You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Salt状态应用失败:acme.cert模块缺失的解决咨询

解决方案

替代方案:直接使用certbot命令(无需额外模块)

既然你已经在状态里安装了certbot包,可以直接通过cmd.run调用certbot原生命令来生成证书,完全不需要依赖acme.cert模块,修改后的certbot.sls如下:

certbot:
  pkg.installed:
    - name: certbot

reload-nginx:
  cmd.run:
    - name: systemctl reload nginx.service
    - onchanges:
      - cmd: <my.domain>-cert

<my.domain>-cert:
  cmd.run:
    - name: certbot certonly --webroot -w /srv/<my.domain>/ -d <my.domain> --email <my.email> --agree-tos --non-interactive
    - creates: /etc/letsencrypt/live/<my.domain>/fullchain.pem
    - require:
      - pkg: certbot

# 配置自动续期
certbot-renew:
  cron.present:
    - name: certbot renew --quiet --renew-hook "systemctl reload nginx.service"
    - user: root
    - minute: 0
    - hour: 3
    - daymonth: '*'
    - month: '*'
    - dayweek: '*'

关键说明:

  • creates参数:检查证书文件是否存在,避免重复执行证书生成命令
  • onchanges关联:只有当证书生成/更新时,才触发nginx重载
  • 自动续期的cron任务:每天凌晨3点执行续期检查,若证书需要更新则自动续期并重载nginx

若坚持使用acme.cert模块

如果一定要用这个模块,需要在minion上安装对应的Salt扩展:

  1. 在minion节点执行pip install salt-acme(需确保pip环境可用)
  2. 重启salt-minion服务:systemctl restart salt-minion
  3. 重新应用Salt状态

不过这种方式可能存在版本兼容性问题,不如直接使用certbot原生命令稳定可靠。

内容的提问来源于stack exchange,提问作者joshi1999

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 04:52:15