You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS环境下Let's Encrypt有效SSL证书致HTTPS无法访问的原因及解决

问题分析与解决

问题背景

使用AKS+Azure DNS,已配置ClusterIssuer与Ingress,HTTP可正常访问网站;kubectl describe certificate显示证书已成功颁发无报错,但HTTPS访问时页面持续挂起直至浏览器提示无响应。

原因分析

1. 核心冲突:Ingress TLS终止与后端应用的TLS配置不匹配

Nginx Ingress Controller会在入口处完成TLS终止——将客户端的HTTPS请求解密为HTTP请求,再转发给后端Service的80端口。但你的Deployment中:

  • 给容器挂载了TLS证书
  • 通过环境变量TLS_CERT/TLS_KEY让应用以HTTPS模式监听80端口
    这就导致应用在80端口等待HTTPS流量,而Ingress发来的是HTTP请求,协议不匹配,请求一直无法被处理,最终超时挂起。

2. 潜在风险:ClusterIssuer与Ingress复用同一Secret

ClusterIssuer的privateKeySecretRef指定了my-website-secret,而Ingress的TLS也用该Secret存储证书。cert-manager会将ACME账户私钥存入此Secret,同时Ingress的证书也存在这里,可能导致Secret内容混乱,虽当前证书颁发成功,但长期运行有稳定性风险。

解决步骤

步骤1:移除后端应用的TLS配置

因为Ingress已负责TLS终止,后端应用只需处理HTTP请求即可。修改Deployment文件:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: gmrfe
spec:
  replicas: 2
  selector:
    matchLabels:
      app: gmrfe
      tier: web
  template:
    metadata:
      labels:
        app: gmrfe
        tier: web
    spec:
      containers:
        - name: gmrfe
          image: <my-aks-repo>:gmrfe_latest
          imagePullPolicy: Always
          ports:
            - containerPort: 80
---

apiVersion: v1
kind: Service
metadata:
  name: gmrfe
  annotations:
    service.beta.kubernetes.io/azure-load-balancer-resource-group: MC_aks-rg_dpt-aks_westus
    service.beta.kubernetes.io/azure-pip-name: myIp
spec:
  type: LoadBalancer
  selector:
    app: gmrfe
  ports:
    - port: 80
      protocol: TCP

应用修改:kubectl apply -f deployment.yaml

步骤2:分离ClusterIssuer的私钥Secret

修改ClusterIssuer.yaml,为ACME账户私钥指定独立的Secret:

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: letsencrypt
  namespace: default
  annotations:
    acme.cert-manager.io/http01-edit-in-place: "true"
spec:
  acme:
    server: https://acme-v02.api.letsencrypt.org/directory
    email: danielptm@me.com
    privateKeySecretRef:
      name: letsencrypt-account-key  # 改为新的Secret名称
    solvers:
      - http01:
          ingress:
            class: nginx

应用修改:kubectl apply -f clusterissuer.yaml

步骤3:验证关键配置

  • 检查Nginx Ingress Controller的Service是否暴露443端口:
    kubectl get service -n ingress-nginx
    
    确认输出中包含443:xxxx/TCP的端口映射。
  • 检查Azure NSG规则:确保AKS集群及Ingress LB对应的NSG已开放443端口入站流量,避免防火墙阻断HTTPS请求。

步骤4:验证HTTPS访问

等待Pod重启完成后,再次访问https://www.mywebsite.io,确认页面正常加载。


内容的提问来源于stack exchange,提问作者slipperypete

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 09:05:36