.NET 8应用部署至Rancher后仅监听HTTP端口问题咨询
.NET 8 Web应用部署到Rancher后仅监听HTTP 8080端口,无法启用HTTPS
我将用于测试Keycloak授权的.NET 8 Web应用部署到Rancher后,尝试过添加https_port环境变量、在appsettings中配置顶层属性等操作,但应用始终只在8080端口监听HTTP流量。业务要求所有流量走HTTPS,预期启动日志应显示类似“Now listening on: https://[::]:8081”的HTTPS端口监听信息,实际日志如下:
warn: Microsoft.AspNetCore.DataProtection.Repositories.FileSystemXmlRepository[60] 2024-09-20T09:50:14.146416699Z Storing keys in a directory '/root/.aspnet/DataProtection-Keys' that may not be persisted outside of the container. Protected data will be unavailable when container is destroyed. For more information go to https://aka.ms/aspnet/dataprotectionwarning 2024-09-20T09:50:14.540842462Z warn: Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager[35] 2024-09-20T09:50:14.540881640Z No XML encryptor configured. Key {b25d69c8-24c9-4281-b5df-71ab43c8182f} may be persisted to storage in unencrypted form. 2024-09-20T09:50:15.340432431Z info: Microsoft.Hosting.Lifetime[14] 2024-09-20T09:50:15.340467342Z Now listening on: http://[::]:8080 2024-09-20T09:50:15.340471006Z info: Microsoft.Hosting.Lifetime[0] Application started. Press Ctrl+C to shut down. 2024-09-20T09:50:15.340475874Z info: Microsoft.Hosting.Lifetime[0] Hosting environment: Production 2024-09-20T09:50:15.340480847Z info: Microsoft.Hosting.Lifetime[0] 2024-09-20T09:50:15.340483241Z Content root path: /app
我怀疑是.NET 8的配置存在遗漏,以下是我的部署文件(部分值已替换为占位符):
apiVersion: apps/v1 kind: Deployment metadata: name: myPOCsite namespace: backend spec: selector: matchLabels: app: myPOCsite replicas: 1 template: metadata: labels: app: myPOCsite log: "yes" spec: containers: - name: myPOCsite image: myimageurl imagePullPolicy: IfNotPresent ports: - containerPort: 8081 resources: limits: memory: "100Mi" cpu: "80m" requests: memory: "60Mi" cpu: "40m" hostname: myPOCsite imagePullSecrets: - name: regsecret --- apiVersion: v1 kind: Service metadata: labels: app: myPOCsite name: myPOCsite namespace: backend spec: ports: - port: 443 protocol: TCP name: https targetPort: 8081 selector: app: myPOCsite type: ClusterIP
解决方法
1. 正确配置.NET 8的HTTPS监听端口
.NET 8不会自动启用HTTPS,需要用正确的配置指定监听地址:
- 环境变量方式:使用
ASPNETCORE_URLS而非https_port,设置值为https://+:8081,让应用直接监听8081端口的HTTPS流量。 - 配置文件方式:在
appsettings.Production.json中添加:
{ "Urls": "https://+:8081" }
2. 提供HTTPS证书
启用HTTPS必须配置证书,容器环境中有几种实现方式:
- 挂载集群证书:在Deployment中添加证书挂载,通过环境变量指定证书路径和密码:
containers: - name: myPOCsite # 其他配置 env: - name: ASPNETCORE_Kestrel__Certificates__Default__Path value: /cert/your-cert.pfx - name: ASPNETCORE_Kestrel__Certificates__Default__Password value: "cert-password" volumeMounts: - name: cert-volume mountPath: /cert volumes: - name: cert-volume secret: secretName: your-cert-secret - Ingress终止HTTPS(推荐生产环境):让Ingress层处理HTTPS证书,后端应用保持HTTP监听。这种方式无需在应用层管理证书,仅需修改Service的
targetPort为8080,并配置Ingress关联SSL证书,将外部HTTPS流量转发到应用的HTTP端口。
3. 修正Deployment配置
在Deployment的容器配置中添加正确的环境变量,确保应用加载HTTPS配置:
containers: - name: myPOCsite # 其他配置 env: - name: ASPNETCORE_URLS value: "https://+:8081"
内容的提问来源于stack exchange,提问作者KristianMedK
相关产品推荐
相关产品推荐

