如何为actions-runner-controller添加自签名证书根CA
为actions-runner-controller添加自定义根CA解决x509证书报错
问题背景
在K3S集群中运行actions-runner-controller时,因无法信任GitHub Enterprise Server的自签名证书,触发以下x509证书未知权威报错:
ERROR runner Failed to get new registration token {"runner": "github-actions-runner-small-001-rw88q-nhmhq", "error": "failed to create registration token: Post \"https://test-github.example.com/api/v3/orgs/myexample/actions/runners/registration-token/\": could not refresh installation id 5's token: could not get access_tokens from GitHub API for installation ID 5: x509: certificate signed by unknown authority"} github.com/actions/actions-runner-controller/controllers/actions%2esummerwind%2enet.(*RunnerReconciler).updateR
需修改actions-runner-controller镜像(非actions-runner镜像)使其信任自定义根CA。
现有Dockerfile问题
当前编写的Dockerfile仅将CA文件复制到/usr/local/share/my-root-ca.pem,但未将其加入系统信任证书库,因此controller进程无法自动识别该CA:
FROM summerwind/actions-runner-controller ADD ./My_Root_CA.pem /usr/local/share/my-root-ca.pem
解决步骤
1. 修改Dockerfile,更新系统证书信任
actions-runner-controller基础镜像基于Debian,需将CA文件放入系统证书目录并更新缓存:
FROM summerwind/actions-runner-controller # 将自定义根CA复制到系统证书目录,注意后缀改为.crt(update-ca-certificates默认识别该后缀) ADD ./My_Root_CA.pem /usr/local/share/ca-certificates/My_Root_CA.crt # 更新系统证书缓存,使新CA生效 RUN update-ca-certificates
2. 构建并推送自定义镜像
替换镜像仓库地址为你的私有仓库:
docker build -t your-registry/actions-runner-controller:custom-ca . docker push your-registry/actions-runner-controller:custom-ca
3. 更新K3S集群中的controller部署
- 找到controller的Deployment资源(默认在
actions-runner-system命名空间):kubectl get deployments -n actions-runner-system - 修改Deployment使用自定义镜像:
通过kubectl edit deployment actions-runner-controller -n actions-runner-system直接编辑,将.spec.template.spec.containers[0].image字段替换为你的自定义镜像地址。 - 保存后,集群会自动滚动更新controller Pod。
4. 验证结果
查看controller日志,确认x509证书错误不再出现:
kubectl logs -n actions-runner-system deployment/actions-runner-controller -f
内容的提问来源于stack exchange,提问作者Saitama
相关产品推荐
相关产品推荐

