You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cert-Manager与Kubernetes卡在ACME HTTP-01挑战问题求助

Cert-Manager HTTP-01挑战失败,EOF错误导致证书无法正常颁发

问题背景

需为online.example.com、admin.example.com等子域名生成Let's Encrypt证书,使用cert-manager时遭遇HTTP-01挑战卡滞,报错EOF;certificate显示Ready=TRUE但实际无法获取有效证书,已尝试多种方案均无效。

配置文件

Issuer配置

apiVersion: cert-manager.io/v1
#kind: ClusterIssuer
kind: Issuer
metadata:
  name: letsencrypt-example
  namespace: example-developement
spec:
  # ACME issuer configuration
  # `email` - the email address to be associated with the ACME account (make sure it's a valid one)
  # `server` - the URL used to access the ACME server’s directory endpoint
  # `privateKeySecretRef` - Kubernetes Secret to store the automatically generated ACME account private key
  acme:
    email: my_email@example.com
    server: https://acme-v02.api.letsencrypt.org/directory
    privateKeySecretRef:
      name: letsencrypt-example-private-key
    solvers:
      # Use the HTTP-01 challenge provider
      - http01:
          ingress:
            class: nginx

Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ingress-deployment
  namespace: example-developement
  annotations:
    #cert-manager.io/cluster-issuer: letsencrypt-example
    cert-manager.io/issuer: letsencrypt-example
    #acme.cert-manager.io/http01-edit-in-place: "true"
    kubernetes.io/ingress.class: "nginx"
spec:
  ingressClassName: nginx
  # This section is only required if TLS is to be enabled for the Ingress
  tls:
    - secretName: letsencrypt-example
      hosts:
      - online.example.com
      - admin.example.com
      #- "*.example.com"
  rules:
    - host: online.example.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: example-deployment-1
                port:
                  number: 5000
    - host: admin.example.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: example-deployment-2
                port:
                  number: 5050

当前环境与状态

  • 服务为ClusterIP类型,运行正常,端口5000、5050已开放
  • 域名DNS解析正常,未使用cert-manager时可正常访问服务
  • cert-manager版本尝试过1.8.0和1.11.0,均无效
  • ACME挑战报错:
Token:       yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo
  Type:        HTTP-01
  URL:         https://acme-v02.api.letsencrypt.org/acme/chall-v3/214222226707/pHSajg
  Wildcard:    false
Status:
  Presented:   true
  Processing:  true
  Reason:      Waiting for HTTP-01 challenge propagation: failed to perform self check GET request 'http://admin.example.com/.well-known/acme-challenge/yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo': Get "http://admin.example.com/.well-known/acme-challenge/yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo": EOF
  State:       pending
Events:
  Type    Reason     Age    From                     Message
  ----    ------     ----   ----                     -------
  Normal  Started    6m40s  cert-manager-challenges  Challenge scheduled for processing
  Normal  Presented  6m39s  cert-manager-challenges  Presented challenge using HTTP-01 challenge mechanism
  • certificaterequest、order、挑战均处于pending状态;certificate显示Ready=TRUE,但实际无法获取有效证书,最长等待8小时无变化

已尝试操作

  • 切换为泛域名*.example.com申请证书
  • 改用ClusterIssuer替代Issuer
  • 重建Kubernetes集群
  • 多次删除Ingress并重装cert-manager

排查与解决方案

1. 验证挑战路径的可访问性

从集群内部和外部分别测试访问挑战路径:

  • 集群内部:在任意Pod中执行curl -v http://admin.example.com/.well-known/acme-challenge/yOnqojz1VkV_7qiMS7SYr6RgqUoayv0Dr4R5VqCD4oo,确认是否返回正确token值
  • 集群外部:本地终端执行上述命令,检查80端口是否被防火墙、负载均衡拦截,网络通路是否正常

2. 检查nginx-ingress控制器状态与日志

  • 查看nginx-ingress Pod日志,过滤ACME相关请求:kubectl logs -n kube-system <nginx-ingress-pod-name> | grep acme,确认挑战请求是否被正确转发到cert-manager的solver Pod
  • 清理Ingress配置冲突:移除kubernetes.io/ingress.class注解,仅保留spec.ingressClassName: nginx,避免双重配置导致路由异常

3. 修复自检查EOF错误

EOF错误通常表示连接被强制断开,可尝试:

  • 检查集群出口网络:确认集群能正常访问Let's Encrypt的ACME服务器,且支持内部DNS回环(即集群内Pod可访问自身域名)
  • 启用http01-edit-in-place:取消Ingress中acme.cert-manager.io/http01-edit-in-place: "true"的注释,让cert-manager直接修改现有Ingress,避免临时Ingress引发的网络规则冲突

4. 检查cert-manager挑战Pod状态

查看临时挑战Pod:kubectl get pods -n example-developement | grep challenge,确认Pod是否正常运行,是否能被nginx-ingress正确路由

5. 用Dry-Run模式验证配置

创建测试证书,排查配置错误:

kubectl apply -f - <<EOF
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: test-cert
  namespace: example-developement
spec:
  secretName: test-cert-secret
  issuerRef:
    name: letsencrypt-example
    kind: Issuer
  commonName: online.example.com
  dnsNames:
    - online.example.com
    - admin.example.com
  privateKey:
    algorithm: RSA
    size: 2048
  usages:
    - server auth
    - client auth
EOF

查看证书状态:kubectl describe certificate test-cert -n example-developement,获取更明确的错误信息


内容的提问来源于stack exchange,提问作者user2572104

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 22:35:39