WSO2分布式部署问题:无法通过Gateway访问已发布API
我来帮你一步步解决这两个核心问题——先搞定Gateway访问API报404的问题,再处理SSL密钥库的配置:
一、解决Gateway访问API出现404的问题
API在Publisher发布后却无法通过Gateway访问,大概率是API没有同步到Gateway节点,或者Gateway的集群配置存在问题,按以下步骤排查:
1. 确认Publisher与Gateway的同步配置
首先检查Publisher的deployment.toml(位于<PUBLISHER_HOME>/repository/conf),确保已正确指向Gateway的服务地址:
[[apim.gateway.environment]] name = "Production" type = "production" display_name = "Production Gateway" description = "Production Gateway" service_url = "https://server2:9443/services/" username = "${admin.username}" password = "${admin.password}" ws_endpoint = "ws://server2:9099" wss_endpoint = "wss://server2:8099" http_endpoint = "http://server2:8280" https_endpoint = "https://server2:8243"
关键注意点:service_url必须指向Gateway的管理端口(默认9443),https_endpoint要和你访问的地址完全一致。
同时检查Gateway的deployment.toml,确保它能连接到APIM的共享数据库(和Publisher/Store共用):
[apim.gateway] gateway_label = "Production" [registry] url = "jdbc:mysql://<你的数据库地址>:<端口>/apimgt_db?useSSL=false" username = "${db.username}" password = "${db.password}" [user_store] type = "database"
Gateway需要从共享数据库获取已发布的API元数据,所以数据库连接必须正常。
2. 验证API的部署状态
- 登录Publisher,进入你的TEST API详情页,切换到「Deployments」标签,确认API已经部署到
server2对应的Production环境。如果没部署,点击「Deploy」按钮手动部署。 - 登录Gateway的Carbon控制台(
https://server2:9443/carbon),进入「API Management」→「APIs」,查看是否能看到你的TEST API。如果看不到,说明同步失败:- 检查Publisher和Gateway之间的网络连通性(9443端口是否开放)
- 确认配置中的admin账号密码正确,且拥有足够权限
3. 检查Gateway的API验证配置
如果API已在Gateway中显示但仍报404,检查<GW_HOME>/repository/conf/api-manager/api.xml的以下配置,确保Gateway能和IS交互验证密钥:
<APIKeyValidator> <ServerURL>https://server1:9443/services/</ServerURL> <Username>${admin.username}</Username> <Password>${admin.password}</Password> </APIKeyValidator> <APIGateway> <Environments> <Environment type="production" api-console="true"> <ServerURL>https://server2:9443/services/</ServerURL> <Username>${admin.username}</Username> <Password>${admin.password}</Password> <GatewayEndpoint>https://server2:8243,http://server2:8280</GatewayEndpoint> </Environment> </Environments> </APIGateway>
确认APIKeyValidator的ServerURL指向你的IS节点(server1),保证Gateway能正常验证API密钥。
二、生成SSL密钥库用于测试API
测试环境下可以生成自签名证书(生产环境请务必使用CA签发的正式证书),步骤如下:
1. 使用keytool生成自签名密钥库
确保服务器已安装JDK,执行以下命令:
keytool -genkey -alias wso2carbon -keyalg RSA -keysize 2048 -storetype JKS -keystore wso2carbon.jks -storepass wso2carbon -validity 3650
- 按照提示输入证书信息(测试环境可随意填写,但域名建议填
server2或Gateway的实际域名) - 命令执行后会生成
wso2carbon.jks密钥库,默认密码为wso2carbon(可自定义)
2. 替换Gateway的密钥库
- 将生成的
wso2carbon.jks复制到<GW_HOME>/repository/resources/security目录,替换原文件(建议先备份原密钥库) - 修改Gateway的
deployment.toml,确保密钥库配置匹配:[keystore.primary] file_name = "wso2carbon.jks" password = "wso2carbon" alias = "wso2carbon" key_password = "wso2carbon"
3. 重启Gateway服务
重启Gateway后,新的SSL密钥就会生效。测试访问时浏览器会提示证书不安全,选择「继续访问」即可(仅测试环境这么做)。
内容的提问来源于stack exchange,提问作者Roman Pankratov

