Keycloak Gatekeeper上游请求10秒超时致502,如何调整至30秒?
Yep, you’re spot on—Keycloak Gatekeeper does have a default 10-second upstream request timeout, which is exactly why you’re seeing that HTTP 502 error when your Kibana queries run longer than 10 seconds. The gatekeeper cuts off the connection once this threshold is hit, while direct access to Kibana uses its own 30-second timeout. Here’s how to adjust this setting for your Helm-based deployment:
1. Understand the Configurable Parameter
The Helm Chart you’re using exposes an upstreamTimeout parameter that maps directly to Gatekeeper’s native --upstream-timeout flag. This controls the maximum time the gatekeeper will wait for a response from upstream services (like Kibana), measured in seconds.
2. Adjust the Timeout (Two Methods)
Method 1: Set During Installation
If you’re installing the gatekeeper for the first time, include the timeout parameter in your helm install command:
helm install keycloak-gatekeeper mvitale1989/keycloak-gatekeeper \ --set upstreamTimeout=30 \ # Add your existing config params here (clientID, clientSecret, discoveryURL, etc.)
Method 2: Update an Existing Deployment
If the gatekeeper is already running, use helm upgrade to modify the setting:
helm upgrade keycloak-gatekeeper mvitale1989/keycloak-gatekeeper \ --set upstreamTimeout=30
3. Verify the Change Took Effect
After applying the update, confirm the timeout is set correctly by checking the gatekeeper pod’s startup arguments:
kubectl exec -it <your-gatekeeper-pod-name> -- ps aux
You should see --upstream-timeout=30 listed in the command line arguments.
Once verified, test your long-running Kibana queries again—they should now run up to 30 seconds before timing out, matching Kibana’s native timeout behavior.
For more granular control (if needed later), the chart also supports separate upstreamConnectTimeout (for connection establishment) and upstreamReadTimeout (for data transfer) parameters, but adjusting upstreamTimeout will cover your current use case.
内容的提问来源于stack exchange,提问作者Bate Stancho

