From 9236c8681bcb39f29508a5d524fbeb501743b7d5 Mon Sep 17 00:00:00 2001 From: seaHi Date: Wed, 30 Sep 2026 13:46:46 +0800 Subject: [PATCH] =?UTF-8?q?fix:=20=E5=A2=9E=E5=BC=BA=20Keystone=20?= =?UTF-8?q?=E8=AE=A4=E8=AF=81=E5=A4=B1=E8=B4=A5=E7=9A=84=E8=AF=8A=E6=96=AD?= =?UTF-8?q?=E4=B8=8E=E9=94=99=E8=AF=AF=E4=BF=A1=E6=81=AF=E8=BE=93=E5=87=BA?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- env3-4-local.sh | 41 ++++++++++++++++++++++++++++++++++++++--- 1 file changed, 38 insertions(+), 3 deletions(-) diff --git a/env3-4-local.sh b/env3-4-local.sh index dd50ec2..773a82c 100755 --- a/env3-4-local.sh +++ b/env3-4-local.sh @@ -465,14 +465,49 @@ for variable in ${!OS_@}; do done source "$ADMIN_OPENRC" +# 认证失败不一定是密码错误;输出连接和 WSGI 诊断,避免只留下统一提示。 +diagnose_keystone() { + local url logfile + log_warn "Keystone 诊断:controller 解析和本机 IPv4 地址" + getent hosts controller || true + ip -4 -o addr show || true + log_warn "Keystone 诊断:Apache 虚拟主机配置" + httpd -S 2>&1 || true + if command -v curl > /dev/null 2>&1; then + # 无凭证探测,绕过代理以区分本机 WSGI 故障与主机名/网络问题。 + for url in http://127.0.0.1:5000/v3/ http://controller:5000/v3/; do + log_info "直接探测 $url" + curl --noproxy '*' \ + -sS -o /dev/null -w 'HTTP 状态码:%{http_code}\n' "$url" || true + done + fi + log_warn "Keystone 诊断:最近的 httpd 服务日志" + journalctl -u httpd -n 30 --no-pager 2>&1 || true + for logfile in /var/log/httpd/error_log /var/log/httpd/*error*.log \ + /var/log/keystone/keystone.log /var/log/keystone/*wsgi*.log; do + [ -f "$logfile" ] || continue + log_warn "日志末尾:$logfile" + tail -n 30 "$logfile" || true + done +} + # Apache 启动后,等待 Keystone 实际可以签发令牌(不输出令牌内容)。 log_info "等待 Keystone 管理员认证就绪..." for attempt in {1..12}; do - if openstack --os-auth-type password --os-api-timeout 10 token issue > /dev/null; then + # 同时捕获 stdout/stderr:部分客户端错误可能写到 stdout,不能直接丢弃。 + if KEYSTONE_AUTH_OUTPUT=$(openstack --os-auth-type password token issue 2>&1); then + unset KEYSTONE_AUTH_OUTPUT + log_info "Keystone 管理员认证成功。" break + else + KEYSTONE_AUTH_STATUS=$? fi + log_warn "Keystone 认证尚未就绪(第 $attempt/12 次,退出码 $KEYSTONE_AUTH_STATUS)。" + printf '%s\n' "${KEYSTONE_AUTH_OUTPUT:-客户端未返回错误信息。}" >&2 + unset KEYSTONE_AUTH_OUTPUT if [ "$attempt" -eq 12 ]; then - log_err "Keystone 认证失败,请检查 httpd、Keystone 配置和管理员密码。" + log_err "Keystone 认证失败;请根据上方客户端错误和下方诊断确定原因。" + diagnose_keystone exit 1 fi sleep 2 @@ -678,7 +713,7 @@ systemctl restart openstack-glance-api openstack-glance-registry "${NOVA_SERVICE log_info "验证 Glance API 和管理员访问..." for attempt in {1..12}; do - if openstack --os-api-timeout 10 --os-image-api-version 2 image list; then + if openstack --os-image-api-version 2 image list; then break fi if [ "$attempt" -eq 12 ]; then