You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE Autopilot集群安装cert-manager Issuer遇x509证书验证错误

GKE Autopilot集群cert-manager Issuer创建失败排查与解决

问题背景

已完成以下操作:

  • 通过Google Cloud Console创建GKE Autopilot集群
  • 使用Helm成功安装nginx ingress controller
  • 配置register.it域名的A记录,指向ingress controller的EXTERNAL IP
  • 成功部署kuard的Deployment、Service和Ingress

cert-manager安装情况:

  • Helm安装失败,报错:Error: INSTALLATION FAILED: failed post-install: timed out waiting for the condition
  • 通过官方YAML文件安装成功:kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.13.2/cert-manager.yaml

报错详情

执行kubectl apply -f issuer.yaml创建Issuer时,触发如下错误:

Error from server (InternalError): error when creating "issuer.yaml":
Internal error occurred: failed calling webhook "webhook.cert-manager.io":
failed to call webhook: Post "https://cert-manager-webhook.cert-manager.svc:443/mutate?timeout=10s":
tls: failed to verify certificate: x509: certificate signed by unknown authority

更新信息:常规GKE集群可正常运行,但需使用Autopilot集群。

解决方案

1. 检查并重新生成webhook CA证书

  1. 查看cert-manager命名空间下的证书状态:
    kubectl get certificates -n cert-manager
    
  2. 若cert-manager-webhook-ca证书状态不为Ready,删除该证书让cert-manager自动重新生成:
    kubectl delete certificate cert-manager-webhook-ca -n cert-manager
    

2. 更新webhook的CA Bundle配置

Autopilot集群中可能存在webhook CA Bundle同步不及时的问题,手动更新:

  1. 获取当前CA证书的base64编码内容:
    CA_BUNDLE=$(kubectl get secret cert-manager-webhook-ca -n cert-manager -o jsonpath='{.data.ca\.crt}')
    
  2. 更新mutating webhook配置:
    kubectl patch mutatingwebhookconfiguration cert-manager-webhook --type='json' -p='[{"op": "replace", "path": "/webhooks/0/clientConfig/caBundle", "value": "'$CA_BUNDLE'"}]'
    
  3. 更新validating webhook配置:
    kubectl patch validatingwebhookconfiguration cert-manager-webhook --type='json' -p='[{"op": "replace", "path": "/webhooks/0/clientConfig/caBundle", "value": "'$CA_BUNDLE'"}]'
    

3. 适配Autopilot的Helm安装参数(避免后续安装失败)

若后续改用Helm安装cert-manager,需添加适配Autopilot的参数:

helm install cert-manager jetstack/cert-manager \
  --namespace cert-manager \
  --create-namespace \
  --version v1.13.2 \
  --set installCRDs=true \
  --set webhook.timeoutSeconds=30 \
  --set webhook.livenessProbe.initialDelaySeconds=60 \
  --set webhook.readinessProbe.initialDelaySeconds=60 \
  --set webhook.resources.requests.cpu=100m \
  --set webhook.resources.requests.memory=128Mi

延长探针初始化时间和超时时间,适配Autopilot的调度延迟;同时设置合理的资源请求,避免Pod被驱逐。

4. 临时禁用webhook(仅用于排查)

若以上方法无效,可临时禁用webhook验证Issuer是否能正常创建(不推荐生产环境使用):

kubectl delete mutatingwebhookconfiguration cert-manager-webhook
kubectl delete validatingwebhookconfiguration cert-manager-webhook

注意:禁用webhook会丢失cert-manager的自动校验和注入功能,仅作为排查手段。


内容的提问来源于stack exchange,提问作者Alessandro R.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 13:43:18