You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EC2部署Grafana v8配置Google OAuth2与HTTPS跳转异常求助

配置修正方案

1. 修正grafana.ini的[server]段配置

你出现路径重复拼接的核心原因是root_url错误填写了OAuth路径,该参数仅需填写你访问Grafana服务的根地址,无需附带任何子路径。调整后配置如下:

[server]
#Protocol (http, https, h2, socket)
protocol = https

#The ip address to bind to, empty will bind to all interfaces
;http_addr =

#The http port  to use
http_port = 3000

#The public facing domain name used to access grafana from a browser
domain = grafana.redacted.io

#Redirect to correct domain if host header does not match domain
#Prevents DNS rebinding attacks
;enforce_domain = false

# 此处填写你实际访问Grafana的根地址,必须带端口,结尾加斜杠
root_url = https://grafana.redacted.io:3000/

# 无反向代理、无子路径部署,保持false即可
serve_from_sub_path = false

2. 优化[auth.google]段配置

将scopes参数合并为一行,避免配置解析异常,其余参数保持不变:

[auth.google]
enabled = true
allow_sign_up = false
client_id = theClientIdFromGoogleCloudConsole
client_secret = theClientSecretFromGoogleCloudConsole
# 合并为同一行,用空格分隔
scopes = https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/userinfo.email
auth_url = https://accounts.google.com/o/oauth2/auth
token_url = https://accounts.google.com/o/oauth2/token
api_url = https://www.googleapis.com/oauth2/v1/userinfo
allowed_domains = redacted.io

3. 修正Google Cloud控制台配置

所有授权地址必须和你实际访问的端口保持一致,调整为:

  • 已授权JS来源:https://grafana.redacted.io:3000
  • 已授权重定向URI:https://grafana.redacted.io:3000/login/google(注意结尾不要加斜杠)

4. 生效验证

修改完成后重启Grafana服务,清空浏览器缓存或使用无痕窗口访问https://grafana.redacted.io:3000即可正常走Google OAuth登录流程。


内容的提问来源于stack exchange,提问作者ABails

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 06:54:02