AWS EC2部署Grafana v8配置Google OAuth2与HTTPS跳转异常求助
配置修正方案
1. 修正grafana.ini的[server]段配置
你出现路径重复拼接的核心原因是root_url错误填写了OAuth路径,该参数仅需填写你访问Grafana服务的根地址,无需附带任何子路径。调整后配置如下:
[server] #Protocol (http, https, h2, socket) protocol = https #The ip address to bind to, empty will bind to all interfaces ;http_addr = #The http port to use http_port = 3000 #The public facing domain name used to access grafana from a browser domain = grafana.redacted.io #Redirect to correct domain if host header does not match domain #Prevents DNS rebinding attacks ;enforce_domain = false # 此处填写你实际访问Grafana的根地址,必须带端口,结尾加斜杠 root_url = https://grafana.redacted.io:3000/ # 无反向代理、无子路径部署,保持false即可 serve_from_sub_path = false
2. 优化[auth.google]段配置
将scopes参数合并为一行,避免配置解析异常,其余参数保持不变:
[auth.google] enabled = true allow_sign_up = false client_id = theClientIdFromGoogleCloudConsole client_secret = theClientSecretFromGoogleCloudConsole # 合并为同一行,用空格分隔 scopes = https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/userinfo.email auth_url = https://accounts.google.com/o/oauth2/auth token_url = https://accounts.google.com/o/oauth2/token api_url = https://www.googleapis.com/oauth2/v1/userinfo allowed_domains = redacted.io
3. 修正Google Cloud控制台配置
所有授权地址必须和你实际访问的端口保持一致,调整为:
- 已授权JS来源:
https://grafana.redacted.io:3000 - 已授权重定向URI:
https://grafana.redacted.io:3000/login/google(注意结尾不要加斜杠)
4. 生效验证
修改完成后重启Grafana服务,清空浏览器缓存或使用无痕窗口访问https://grafana.redacted.io:3000即可正常走Google OAuth登录流程。
内容的提问来源于stack exchange,提问作者ABails
相关产品推荐
相关产品推荐

