You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Kubernetes上禁用WSO2 APIM与IS的SSL连接并测试SSL卸载

配置方案:禁用WSO2 APIM/IS与Ingress及内部的SSL连接

1. 调整Ingress配置,强制走HTTP

原来的Ingress如果配了TLS,直接删掉TLS相关配置,把转发端口改成WSO2组件的HTTP端口,同时关闭SSL重定向:

ingress:
  enabled: true
  annotations:
    # 关掉SSL自动重定向,避免用户访问HTTP被跳转到HTTPS
    nginx.ingress.kubernetes.io/ssl-redirect: "false"
  hosts:
    - host: your-preprod-domain.com
      paths:
        - path: /
          pathType: Prefix
          backend:
            service:
              name: wso2apim-gateway-service
              port:
                number: 8280 # 用网关的HTTP端口,别用8243的HTTPS端口
  # 直接删掉整个tls字段,别让Ingress尝试加载证书
  # tls:
  #   - hosts:
  #       - your-preprod-domain.com
  #     secretName: your-cert-secret

2. 禁用WSO2 APIM各组件的HTTPS

在Helm的values.yaml里,给APIM的网关、发布者、开发者门户添加环境变量,强制禁用HTTPS,只用HTTP:

网关配置

wso2apim:
  gateway:
    service:
      ports:
        http: 8280
        https: 8243 # 保留端口但不暴露,或者直接注释掉
    deployment:
      env:
        - name: APIM_GATEWAY_DISABLE_HTTPS
          value: "true"
        - name: APIM_GATEWAY_HTTP_PORT
          value: "8280"

发布者与开发者门户配置

wso2apim:
  publisher:
    service:
      ports:
        http: 9763
        https: 9443
    deployment:
      env:
        - name: APIM_PUBLISHER_DISABLE_HTTPS
          value: "true"
        - name: APIM_PUBLISHER_HTTP_PORT
          value: "9763"
  devportal:
    service:
      ports:
        http: 9763
        https: 9443
    deployment:
      env:
        - name: APIM_DEVPORTAL_DISABLE_HTTPS
          value: "true"
        - name: APIM_DEVPORTAL_HTTP_PORT
          value: "9763"

3. 调整WSO2 IS(密钥管理器)的SSL配置

同样在values.yaml里禁用IS的HTTPS,同时修改APIM和IS的通信协议为HTTP:

wso2is:
  service:
    ports:
      http: 9763
      https: 9443
  deployment:
    env:
      - name: IS_DISABLE_HTTPS
        value: "true"
      - name: IS_HTTP_PORT
        value: "9763"

# 让APIM用HTTP和IS通信
wso2apim:
  configs:
    deployment.toml:
      [apim.key_manager]
      service_url = "http://wso2is-service:9763/services/"  # 替换原来的https地址
      oauth2.token_endpoint = "http://wso2is-service:9763/oauth2/token"
      oauth2.authorize_endpoint = "http://wso2is-service:9763/oauth2/authorize"

4. 禁用组件内部的SSL通信

修改APIM的deployment.toml配置,强制所有内部通信走HTTP:

[transport.http]
listener.enabled = true
listener.port = 8280

[transport.https]
listener.enabled = false

[apim.gateway.environment]
service_url = "http://wso2apim-gateway-service:8280/services/"
ws_endpoint = "ws://wso2apim-gateway-service:9099"
wss_endpoint = ""  # 禁用加密的WebSocket

[apim.key_manager]
service_url = "http://wso2is-service:9763/services/"

5. 应用配置并验证

  • 跑Helm升级命令生效配置:
helm upgrade wso2-apim wso2/wso2apim --values your-modified-values.yaml -n your-namespace
  • 检查Ingress状态,确认只监听80端口:
kubectl get ingress -n your-namespace
  • 直接访问http://your-preprod-domain.com/publisher或http://your-preprod-domain.com/devportal,确认能正常打开,不会被重定向到HTTPS。
  • 查看APIM网关的Pod日志,确认和IS的通信没有SSL相关报错。

内容的提问来源于stack exchange,提问作者ahmadubuntu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 16:15:03