KeyCloak令牌签发者验证失败问题排查求助
Keycloak与Spring Boot集成的Token Issuer不匹配问题解决
问题现象
Spring Boot应用日志抛出Token验证错误:
o.k.adapters.OAuthRequestAuthenticator : failed verification of token: Invalid token issuer. Expected 'http://auth.example.com/realms/MyRealm', but was 'https://auth.example.com/realms/MyRealm'
环境背景:
- KeyCloak 19.0.1自定义Docker镜像部署在Kubernetes,通过Nginx Ingress对外提供
https://auth.example.com访问 - Spring Boot应用通过
https://example.com对外访问,集群内原配置通过KeyCloak Service的HTTP地址http://gap-got-chart-keycloak-svc:8080与KeyCloak通信 - KeyCloak已配置
KC_PROXY=edge适配Ingress代理,外部OpenID配置返回的URI均为HTTPS格式
问题原因
Spring Boot客户端配置的auth-server-url是集群内的HTTP地址,因此它验证Token时会期望Issuer为http://auth.example.com/realms/MyRealm;但KeyCloak通过KC_HOSTNAME_URL=https://auth.example.com配置,生成的Token中Issuer是外部HTTPS地址,两者不匹配导致验证失败。
解决方案
将Spring Boot的auth-server-url统一配置为KeyCloak的外部HTTPS地址,确保与KeyCloak生成的Token Issuer一致:
修改Spring Boot配置
- 调整环境变量:
env: - name: KEYCLOAK_AUTHSERVERURL value: "https://auth.example.com"
- 同步修改
application.yaml中的默认配置(或确保环境变量覆盖默认值):
keycloak: auth-server-url: https://auth.example.com realm: MyRealm resource: my-app-id public-client: true principal-attribute: preferred_username
补充说明
- 集群内应用访问外部HTTPS域名需要确保内部DNS可解析,或通过Ingress配置支持内部访问(部分Ingress Controller默认支持内部流量转发)
- KeyCloak的
KC_PROXY=edge、KC_HOSTNAME、KC_HOSTNAME_URL配置无需调整,当前配置已正确适配外部HTTPS访问场景
内容的提问来源于stack exchange,提问作者Marcin Stachniuk
相关产品推荐
相关产品推荐

