You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K8s部署AWX同步GitLab遇SSL错误:unsafe legacy renegotiation disabled

解决Kubernetes部署AWX同步GitLab时的SSL旧版协商问题

方案一:用ConfigMap覆盖AWX Pod的openssl.cnf

  • 创建包含UnsafeLegacyRenegotiation配置的openssl.cnf文件:
openssl_conf = openssl_init

[openssl_init]
ssl_conf = ssl_sect

[ssl_sect]
system_default = system_default_sect

[system_default_sect]
Options = UnsafeLegacyRenegotiation
  • 在AWX所在命名空间创建ConfigMap:
kubectl create configmap custom-openssl-cnf --from-file=openssl.cnf -n <你的AWX命名空间>
  • 修改AWX的Deployment资源,将ConfigMap挂载到Pod的/etc/ssl/目录以覆盖默认配置:
    在Deployment的spec.template.spec.volumes中添加:
    volumes:
      - name: custom-openssl-config
        configMap:
          name: custom-openssl-cnf
    
    在容器的volumeMounts中添加:
    volumeMounts:
      - name: custom-openssl-config
        mountPath: /etc/ssl/openssl.cnf
        subPath: openssl.cnf
    
  • 重启AWX Pod使配置生效:
kubectl rollout restart deployment/<AWX部署名称> -n <你的AWX命名空间>

方案二:通过环境变量指定SSL配置

AWX基于Python/Ansible运行,可通过环境变量强制加载自定义SSL配置:

  • 修改AWX的Deployment,添加环境变量:
env:
  - name: OPENSSL_CONF
    value: /etc/ssl/openssl.cnf

该配置需配合方案一的ConfigMap使用,确保Pod能加载到包含UnsafeLegacyRenegotiation的配置文件。

方案三:验证配置与测试

  • 进入AWX Pod检查openssl配置是否生效:
kubectl exec -it <AWX Pod名称> -n <你的AWX命名空间> -- openssl ciphers -v | grep -i renegotiation
  • 直接测试GitLab仓库克隆,确认问题是否解决:
kubectl exec -it <AWX Pod名称> -n <你的AWX命名空间> -- git clone https://<你的GitLab仓库地址>

内容的提问来源于stack exchange,提问作者Habbakuk barrera gomez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 22:43:13