oauth2_proxy对接Google SSO向Kibana传Basic Auth时变量为空如何解决
问题核心原因
- 你用错了变量:
$remote_user仅在Nginx自身执行基础认证(auth_basic)或ngx_http_auth_request_module完成认证后才会自动赋值,当前场景下该变量无值是正常的。 $upstream_http_*前缀的变量是用来读取当前Nginx转发请求到上游服务后,上游返回的响应头,你要读取的是oauth2_proxy转发给8080 Nginx的入站请求头,应该用$http_*前缀的变量。
修正方案
oauth2_proxy开启--set-xauthrequest=true后,会自动给上游请求添加X-Auth-Request-User(用户名)、X-Auth-Request-Email(完整邮箱)两个请求头,你直接在8080端口的Nginx配置中读取对应头即可。
修正后的kibana.conf示例:
server { listen 8080; # 如果需要从邮箱中提取@前面的部分作为用户名,可以提前加map映射 map $http_x_auth_request_email $remote_user_name { ~^(?P<user>[^@]+)@.*$ $user; default $http_x_auth_request_user; } location / { proxy_pass http://127.0.0.1:5601; # 直接用oauth2_proxy传过来的X-Auth-Request-User或者提取后的用户名 set $auth_string "${remote_user_name}:<my_strong-password>"; set_encode_base64 $encoded_string $auth_string; proxy_set_header Authorization "Basic $encoded_string"; #处理登出跳转 rewrite /login https://example.com/oauth2/sign_in redirect; } }
额外排查项
如果修改后还是取不到值,按优先级检查:
- 确认oauth2_proxy启动参数中
--pass-user-headers=true和--set-xauthrequest=true两个参数确实生效,没有拼写错误 - 在8080 Nginx的access_log中添加
$http_x_auth_request_user变量打印日志,确认头确实被传递过来了,示例日志配置:
log_format auth_debug '$remote_addr - $http_x_auth_request_user - $http_x_auth_request_email - [$time_local] "$request" $status $body_bytes_sent'; access_log /var/log/nginx/kibana_access.log auth_debug;
- 确认你配置的用户名+固定密码组合确实匹配Kibana的基础认证规则。
内容的提问来源于stack exchange,提问作者Gianluca
相关产品推荐
相关产品推荐

