Envoy搭配OpenIddict出现504 Gateway Timeout错误如何解决?
问题修复方案
你遇到的504超时问题核心有两个常见诱因:一是当前Envoy配置的超时阈值远低于OpenIddict接口的实际处理耗时,二是可能存在路由规则未覆盖OpenIddict标准端点的情况,可按以下步骤修复:
1. 调整超时配置
你当前配置中集群的connect_timeout仅为0.25s,且未设置请求级别的响应超时,OpenIddict的令牌签发、授权校验等逻辑涉及加密计算、数据库查询等操作,耗时很容易超过阈值,按以下方式修改配置:
- 调整集群连接超时,预留足够的TCP握手时间
- 给路由新增请求总超时配置,可根据业务实际耗时调整
- 可选调整HTTP连接管理器的空闲超时,避免长连接被意外断开
修改后的配置参考:
static_resources: listeners: - name: listener_0 address: socket_address: protocol: TCP address: 0.0.0.0 port_value: 10000 filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.config.filter.network.http_connection_manager.v2.HttpConnectionManager stat_prefix: ingress_http idle_timeout: 60s # 新增:空闲连接超时设为60秒 route_config: name: local_route virtual_hosts: - name: local_service domains: ["*"] routes: - match: prefix: "/a" route: prefix_rewrite: "/api" cluster: api_service timeout: 30s # 新增:单请求总超时设为30秒 # 新增:覆盖OpenIddict标准端点路由(如果你的端点没有挂在/a前缀下必须加) - match: prefix: "/.well-known" route: cluster: api_service timeout: 10s - match: prefix: "/connect" route: cluster: api_service timeout: 30s http_filters: - name: envoy.filters.http.router clusters: - name: api_service connect_timeout: 1s # 从0.25s调整为1s,预留足够连接建立时间 type: LOGICAL_DNS dns_lookup_family: V4_ONLY lb_policy: ROUND_ROBIN load_assignment: cluster_name: api_service endpoints: - lb_endpoints: - endpoint: address: socket_address: address: api port_value: 80
2. 连通性排查
如果调整超时后仍有504错误,需确认Envoy和上游服务的网络连通性:
- 进入Envoy实例执行
curl http://api/.well-known/openid-configuration,确认可以正常拿到OpenIddict的元数据响应 - 查看上游api服务的访问日志,确认请求是否已经转发到上游,排查上游服务本身是否存在处理过慢的问题
内容的提问来源于stack exchange,提问作者James Rhodes
相关产品推荐
相关产品推荐

