连接Azure Kubernetes API服务器遇SSL/TLS错误,求证书获取路径
AKS API端点SSL/TLS信任问题解决指南
问题描述
我能成功访问AKS服务器,执行kubectl get nodes命令输出如下:
kubectl get nodes NAME STATUS ROLES AGE VERSION aks-agentpool-27764677-vmss000000 Ready agent 11m v1.25.6 aks-userpool-27764677-vmss000000 Ready agent 11m v1.25.6
但通过curl访问AKS API端点时因SSL/TLS错误失败,报错信息如下:
curl https://di-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/ curl : The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. At line:1 char:1 + curl https://di-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/ + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebException + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand
受此连接问题影响,PowerShell中的大部分helm安装命令也失败了,示例报错如下:
helm upgrade --install appgw-ingress-internet -f helm-config-internet.yaml application-gateway-kubernetes-ingress/ingress-azure Release "appgw-ingress-internet" does not exist. Installing it now. E0626 12:25:44.907210 12260 memcache.go:238] couldn't get current server API group list: Get "https://dian-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/apis?timeout=32s": read tcp 192.168.19.32:64663->52.143.251.102:443: wsarecv: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond. Error: failed to install CRD crds/azureapplicationgatewayrewrite.yaml: unable to recognize "": Get "https://dian-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/apis?timeout=32s": read tcp 192.168.19.32:64663->52.143.251.102:443: wsarecv: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
请问我应该从哪里下载证书并添加到Windows信任存储来解决该错误?
解决方案
1. 获取AKS API服务器CA证书
直接从本地kubeconfig文件提取,默认路径为%USERPROFILE%\.kube\config。打开文件后,找到对应AKS集群配置中的certificate-authority-data字段,该字段值是Base64编码的CA证书内容。
2. 解码并导出证书文件
使用PowerShell执行以下命令(替换占位符为实际的编码值):
$encodedCert = "你的certificate-authority-data字段值" $decodedCert = [System.Convert]::FromBase64String($encodedCert) [System.IO.File]::WriteAllBytes("C:\temp\aks-ca.crt", $decodedCert)
执行完成后,C:\temp\aks-ca.crt就是可导入的证书文件。
3. 添加到Windows信任存储
- 右键点击
aks-ca.crt文件,选择「安装证书」。 - 在导入向导中选择「本地计算机」,点击「下一步」。
- 选择「将所有证书放入下列存储」,点击「浏览」,选中「受信任的根证书颁发机构」,点击「确定」。
- 完成剩余步骤,确认证书导入。
额外提示
注意到helm报错中的API端点域名(dian-poc-dns)与curl使用的域名(di-poc-dns)不一致,请同步检查kubeconfig中的集群API地址是否正确,避免因域名拼写错误导致的连接失败。
内容的提问来源于stack exchange,提问作者priyam
相关产品推荐
相关产品推荐

