You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AKS的Pod、IP或域名上启用SSL/HTTPS?已尝试Cert-Manager无效

微服务路由启用HTTPS的完整配置方案

1. 修正Deployment配置

你当前的Deployment仅挂载了tls-secret但未在容器内实际使用,且应用未配置HTTPS监听。需做以下修改:

  • 将证书文件挂载到容器内指定路径
  • 添加环境变量让应用加载证书并启用HTTPS

修改后的Deployment:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: ms-app-deployment
  labels:
    app: ms-app-deployment
spec:
  replicas: 1
  selector:
    matchLabels:
      app: ms-app-deployment
  template:
    metadata:
      labels:
        app: ms-app-deployment
    spec:
      volumes:
        - name: tls-cert
          secret:
            secretName: tls-secret
      containers:
        - name: ms-app
          image: qa.azurecr.io/ms-app:1.00
          resources:
            limits:
              memory: "512Mi"
              cpu: "1"
            requests:
              memory: "256Mi"
              cpu: "0.5"
          ports:
            - containerPort: 3000  # 保留原HTTP端口(可选)
            - containerPort: 3443  # 新增HTTPS监听端口
          volumeMounts:
            - name: tls-cert
              mountPath: /app/certs  # 证书挂载到容器内路径
              readOnly: true
          env:
            - name: VERSION
              value: "1.00"
            - name: SECRET_KEY
              value: ""
            - name: TOKEN_EXPIRATION
              value: "60"
            - name: PORT
              value: "3000"
            - name: HTTPS_PORT
              value: "3443"
            - name: TLS_CERT_PATH
              value: "/app/certs/tls.crt"
            - name: TLS_KEY_PATH
              value: "/app/certs/tls.key"

2. 更新Service配置

当前Service仅暴露HTTP端口,需新增HTTPS端口映射:

apiVersion: v1
kind: Service
metadata:
  name: ms-app-service
spec:
  selector:
    app: ms-app-deployment
  ports:
    - name: http
      protocol: TCP
      port: 80
      targetPort: 3000
    - name: https
      protocol: TCP
      port: 443
      targetPort: 3443  # 对应容器的HTTPS端口
  type: LoadBalancer

3. 验证Cert-Manager的Certificate配置

若证书未生效,需确认Certificate资源是否正确生成tls-secret。示例配置:

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: ms-app-tls
spec:
  secretName: tls-secret  # 需与Deployment中引用的Secret名称一致
  issuerRef:
    name: letsencrypt-prod  # 替换为你的Issuer/ClusterIssuer名称
    kind: ClusterIssuer
  commonName: your-domain.com  # 替换为你的实际域名
  dnsNames:
    - your-domain.com
    - api.your-domain.com  # 如有子域名需添加
  acme:
    config:
      - http01:
          ingressClass: nginx  # 替换为你的Ingress控制器类
        domains:
          - your-domain.com
          - api.your-domain.com

4. 添加Ingress资源(实现HTTPS路由)

仅暴露Service的443端口无法完成域名绑定和HTTPS终止,需配置Ingress:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ms-app-ingress
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod  # 关联Cert-Manager的ClusterIssuer
spec:
  tls:
    - hosts:
        - your-domain.com
      secretName: tls-secret  # 证书Secret名称
  rules:
    - host: your-domain.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: ms-app-service
                port:
                  number: 80  # Ingress自动完成HTTPS终止,后端转发HTTP请求

常见问题排查

  • 检查cert-manager日志:kubectl logs -n cert-manager -l app=cert-manager,确认证书是否成功颁发
  • 验证tls-secret内容:kubectl get secret tls-secret -o yaml,查看data字段下的tls.crt和tls.key是否存在
  • 确认应用已配置加载证书并监听HTTPS端口,部分框架需额外代码或配置文件开启HTTPS
  • 检查Ingress控制器状态:kubectl get pods -n ingress-nginx(若使用nginx-ingress)

内容的提问来源于stack exchange,提问作者user75463

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 00:12:53