如何绕过KubeFlow的Dex认证,通过curl访问Seldon模型
绕过Dex认证访问Kubeflow中的Seldon模型
问题场景
已完成以下操作:
- 端口转发暴露Istio网关:
kubectl port-forward $(kubectl get pods -l istio=ingressgateway -n istio-system -o jsonpath='{.items[0].metadata.name}') -n istio-system 8005:80 - 创建并切换至命名空间
kubeflow-user-example-com - 构建Seldon模型封装器并上传至Docker仓库
- 部署SeldonDeployment(配置如下):
apiVersion: machinelearning.seldon.io/v1 kind: SeldonDeployment metadata: labels: app: seldon name: seldon-sentiment namespace: kubeflow-user-example-com spec: annotations: project_name: NLP Pipeline deployment_version: v1 name: seldon-sentiment predictors: - componentSpecs: - spec: containers: - image: 'localhost:5000/seldon-sentiment:0.1' imagePullPolicy: IfNotPresent name: sentiment resources: requests: memory: 1Mi terminationGracePeriodSeconds: 20 graph: children: [] endpoint: type: REST name: sentiment type: MODEL name: sentiment replicas: 1 annotations: predictor_version: v1
执行curl访问时被重定向至Dex认证:
curl -k -O http://localhost:8005/seldon/kubeflow-user-example-com/seldon-sentiment-sentiment-0-sentiment/api/v0.1/predictions -d "{'data': { 'ndarray': ['Hello world this is a test']}}" -H 'Content-Type: application/json'
返回302重定向到Dex登录页面。
解决方案
1. 直接端口转发到Seldon模型Pod
绕过Istio网关和认证,直接访问模型Pod:
- 查找Seldon模型Pod:
kubectl get pods -l seldon-deployment-id=seldon-sentiment - 端口转发到Pod的5000端口(Seldon默认REST端口):
kubectl port-forward <pod-name> 5000:5000 - 用curl访问本地端口:
curl -X POST http://localhost:5000/api/v0.1/predictions -d '{"data": {"ndarray": ["Hello world this is a test"]}}' -H 'Content-Type: application/json'
2. 为SeldonDeployment添加注解跳过Istio认证
修改SeldonDeployment,添加注解让Istio跳过该服务的认证检查:
- 编辑SeldonDeployment:
kubectl edit seldondeployment seldon-sentiment -n kubeflow-user-example-com - 在
spec.annotations中添加:seldon.io/istio-auth: "false" - 保存后等待重新部署,之后用正确路径访问:
curl -X POST http://localhost:8005/seldon/kubeflow-user-example-com/seldon-sentiment/api/v0.1/predictions -d '{"data": {"ndarray": ["Hello world this is a test"]}}' -H 'Content-Type: application/json'
3. 携带认证Token访问
通过浏览器获取Kubeflow认证Token,用curl携带访问:
- 打开浏览器登录Kubeflow,按下F12打开开发者工具,切换到网络标签
- 任意请求一个Kubeflow接口,复制请求头中的
Authorization字段(格式为Bearer <token>) - 用curl携带该Token访问:
curl -X POST http://localhost:8005/seldon/kubeflow-user-example-com/seldon-sentiment/api/v0.1/predictions -d '{"data": {"ndarray": ["Hello world this is a test"]}}' -H 'Content-Type: application/json' -H 'Authorization: Bearer <your-token>'
注意事项
- 原curl请求存在两个问题:路径错误(应使用SeldonDeployment名称而非Pod名称)、JSON格式错误(单引号嵌套会导致Content-Type被自动识别为
application/x-www-form-urlencoded,需用单引号包裹整体JSON或转义双引号)。
内容的提问来源于stack exchange,提问作者GigliOneiric
相关产品推荐
相关产品推荐

