Kubernetes中cert-manager无法通过Let's Encrypt签发证书求助
cert-manager对接Let's Encrypt证书签发失败排查求助
配置信息
ClusterIssuer配置
Name: letsencrypt-prod Spec: Acme: Email: xxx@gmail.com Private Key Secret Ref: Name: letsencrypt-prod Server: https://acme-v02.api.letsencrypt.org/directory Solvers: http01: Ingress: Class: nginx
Certificate配置
Name: frontend-tls Namespace: default Spec: Dns Names: xxx.in Issuer Ref: Group: cert-manager.io Kind: ClusterIssuer Name: letsencrypt-prod Secret Name: frontend-tls
Ingress配置
Name: frontend-ingress Namespace: default Address: xxx.xxx.xxx.xxx Ingress Class: nginx Annotations: cert-manager.io/cluster-issuer: letsencrypt-prod
DNS配置
Name: xxx.in Addresses: 15.197.345.173 3.33.234.147
错误详情
Name: frontend-tls-nlgtl-2344426666-3388921781 Status: Presented: false Reason: Error accepting authorization: acme: authorization error for xxx.in: 403 urn:ietf:params:acme:error:unauthorized: 3.33.152.147: Invalid response from http://xxx.in/.well-known/acme-challenge/WB9s5TUw3y95tMZPdKVEjMR9mbeh5PhuObAH5Z2FPug: 404 State: invalid
额外信息
- 证书对应的Secret未创建:
kubectl get secret frontend-tls -n default Error from server (NotFound): secrets "frontend-tls" not found
已确认事项
- 域名DNS记录已正确指向Ingress Controller的服务IP
- Ingress资源已配置使用该ClusterIssuer
求助内容
已配置ClusterIssuer、Certificate及关联证书的Ingress,但证书始终无法签发,不清楚遗漏了什么或配置存在哪些问题,恳请帮忙分析cert-manager无法签发证书的原因,以及进一步的排查方法。
内容的提问来源于stack exchange,提问作者Suprava
相关产品推荐
相关产品推荐

