如何将Azure Key Vault中的PFX证书导入AKS的Windows容器本地证书存储
将Azure Key Vault中的PFX证书部署到AKS Windows容器的本地证书存储
1. 前提条件
- 已创建包含Windows节点池的AKS集群
- 已创建Azure Key Vault,目标PFX证书已存入Vault(需设置为允许导出私钥)
- AKS集群已启用Azure Key Vault CSI驱动(未启用则先执行启用步骤)
- 已为AKS集群的托管标识/服务主体分配AKV的
Certificate User权限
2. 启用AKV CSI驱动(若未启用)
执行Azure CLI命令启用驱动:
az aks enable-addons --addons azure-keyvault-secrets-provider --name <AKS_CLUSTER_NAME> --resource-group <RESOURCE_GROUP_NAME>
3. 定义SecretProviderClass资源
创建secret-provider-class.yaml文件,配置从AKV拉取证书的规则:
apiVersion: secrets-store.csi.x-k8s.io/v1 kind: SecretProviderClass metadata: name: akv-pfx-cert spec: provider: azure parameters: useVMManagedIdentity: "true" userAssignedIdentityID: <YOUR_MANAGED_IDENTITY_CLIENT_ID> # 替换为你的托管标识客户端ID keyvaultName: <AKV_NAME> # 替换为你的Key Vault名称 objects: | array: - | objectName: <PFX_CERT_NAME> # 替换为AKV中证书的名称 objectType: cert objectVersion: "" # 留空使用最新版本 tenantId: <AZURE_TENANT_ID> # 替换为你的Azure租户ID
应用该资源:
kubectl apply -f secret-provider-class.yaml
4. 部署Windows容器并导入证书
创建windows-cert-deployment.yaml,通过CSI卷挂载证书,并用启动脚本导入到本地证书存储:
apiVersion: apps/v1 kind: Deployment metadata: name: windows-cert-app spec: replicas: 1 selector: matchLabels: app: windows-cert-app template: metadata: labels: app: windows-cert-app spec: nodeSelector: kubernetes.io/os: windows volumes: - name: certs-store csi: driver: secrets-store.csi.k8s.io readOnly: true volumeAttributes: secretProviderClass: "akv-pfx-cert" containers: - name: windows-app-container image: <YOUR_WINDOWS_APP_IMAGE> # 替换为你的Windows应用镜像 volumeMounts: - name: certs-store mountPath: "C:\\certs" command: ["powershell.exe"] args: - "-Command" - | # 将PFX证书导入本地计算机的个人证书存储 $certPath = "C:\certs\<PFX_CERT_NAME>.pfx" # 替换为证书文件名 $null = Import-PfxCertificate -FilePath $certPath -CertStoreLocation Cert:\LocalMachine\My -Password (ConvertTo-SecureString "" -AsPlainText -Force) # 启动你的应用程序 Start-Process -FilePath "C:\path\to\your\application.exe" -Wait
应用部署:
kubectl apply -f windows-cert-deployment.yaml
5. 验证证书导入结果
进入容器执行PowerShell命令查看证书:
kubectl exec -it <POD_NAME> -- powershell.exe
在容器内运行以下命令确认证书存在:
Get-ChildItem Cert:\LocalMachine\My
关键注意事项
- Windows容器证书存储路径可根据需求调整(如
Cert:\LocalMachine\Root用于根证书) - 若AKV中的PFX证书设置了密码,需在SecretProviderClass中额外配置密码对象的拉取规则
- 确保AKS节点版本在1.21及以上,以支持Windows节点的AKV CSI驱动
内容的提问来源于stack exchange,提问作者ciaranj
相关产品推荐
相关产品推荐

