fix: 增强 Keystone 认证失败的诊断与错误信息输出

This commit is contained in:
seahi committed 2026-09-30 13:46:46 +08:00
1 parent af2c88a682
commit 9236c8681b
1 file changed
+38 -3
+38 -3
View File
@@ -465,14 +465,49 @@ for variable in ${!OS_@}; do
done done
source "$ADMIN_OPENRC" source "$ADMIN_OPENRC"
# 认证失败不一定是密码错误;输出连接和 WSGI 诊断,避免只留下统一提示。
diagnose_keystone() {
local url logfile
log_warn "Keystone 诊断:controller 解析和本机 IPv4 地址"
getent hosts controller || true
ip -4 -o addr show || true
log_warn "Keystone 诊断:Apache 虚拟主机配置"
httpd -S 2>&1 || true
if command -v curl > /dev/null 2>&1; then
# 无凭证探测,绕过代理以区分本机 WSGI 故障与主机名/网络问题。
for url in http://127.0.0.1:5000/v3/ http://controller:5000/v3/; do
log_info "直接探测 $url"
curl --noproxy '*' \
-sS -o /dev/null -w 'HTTP 状态码:%{http_code}\n' "$url" || true
done
fi
log_warn "Keystone 诊断:最近的 httpd 服务日志"
journalctl -u httpd -n 30 --no-pager 2>&1 || true
for logfile in /var/log/httpd/error_log /var/log/httpd/*error*.log \
/var/log/keystone/keystone.log /var/log/keystone/*wsgi*.log; do
[ -f "$logfile" ] || continue
log_warn "日志末尾:$logfile"
tail -n 30 "$logfile" || true
done
}
# Apache 启动后,等待 Keystone 实际可以签发令牌(不输出令牌内容)。 # Apache 启动后,等待 Keystone 实际可以签发令牌(不输出令牌内容)。
log_info "等待 Keystone 管理员认证就绪..." log_info "等待 Keystone 管理员认证就绪..."
for attempt in {1..12}; do for attempt in {1..12}; do
if openstack --os-auth-type password --os-api-timeout 10 token issue > /dev/null; then # 同时捕获 stdout/stderr:部分客户端错误可能写到 stdout,不能直接丢弃。
if KEYSTONE_AUTH_OUTPUT=$(openstack --os-auth-type password token issue 2>&1); then
unset KEYSTONE_AUTH_OUTPUT
log_info "Keystone 管理员认证成功。"
break break
else
KEYSTONE_AUTH_STATUS=$?
fi fi
log_warn "Keystone 认证尚未就绪(第 $attempt/12 次,退出码 $KEYSTONE_AUTH_STATUS)。"
printf '%s\n' "${KEYSTONE_AUTH_OUTPUT:-客户端未返回错误信息。}" >&2
unset KEYSTONE_AUTH_OUTPUT
if [ "$attempt" -eq 12 ]; then if [ "$attempt" -eq 12 ]; then
log_err "Keystone 认证失败,请检查 httpd、Keystone 配置和管理员密码。" log_err "Keystone 认证失败;请根据上方客户端错误和下方诊断确定原因。"
diagnose_keystone
exit 1 exit 1
fi fi
sleep 2 sleep 2
@@ -678,7 +713,7 @@ systemctl restart openstack-glance-api openstack-glance-registry "${NOVA_SERVICE
log_info "验证 Glance API 和管理员访问..." log_info "验证 Glance API 和管理员访问..."
for attempt in {1..12}; do for attempt in {1..12}; do
if openstack --os-api-timeout 10 --os-image-api-version 2 image list; then if openstack --os-image-api-version 2 image list; then
break break
fi fi
if [ "$attempt" -eq 12 ]; then if [ "$attempt" -eq 12 ]; then