You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS中Cert-Manager签发多域名证书后部分域名SSL失效问题排查

问题排查与解决方案

1. 先确认证书本身是否包含所有域名

签发完成后,先验证secret中的证书是否真的包含所有配置的DNS域名:

kubectl get secret istio-cert -n istio-system -o jsonpath='{.data.tls\.crt}' | base64 -d | openssl x509 -text -noout | grep -A 10 "Subject Alternative Name"

如果输出的SAN列表里缺少部分域名,说明证书签发过程有问题,需要检查:

  • 核对ClusterIssuer的solver配置缩进:你提供的ClusterIssuer中solvers的缩进错误,应该与privateKeySecretRef同级,修正后的配置示例:
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: test-cluster-issuer
spec:
  acme:
    server: https://acme-v02.api.letsencrypt.org/directory
    email: <my-email>
    privateKeySecretRef:
      name: test-cluster-issuer
    solvers:
      - selector:
          dnsZones:
            - "my-domain.com"
        dns01:
          route53:
            region: eu-west-1
            accessKeyID: "AWSID"
            secretAccessKeySecretRef:
              name: route53-secret
              key: secretAccessKey
  • 检查Certificate资源的事件记录:kubectl describe certificate istio-cert -n istio-system,查看是否有部分域名验证异常的信息。

2. 排查Istio流量路由配置

如果证书本身是完整的,问题大概率出在Istio的Gateway/VirtualService配置上:

  • 确认Gateway的TLS配置正确引用目标secret:
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: istio-ingressgateway
  namespace: istio-system
spec:
  selector:
    istio: ingressgateway
  servers:
  - port:
      number: 443
      name: https
      protocol: HTTPS
    tls:
      mode: SIMPLE
      credentialName: istio-cert  # 必须与Certificate的spec.secretName一致
    hosts:
    - "dns1.example.com"
    - "dns2.example.com"
    # 需包含所有使用该证书的域名
  • 检查每个域名对应的VirtualService是否正确绑定到上述Gateway,且hosts配置与证书域名匹配:
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: example-vs
  namespace: istio-system
spec:
  hosts:
  - "dns1.example.com"
  gateways:
  - istio-ingressgateway  # 绑定到正确的Gateway
  http:
  - route:
    - destination:
        host: your-service
        port:
          number: 80
  • 验证Istio ingressgateway pod是否加载最新证书:
kubectl exec -n istio-system <ingressgateway-pod-name> -- cat /etc/istio/ingressgateway-certs/tls.crt | openssl x509 -text -noout | grep -A 10 "Subject Alternative Name"

如果pod内证书未更新,可重启ingressgateway部署:kubectl rollout restart deployment istio-ingressgateway -n istio-system

3. 排除DNS与客户端缓存问题

  • 用dig检查每个域名的A记录是否指向AKS ingressgateway的公网IP:
dig dns1.example.com +short

确保所有域名解析结果一致且指向正确入口IP。

  • 用curl绕过浏览器缓存测试:
curl -v https://dns1.example.com 2>&1 | grep -A 20 "SSL connection using"

观察返回的证书SAN字段是否包含当前测试域名,多次测试不同域名确认稳定性。

4. 关于cert-manager日志的说明

你提供的日志是证书签发完成后出现的内部乐观锁冲突与过期挑战清理信息,不会影响证书的有效性与使用,可忽略。

内容的提问来源于stack exchange,提问作者Nayden Van

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 06:42:16