使用 docker 启动 quarkus 时,错误 OIDC 服务器在“quarkus.oidc.auth-server-url”URL 处不可用

Chr*_*chl 5 java config docker docker-compose quarkus

当我在 docker compose 中使用 Quarkus 和 Keycloak 时,我遇到了一个非常令人困惑的问题。当我设置环境变量来覆盖开发配置(又名quarkus.oidc.auth-server-urlquarkus.datasource.jdbc.url),然后尝试运行 docker-compose 文件时,会出现错误消息。它说我的 auth-server-url 不正确,但我在 auth-server-url 中没有看到拼写错误或错误。

错误信息:

dbk-core    | exec java -Dquarkus.http.host=0.0.0.0 -Djava.util.logging.manager=org.jboss.logmanager.LogManager -XX:+ExitOnOutOfMemoryError -cp . -jar /deployments/app.jar
dbk-core    | __  ____  __  _____   ___  __ ____  ______ 
dbk-core    |  --/ __ \/ / / / _ | / _ \/ //_/ / / / __/ 
dbk-core    |  -/ /_/ / /_/ / __ |/ , _/ ,< / /_/ /\ \   
dbk-core    | --\___\_\____/_/ |_/_/|_/_/|_|\____/___/   
dbk-core    | 11:32:08 ERROR [io.qu.application] (main) Failed to start application (with profile prod): io.quarkus.oidc.OIDCException: OIDC server is not available at the 'quarkus.oidc.auth-server-url' URL. Please make sure it is correct. Note it has to end with a realm value if you work with Keycloak, for example: 'https://localhost:8180/auth/realms/quarkus'
..........
dbk-core    |   at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30)
dbk-core    |   at java.base/java.lang.Thread.run(Thread.java:834)
dbk-core    | Caused by: io.netty.channel.AbstractChannel$AnnotatedConnectException: Connection refused: keycloak/172.24.0.3:8180
dbk-core    | Caused by: java.net.ConnectException: Connection refused
dbk-core    |   at java.base/sun.nio.ch.SocketChannelImpl.checkConnect(Native Method)
Run Code Online (Sandbox Code Playgroud)

我的 docker-compose.yml

services:
database:
build:
   context: ./db-init
   dockerfile: Dockerfile.db
container_name: dbk-database
ports:
- 5432:5432
volumes:
- "$HOME/databases/postgres:/var/lib/postgresql/data"
keycloak:
 image: quay.io/keycloak/keycloak:latest
 container_name: dbk-keycloak
 environment:
  DB_VENDOR: POSTGRES
  DB_ADDR: database
  DB_DATABASE: keycloak_database
  DB_USER: keycloak
  DB_SCHEMA: public
  DB_PASSWORD: keycloak
  KEYCLOAK_USER: admin
  KEYCLOAK_PASSWORD: admin
  ports:
  - 8180:8080
  depends_on:
  - database
core:
 image: registry.gitlab.com/baudoku/dbk-core:dev
 container_name: dbk-core
 environment:
   QUARKUS_OIDC_AUTH_SERVER_URL: http://keycloak:8180/auth/realms/dbk
   QUARKUS_DATASOURCE_JDBC_URL: jdbc:postgresql://database:5432/dbk_core_database
 depends_on:
 - database
 - keycloak
 ports:
 - 8080:8080
Run Code Online (Sandbox Code Playgroud)

我的 Quarkus application.properties:

quarkus.oidc.auth-server-url=http://localhost:8180/auth/realms/dbk
quarkus.oidc.client-id=dbk-core
quarkus.oidc.credentials.secret=3a17e7e8-0099-49d9-8e33-d0eb954daba0

quarkus.datasource.db-kind = postgresql
quarkus.datasource.username = core
quarkus.datasource.password = core
quarkus.datasource.jdbc.url = jdbc:postgresql://localhost:5432/dbk_core_database
Run Code Online (Sandbox Code Playgroud)

当我使用 docker 启动 keycloak 服务并使用 ./mvnw quarkus:dev 手动启动 quarkus 应用程序时,一切正常。

Chr*_*chl 4

我自己解决了这个问题:)。问题是我的 quarkus.oidc.auth-server-url 因为我使用了错误的端口。解决方案是使用 keycloak 服务的内部端口而不是公开端口。

正确的 auth-server-url 是:http://keycloak:8080/auth/realms/dbk

正确的 docker-compose:

core:
 image: registry.gitlab.com/baudoku/dbk-core:dev
 container_name: dbk-core
 environment:
   QUARKUS_HTTP_PORT: 7000
   QUARKUS_OIDC_AUTH_SERVER_URL: http://keycloak:8080/auth/realms/dbk
   QUARKUS_DATASOURCE_JDBC_URL: jdbc:postgresql://database:5432/dbk_core_database
 depends_on:
 - database
 - keycloak
 ports:
 - 8080:7000
Run Code Online (Sandbox Code Playgroud)