如何在GKE Ingress或Istio Ingress中使用已创建的Google托管SSL证书
问题解答
一、将已有的DNS验证Google托管SSL证书用于Istio Ingress
Istio没有直接绑定GCP托管证书的专属注解,但可以通过GKE的BackendConfig资源关联证书,再绑定到Istio Gateway对应的Service上:
创建BackendConfig资源
编写YAML文件,引用你已在GCP证书管理器中创建的DNS验证证书(替换YOUR_CERT_NAME为实际证书名称):apiVersion: cloud.google.com/v1 kind: BackendConfig metadata: name: istio-gateway-backendconfig spec: ssl: sslCertificates: - certRef: name: YOUR_CERT_NAME关联BackendConfig到Istio Gateway Service
在Istio Gateway的LoadBalancer Service上添加注解,绑定上述BackendConfig:apiVersion: v1 kind: Service metadata: name: istio-ingressgateway namespace: istio-system annotations: cloud.google.com/backend-config: '{"default": "istio-gateway-backendconfig"}' spec: type: LoadBalancer ports: - port: 443 name: https targetPort: 8443 selector: istio: ingressgateway更新Istio Gateway配置
开启HTTPS监听,根据SSL终止位置调整配置:- 若由GCP LB终止SSL,Istio处理HTTP流量:设置
tls.mode: PASSTHROUGH - 若由Istio终止SSL,需将证书内容导入K8s Secret,在
credentialName中指定Secret名称
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: istio-ingressgateway namespace: istio-system spec: selector: istio: ingressgateway servers: - port: number: 443 name: https protocol: HTTPS tls: mode: SIMPLE # 或PASSTHROUGH credentialName: your-cert-secret # 仅SIMPLE模式需要 hosts: - "*.example.com" - "example.com"- 若由GCP LB终止SSL,Istio处理HTTP流量:设置
二、创建通配符证书(*.example.com)并绑定到Istio/GKE Ingress
由于GKE原生ManagedCertificate仅支持HTTP-01验证,无法生成通配符证书,必须通过GCP证书管理器手动创建DNS验证的通配符证书,再分别绑定:
步骤1:创建通配符证书
通过gcloud命令创建(替换YOUR_GCP_PROJECT为你的项目ID):
gcloud certificates create wildcard-example-com \ --domains "*.example.com" \ --dns-managed \ --project YOUR_GCP_PROJECT
执行后,GCP会返回需添加的DNS CNAME记录,在域名服务商处完成记录添加,等待验证完成(通常几分钟到数小时)。
步骤2:绑定到GKE Ingress
在GKE Ingress资源中添加注解,引用通配符证书:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: example-ingress annotations: networking.gke.io/managed-certificates: "wildcard-example-com" kubernetes.io/ingress.class: "gce" spec: rules: - host: "app.example.com" http: paths: - path: /* pathType: ImplementationSpecific backend: service: name: example-service port: number: 80
步骤3:绑定到Istio Ingress(Gateway)
与第一部分的配置逻辑一致:
- 创建BackendConfig引用通配符证书
- 将BackendConfig关联到Istio Gateway的LoadBalancer Service
- 更新Istio Gateway的HTTPS监听配置,指定hosts为
*.example.com
内容的提问来源于stack exchange,提问作者bhumiraj parmar
相关产品推荐
相关产品推荐

