使用Azure DNS与cert-manager申请DNS证书时遇授权错误求助
使用cert-manager结合Azure DNS生成DNS证书时的403授权错误及凭据刷新问题
我按照cert-manager的Azure DNS DNS01挑战配置文档(托管标识+AAD Pod Identity方式)操作,已完成以下步骤:
- 添加托管标识及联合凭据,且联合凭据已关联cert-manager使用的服务账户和对应命名空间
- 在Azure门户确认该托管标识已被授予目标DNS区域的DNS Contributor角色
但证书挑战过程中仍抛出403授权错误:
Status=403 Code="AuthorizationFailed" Message="The client '<principal_id>' with object id '<principal_id>' does not have authorization to perform action 'Microsoft.Network/dnsZones/TXT/write' over scope '/subscriptions/<sub_id>/resourceGroups/<resource_group>/providers/Microsoft.Network/dnsZones/<dns_zone>/TXT/_acme-challenge' or the scope is invalid. If access was recently granted, please refresh your credentials."
我已经尝试通过kubectl重新创建签发者和挑战资源,请问该如何刷新凭据?


内容的提问来源于stack exchange,提问作者Amartya Gaur
相关产品推荐
相关产品推荐

