使用Helm部署Kafka Connector时Strimzi无法解析Secret报错
问题重现
创建Debezium PostgreSQL源连接器时,Kafka Connect Pod抛出以下错误:
ERROR Uncaught exception in REST call to /connectors/pg-source-connector/config (org.apache.kafka.connect.runtime.rest.errors.ConnectExceptionMapper)
org.apache.kafka.common.config.ConfigException:
Invalid path . It has to be in format/ (or for default namespace).
at io.strimzi.kafka.KubernetesResourceIdentifier.fromConfigString(KubernetesResourceIdentifier.java:33)
同时发现容器内/opt/kafka/secrets目录不存在,此前使用KubernetesEnvProvider也遇到过类似解析问题。
错误原因分析
Secret引用格式错误:
Strimzi的KubernetesSecretConfigProvider要求的引用格式为:- 默认命名空间:
${secrets:<secret-name>:<key>} - 指定命名空间:
${secrets:<namespace>/<secret-name>:<key>}
当前连接器配置中使用了${secrets:kc-namespace/db-creds/password},用斜杠分隔Secret和key,导致解析器将整个字符串识别为无效路径。
- 默认命名空间:
只读根文件系统限制:
容器配置了readOnlyRootFilesystem: true,但未挂载可写目录到/opt/kafka/secrets,Strimzi运行时可能需要该目录存储临时文件,引发目录不存在问题。权限缺失(潜在风险):
Kafka Connect的ServiceAccount可能缺少读取目标Secret的RBAC权限,导致无法获取凭据(当前错误未直接体现,但需提前排查)。
解决方案
1. 修正连接器的Secret引用格式
修改pg-source-connector.yaml中的数据库凭据配置,将最后一个斜杠替换为冒号:
spec: config: # ... 其他配置 database.password: "${secrets:kc-namespace/db-creds:password}" database.user: "${secrets:kc-namespace/db-creds:username}"
2. 配置RBAC权限确保Secret读取权限
创建Role和RoleBinding,允许Kafka Connect的ServiceAccount读取kc-namespace下的Secret:
apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: kc-secret-reader namespace: kc-namespace rules: - apiGroups: [""] resources: ["secrets"] verbs: ["get", "list"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: kc-secret-reader-binding namespace: kc-namespace subjects: - kind: ServiceAccount name: kc-cluster-connect # Strimzi默认生成的ServiceAccount,格式为<KafkaConnect名称>-connect namespace: kc-namespace roleRef: kind: Role name: kc-secret-reader apiGroup: rbac.authorization.k8s.io
3. 调整容器配置解决目录不存在问题
在kafka-connect.yaml中添加emptyDir挂载到/opt/kafka/secrets,适配只读根文件系统:
apiVersion: kafka.strimzi.io/v1beta2 kind: KafkaConnect metadata: name: kc-cluster annotations: strimzi.io/use-connector-resources: "true" spec: # ... 其他配置 template: connectContainer: securityContext: # ... 现有安全上下文配置 volumeMounts: - name: secrets-dir mountPath: /opt/kafka/secrets volumes: - name: secrets-dir emptyDir: {}
验证步骤
- 应用所有修改后的配置文件:
kubectl apply -f kafka-connect.yaml -n kc-namespace kubectl apply -f pg-source-connector.yaml -n kc-namespace kubectl apply -f rbac-config.yaml -n kc-namespace # 替换为你的RBAC配置文件名 - 查看Kafka Connect Pod日志,确认错误消失:
kubectl logs -f <kc-cluster-connect-pod-name> -n kc-namespace - 检查连接器状态:
确认kubectl get kafkaconnector pg-source-connector -n kc-namespace -o yamlstatus.conditions中READY状态为True。
内容的提问来源于stack exchange,提问作者Simba

