You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Kubernetes中部署带TLS的Ingress时出现"backend - 404 error"问题求助

Troubleshooting "backend - 404 error" with TLS-enabled Ingress

Let’s break down the possible issues and actionable fixes for your TLS-enabled Ingress returning a 404 error—since your non-TLS setup works, we can narrow the problem to the TLS/Ingress integration or certificate lifecycle.

1. First: Confirm Your TLS Certificate Was Successfully Issued

The most common root cause here is a failed certificate issuance, which breaks the Ingress routing. Run this command to check certificate status:

kubectl get certificates

Look for the esp-tls entry. If its status is not Ready, dig into the ACME challenge details:

  • List active challenges:
    kubectl get challenges
    
  • Inspect the failing challenge for clues:
    kubectl describe challenge <your-challenge-name>
    

Common challenge failures:

  • Your domain.com isn’t pointing to your static IP (verify with nslookup domain.com).
  • Port 80 is blocked (Let’s Encrypt needs port 80 open to validate domain ownership via HTTP01).
  • The email in your Issuer config is invalid (Let’s Encrypt sends critical alerts to this address).

2. Validate Backend Service Health

Even with a valid certificate, a broken backend will trigger 404s. Confirm your service and pods are working:

  • Check if your service has active endpoints (pods attached):
    kubectl get endpoints taxisbahia
    
    You should see at least one pod IP listed here. If not, check your Deployment’s pod status with kubectl get pods.
  • Test the backend directly to rule out app-level issues:
    kubectl port-forward service/taxisbahia 8080:8080
    
    Visit http://localhost:8080—if this loads the hello app, the problem is definitely in the Ingress/TLS layer.

3. Inspect Ingress Resource and Controller Logs

Check your Ingress for configuration errors or event alerts:

kubectl describe ingress esp-ingress

Look at the Events section—cert-manager should log messages like "Successfully authorized certificate" or "Certificate is ready". Any errors here will directly point to the issue.

Next, check the nginx-ingress controller logs for TLS or routing issues:

# Get the name of your nginx controller pod
kubectl get pods -l app.kubernetes.io/name=nginx-ingress-controller
# View logs for the pod
kubectl logs <nginx-controller-pod-name>

Look for lines mentioning esp-tls, domain.com, or 404 errors—these will tell you if the controller is failing to load the certificate or route traffic to the backend.

4. Verify Cert-manager and Ingress Class Compatibility

Your Issuer uses ingress.class: nginx and your Ingress uses the kubernetes.io/ingress.class: nginx annotation—this matches, so that’s good. However, if you’re using a newer nginx-ingress setup that relies on ingressClassName instead of annotations, you’d need to update the Issuer’s solver:

solvers:
- http01:
    ingress:
      ingressClassName: nginx

Since your non-TLS Ingress works with the annotation, this is unlikely the issue, but it’s worth checking if your nginx controller uses the newer class field.

5. Reset the TLS Secret (If Certificate Is Ready But Ingress Fails)

If the certificate shows Ready but the Ingress still returns 404, try deleting the existing secret to force cert-manager to reissue it:

kubectl delete secret esp-tls

Wait 30 seconds, then reapply your Ingress config:

kubectl apply -f ingress-tls.yaml

Check the certificate status again to ensure it’s recreated successfully.


内容的提问来源于stack exchange,提问作者Francisco Villegas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 22:17:32