K8s集群部署UAA遇“子域未映射有效身份域”错误求助
Got it, let's break down what's happening here and walk through fixes—this is a common gotcha with UAA's identity zone system when using custom domains without cloud-managed DNS.
Core Problem: UAA's Identity Zone-Domain Binding
UAA uses identity zones to isolate tenants or domain-specific configurations. The default uaa identity zone only recognizes the domain/IP you specified when deploying UAA (via base_url). When you try to access it via uaa.mydoman.com, UAA can't find a zone mapped to that subdomain, hence the error: "The subdomain does not map to a valid identity zone". The readiness probe is failing for the exact same reason—it's hitting a URL that UAA doesn't associate with its default zone.
Step-by-Step Fixes
1. Align UAA's base_url with Your Custom Domain
First, make sure UAA's core configuration knows about your custom domain. If you deployed via Helm, check your values.yaml and set:
uaa: base_url: "https://uaa.mydoman.com:8443"
If you used raw manifests, look for the UAA_BASE_URL environment variable in the UAA Deployment and update it to match the above value. Apply the changes and restart the UAA Pods.
2. Map Your Custom Domain to the Default Identity Zone
You need to tell UAA that uaa.mydoman.com belongs to its default identity zone. Use the UAA API to update this (you'll need admin credentials):
- First, grab an admin access token (use your work node's internal IP here since the public IP might not be trusted yet):
curl -k -X POST https://<WORKER_INTERNAL_IP>:8443/oauth/token \ -u "admin:<YOUR_ADMIN_SECRET>" \ -d "grant_type=client_credentials" - Use the returned
access_tokento update the default zone's domain list:
Include all domains/IPs you might use to access UAA (internal, public, custom) in thecurl -k -X PUT https://<WORKER_INTERNAL_IP>:8443/identity-zones/uaa \ -H "Authorization: Bearer <YOUR_ACCESS_TOKEN>" \ -H "Content-Type: application/json" \ -d '{ "name": "uaa", "subdomain": "uaa", "domains": ["uaa.mydoman.com", "<WORKER_INTERNAL_IP>", "<WORKER_PUBLIC_IP>"], "description": "Default identity zone for on-prem cluster" }'domainsarray to avoid future issues.
3. Fix the Readiness Probe
The probe is failing because it's checking a URL that UAA doesn't recognize. Update the UAA Deployment's readiness probe to use your custom domain:
readinessProbe: httpGet: scheme: HTTPS path: /info port: 8443 host: uaa.mydoman.com # Add this line to match your custom domain initialDelaySeconds: 10 periodSeconds: 5
Alternatively, if you prefer to keep using the internal IP for the probe, just make sure that internal IP is in the domains list you updated in step 2—UAA will then accept the probe request.
4. Double-Check Hosts File Mappings
Ensure every VM in your cluster (control plane and workers) has the correct hosts entry:
<WORKER_PUBLIC_IP> uaa.mydoman.com
Also, verify your local machine (where you're testing the URL) has this entry too, so your browser can resolve the domain to the right IP.
Quick Verification
After making these changes:
- Restart UAA Pods to apply configs
- Test access to
https://uaa.mydoman.com:8443/info—it should return valid JSON instead of the identity zone error - Check the Pod status—readiness probes should now pass
内容的提问来源于stack exchange,提问作者rasadus

