如何在Kubernetes上禁用WSO2 APIM与IS的SSL连接并测试SSL卸载
配置方案:禁用WSO2 APIM/IS与Ingress及内部的SSL连接
1. 调整Ingress配置,强制走HTTP
原来的Ingress如果配了TLS,直接删掉TLS相关配置,把转发端口改成WSO2组件的HTTP端口,同时关闭SSL重定向:
ingress: enabled: true annotations: # 关掉SSL自动重定向,避免用户访问HTTP被跳转到HTTPS nginx.ingress.kubernetes.io/ssl-redirect: "false" hosts: - host: your-preprod-domain.com paths: - path: / pathType: Prefix backend: service: name: wso2apim-gateway-service port: number: 8280 # 用网关的HTTP端口,别用8243的HTTPS端口 # 直接删掉整个tls字段,别让Ingress尝试加载证书 # tls: # - hosts: # - your-preprod-domain.com # secretName: your-cert-secret
2. 禁用WSO2 APIM各组件的HTTPS
在Helm的values.yaml里,给APIM的网关、发布者、开发者门户添加环境变量,强制禁用HTTPS,只用HTTP:
网关配置
wso2apim: gateway: service: ports: http: 8280 https: 8243 # 保留端口但不暴露,或者直接注释掉 deployment: env: - name: APIM_GATEWAY_DISABLE_HTTPS value: "true" - name: APIM_GATEWAY_HTTP_PORT value: "8280"
发布者与开发者门户配置
wso2apim: publisher: service: ports: http: 9763 https: 9443 deployment: env: - name: APIM_PUBLISHER_DISABLE_HTTPS value: "true" - name: APIM_PUBLISHER_HTTP_PORT value: "9763" devportal: service: ports: http: 9763 https: 9443 deployment: env: - name: APIM_DEVPORTAL_DISABLE_HTTPS value: "true" - name: APIM_DEVPORTAL_HTTP_PORT value: "9763"
3. 调整WSO2 IS(密钥管理器)的SSL配置
同样在values.yaml里禁用IS的HTTPS,同时修改APIM和IS的通信协议为HTTP:
wso2is: service: ports: http: 9763 https: 9443 deployment: env: - name: IS_DISABLE_HTTPS value: "true" - name: IS_HTTP_PORT value: "9763" # 让APIM用HTTP和IS通信 wso2apim: configs: deployment.toml: [apim.key_manager] service_url = "http://wso2is-service:9763/services/" # 替换原来的https地址 oauth2.token_endpoint = "http://wso2is-service:9763/oauth2/token" oauth2.authorize_endpoint = "http://wso2is-service:9763/oauth2/authorize"
4. 禁用组件内部的SSL通信
修改APIM的deployment.toml配置,强制所有内部通信走HTTP:
[transport.http] listener.enabled = true listener.port = 8280 [transport.https] listener.enabled = false [apim.gateway.environment] service_url = "http://wso2apim-gateway-service:8280/services/" ws_endpoint = "ws://wso2apim-gateway-service:9099" wss_endpoint = "" # 禁用加密的WebSocket [apim.key_manager] service_url = "http://wso2is-service:9763/services/"
5. 应用配置并验证
- 跑Helm升级命令生效配置:
helm upgrade wso2-apim wso2/wso2apim --values your-modified-values.yaml -n your-namespace
- 检查Ingress状态,确认只监听80端口:
kubectl get ingress -n your-namespace
- 直接访问
http://your-preprod-domain.com/publisher或http://your-preprod-domain.com/devportal,确认能正常打开,不会被重定向到HTTPS。 - 查看APIM网关的Pod日志,确认和IS的通信没有SSL相关报错。
内容的提问来源于stack exchange,提问作者ahmadubuntu
相关产品推荐
相关产品推荐

