GKE Autopilot集群安装cert-manager Issuer遇x509证书验证错误
GKE Autopilot集群cert-manager Issuer创建失败排查与解决
问题背景
已完成以下操作:
- 通过Google Cloud Console创建GKE Autopilot集群
- 使用Helm成功安装nginx ingress controller
- 配置register.it域名的A记录,指向ingress controller的EXTERNAL IP
- 成功部署kuard的Deployment、Service和Ingress
cert-manager安装情况:
- Helm安装失败,报错:
Error: INSTALLATION FAILED: failed post-install: timed out waiting for the condition - 通过官方YAML文件安装成功:
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.13.2/cert-manager.yaml
报错详情
执行kubectl apply -f issuer.yaml创建Issuer时,触发如下错误:
Error from server (InternalError): error when creating "issuer.yaml": Internal error occurred: failed calling webhook "webhook.cert-manager.io": failed to call webhook: Post "https://cert-manager-webhook.cert-manager.svc:443/mutate?timeout=10s": tls: failed to verify certificate: x509: certificate signed by unknown authority
更新信息:常规GKE集群可正常运行,但需使用Autopilot集群。
解决方案
1. 检查并重新生成webhook CA证书
- 查看cert-manager命名空间下的证书状态:
kubectl get certificates -n cert-manager - 若
cert-manager-webhook-ca证书状态不为Ready,删除该证书让cert-manager自动重新生成:kubectl delete certificate cert-manager-webhook-ca -n cert-manager
2. 更新webhook的CA Bundle配置
Autopilot集群中可能存在webhook CA Bundle同步不及时的问题,手动更新:
- 获取当前CA证书的base64编码内容:
CA_BUNDLE=$(kubectl get secret cert-manager-webhook-ca -n cert-manager -o jsonpath='{.data.ca\.crt}') - 更新mutating webhook配置:
kubectl patch mutatingwebhookconfiguration cert-manager-webhook --type='json' -p='[{"op": "replace", "path": "/webhooks/0/clientConfig/caBundle", "value": "'$CA_BUNDLE'"}]' - 更新validating webhook配置:
kubectl patch validatingwebhookconfiguration cert-manager-webhook --type='json' -p='[{"op": "replace", "path": "/webhooks/0/clientConfig/caBundle", "value": "'$CA_BUNDLE'"}]'
3. 适配Autopilot的Helm安装参数(避免后续安装失败)
若后续改用Helm安装cert-manager,需添加适配Autopilot的参数:
helm install cert-manager jetstack/cert-manager \ --namespace cert-manager \ --create-namespace \ --version v1.13.2 \ --set installCRDs=true \ --set webhook.timeoutSeconds=30 \ --set webhook.livenessProbe.initialDelaySeconds=60 \ --set webhook.readinessProbe.initialDelaySeconds=60 \ --set webhook.resources.requests.cpu=100m \ --set webhook.resources.requests.memory=128Mi
延长探针初始化时间和超时时间,适配Autopilot的调度延迟;同时设置合理的资源请求,避免Pod被驱逐。
4. 临时禁用webhook(仅用于排查)
若以上方法无效,可临时禁用webhook验证Issuer是否能正常创建(不推荐生产环境使用):
kubectl delete mutatingwebhookconfiguration cert-manager-webhook kubectl delete validatingwebhookconfiguration cert-manager-webhook
注意:禁用webhook会丢失cert-manager的自动校验和注入功能,仅作为排查手段。
内容的提问来源于stack exchange,提问作者Alessandro R.
相关产品推荐
相关产品推荐

