You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

新手求助:K8ssandra中Cassandra TLS/SSL加密配置失败

Troubleshooting TLS/SSL Setup for Cassandra in K8ssandra

Let's work through your issues step by step—there are two key problems to resolve: the missing keystore/truststore files in your Cassandra pods, and the failed SSL login via cqlsh.

1. Why Your Key/Truststore Files Aren't Showing Up in the Pod

You created the Secrets for your keystore and truststore, but you haven't told the K8ssandra operator to mount these Secrets into your Cassandra pods. The values.yaml you used with helm upgrade applies to the K8ssandra operator itself, not the Cassandra workloads it manages. We need to update your K8ssandraCluster CRD to add the volume mounts.

Fix: Update the K8ssandraCluster CRD to Mount Secrets

Modify your existing K8ssandraCluster manifest (or create a new updated version) to include volume mounts for the keystore and truststore Secrets:

apiVersion: k8ssandra.io/v1alpha1
kind: K8ssandraCluster
metadata:
  name: demo
spec:
  cassandra:
    serverVersion: "4.0.1"
    datacenters:
      - metadata:
          name: dc1
        size: 3
        storageConfig:
          cassandraDataVolumeClaimSpec:
            storageClassName: standard
            accessModes:
              - ReadWriteOnce
            resources:
              requests:
                storage: 5Gi
        config:
          jvmOptions:
            heapSize: 512M
        # Add this section to mount the secrets into Cassandra pods
        podTemplateSpec:
          spec:
            volumes:
              - name: keystore-volume
                secret:
                  secretName: keystore
              - name: truststore-volume
                secret:
                  secretName: truststore
            containers:
              - name: cassandra
                volumeMounts:
                  - name: keystore-volume
                    mountPath: /mnt/keystore
                    readOnly: true
                  - name: truststore-volume
                    mountPath: /mnt/truststore
                    readOnly: true
        stargate:
          size: 1
          heapSize: 256M

Apply this updated CRD with:

kubectl apply -f updated-k8ssandracluster.yaml -n k8ssandra-operator

Wait for the Cassandra StatefulSet to roll out (pods will restart to apply the new mounts). Check the status with:

kubectl rollout status statefulset demo-dc1-default-sts -n k8ssandra-operator

Once pods are running, verify the files exist:

kubectl exec -it demo-dc1-default-sts-0 -n k8ssandra-operator -c cassandra -- ls -l /mnt/keystore /mnt/truststore

2. Fixing the cqlsh SSL Login Failure

The error you're seeing happens because cqlsh needs a valid certificate to verify Cassandra's SSL certificate. Here are two ways to fix this:

First, extract the CA certificate from your local truststore (you'll need keytool installed on your machine):

keytool -export -alias cassandra -file cassandra.crt -keystore ./mnt/truststore/truststore.jks -storepass cassandra

Copy this certificate into the Cassandra pod:

kubectl cp cassandra.crt k8ssandra-operator/demo-dc1-default-sts-0:/home/cassandra/.cassandra/ -c cassandra

Create a cqlshrc file in the pod to reference the certificate:

kubectl exec -it demo-dc1-default-sts-0 -n k8ssandra-operator -c cassandra -- bash -c 'cat > /home/cassandra/.cassandra/cqlshrc << EOF
[ssl]
certfile = /home/cassandra/.cassandra/cassandra.crt
validate = true
EOF'

Now you can connect with SSL:

cqlsh --ssl -u demo-superuser -p JKv59QPynp3s0qGSf1DZ demo-dc1-stargate-service

Option 2: Disable Certificate Validation (Only for Testing)

If you just need to test connectivity without strict validation (not recommended for production), disable it via cqlshrc:

kubectl exec -it demo-dc1-default-sts-0 -n k8ssandra-operator -c cassandra -- bash -c 'cat > /home/cassandra/.cassandra/cqlshrc << EOF
[ssl]
validate = false
EOF'

Then connect with:

cqlsh --ssl -u demo-superuser -p JKv59QPynp3s0qGSf1DZ demo-dc1-stargate-service

Quick Additional Checks

  • Double-check your cassandra.yaml ConfigMap to ensure the keystore/truststore paths and passwords match your actual files.
  • Verify your Secrets contain the correct files:
    kubectl get secret keystore -n k8ssandra-operator -o jsonpath='{.data.keystore\.jks}' | base64 --decode > test-keystore.jks
    keytool -list -keystore test-keystore.jks -storepass cassandra # This should show your keystore entries
    

内容的提问来源于stack exchange,提问作者Jennifer Schuhmacher

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 17:06:50