Cert-Manager与Kubernetes卡在ACME HTTP-01挑战问题求助
Cert-Manager HTTP-01挑战失败,EOF错误导致证书无法正常颁发
问题背景
需为online.example.com、admin.example.com等子域名生成Let's Encrypt证书,使用cert-manager时遭遇HTTP-01挑战卡滞,报错EOF;certificate显示Ready=TRUE但实际无法获取有效证书,已尝试多种方案均无效。
配置文件
Issuer配置
apiVersion: cert-manager.io/v1 #kind: ClusterIssuer kind: Issuer metadata: name: letsencrypt-example namespace: example-developement spec: # ACME issuer configuration # `email` - the email address to be associated with the ACME account (make sure it's a valid one) # `server` - the URL used to access the ACME server’s directory endpoint # `privateKeySecretRef` - Kubernetes Secret to store the automatically generated ACME account private key acme: email: my_email@example.com server: https://acme-v02.api.letsencrypt.org/directory privateKeySecretRef: name: letsencrypt-example-private-key solvers: # Use the HTTP-01 challenge provider - http01: ingress: class: nginx
Ingress配置
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress-deployment namespace: example-developement annotations: #cert-manager.io/cluster-issuer: letsencrypt-example cert-manager.io/issuer: letsencrypt-example #acme.cert-manager.io/http01-edit-in-place: "true" kubernetes.io/ingress.class: "nginx" spec: ingressClassName: nginx # This section is only required if TLS is to be enabled for the Ingress tls: - secretName: letsencrypt-example hosts: - online.example.com - admin.example.com #- "*.example.com" rules: - host: online.example.com http: paths: - path: / pathType: Prefix backend: service: name: example-deployment-1 port: number: 5000 - host: admin.example.com http: paths: - path: / pathType: Prefix backend: service: name: example-deployment-2 port: number: 5050
当前环境与状态
- 服务为ClusterIP类型,运行正常,端口5000、5050已开放
- 域名DNS解析正常,未使用cert-manager时可正常访问服务
- cert-manager版本尝试过1.8.0和1.11.0,均无效
- ACME挑战报错:
Token: yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo Type: HTTP-01 URL: https://acme-v02.api.letsencrypt.org/acme/chall-v3/214222226707/pHSajg Wildcard: false Status: Presented: true Processing: true Reason: Waiting for HTTP-01 challenge propagation: failed to perform self check GET request 'http://admin.example.com/.well-known/acme-challenge/yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo': Get "http://admin.example.com/.well-known/acme-challenge/yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo": EOF State: pending Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal Started 6m40s cert-manager-challenges Challenge scheduled for processing Normal Presented 6m39s cert-manager-challenges Presented challenge using HTTP-01 challenge mechanism
- certificaterequest、order、挑战均处于pending状态;certificate显示
Ready=TRUE,但实际无法获取有效证书,最长等待8小时无变化
已尝试操作
- 切换为泛域名
*.example.com申请证书 - 改用ClusterIssuer替代Issuer
- 重建Kubernetes集群
- 多次删除Ingress并重装cert-manager
排查与解决方案
1. 验证挑战路径的可访问性
从集群内部和外部分别测试访问挑战路径:
- 集群内部:在任意Pod中执行
curl -v http://admin.example.com/.well-known/acme-challenge/yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo,确认是否返回正确token值 - 集群外部:本地终端执行上述命令,检查80端口是否被防火墙、负载均衡拦截,网络通路是否正常
2. 检查nginx-ingress控制器状态与日志
- 查看nginx-ingress Pod日志,过滤ACME相关请求:
kubectl logs -n kube-system <nginx-ingress-pod-name> | grep acme,确认挑战请求是否被正确转发到cert-manager的solver Pod - 清理Ingress配置冲突:移除
kubernetes.io/ingress.class注解,仅保留spec.ingressClassName: nginx,避免双重配置导致路由异常
3. 修复自检查EOF错误
EOF错误通常表示连接被强制断开,可尝试:
- 检查集群出口网络:确认集群能正常访问Let's Encrypt的ACME服务器,且支持内部DNS回环(即集群内Pod可访问自身域名)
- 启用
http01-edit-in-place:取消Ingress中acme.cert-manager.io/http01-edit-in-place: "true"的注释,让cert-manager直接修改现有Ingress,避免临时Ingress引发的网络规则冲突
4. 检查cert-manager挑战Pod状态
查看临时挑战Pod:kubectl get pods -n example-developement | grep challenge,确认Pod是否正常运行,是否能被nginx-ingress正确路由
5. 用Dry-Run模式验证配置
创建测试证书,排查配置错误:
kubectl apply -f - <<EOF apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: test-cert namespace: example-developement spec: secretName: test-cert-secret issuerRef: name: letsencrypt-example kind: Issuer commonName: online.example.com dnsNames: - online.example.com - admin.example.com privateKey: algorithm: RSA size: 2048 usages: - server auth - client auth EOF
查看证书状态:kubectl describe certificate test-cert -n example-developement,获取更明确的错误信息
内容的提问来源于stack exchange,提问作者user2572104
相关产品推荐
相关产品推荐

