Docker Compose下带Nginx的SonarQube配置Azure AD SAML认证报错排查
- SonarQube容器日志报错:
ERROR web[AXxUzLA1NnhuSmG1AAB5][c.o.s.a.SamlResponse] The response was received at http://sonarqube:9000/oauth2/callback/saml instead of https://sonarqube-hello.msappproxy.net/oauth2/callback/saml
ERROR web[AXxUzLA1NnhuSmG1AAB5][c.o.saml2.Auth] processResponse error. invalid_response
- 前端界面报错:

SAML身份认证协议要求身份提供商返回的响应接收地址必须和服务端预期的回调地址完全一致。当前SonarQube没有正确识别Nginx反向代理传递的公网域名与HTTPS协议,内部生成的预期回调地址为http://sonarqube:9000/oauth2/callback/saml,和Azure AD实际返回的回调地址https://sonarqube-hello.msappproxy.net/oauth2/callback/saml不匹配,因此触发校验失败报错。
1. 调整SonarQube配置
在你的docker-compose.yaml中为SonarQube服务添加以下环境变量,启用反向代理头识别并指定公网访问地址:
environment: # 填写SonarQube的公网访问根地址 - SONAR_SERVER_BASE_URL=https://sonarqube-hello.msappproxy.net # 启用反向代理转发头识别 - SONAR_WEB_FORWARDED_HEADERS_ENABLED=true
修改后重启SonarQube容器生效。
2. 补充Nginx配置
修改Nginx配置,补充正确的域名匹配规则,同时将80端口请求统一重定向到HTTPS避免异常访问:
# 80端口配置调整为跳转HTTPS server { listen 80; client_max_body_size 100M; server_name sonarqube-hello.msappproxy.net sonarqube.local; # 所有HTTP请求301跳转HTTPS return 301 https://$host$request_uri; } server { listen 443 ssl; ssl_certificate /etc/nginx/conf.d/ssl/server.pem; ssl_certificate_key /etc/nginx/conf.d/ssl/server.key; # 匹配公网访问域名 server_name sonarqube-hello.msappproxy.net; location / { proxy_pass http://sonarqube:9000; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto https; } }
修改后重载Nginx配置:nginx -s reload
3. 校验Azure AD配置
确认Azure AD侧SAML应用的回复URL(断言使用者服务URL) 填写的是https://sonarqube-hello.msappproxy.net/oauth2/callback/saml,和SonarQube预期的回调地址完全一致。
以上配置全部调整完成后重新触发SAML登录即可恢复正常。
内容的提问来源于stack exchange,提问作者Yahm Levi Firseck

