【发布时间】:2020-07-31 01:28:16
【问题描述】:
我有一个运行需要基本身份验证的 http/rest 服务的容器。 我已将 istio 配置为服务对这个容器的请求。 该服务在没有 istio 的集群上正常运行。
使用 curl 查询服务时, istio-envoy 返回状态 401 和消息“需要完整身份验证才能访问此资源”。
我可以通过登录容器并在没有提供身份验证详细信息的情况下查询 localhost 来获得相同的错误。 因此,从各方面来看,似乎 istio 并没有在基本身份验证标头上进行转发。
容器日志从不确认登录尝试,我只在特使容器中看到 401 日志消息。
我尝试过启用和禁用 mtls。 网关监听443端口,转发到80端口的服务
如何配置 istio 以将基本身份验证转发到我的容器
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
name: mfm-gateway
namespace: mfm-istio
spec:
selector:
istio: ingressgateway
servers:
- port:
number: 443
name: https
protocol: HTTPS
hosts:
- dev-mfm-istio.testing.co.uk
tls:
mode: SIMPLE
serverCertificate: /etc/istio/testing-co-uk-certs/tls.crt
privateKey: /etc/istio/testing-co-uk-certs/tls.key
caCertificates: /etc/istio/testing-co-uk-certs/ca.crt
httpsRedirect: true
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: mfm-virtualservice
namespace: mfm-istio
spec:
hosts:
- "dev-mfm-istio.testing.co.uk"
gateways:
- mfm-istio/mfm-gateway
http:
- name: "Auth"
match:
- uri:
prefix: "/auth"
route:
- destination:
host: authentication-service.mfm-istio.svc.cluster.local
port:
number: 80
- name: "Base"
route:
- destination:
host: web-application-service.mfm-istio.svc.cluster.local
port:
number: 80
localhost: curl -ik https://dev-mfm-istio.testing.co.uk/auth/oauth/token -d username=admin -d password=lolpassword -d grant_type=password -d scope=a -H -u admin
HTTP/2 401
pragma: no-cache
www-authenticate: Bearer realm="authentication-service", error="unauthorized", error_description="Full authentication is required to access this resource"
cache-control: no-store
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: DENY
content-type: application/json;charset=UTF-8
date: Fri, 17 Apr 2020 13:51:43 GMT
x-envoy-upstream-service-time: 4
server: istio-envoy
{"error":"unauthorized","error_description":"Full authentication is required to access this resource"}
【问题讨论】:
-
感谢您的回复。是的,容器通过 spring boot 实现了 jwt。但这与 istio 是分开的,我不是特别想在 istio 中实现 jwt 或让 istio 进行身份验证,我希望容器来处理身份验证,但 sidecar 似乎不合作。我不知道这是一个限制还是我对 istio 的理解不够好
-
没有 istio 也能用?您能否尝试使用您的发行者和 jwkUri 为您的网关添加提到的 here 策略?有istio documentation。如果这不起作用,我宁愿专注于通过 spring boot 实现 jwt。您是否尝试从 curl 中找到错误的解决方案?例如here?
-
这可以在没有 istio 的情况下工作,也可以在 linkerd 上工作。一个难点是 jwkuri,我们不能公开一个,我不希望 istio 进行身份验证,它需要由应用程序处理。几乎可以肯定问题出在特使身上,我不愿意为如此简单的事情添加复杂的过滤器,但这似乎是唯一的解决方案
标签: istio