You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes中cert-manager无法通过Let's Encrypt签发证书求助

cert-manager对接Let's Encrypt证书签发失败排查求助

配置信息

ClusterIssuer配置

Name: letsencrypt-prod
Spec:
  Acme:
    Email: xxx@gmail.com
    Private Key Secret Ref:
      Name:  letsencrypt-prod
    Server:  https://acme-v02.api.letsencrypt.org/directory
    Solvers:
      http01:
        Ingress:
          Class:  nginx

Certificate配置

Name: frontend-tls
Namespace: default
Spec:
  Dns Names:
    xxx.in
  Issuer Ref:
    Group: cert-manager.io
    Kind: ClusterIssuer
    Name: letsencrypt-prod
  Secret Name: frontend-tls

Ingress配置

Name: frontend-ingress
Namespace: default
Address: xxx.xxx.xxx.xxx
Ingress Class: nginx
Annotations: cert-manager.io/cluster-issuer: letsencrypt-prod

DNS配置

Name:    xxx.in
Addresses:  15.197.345.173
          3.33.234.147

错误详情

Name: frontend-tls-nlgtl-2344426666-3388921781
    Status:
      Presented:   false
      Reason:      Error accepting authorization: acme: authorization error for xxx.in: 403 urn:ietf:params:acme:error:unauthorized: 3.33.152.147: Invalid response from http://xxx.in/.well-known/acme-challenge/WB9s5TUw3y95tMZPdKVEjMR9mbeh5PhuObAH5Z2FPug: 404
      State:       invalid

额外信息

  • 证书对应的Secret未创建:
kubectl get secret frontend-tls -n default
Error from server (NotFound): secrets "frontend-tls" not found

已确认事项

  • 域名DNS记录已正确指向Ingress Controller的服务IP
  • Ingress资源已配置使用该ClusterIssuer

求助内容

已配置ClusterIssuer、Certificate及关联证书的Ingress,但证书始终无法签发,不清楚遗漏了什么或配置存在哪些问题,恳请帮忙分析cert-manager无法签发证书的原因,以及进一步的排查方法。

内容的提问来源于stack exchange,提问作者Suprava

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 01:38:29