You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak Gatekeeper上游请求10秒超时致502,如何调整至30秒?

Fixing Keycloak Gatekeeper 10-Second Timeout for Long Kibana Queries

Yep, you’re spot on—Keycloak Gatekeeper does have a default 10-second upstream request timeout, which is exactly why you’re seeing that HTTP 502 error when your Kibana queries run longer than 10 seconds. The gatekeeper cuts off the connection once this threshold is hit, while direct access to Kibana uses its own 30-second timeout. Here’s how to adjust this setting for your Helm-based deployment:

1. Understand the Configurable Parameter

The Helm Chart you’re using exposes an upstreamTimeout parameter that maps directly to Gatekeeper’s native --upstream-timeout flag. This controls the maximum time the gatekeeper will wait for a response from upstream services (like Kibana), measured in seconds.

2. Adjust the Timeout (Two Methods)

Method 1: Set During Installation

If you’re installing the gatekeeper for the first time, include the timeout parameter in your helm install command:

helm install keycloak-gatekeeper mvitale1989/keycloak-gatekeeper \
  --set upstreamTimeout=30 \
  # Add your existing config params here (clientID, clientSecret, discoveryURL, etc.)

Method 2: Update an Existing Deployment

If the gatekeeper is already running, use helm upgrade to modify the setting:

helm upgrade keycloak-gatekeeper mvitale1989/keycloak-gatekeeper \
  --set upstreamTimeout=30

3. Verify the Change Took Effect

After applying the update, confirm the timeout is set correctly by checking the gatekeeper pod’s startup arguments:

kubectl exec -it <your-gatekeeper-pod-name> -- ps aux

You should see --upstream-timeout=30 listed in the command line arguments.

Once verified, test your long-running Kibana queries again—they should now run up to 30 seconds before timing out, matching Kibana’s native timeout behavior.

For more granular control (if needed later), the chart also supports separate upstreamConnectTimeout (for connection establishment) and upstreamReadTimeout (for data transfer) parameters, but adjusting upstreamTimeout will cover your current use case.

内容的提问来源于stack exchange,提问作者Bate Stancho

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 09:05:08