新手求助:K8ssandra中Cassandra TLS/SSL加密配置失败
Let's work through your issues step by step—there are two key problems to resolve: the missing keystore/truststore files in your Cassandra pods, and the failed SSL login via cqlsh.
1. Why Your Key/Truststore Files Aren't Showing Up in the Pod
You created the Secrets for your keystore and truststore, but you haven't told the K8ssandra operator to mount these Secrets into your Cassandra pods. The values.yaml you used with helm upgrade applies to the K8ssandra operator itself, not the Cassandra workloads it manages. We need to update your K8ssandraCluster CRD to add the volume mounts.
Fix: Update the K8ssandraCluster CRD to Mount Secrets
Modify your existing K8ssandraCluster manifest (or create a new updated version) to include volume mounts for the keystore and truststore Secrets:
apiVersion: k8ssandra.io/v1alpha1 kind: K8ssandraCluster metadata: name: demo spec: cassandra: serverVersion: "4.0.1" datacenters: - metadata: name: dc1 size: 3 storageConfig: cassandraDataVolumeClaimSpec: storageClassName: standard accessModes: - ReadWriteOnce resources: requests: storage: 5Gi config: jvmOptions: heapSize: 512M # Add this section to mount the secrets into Cassandra pods podTemplateSpec: spec: volumes: - name: keystore-volume secret: secretName: keystore - name: truststore-volume secret: secretName: truststore containers: - name: cassandra volumeMounts: - name: keystore-volume mountPath: /mnt/keystore readOnly: true - name: truststore-volume mountPath: /mnt/truststore readOnly: true stargate: size: 1 heapSize: 256M
Apply this updated CRD with:
kubectl apply -f updated-k8ssandracluster.yaml -n k8ssandra-operator
Wait for the Cassandra StatefulSet to roll out (pods will restart to apply the new mounts). Check the status with:
kubectl rollout status statefulset demo-dc1-default-sts -n k8ssandra-operator
Once pods are running, verify the files exist:
kubectl exec -it demo-dc1-default-sts-0 -n k8ssandra-operator -c cassandra -- ls -l /mnt/keystore /mnt/truststore
2. Fixing the cqlsh SSL Login Failure
The error you're seeing happens because cqlsh needs a valid certificate to verify Cassandra's SSL certificate. Here are two ways to fix this:
Option 1: Configure cqlsh with Your Truststore Certificate (Recommended for Production)
First, extract the CA certificate from your local truststore (you'll need keytool installed on your machine):
keytool -export -alias cassandra -file cassandra.crt -keystore ./mnt/truststore/truststore.jks -storepass cassandra
Copy this certificate into the Cassandra pod:
kubectl cp cassandra.crt k8ssandra-operator/demo-dc1-default-sts-0:/home/cassandra/.cassandra/ -c cassandra
Create a cqlshrc file in the pod to reference the certificate:
kubectl exec -it demo-dc1-default-sts-0 -n k8ssandra-operator -c cassandra -- bash -c 'cat > /home/cassandra/.cassandra/cqlshrc << EOF [ssl] certfile = /home/cassandra/.cassandra/cassandra.crt validate = true EOF'
Now you can connect with SSL:
cqlsh --ssl -u demo-superuser -p JKv59QPynp3s0qGSf1DZ demo-dc1-stargate-service
Option 2: Disable Certificate Validation (Only for Testing)
If you just need to test connectivity without strict validation (not recommended for production), disable it via cqlshrc:
kubectl exec -it demo-dc1-default-sts-0 -n k8ssandra-operator -c cassandra -- bash -c 'cat > /home/cassandra/.cassandra/cqlshrc << EOF [ssl] validate = false EOF'
Then connect with:
cqlsh --ssl -u demo-superuser -p JKv59QPynp3s0qGSf1DZ demo-dc1-stargate-service
Quick Additional Checks
- Double-check your
cassandra.yamlConfigMap to ensure the keystore/truststore paths and passwords match your actual files. - Verify your Secrets contain the correct files:
kubectl get secret keystore -n k8ssandra-operator -o jsonpath='{.data.keystore\.jks}' | base64 --decode > test-keystore.jks keytool -list -keystore test-keystore.jks -storepass cassandra # This should show your keystore entries
内容的提问来源于stack exchange,提问作者Jennifer Schuhmacher

