You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Kubernetes上实现.NET Core MVC应用的HTTP与HTTPS访问

Got it, let's figure out why you're seeing that "Kubernetes Ingress Controller Fake Certificate" instead of your self-signed one, and get your HTTPS working properly with your .NET Core MVC app on Kubernetes.

What's Causing the Fake Certificate?

Your setup has two key mismatches right now:

  1. The ssl-passthrough annotation isn't working (or shouldn't be used here):Docker Desktop's default nginx-ingress controller doesn't enable SSL passthrough out of the box—it requires a special flag to turn on. Since this annotation is being ignored, the ingress is trying to terminate TLS itself, but can't find/use your secret correctly, so it falls back to its default fake certificate.
  2. Your SSL handling model doesn't match your Docker Compose setup:In Docker Compose, you had Nginx handling SSL termination (it took HTTPS traffic, decrypted it, and sent HTTP to your MVC app). But in Kubernetes, you're using ssl-passthrough, which tells the ingress to send encrypted HTTPS traffic straight to your backend. Your MVC app isn't configured to handle HTTPS (since it relied on Nginx before), so this breaks the certificate flow.

Fix #1: Use Ingress for SSL Termination (Match Your Docker Compose Setup)

This is the easiest path since it mirrors what you were already doing with Docker Compose. Here's how to adjust your configs:

1. Update Your Ingress Manifest

Remove the ssl-passthrough annotation (we don't need it) and upgrade to the stable networking.k8s.io/v1 API version (v1beta1 is deprecated):

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: mvc-ingress
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/rewrite-target: /
spec:
  tls:
  - hosts:
    - mymvc.local
    secretName: mvcsecret-tls
  rules:
  - host: mymvc.local
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: mvc
            port:
              number: 5000

2. Verify Your TLS Secret is Correct

Double-check that your secret was created properly with the right certificate and key:

kubectl describe secret mvcsecret-tls -n default

Look for the Data section to confirm tls.crt and tls.key are present. If you need to re-create it (maybe the base64 encoding was off), run this:

kubectl create secret tls mvcsecret-tls --cert=./path/to/your/mymvc.local.crt --key=./path/to/your/mymvc.local.key

3. Restart the Ingress Controller (If Needed)

Sometimes the controller needs a nudge to pick up new configs:

kubectl rollout restart deployment nginx-ingress-controller -n kube-system

Fix #2: Use SSL Passthrough (If You Want Your App to Handle HTTPS)

If you want your .NET MVC app to handle HTTPS directly (instead of the ingress), you'll need to adjust a few things:

1. Configure Your .NET App for HTTPS

Package your self-signed certificate into your Docker image, or mount it via a Kubernetes secret. Update your app's startup code to listen on HTTPS (usually port 5001).

2. Update Your Service to Expose the HTTPS Port

Add a port for HTTPS to your service manifest:

apiVersion: v1
kind: Service
metadata:
  name: mvc
  labels:
    app: mymvc
spec:
  ports:
  - name: "mvc-http"
    port: 5000
    targetPort: 5000
  - name: "mvc-https"
    port: 5001
    targetPort: 5001
  selector:
    app: mymvc
  type: ClusterIP

3. Enable SSL Passthrough in the Ingress Controller

Docker Desktop's nginx-ingress doesn't have this enabled by default:

  1. Open Docker Desktop Settings → Kubernetes → Check "Show system containers (advanced)"
  2. Find the nginx-ingress-controller deployment in the kube-system namespace
  3. Edit the deployment, add --enable-ssl-passthrough to the container's args list
  4. Save and let the deployment restart

4. Update Your Ingress to Use Passthrough

Point the ingress to your app's HTTPS port and keep the ssl-passthrough annotation:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: mvc-ingress
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/ssl-passthrough: "true"
    nginx.ingress.kubernetes.io/rewrite-target: /
spec:
  tls:
  - hosts:
    - mymvc.local
    secretName: mvcsecret-tls
  rules:
  - host: mymvc.local
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: mvc
            port:
              number: 5001

Test It Out

After making changes, check your ingress status with:

kubectl describe ingress mvc-ingress

Then visit https://mymvc.local in your browser. You should see your self-signed certificate (not the fake one). To avoid browser warnings, import your self-signed cert into Windows' trusted root certificate store.

内容的提问来源于stack exchange,提问作者TheRoadrunner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 09:17:37