You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Ingress Nginx访问Apache NiFi集群登录失败求助

问题根源

你遇到的JWT解码错误和Ingress证书问题是关联的:NiFi单用户认证的JWT是用自身集群CA签名的,当Ingress使用默认TLS证书时,客户端(浏览器)和NiFi之间的TLS链路使用了非NiFi CA签发的证书,导致NiFi无法验证JWT的签名合法性,抛出Signed JWT rejected: Another algorithm expected, or no matching key(s) found错误。

解决方案

1. 定位NiFi CA证书Secret

helm部署的nifi集群,CA证书和私钥默认存在名为<你的helm发布名>-nifi-ca的Secret里,用以下命令确认:

kubectl get secret <release-name>-nifi-ca -o yaml

检查输出里是否包含tls.crt和tls.key字段,这就是NiFi的CA证书和密钥。

2. 修正Ingress的TLS配置

修改你的Ingress YAML,指定TLS部分使用NiFi的CA Secret,同时确保Ingress以HTTPS方式转发请求到NiFi:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: nifi-ingress
  annotations:
    # 针对nginx-ingress的必要注解,其他Ingress控制器可调整
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
spec:
  tls:
  - hosts:
    - nifi.dev-tools.mycompany.com
    secretName: <release-name>-nifi-ca  # 替换为你的NiFi CA Secret名称
  rules:
  - host: nifi.dev-tools.mycompany.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: <release-name>-nifi  # 替换为你的NiFi服务名称
            port:
              number: 8443

3. 应用配置并验证

执行命令更新Ingress:

kubectl apply -f nifi-ingress.yaml

然后检查Ingress的TLS配置是否生效:

kubectl describe ingress nifi-ingress

确认TLS部分的SecretName和Hosts与配置一致。

4. 清理缓存后测试

浏览器可能缓存了之前的默认证书,用无痕模式打开https://nifi.dev-tools.mycompany.com,尝试登录。如果还是有问题,清除浏览器对应域名的缓存后再试。

5. 验证NiFi JWT配置(可选)

如果问题依旧,检查helm values.yaml里的JWT签名配置是否和CA证书匹配:

security:
  user:
    jwt:
      signatureAlgorithm: "RS256"  # RSA证书对应RS256,EC证书对应ES256等

确保签名算法和NiFi CA证书的类型一致。

关键注意点
  • 不要让Ingress Controller的全局默认证书覆盖你配置的NiFi CA证书,部分控制器需要显式关闭全局TLS或提升Ingress资源的优先级。
  • 必须保证Ingress以HTTPS方式连接NiFi后端,否则会出现协议不匹配的问题。

内容的提问来源于stack exchange,提问作者Shayki Abramczyk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 01:10:32