在Kubernetes中部署带TLS的Ingress时出现"backend - 404 error"问题求助
Let’s break down the possible issues and actionable fixes for your TLS-enabled Ingress returning a 404 error—since your non-TLS setup works, we can narrow the problem to the TLS/Ingress integration or certificate lifecycle.
1. First: Confirm Your TLS Certificate Was Successfully Issued
The most common root cause here is a failed certificate issuance, which breaks the Ingress routing. Run this command to check certificate status:
kubectl get certificates
Look for the esp-tls entry. If its status is not Ready, dig into the ACME challenge details:
- List active challenges:
kubectl get challenges - Inspect the failing challenge for clues:
kubectl describe challenge <your-challenge-name>
Common challenge failures:
- Your
domain.comisn’t pointing to your static IP (verify withnslookup domain.com). - Port 80 is blocked (Let’s Encrypt needs port 80 open to validate domain ownership via HTTP01).
- The email in your Issuer config is invalid (Let’s Encrypt sends critical alerts to this address).
2. Validate Backend Service Health
Even with a valid certificate, a broken backend will trigger 404s. Confirm your service and pods are working:
- Check if your service has active endpoints (pods attached):
You should see at least one pod IP listed here. If not, check your Deployment’s pod status withkubectl get endpoints taxisbahiakubectl get pods. - Test the backend directly to rule out app-level issues:
Visitkubectl port-forward service/taxisbahia 8080:8080http://localhost:8080—if this loads the hello app, the problem is definitely in the Ingress/TLS layer.
3. Inspect Ingress Resource and Controller Logs
Check your Ingress for configuration errors or event alerts:
kubectl describe ingress esp-ingress
Look at the Events section—cert-manager should log messages like "Successfully authorized certificate" or "Certificate is ready". Any errors here will directly point to the issue.
Next, check the nginx-ingress controller logs for TLS or routing issues:
# Get the name of your nginx controller pod kubectl get pods -l app.kubernetes.io/name=nginx-ingress-controller # View logs for the pod kubectl logs <nginx-controller-pod-name>
Look for lines mentioning esp-tls, domain.com, or 404 errors—these will tell you if the controller is failing to load the certificate or route traffic to the backend.
4. Verify Cert-manager and Ingress Class Compatibility
Your Issuer uses ingress.class: nginx and your Ingress uses the kubernetes.io/ingress.class: nginx annotation—this matches, so that’s good. However, if you’re using a newer nginx-ingress setup that relies on ingressClassName instead of annotations, you’d need to update the Issuer’s solver:
solvers: - http01: ingress: ingressClassName: nginx
Since your non-TLS Ingress works with the annotation, this is unlikely the issue, but it’s worth checking if your nginx controller uses the newer class field.
5. Reset the TLS Secret (If Certificate Is Ready But Ingress Fails)
If the certificate shows Ready but the Ingress still returns 404, try deleting the existing secret to force cert-manager to reissue it:
kubectl delete secret esp-tls
Wait 30 seconds, then reapply your Ingress config:
kubectl apply -f ingress-tls.yaml
Check the certificate status again to ensure it’s recreated successfully.
内容的提问来源于stack exchange,提问作者Francisco Villegas

