Kubernetes 1.24中Kong Consumer无法找到Secrets问题求助
问题现象
在Kubernetes 1.24环境测试Kong API密钥限流功能时,KongConsumer无法找到已存在的Secret,报错如下:
time="2023-08-15T06:57:08Z" level=error msg="resource processing failed: credential "test-apikey" failure: failed to fetch secret: Secret kong/test-apikey not found" GVK="configuration.konghq.com/v1, Kind=KongConsumer" name=my-consumer namespace=kong
已确认Secret存在于kong命名空间:
k get secret test-apikey -n kong NAME TYPE DATA AGE test-apikey Opaque 2 21h
同时相关角色已配置足够权限:
rules: - apiGroups: - "" resources: - configmaps - pods - secrets - namespaces verbs: - get - list
KongConsumer清单:
apiVersion: configuration.konghq.com/v1 kind: KongConsumer metadata: name: my-consumer namespace: kong annotations: kubernetes.io/ingress.class: kong username: test-username credentials: - "test-apikey"
排查与解决步骤
1. 检查Secret的标签是否符合要求
Kong控制器需要Secret带有特定标签才能识别为API密钥凭证,执行以下命令为Secret添加标签:
kubectl label secret test-apikey konghq.com/credential=apikey -n kong
2. 验证Secret的键名是否正确
API密钥类型的Secret必须包含key键(存储实际API密钥值),检查Secret内容:
kubectl get secret test-apikey -n kong -o jsonpath='{.data.key}' | base64 -d
若不存在key键,需更新Secret:
apiVersion: v1 kind: Secret metadata: name: test-apikey namespace: kong labels: konghq.com/credential: apikey type: Opaque data: key: <base64编码的API密钥字符串>
3. 确认ServiceAccount与角色绑定的有效性
检查Kong控制器使用的ServiceAccount是否绑定了拥有Secret权限的角色,且绑定范围覆盖kong命名空间:
# 查看Kong控制器的ServiceAccount kubectl get deployments -n kong -o jsonpath='{.items[*].spec.template.spec.serviceAccountName}' # 检查对应角色绑定 kubectl get rolebindings -n kong | grep <上述获取的ServiceAccount名称>
4. 确认命名空间隔离配置
Kong控制器默认不跨命名空间处理资源,确保KongConsumer和Secret在同一命名空间(本次已满足),若需跨命名空间,需在控制器启动参数中添加--enable-namespace-isolation=false。
5. 重启Kong控制器
若以上配置均正确,可能是控制器缓存问题,重启控制器Pod:
kubectl rollout restart deployment kong-controller -n kong
内容的提问来源于stack exchange,提问作者Utkarsh Jain

