【问题标题】:Configure istio for container that requires basic auth为需要基本身份验证的容器配置 istio
【发布时间】:2020-07-31 01:28:16
【问题描述】:

我有一个运行需要基本身份验证的 http/rest 服务的容器。 我已将 istio 配置为服务对这个容器的请求。 该服务在没有 istio 的集群上正常运行。

使用 curl 查询服务时, istio-envoy 返回状态 401 和消息“需要完整身份验证才能访问此资源”。

我可以通过登录容器并在没有提供身份验证详细信息的情况下查询 localhost 来获得相同的错误。 因此,从各方面来看,似乎 istio 并没有在基本身份验证标头上进行转发。

容器日志从不确认登录尝试,我只在特使容器中看到 401 日志消息。

我尝试过启用和禁用 mtls。 网关监听443端口,转发到80端口的服务

如何配置 istio 以将基本身份验证转发到我的容器

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: mfm-gateway
  namespace: mfm-istio
spec:
  selector:
    istio: ingressgateway
  servers:
  - port:
      number: 443
      name: https
      protocol: HTTPS
    hosts:
      - dev-mfm-istio.testing.co.uk
    tls:
      mode: SIMPLE
      serverCertificate: /etc/istio/testing-co-uk-certs/tls.crt
      privateKey: /etc/istio/testing-co-uk-certs/tls.key
      caCertificates: /etc/istio/testing-co-uk-certs/ca.crt
      httpsRedirect: true
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: mfm-virtualservice
  namespace: mfm-istio
spec:
  hosts:
  - "dev-mfm-istio.testing.co.uk"
  gateways:
  - mfm-istio/mfm-gateway
  http:
  - name: "Auth"
    match:
    -  uri:
         prefix: "/auth"
    route:
    - destination:
        host: authentication-service.mfm-istio.svc.cluster.local
        port:
          number: 80
  - name: "Base"
    route:
    - destination:
        host: web-application-service.mfm-istio.svc.cluster.local
        port:
          number: 80
localhost: curl -ik https://dev-mfm-istio.testing.co.uk/auth/oauth/token -d username=admin -d password=lolpassword -d grant_type=password -d scope=a -H -u admin

HTTP/2 401 
pragma: no-cache
www-authenticate: Bearer realm="authentication-service", error="unauthorized", error_description="Full authentication is required to access this resource"
cache-control: no-store
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: DENY
content-type: application/json;charset=UTF-8
date: Fri, 17 Apr 2020 13:51:43 GMT
x-envoy-upstream-service-time: 4
server: istio-envoy

{"error":"unauthorized","error_description":"Full authentication is required to access this resource"}

【问题讨论】:

  • 据我所知,您使用带有 auth0 的 jwt 作为身份验证器,对吗?您是否按照任何教程使其工作?根据github 上的 istio 代码,jwt 状态似乎存在一些问题。您可以在过滤器中打开调试级别以查看问题所在。关注对话here。
  • 感谢您的回复。是的,容器通过 spring boot 实现了 jwt。但这与 istio 是分开的,我不是特别想在 istio 中实现 jwt 或让 istio 进行身份验证,我希望容器来处理身份验证,但 sidecar 似乎不合作。我不知道这是一个限制还是我对 istio 的理解不够好
  • 没有 istio 也能用?您能否尝试使用您的发行者和 jwkUri 为您的网关添加提到的 here 策略?有istio documentation。如果这不起作用,我宁愿专注于通过 spring boot 实现 jwt。您是否尝试从 curl 中找到错误的解决方案?例如here?
  • 这可以在没有 istio 的情况下工作,也可以在 linkerd 上工作。一个难点是 jwkuri,我们不能公开一个,我不希望 istio 进行身份验证,它需要由应用程序处理。几乎可以肯定问题出在特使身上,我不愿意为如此简单的事情添加复杂的过滤器,但这似乎是唯一的解决方案
  • AFAIK 如果添加 policy,它定义了工作负载可以接受哪些身份验证方法,如果经过身份验证,哪个方法/证书将设置请求主体,它应该允许 jwt from springboot 在 istio 中进行身份验证。检查this。

标签: istio


【解决方案1】:

AFAIK ff 你的容器通过 spring boot 实现了 jwt,与 istio 分开,你应该在 istio 中添加policy,它定义了工作负载可以接受哪些身份验证方法,如果经过身份验证,哪个方法/证书将设置请求主体。

它应该允许来自 springboot 的 jwt 在 istio 中进行身份验证。


关于 jwt 的 istio 策略的有用链接。


关于错误的有用链接

{"error":"unauthorized","error_description":"访问此资源需要完全认证"}


要检查导致 401 的确切原因,在使用 JWT 身份验证时,您可以关注此github issue。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2021-10-10
    • 2020-11-21
    • 1970-01-01
    • 2021-07-19
    • 2011-05-10
    • 1970-01-01
    • 1970-01-01
    • 2013-07-07
    相关资源
    最近更新 更多