You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE标准层区域网关配置Let's Encrypt SSL:Cert-Manager无法更新CA证书

GKE区域Gateway(标准层)配置Let's Encrypt SSL问题

项目与配置背景

  • 个人PoC项目,将Web应用迁移至GKE集群,核心需求为控制成本,可接受较长加载时间
  • 集群配置:单集群、标准层网络、区域Gateway(TLS仅在指定区域终止)、区域静态IP,所有节点部署在同一区域
  • 配置SSL时遇到问题:参考的指南多基于Ingress或Premium层全球LB(该层支持谷歌免费托管SSL证书,但标准层无此服务),还有cert-manager旧版Ingress指南;按流程创建自签证书后,cert-manager未自动将CA更新为Let's Encrypt,证书始终保持自签状态
  • Gateway的80端口HTTP路由功能正常,但443端口配置HTTPS Secret后,未触发CA更新流程

Gateway配置示例

spec:
  gatewayClassName: gke-l7-regional-external-managed #single cluster regional external load balancer. TLS terminates at this regional LB instead of at various global PoPs
  addresses: 
  - type: NamedAddress #references the name of the static ip address
    value: main
  listeners:
#HTTP below this line
  - name: any-http
    hostname: "*.--------------.com"
    port: 80
    protocol: HTTP
    allowedRoutes:
      kinds:
      - kind: HTTPRoute
      namespaces:
         from: All 
#HTTPS below this line
  - hostname: "www.---------------.com"
    name: any-https
    protocol: HTTPS
    port: 443
    tls:
      mode: Terminate
      certificateRefs:
      - kind: Secret
        group: ""
        name: secret-tls
    allowedRoutes:
      kinds:
      - kind: HTTPRoute
      namespaces:
        from: All

疑问

有没有人成功在GKE的区域负载均衡器Gateway上完成过Let's Encrypt SSL的配置?


内容的提问来源于stack exchange,提问作者heyyy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 14:05:11