对WebConsole映射了域名,然后在使用域名的情况下,打开容器终端时候,失败,提示如下:
Could not connect to the container. Do you have sufficient privileges?
在使用IP:30880情况下,一切正常。
请问有人知道需要修改什么配置么?

  • Feynman 回复了此帖
  • 谢谢,把所有的/api都加上后果然可以了。
    就是这个配置方式感觉有点坑

    7 天 后

    谢谢,把所有的/api都加上后果然可以了。
    就是这个配置方式感觉有点坑

    按前面方式终端可行了,不过在域名方式下删除企业空间,一直是502,回到IP:PORT则正常。

      wolcen 加入/apis/tenant.kubesphere.io/v1alpha1/workspaces/ 后正常
      总得来说是不同请求路径需求不同引起,部分需要upgrade,部分不需要,只能遇到一个调整一个
      @Feynman 问下,有相关的资料么?

        1 个月 后
        4 天 后

        zhangyuxiansen2017 近期正在验证从2.1.1升级到3.0,不过使用中的功能基本上都OK了,在用配置如下:
        `
        server {
        listen 80;
        server_name kubesphere.mydomain.com;
        rewrite .* https://$server_name$1 permanent;

        }
        server {
        listen 443 ssl;
        ssl_certificate ssl/mydomain/.mydomain.com.pem;
        ssl_certificate_key ssl/mydomain/.mydomain.com.key;
        server_name kubesphere.mydomain.com;
        ssl_session_timeout 5m;
        ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;
        ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
        ssl_prefer_server_ciphers on;

        location /api/v1/ {
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        location /api/ {
        	proxy_http_version 1.1;
        	proxy_redirect off;
        	proxy_pass http://$host;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header Upgrade $http_upgrade;
        	proxy_set_header X-Forwarded-Proto $scheme;
        	proxy_set_header Connection "upgrade";
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        }
        
        location /apis/devops.kubesphere.io/ {
        	proxy_http_version 1.1;
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        
        location /apis/monitoring.coreos.com/ {
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        
        location /apis/storage.k8s.io/ {
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        
        location /apis/extensions/v1beta1/namespaces/ {
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        
        location /apis/autoscaling/v2beta2/namespaces/ {
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        
        location /apis/tenant.kubesphere.io/v1alpha1/workspaces/ {
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        
        location /apis/apps/v1/namespaces/ {
        	proxy_http_version 1.1;
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }
        
        location /apis/ {
        	proxy_http_version 1.1;
        	proxy_redirect off;
        	proxy_pass http://$host;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header Upgrade $http_upgrade;
        	proxy_set_header X-Forwarded-Proto $scheme;
        	proxy_set_header Connection "upgrade";
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        }
        
        location /kapis/terminal.kubesphere.io/ {
        	proxy_http_version 1.1;
        	proxy_redirect off;
        	proxy_pass http://$host;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header Upgrade $http_upgrade;
        	proxy_set_header X-Forwarded-Proto $scheme;
        	proxy_set_header Connection "upgrade";
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        }
        location /kapis/resources.kubesphere.io/v1alpha2/namespaces {
        	proxy_http_version 1.1;
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        }
        location /kapis/resources.kubesphere.io/v1alpha2/users {
        	proxy_http_version 1.1;
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        }
        location /kapis/resources.kubesphere.io/ {
        	proxy_http_version 1.1;
        	proxy_redirect off;
        	proxy_pass http://$host;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header Upgrade $http_upgrade;
        	proxy_set_header X-Forwarded-Proto $scheme;
        	proxy_set_header Connection "upgrade";
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        }
        
        location /kapis/ {
        	proxy_http_version 1.1;
        	proxy_redirect off;
        	proxy_pass http://$host;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header Upgrade $http_upgrade;
        	proxy_set_header X-Forwarded-Proto $scheme;
        	proxy_set_header Connection "upgrade";
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        }
        
        location / {
        	proxy_http_version 1.1;
        	proxy_pass http://$host;
        	proxy_redirect off;
        	proxy_set_header Host $host:$server_port;
        	proxy_set_header X-Real-IP $remote_addr;
        	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        	proxy_connect_timeout 3600s;
        	proxy_read_timeout 3600s;
        	proxy_send_timeout 3600s;
        	send_timeout 3600s;
        }

        }

        upstream kubesphere.mydomain.com {
        server 172.10.10.1:30880;
        }
        `

          wolcen 你学着debug下,看下浏览器console的websocket请求报什么错误,你加域名肯定和你的nginx设置有关,网上也搜下

          8 个月 后
          4 年 后

          hongming 配置了还是不行