You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K8s Nginx Ingress SSL配置:集群内部是否也需启用SSL?

正确的SSL配置方案(基于K8s Nginx Ingress Controller场景)

结论:只需要在Nginx Ingress Controller层面配置SSL证书即可,Pod内的Nginx完全不需要配置SSL

核心原因

  1. 流量路径优化:外部HTTPS请求先到达作为集群入口的Ingress Controller,由Ingress完成SSL解密后,以HTTP方式转发到后端Pod的Nginx。这种方式避免了Pod内重复做SSL加解密的资源消耗,同时大幅简化配置维护。
  2. 证书复用便捷:你用的是同一域名下的通配符证书(比如*.example.com),只需要在K8s中创建一次证书Secret,所有子域名对应的Ingress规则都能直接复用这个Secret,无需在每个Pod里重复部署证书。

具体配置步骤

1. 创建证书Secret

把你的SSL证书和私钥转换成K8s Secret:

kubectl create secret tls example-tls --cert=./fullchain.pem --key=./privkey.pem -n your-app-namespace

2. 编写Ingress资源配置(复用同一证书)

针对每个子域名的应用编写Ingress规则,都指向同一个证书Secret:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: app1-ingress
  namespace: your-app-namespace
  annotations:
    nginx.ingress.kubernetes.io/ssl-redirect: "true" # 强制HTTP请求转HTTPS
spec:
  tls:
  - hosts:
    - app1.example.com
    secretName: example-tls # 复用通配符证书Secret
  rules:
  - host: app1.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: app1-service
            port:
              number: 80
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: app2-ingress
  namespace: your-app-namespace
  annotations:
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
  tls:
  - hosts:
    - app2.example.com
    secretName: example-tls # 同样复用该证书
  rules:
  - host: app2.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: app2-service
            port:
              number: 80

额外注意点

  • Pod内的Nginx只需要监听80端口,删除所有SSL相关配置(比如ssl_certificate、ssl_certificate_key等指令),专注处理HTTP请求即可。
  • 除非你有集群内部Pod间通信必须加密的特殊需求,否则完全不需要在Pod内配置SSL——集群内部通信默认是可信环境,HTTP足够用,也可以通过NetworkPolicy限制Pod间的访问权限。

内容的提问来源于stack exchange,提问作者prosto.vint

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 05:02:43