You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak作为Traefik认证服务登出后存在访问延迟问题求助

Fixing Traefik's 30s Access Delay After Keycloak Logout

This delay you're seeing is almost certainly caused by Traefik's ForwardAuth middleware caching successful authentication responses by default. Even after you log out of Keycloak, Traefik keeps using the cached "allowed" result for a short period (usually ~30s) before revalidating with Keycloak. Here's how to fix it:

1. Disable or Shorten ForwardAuth Cache

The core fix is to adjust the caching behavior of your Keycloak-auth ForwardAuth middleware. Depending on how you've configured Traefik, use one of these approaches:

If using Docker Labels

Add these labels to your Traefik service or middleware definition:

traefik.http.middlewares.keycloak-auth.forwardauth.cache: "false"
# OR, if you want a shorter cache window instead of disabling entirely
traefik.http.middlewares.keycloak-auth.forwardauth.cacheDuration: "5s"

Disabling cache (cache: "false") forces Traefik to validate every request against Keycloak immediately, eliminating the delay. A short cache duration is a compromise if you want minimal performance impact but near-instant logout behavior.

If using a Dynamic Config File (YAML/JSON)

Update your middleware config to include the cache settings:

http:
  middlewares:
    keycloak-auth:
      forwardAuth:
        address: "http://keycloak-auth-service:8080/auth/realms/your-realm/protocol/openid-connect/auth"
        # Add these lines
        cache: false
        # cacheDuration: "5s" # Alternative to disabling

Even with cache disabled, make sure your Keycloak logout properly invalidates session cookies Traefik relies on:

  • Confirm Keycloak clears KEYCLOAK_SESSION and KEYCLOAK_SESSION_LEGACY cookies automatically (check your browser's dev tools to verify).
  • Redirect users back to your application's logout page after Keycloak logout to explicitly clear any local cookies that might interfere.

3. Verify ForwardAuth Request Validation

Ensure your ForwardAuth setup forwards the user's session cookies to Keycloak for every validation check. Add this to your config:

traefik.http.middlewares.keycloak-auth.forwardauth.authRequestHeaders: "Cookie"

This guarantees Traefik sends the user's current session state to Keycloak, so invalid sessions are detected immediately.

Testing the Fix

After applying changes:

  1. Restart Traefik and Keycloak to load the new middleware config.
  2. Log in to your protected service, trigger a Keycloak logout, then immediately try accessing the service again—you should be redirected to the login page right away, no 30s delay.

内容的提问来源于stack exchange,提问作者mostafashr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:30:04