You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GKE ManagedCertificate搭配Gateway资源报错,咨询支持情况及用法

GKE Gateway与ManagedCertificate资源的兼容问题及配置方案

核心结论

GKE Gateway(基于Kubernetes Gateway API)不直接支持ManagedCertificate资源,从报错信息可明确:它仅允许引用Kubernetes原生的Secret类型证书。不过可以通过BackendConfig间接实现ManagedCertificate与Gateway的配合使用。

配置步骤

1. 创建ManagedCertificate资源

先定义托管证书,指定要覆盖的域名:

apiVersion: networking.gke.io/v1
kind: ManagedCertificate
metadata:
  name: platform-cert
spec:
  domains:
    - your-domain.example.com # 替换为你的实际域名

2. 创建BackendConfig关联证书

通过BackendConfig将ManagedCertificate与后端服务绑定:

apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
  name: platform-backend-config
spec:
  ssl:
    managedCertificates:
      - name: platform-cert # 关联上面创建的ManagedCertificate

3. 在Service中引用BackendConfig

给后端服务添加注解,关联刚创建的BackendConfig:

apiVersion: v1
kind: Service
metadata:
  name: platform-service
  annotations:
    cloud.google.com/backend-config: '{"default": "platform-backend-config"}'
spec:
  selector:
    app: platform # 替换为你的服务标签
  ports:
    - port: 80
      targetPort: 8080 # 替换为服务的实际端口
  type: ClusterIP

4. 配置Gateway资源

创建Gateway,指定HTTPS监听并关联后端服务,无需在Gateway中直接引用证书:

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: platform-gateway
  namespace: gateway
spec:
  gatewayClassName: gke-l7-global-external-managed # 根据需求选择网关类,区域型可用gke-l7-regional-external-managed
  listeners:
  - name: platform
    port: 443
    protocol: HTTPS
    allowedRoutes:
      namespaces:
        from: Same
  addresses:
  - type: IPAddress
    value: your-static-ip-address # 替换为你的静态公网IP

原理说明

GKE Gateway本身仅识别Kubernetes标准的Secret证书,但BackendConfig是GKE扩展资源,可与Google Cloud负载均衡器深度集成。通过将ManagedCertificate关联到BackendConfig再绑定到后端Service,GKE会自动将托管证书配置到Gateway对应的负载均衡器上,实现HTTPS访问。

内容的提问来源于stack exchange,提问作者Axe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 17:13:25