You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes Pod内发起HTTPS请求出现TLS握手失败求助

Kubernetes Pod内HTTPS请求TLS握手失败排查方案

问题场景

Kubernetes v1.27.0集群(使用Flannel网络插件)中,Pod内部发起HTTPS请求时出现TLS握手失败,节点上执行相同请求正常。Pod内curl命令输出如下:

# curl -v https://google.com
*   Trying 104.21.41.20:443...
* Connected to google.com (104.21.41.20) port 443 (#0)
* ALPN: offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
*  CAfile: /etc/ssl/certs/ca-certificates.crt
*  CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS alert, handshake failure (552):
* OpenSSL/3.0.9: error:0A000410:SSL routines::sslv3 alert handshake failure
* Closing connection 0
curl: (35) OpenSSL/3.0.9: error:0A000410:SSL routines::sslv3 alert handshake failure

排查与解决步骤

  • 验证Pod内CA证书完整性
    对比Pod内/etc/ssl/certs/ca-certificates.crt与节点上的同文件内容,若证书缺失或不完整:

    • Debian/Ubuntu系镜像执行:apt update && apt install -y ca-certificates
    • RHEL/CentOS系镜像执行:yum install -y ca-certificates
  • 排查网络层干扰

    • 确认Pod的网络策略是否允许出站443端口流量,检查节点iptables规则是否过滤了Pod的TLS数据包
    • 强制指定TLS版本测试兼容性:curl -v --tlsv1.2 https://google.com,排查TLSv1.3适配问题
  • 检查OpenSSL版本兼容性
    Pod内使用的OpenSSL 3.0.9可能与部分服务存在握手兼容性问题,可更换使用OpenSSL 1.x的基础镜像(如debian:bullseye)测试

  • 确认DNS解析有效性
    执行nslookup google.com验证Pod的DNS配置是否正常,排除解析到异常IP导致的握手失败

内容的提问来源于stack exchange,提问作者nariman amani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 08:40:06