Kubernetes Pod内发起HTTPS请求出现TLS握手失败求助
Kubernetes Pod内HTTPS请求TLS握手失败排查方案
问题场景
Kubernetes v1.27.0集群(使用Flannel网络插件)中,Pod内部发起HTTPS请求时出现TLS握手失败,节点上执行相同请求正常。Pod内curl命令输出如下:
# curl -v https://google.com * Trying 104.21.41.20:443... * Connected to google.com (104.21.41.20) port 443 (#0) * ALPN: offers h2,http/1.1 * TLSv1.3 (OUT), TLS handshake, Client hello (1): * CAfile: /etc/ssl/certs/ca-certificates.crt * CApath: /etc/ssl/certs * TLSv1.3 (IN), TLS alert, handshake failure (552): * OpenSSL/3.0.9: error:0A000410:SSL routines::sslv3 alert handshake failure * Closing connection 0 curl: (35) OpenSSL/3.0.9: error:0A000410:SSL routines::sslv3 alert handshake failure
排查与解决步骤
验证Pod内CA证书完整性
对比Pod内/etc/ssl/certs/ca-certificates.crt与节点上的同文件内容,若证书缺失或不完整:- Debian/Ubuntu系镜像执行:
apt update && apt install -y ca-certificates - RHEL/CentOS系镜像执行:
yum install -y ca-certificates
- Debian/Ubuntu系镜像执行:
排查网络层干扰
- 确认Pod的网络策略是否允许出站443端口流量,检查节点iptables规则是否过滤了Pod的TLS数据包
- 强制指定TLS版本测试兼容性:
curl -v --tlsv1.2 https://google.com,排查TLSv1.3适配问题
检查OpenSSL版本兼容性
Pod内使用的OpenSSL 3.0.9可能与部分服务存在握手兼容性问题,可更换使用OpenSSL 1.x的基础镜像(如debian:bullseye)测试确认DNS解析有效性
执行nslookup google.com验证Pod的DNS配置是否正常,排除解析到异常IP导致的握手失败
内容的提问来源于stack exchange,提问作者nariman amani
相关产品推荐
相关产品推荐

