You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在GKE Ingress或Istio Ingress中使用已创建的Google托管SSL证书

问题解答

一、将已有的DNS验证Google托管SSL证书用于Istio Ingress

Istio没有直接绑定GCP托管证书的专属注解,但可以通过GKE的BackendConfig资源关联证书,再绑定到Istio Gateway对应的Service上:

  1. 创建BackendConfig资源
    编写YAML文件,引用你已在GCP证书管理器中创建的DNS验证证书(替换YOUR_CERT_NAME为实际证书名称):

    apiVersion: cloud.google.com/v1
    kind: BackendConfig
    metadata:
      name: istio-gateway-backendconfig
    spec:
      ssl:
        sslCertificates:
        - certRef:
            name: YOUR_CERT_NAME
    
  2. 关联BackendConfig到Istio Gateway Service
    在Istio Gateway的LoadBalancer Service上添加注解,绑定上述BackendConfig:

    apiVersion: v1
    kind: Service
    metadata:
      name: istio-ingressgateway
      namespace: istio-system
      annotations:
        cloud.google.com/backend-config: '{"default": "istio-gateway-backendconfig"}'
    spec:
      type: LoadBalancer
      ports:
        - port: 443
          name: https
          targetPort: 8443
      selector:
        istio: ingressgateway
    
  3. 更新Istio Gateway配置
    开启HTTPS监听,根据SSL终止位置调整配置:

    • 若由GCP LB终止SSL,Istio处理HTTP流量:设置tls.mode: PASSTHROUGH
    • 若由Istio终止SSL,需将证书内容导入K8s Secret,在credentialName中指定Secret名称
    apiVersion: networking.istio.io/v1alpha3
    kind: Gateway
    metadata:
      name: istio-ingressgateway
      namespace: istio-system
    spec:
      selector:
        istio: ingressgateway
      servers:
        - port:
            number: 443
            name: https
            protocol: HTTPS
          tls:
            mode: SIMPLE # 或PASSTHROUGH
            credentialName: your-cert-secret # 仅SIMPLE模式需要
          hosts:
            - "*.example.com"
            - "example.com"
    

二、创建通配符证书(*.example.com)并绑定到Istio/GKE Ingress

由于GKE原生ManagedCertificate仅支持HTTP-01验证,无法生成通配符证书,必须通过GCP证书管理器手动创建DNS验证的通配符证书,再分别绑定:

步骤1:创建通配符证书

通过gcloud命令创建(替换YOUR_GCP_PROJECT为你的项目ID):

gcloud certificates create wildcard-example-com \
  --domains "*.example.com" \
  --dns-managed \
  --project YOUR_GCP_PROJECT

执行后,GCP会返回需添加的DNS CNAME记录,在域名服务商处完成记录添加,等待验证完成(通常几分钟到数小时)。

步骤2:绑定到GKE Ingress

在GKE Ingress资源中添加注解,引用通配符证书:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: example-ingress
  annotations:
    networking.gke.io/managed-certificates: "wildcard-example-com"
    kubernetes.io/ingress.class: "gce"
spec:
  rules:
    - host: "app.example.com"
      http:
        paths:
          - path: /*
            pathType: ImplementationSpecific
            backend:
              service:
                name: example-service
                port:
                  number: 80

步骤3:绑定到Istio Ingress(Gateway)

与第一部分的配置逻辑一致:

  1. 创建BackendConfig引用通配符证书
  2. 将BackendConfig关联到Istio Gateway的LoadBalancer Service
  3. 更新Istio Gateway的HTTPS监听配置,指定hosts为*.example.com

内容的提问来源于stack exchange,提问作者bhumiraj parmar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 11:41:00