. 直接端口转发到Seldon模型Pod

绕过Istio网关和认证,直接访问模型Pod:

  • 查找Seldon模型Pod:
    kubectl get pods -l seldon-deployment-id=seldon-sentiment
    
  • 端口转发到Pod的5000端口(Seldon默认REST端口):
    kubectl port-forward <pod-name> 5000:5000
    
  • 用curl访问本地端口:
    curl -X POST http://localhost:5000/api/v0.1/predictions -d '{"data": {"ndarray": ["Hello world this is a test"]}}' -H 'Content-Type: application/json'
    

2. 为SeldonDeployment添加注解跳过Istio认证

修改SeldonDeployment,添加注解让Istio跳过该服务的认证检查:

  • 编辑SeldonDeployment:
    kubectl edit seldondeployment seldon-sentiment -n kubeflow-user-example-com
    
  • 在spec.annotations中添加:
    seldon.io/istio-auth: "false"
    
  • 保存后等待重新部署,之后用正确路径访问:
    curl -X POST http://localhost:8005/seldon/kubeflow-user-example-com/seldon-sentiment/api/v0.1/predictions -d '{"data": {"ndarray": ["Hello world this is a test"]}}' -H 'Content-Type: application/json'
    

3. 携带认证Token访问

通过浏览器获取Kubeflow认证Token,用curl携带访问:

  • 打开浏览器登录Kubeflow,按下F12打开开发者工具,切换到网络标签
  • 任意请求一个Kubeflow接口,复制请求头中的Authorization字段(格式为Bearer <token>)
  • 用curl携带该Token访问:
    curl -X POST http://localhost:8005/seldon/kubeflow-user-example-com/seldon-sentiment/api/v0.1/predictions -d '{"data": {"ndarray": ["Hello world this is a test"]}}' -H 'Content-Type: application/json' -H 'Authorization: Bearer <your-token>'
    

注意事项

  • 原curl请求存在两个问题:路径错误(应使用SeldonDeployment名称而非Pod名称)、JSON格式错误(单引号嵌套会导致Content-Type被自动识别为application/x-www-form-urlencoded,需用单引号包裹整体JSON或转义双引号)。

内容的提问来源于stack exchange,提问作者GigliOneiric

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 05:20:27