You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker运行证书过期监控控制器报错:需定义KUBERNETES环境变量

问题解答

Kubernetes是否为必填项?

是的,mercari/certificate-expiry-monitor-controller本质是Kubernetes控制器组件,核心逻辑是对接Kubernetes API,扫描集群内Ingress、Secret等资源中的证书并监控过期时间。从你遇到的错误能明确看出,它启动时会强制加载K8s集群内配置,依赖KUBERNETES_SERVICE_HOST和KUBERNETES_SERVICE_PORT这两个K8s专属环境变量连接集群,没有Kubernetes的话,这个工具无法正常运行。

仅用Docker运行证书过期监控的替代方案

既然你的环境没有Kubernetes,推荐以下纯Docker可运行的证书监控工具:

  • cert-monitor:轻量级工具,支持扫描本地证书文件或远程HTTPS站点证书,可配置邮件、钉钉等告警方式
    运行示例:

    docker run -d \
      -e CHECK_INTERVAL=86400 \
      -e ALERT_EMAIL=your-email@example.com \
      -e TARGETS="https://example.com,/path/to/local/cert.pem" \
      ghcr.io/joe-speedboat/cert-monitor:latest
    
  • cert-exporter:除监控外还能导出Prometheus指标(适配已有监控系统场景),支持远程站点和本地证书扫描
    运行示例:

    docker run -d \
      -p 9117:9117 \
      -v /path/to/certs:/certs:ro \
      quay.io/giantswarm/cert-exporter:latest \
      --listen-address=:9117 \
      --cert-glob="/certs/*.pem" \
      --web-addresses="https://example.com"
    
  • simple-cert-monitor:极简脚本式工具,专注证书过期检查和邮件告警,适合轻量需求场景
    运行示例:

    docker run -d \
      -e CERT_URLS="https://example.com" \
      -e SMTP_HOST=smtp.example.com \
      -e SMTP_PORT=587 \
      -e SMTP_USER=your-user \
      -e SMTP_PASS=your-pass \
      -e ALERT_TO=alert@example.com \
      msoap/simple-cert-monitor:latest
    

内容的提问来源于stack exchange,提问作者andrew

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 05:10:01