You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用K6 v0.20.0-dev-dccb254测试NTLM认证:首请求成功后遇异常

Troubleshooting NTLM Authentication Failures in k6 v0.20.0-dev-dccb254

Let's start by grounding ourselves in your setup:

  • You're running k6 v0.20.0-dev-dccb254
  • Test command: bin\k6.exe run --vus 3 --duration 30s scripts/getOrder.js
  • Your test script:
import http from "k6/http"; 
import { check, sleep } from "k6"; 
export default function() { 
  let res = http.get("http://user:password@localhost:8247/orders/2377", {auth: "ntlm"}); 
  console.log("Status code: " + res.status); 
  check(res, { "status was 200": (r) => r.status == 200 }); 
  sleep(1); 
}; 

You noted the first request works fine, but subsequent ones throw exceptions—here are the most likely culprits and how to fix them:

Common Causes & Fixes

1. Connection Pooling Conflicts with NTLM

NTLM authentication is tied to a specific persistent connection, and older k6 builds (especially dev versions like yours) had known issues with connection pooling for NTLM. When subsequent requests try to reuse an already authenticated connection, the server often rejects it because NTLM doesn't support re-authenticating on the same connection.

Quick Fix:
Disable connection pooling for your request by adding the noKeepAlive option. This forces k6 to create a fresh connection each time:

let res = http.get("http://user:password@localhost:8247/orders/2377", {
  auth: "ntlm",
  noKeepAlive: true
});

2. VU Auth State Leaks

NTLM relies on per-connection context, and if k6 isn't properly isolating authentication state per VU (a bug in older dev builds), requests from the same VU might try to use an invalidated session.

Fix:
Either explicitly handle auth per VU (your script already runs per iteration, which helps) or upgrade to a stable k6 release. Versions v0.30 and above have much better NTLM handling and VU state isolation.

3. Server-Side NTLM Limits

Most servers (like IIS) enforce limits on concurrent NTLM authenticated sessions or have short connection timeouts. With 3 VUs hitting the server every second, you might be hitting these thresholds.

Fixes to Try:

  • Check your server's NTLM config: look for settings like max concurrent connections or auth session timeouts and adjust them if possible.
  • Slow down your request rate by increasing the sleep duration (try sleep(2) instead of sleep(1)).
  • Test with just 1 VU first (--vus 1)—if the issue goes away, you know it's a concurrency-related limit.

4. Credential Encoding Problems

If your username includes a domain (like domain\user) or special characters, embedding them directly in the URL can cause encoding issues that break authentication after the first request.

Fix:
Use the explicit auth object instead of URL-embedded credentials to ensure proper encoding:

let res = http.get("http://localhost:8247/orders/2377", {
  auth: {
    type: "ntlm",
    user: "domain\\user", // Remember to escape backslashes
    pass: "password"
  }
});

Debugging Steps to Pinpoint the Exact Issue

  • Enable full HTTP debug logging in k6 to see what's happening under the hood:
    bin\k6.exe run --vus 3 --duration 30s --http-debug="full" scripts/getOrder.js
    
    Look for 401 Unauthorized responses or connection reset errors—this will tell you if it's an auth failure or a connection issue.
  • Test with a single VU to rule out concurrency problems.
  • Swap your dev build for a stable k6 release (like v0.45.1) to eliminate bugs specific to the dev version.

内容的提问来源于stack exchange,提问作者Marian Busila

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 04:26:49