You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Grafana从8.1升级至9.0报Origin not allowed错误排查

问题原因与修复方案

这个报错是Grafana源校验不通过导致的,分别需要调整Grafana服务端配置、补全Apache反向代理规则,两侧配置匹配后即可解决。


1. 调整Grafana服务端配置

Grafana默认以根路径部署、仅校验本地请求源,子路径反代场景下必须修改对应配置,配置文件通常路径为/etc/grafana/grafana.ini:

  • 调整[server]段,适配子路径部署:
[server]
domain = example.com
# 必须和你实际访问Grafana的完整地址一致,末尾带斜杠
root_url = https://example.com/grafana/
# 开启子路径服务支持
serve_from_sub_path = true
  • 调整[security]段,添加允许的访问源:
[security]
cookie_secure = true
# 把你所有用于访问Grafana的域名、IP全部加入列表,多个地址用逗号分隔
allowed_origins = https://example.com,https://11.11.11.11

修改完成后执行systemctl restart grafana-server重启服务生效。


2. 补全Apache反向代理配置

当前代理规则缺少必要的请求头传递,路径拼接也存在问题,调整/grafana路径的Location配置如下:

<Location "/grafana">
    ProxyPreserveHost On
    # 需提前加载mod_headers模块,传递真实访问信息给Grafana
    RequestHeader set X-Forwarded-Proto "https"
    RequestHeader set X-Forwarded-Port "443"
    # 转发地址末尾必须加斜杠,避免路径拼接错误
    ProxyPass http://localhost:3000/
    ProxyPassReverse http://localhost:3000/
    ProxyPassReverse https://example.com/grafana/
</Location>

修改完成后执行apachectl configtest校验配置无报错,再执行systemctl reload httpd重载配置生效。


3. 额外排查项

  • 执行httpd -M检查已加载模块,确认mod_proxy、mod_proxy_http、mod_headers均已启用,未启用的话通过a2enmod 模块名开启后再重载Apache
  • 配置生效前清空浏览器缓存、本地站点Cookie,避免旧缓存导致校验不通过
  • 如果开启了匿名访问,确认[auth.anonymous]段配置符合预期,避免未认证请求被拦截触发误报

内容的提问来源于stack exchange,提问作者Alexandre Torres

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 13:06:23