You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K8s集群部署UAA遇“子域未映射有效身份域”错误求助

Troubleshooting UAA Identity Zone & Readiness Probe Issues on Your On-Prem K8s Cluster

Got it, let's break down what's happening here and walk through fixes—this is a common gotcha with UAA's identity zone system when using custom domains without cloud-managed DNS.

Core Problem: UAA's Identity Zone-Domain Binding

UAA uses identity zones to isolate tenants or domain-specific configurations. The default uaa identity zone only recognizes the domain/IP you specified when deploying UAA (via base_url). When you try to access it via uaa.mydoman.com, UAA can't find a zone mapped to that subdomain, hence the error: "The subdomain does not map to a valid identity zone". The readiness probe is failing for the exact same reason—it's hitting a URL that UAA doesn't associate with its default zone.

Step-by-Step Fixes

1. Align UAA's base_url with Your Custom Domain

First, make sure UAA's core configuration knows about your custom domain. If you deployed via Helm, check your values.yaml and set:

uaa:
  base_url: "https://uaa.mydoman.com:8443"

If you used raw manifests, look for the UAA_BASE_URL environment variable in the UAA Deployment and update it to match the above value. Apply the changes and restart the UAA Pods.

2. Map Your Custom Domain to the Default Identity Zone

You need to tell UAA that uaa.mydoman.com belongs to its default identity zone. Use the UAA API to update this (you'll need admin credentials):

  • First, grab an admin access token (use your work node's internal IP here since the public IP might not be trusted yet):
    curl -k -X POST https://<WORKER_INTERNAL_IP>:8443/oauth/token \
      -u "admin:<YOUR_ADMIN_SECRET>" \
      -d "grant_type=client_credentials"
    
  • Use the returned access_token to update the default zone's domain list:
    curl -k -X PUT https://<WORKER_INTERNAL_IP>:8443/identity-zones/uaa \
      -H "Authorization: Bearer <YOUR_ACCESS_TOKEN>" \
      -H "Content-Type: application/json" \
      -d '{
        "name": "uaa",
        "subdomain": "uaa",
        "domains": ["uaa.mydoman.com", "<WORKER_INTERNAL_IP>", "<WORKER_PUBLIC_IP>"],
        "description": "Default identity zone for on-prem cluster"
      }'
    
    Include all domains/IPs you might use to access UAA (internal, public, custom) in the domains array to avoid future issues.

3. Fix the Readiness Probe

The probe is failing because it's checking a URL that UAA doesn't recognize. Update the UAA Deployment's readiness probe to use your custom domain:

readinessProbe:
  httpGet:
    scheme: HTTPS
    path: /info
    port: 8443
    host: uaa.mydoman.com  # Add this line to match your custom domain
  initialDelaySeconds: 10
  periodSeconds: 5

Alternatively, if you prefer to keep using the internal IP for the probe, just make sure that internal IP is in the domains list you updated in step 2—UAA will then accept the probe request.

4. Double-Check Hosts File Mappings

Ensure every VM in your cluster (control plane and workers) has the correct hosts entry:

<WORKER_PUBLIC_IP>  uaa.mydoman.com

Also, verify your local machine (where you're testing the URL) has this entry too, so your browser can resolve the domain to the right IP.

Quick Verification

After making these changes:

  1. Restart UAA Pods to apply configs
  2. Test access to https://uaa.mydoman.com:8443/info—it should return valid JSON instead of the identity zone error
  3. Check the Pod status—readiness probes should now pass

内容的提问来源于stack exchange,提问作者rasadus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:28:33