You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure DNS与cert-manager申请DNS证书时遇授权错误求助

使用cert-manager结合Azure DNS生成DNS证书时的403授权错误及凭据刷新问题

我按照cert-manager的Azure DNS DNS01挑战配置文档(托管标识+AAD Pod Identity方式)操作,已完成以下步骤:

  • 添加托管标识及联合凭据,且联合凭据已关联cert-manager使用的服务账户和对应命名空间
  • 在Azure门户确认该托管标识已被授予目标DNS区域的DNS Contributor角色

但证书挑战过程中仍抛出403授权错误:

Status=403 Code="AuthorizationFailed" Message="The client '<principal_id>' with object id '<principal_id>' does not have authorization to perform action 'Microsoft.Network/dnsZones/TXT/write' over scope '/subscriptions/<sub_id>/resourceGroups/<resource_group>/providers/Microsoft.Network/dnsZones/<dns_zone>/TXT/_acme-challenge' or the scope is invalid. If access was recently granted, please refresh your credentials."

我已经尝试通过kubectl重新创建签发者和挑战资源,请问该如何刷新凭据?

联合凭据配置截图
DNS区域角色权限配置截图


内容的提问来源于stack exchange,提问作者Amartya Gaur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 02:15:26