You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AKS应用路由插件配置SSL终止时返回K8S虚假证书问题

AKS应用路由插件SSL终止配置异常:始终返回K8S默认虚假证书

严格遵循AKS应用路由及SSL配置相关官方指南部署hello-world应用并配置SSL终止,但访问站点时始终返回K8S默认虚假证书,而非上传至Key Vault的目标证书。

已确认的有效配置信息

1. Key Vault同步的Secret验证正常

对应的Secret已存在于集群中,提取并解码tls.crt和tls.key后确认是正确的目标证书:

$ kubectl describe secret
Name:         keyvault-aks-helloworld
Namespace:    hello-web-app-routing
Labels:       secrets-store.csi.k8s.io/managed=true
Annotations:  <none>

Type:  kubernetes.io/tls

Data
====
tls.crt:  1155 bytes
tls.key:  1679 bytes

2. Ingress配置包含正确的TLS设置与注解

Ingress资源已关联指定Secret,且配置了Key Vault证书URI注解:

$ kubectl describe ingress
Name:             aks-helloworld
Labels:           <none>
Namespace:        hello-web-app-routing
Address:          1.2.3.4
Ingress Class:    webapprouting.kubernetes.azure.com
Default backend:  <default>
TLS:
  keyvault-aks-helloworld terminates mydomain.com
Rules:
  Host          Path  Backends
  ----          ----  --------
  mydomain.com
                /   aks-helloworld:80 (10.1.2.3:80)
Annotations:    kubernetes.azure.com/tls-cert-keyvault-uri: https://myvault.azure.net/certificates/mycert
Events:
  Type    Reason  Age                From                      Message
  ----    ------  ----               ----                      -------
  Normal  Sync    20m (x2 over 21m)  nginx-ingress-controller  Scheduled for sync
  Normal  Sync    20m (x2 over 21m)  nginx-ingress-controller  Scheduled for sync

异常测试现象

  • 禁用Key Vault中的证书后,Ingress出现挂载失败错误,说明集群确实在尝试从Key Vault拉取证书:
Events:
  Type     Reason       Age                            From                      Message
  ----     ------       ----                           ----                      -------
  Warning  FailedMount  <invalid>                      aks-app-routing-operator  MountVolume.SetUp failed for volume "secrets" : rpc error: code = Unknown desc = failed to mount secrets store objects for pod hello-web-app-routing/keyvault-aks-helloworld-6f8f6446d8-j6q99, err: rpc error: code = Unknown desc = failed to mount objects, error: failed to get objectType:secret, objectName:mycert, objectVersion:: keyvault.BaseClient#GetSecret: Failure responding to request: StatusCode=403 -- Original Error: autorest/azure: Service returned an error. Status=403 Code="Forbidden" Message="Operation get is not allowed on a disabled secret." InnerError={"code":"SecretDisabled"}
  • 重新启用Key Vault证书并重建Ingress后,上述错误消失,但访问站点仍只能获取K8S默认虚假证书,证书关联问题未解决。

内容的提问来源于stack exchange,提问作者Guy Wood

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 18:45:25