You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

KeyCloak令牌签发者验证失败问题排查求助

Keycloak与Spring Boot集成的Token Issuer不匹配问题解决

问题现象

Spring Boot应用日志抛出Token验证错误:

o.k.adapters.OAuthRequestAuthenticator   : failed verification of token: Invalid token issuer. Expected 'http://auth.example.com/realms/MyRealm', but was 'https://auth.example.com/realms/MyRealm'

环境背景:

  • KeyCloak 19.0.1自定义Docker镜像部署在Kubernetes,通过Nginx Ingress对外提供https://auth.example.com访问
  • Spring Boot应用通过https://example.com对外访问,集群内原配置通过KeyCloak Service的HTTP地址http://gap-got-chart-keycloak-svc:8080与KeyCloak通信
  • KeyCloak已配置KC_PROXY=edge适配Ingress代理,外部OpenID配置返回的URI均为HTTPS格式

问题原因

Spring Boot客户端配置的auth-server-url是集群内的HTTP地址,因此它验证Token时会期望Issuer为http://auth.example.com/realms/MyRealm;但KeyCloak通过KC_HOSTNAME_URL=https://auth.example.com配置,生成的Token中Issuer是外部HTTPS地址,两者不匹配导致验证失败。

解决方案

将Spring Boot的auth-server-url统一配置为KeyCloak的外部HTTPS地址,确保与KeyCloak生成的Token Issuer一致:

修改Spring Boot配置

  1. 调整环境变量:
env:
  - name: KEYCLOAK_AUTHSERVERURL
    value: "https://auth.example.com"
  1. 同步修改application.yaml中的默认配置(或确保环境变量覆盖默认值):
keycloak:
  auth-server-url: https://auth.example.com
  realm: MyRealm
  resource: my-app-id
  public-client: true
  principal-attribute: preferred_username

补充说明

  • 集群内应用访问外部HTTPS域名需要确保内部DNS可解析,或通过Ingress配置支持内部访问(部分Ingress Controller默认支持内部流量转发)
  • KeyCloak的KC_PROXY=edge、KC_HOSTNAME、KC_HOSTNAME_URL配置无需调整,当前配置已正确适配外部HTTPS访问场景

内容的提问来源于stack exchange,提问作者Marcin Stachniuk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 17:35:25