Salt状态应用失败:acme.cert模块缺失的解决咨询
解决方案
替代方案:直接使用certbot命令(无需额外模块)
既然你已经在状态里安装了certbot包,可以直接通过cmd.run调用certbot原生命令来生成证书,完全不需要依赖acme.cert模块,修改后的certbot.sls如下:
certbot: pkg.installed: - name: certbot reload-nginx: cmd.run: - name: systemctl reload nginx.service - onchanges: - cmd: <my.domain>-cert <my.domain>-cert: cmd.run: - name: certbot certonly --webroot -w /srv/<my.domain>/ -d <my.domain> --email <my.email> --agree-tos --non-interactive - creates: /etc/letsencrypt/live/<my.domain>/fullchain.pem - require: - pkg: certbot # 配置自动续期 certbot-renew: cron.present: - name: certbot renew --quiet --renew-hook "systemctl reload nginx.service" - user: root - minute: 0 - hour: 3 - daymonth: '*' - month: '*' - dayweek: '*'
关键说明:
creates参数:检查证书文件是否存在,避免重复执行证书生成命令onchanges关联:只有当证书生成/更新时,才触发nginx重载- 自动续期的cron任务:每天凌晨3点执行续期检查,若证书需要更新则自动续期并重载nginx
若坚持使用acme.cert模块
如果一定要用这个模块,需要在minion上安装对应的Salt扩展:
- 在minion节点执行
pip install salt-acme(需确保pip环境可用) - 重启salt-minion服务:
systemctl restart salt-minion - 重新应用Salt状态
不过这种方式可能存在版本兼容性问题,不如直接使用certbot原生命令稳定可靠。
内容的提问来源于stack exchange,提问作者joshi1999
相关产品推荐
相关产品推荐

