在Kubernetes上实现.NET Core MVC应用的HTTP与HTTPS访问
Got it, let's figure out why you're seeing that "Kubernetes Ingress Controller Fake Certificate" instead of your self-signed one, and get your HTTPS working properly with your .NET Core MVC app on Kubernetes.
What's Causing the Fake Certificate?
Your setup has two key mismatches right now:
- The
ssl-passthroughannotation isn't working (or shouldn't be used here):Docker Desktop's default nginx-ingress controller doesn't enable SSL passthrough out of the box—it requires a special flag to turn on. Since this annotation is being ignored, the ingress is trying to terminate TLS itself, but can't find/use your secret correctly, so it falls back to its default fake certificate. - Your SSL handling model doesn't match your Docker Compose setup:In Docker Compose, you had Nginx handling SSL termination (it took HTTPS traffic, decrypted it, and sent HTTP to your MVC app). But in Kubernetes, you're using
ssl-passthrough, which tells the ingress to send encrypted HTTPS traffic straight to your backend. Your MVC app isn't configured to handle HTTPS (since it relied on Nginx before), so this breaks the certificate flow.
Fix #1: Use Ingress for SSL Termination (Match Your Docker Compose Setup)
This is the easiest path since it mirrors what you were already doing with Docker Compose. Here's how to adjust your configs:
1. Update Your Ingress Manifest
Remove the ssl-passthrough annotation (we don't need it) and upgrade to the stable networking.k8s.io/v1 API version (v1beta1 is deprecated):
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: mvc-ingress annotations: kubernetes.io/ingress.class: nginx nginx.ingress.kubernetes.io/rewrite-target: / spec: tls: - hosts: - mymvc.local secretName: mvcsecret-tls rules: - host: mymvc.local http: paths: - path: / pathType: Prefix backend: service: name: mvc port: number: 5000
2. Verify Your TLS Secret is Correct
Double-check that your secret was created properly with the right certificate and key:
kubectl describe secret mvcsecret-tls -n default
Look for the Data section to confirm tls.crt and tls.key are present. If you need to re-create it (maybe the base64 encoding was off), run this:
kubectl create secret tls mvcsecret-tls --cert=./path/to/your/mymvc.local.crt --key=./path/to/your/mymvc.local.key
3. Restart the Ingress Controller (If Needed)
Sometimes the controller needs a nudge to pick up new configs:
kubectl rollout restart deployment nginx-ingress-controller -n kube-system
Fix #2: Use SSL Passthrough (If You Want Your App to Handle HTTPS)
If you want your .NET MVC app to handle HTTPS directly (instead of the ingress), you'll need to adjust a few things:
1. Configure Your .NET App for HTTPS
Package your self-signed certificate into your Docker image, or mount it via a Kubernetes secret. Update your app's startup code to listen on HTTPS (usually port 5001).
2. Update Your Service to Expose the HTTPS Port
Add a port for HTTPS to your service manifest:
apiVersion: v1 kind: Service metadata: name: mvc labels: app: mymvc spec: ports: - name: "mvc-http" port: 5000 targetPort: 5000 - name: "mvc-https" port: 5001 targetPort: 5001 selector: app: mymvc type: ClusterIP
3. Enable SSL Passthrough in the Ingress Controller
Docker Desktop's nginx-ingress doesn't have this enabled by default:
- Open Docker Desktop Settings → Kubernetes → Check "Show system containers (advanced)"
- Find the
nginx-ingress-controllerdeployment in thekube-systemnamespace - Edit the deployment, add
--enable-ssl-passthroughto the container'sargslist - Save and let the deployment restart
4. Update Your Ingress to Use Passthrough
Point the ingress to your app's HTTPS port and keep the ssl-passthrough annotation:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: mvc-ingress annotations: kubernetes.io/ingress.class: nginx nginx.ingress.kubernetes.io/ssl-passthrough: "true" nginx.ingress.kubernetes.io/rewrite-target: / spec: tls: - hosts: - mymvc.local secretName: mvcsecret-tls rules: - host: mymvc.local http: paths: - path: / pathType: Prefix backend: service: name: mvc port: number: 5001
Test It Out
After making changes, check your ingress status with:
kubectl describe ingress mvc-ingress
Then visit https://mymvc.local in your browser. You should see your self-signed certificate (not the fake one). To avoid browser warnings, import your self-signed cert into Windows' trusted root certificate store.
内容的提问来源于stack exchange,提问作者TheRoadrunner

