You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio中通过Kubernetes CSR集成AWS PCA自定义CA失败求助

Istio 通过 Kubernetes CSR 集成 AWS PCA 启动失败排查指南

问题背景

已按《Istio / Custom CA Integration using Kubernetes CSR》文档完成以下操作:

  • 在cert-manager控制器启用特性门控:--feature-gates=ExperimentalCertificateSigningRequestControllers=true
  • 部署AWS PCA及aws-privateca-issuer插件
  • 配置包含完整AWS PCA ARN的AWSPcaClusterIssuer对象
  • 修改Istio Operator,配置AWS PCA签发者的defaultConfig和caCertificates
  • 调整istiod部署,添加文档要求的环境变量及集群角色

但istiod启动失败,报错:

Generating K8S-signed cert for [istiod.istio-system.svc istiod-remote.istio-system.svc istio-pilot.istio-system.svc] using signer awspcaclusterissuers.awspca.cert-manager.io/cert-manager-aws-root-ca
2023-01-04T07:25:26.942944Z error failed to create discovery service: failed generating key and cert by kubernetes: no certificate returned for the CSR: "csr-workload-lg6kct8nh6r9vx4ld4"
Error: failed to create discovery service: failed generating key and cert by kubernetes: no certificate returned for the CSR: "csr-workload-lg6kct8nh6r9vx4ld4"

环境版本:K8S 1.22,Istio 1.13.5;cert-manager与AWS PCA通过Certificates对象集成正常,仅Kubernetes CSR方式失败。


排查步骤

1. 检查目标CSR的状态与详情

执行命令查看对应CSR的完整信息:

kubectl describe csr csr-workload-lg6kct8nh6r9vx4ld4

重点关注:

  • Status字段是否包含Approved状态记录
  • Events列表中是否有cert-manager处理失败的日志
  • Spec.SignerName是否与AWSPcaClusterIssuer配置的signer名称完全一致

2. 验证AWSPcaClusterIssuer的可用性

确认签发者处于就绪状态:

kubectl describe awspcaclusterissuers cert-manager-aws-root-ca

检查:

  • Status.Conditions中是否存在Type=Ready且Status=True的条目
  • 配置的AWS PCA ARN是否完整(需包含CA ID,格式应为arn:aws:acm-pca:us-west-2:<account_id>:certificate-authority/xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx,避免末尾多余斜杠)

3. 核对权限配置

Istiod ServiceAccount权限

检查istiod绑定的ClusterRole是否包含CSR相关权限:

apiGroups: ["certificates.k8s.io"]
resources: ["certificatesigningrequests"]
verbs: ["create", "get", "list", "watch", "update"]
---
apiGroups: ["certificates.k8s.io"]
resources: ["certificatesigningrequests/approval"]
verbs: ["update"]
---
apiGroups: ["certificates.k8s.io"]
resources: ["certificatesigningrequests/status"]
verbs: ["update"]

cert-manager权限

确认cert-manager控制器有权限审批Istiod提交的CSR,其ClusterRole需包含:

apiGroups: ["certificates.k8s.io"]
resources: ["certificatesigningrequests"]
verbs: ["get", "list", "watch", "approve"]

4. 校验Istio Operator配置准确性

检查Istio Operator中的关键配置项:

  • spec.meshConfig.defaultConfig.caAddress是否为awspcaclusterissuers.awspca.cert-manager.io/cert-manager-aws-root-ca
  • spec.meshConfig.caCertificates是否正确配置了AWS PCA的根证书(需提前从AWS PCA导出并格式化为PEM字符串)

5. 查看cert-manager控制器日志

抓取cert-manager日志定位具体错误:

kubectl logs -n cert-manager -l app=cert-manager

搜索目标CSR名称csr-workload-lg6kct8nh6r9vx4ld4,重点排查:

  • AWS API调用失败(如权限不足、CA不可用)
  • 证书模板不兼容(如不支持多SAN域名)
  • CSR格式不符合AWS PCA要求

常见问题点

  • AWS PCA证书模板限制:Istio CSR包含多个服务域名,需确认AWS PCA使用的证书模板允许添加多个Subject Alternative Name(SAN)
  • 版本兼容性:Istio 1.13.5与K8S 1.22、cert-manager版本需匹配,建议使用cert-manager 1.8+版本(ExperimentalCertificateSigningRequestControllers特性在该版本引入)
  • CSR审批策略:需确保cert-manager已配置自动审批Istiod提交的CSR规则,或手动审批测试

内容的提问来源于stack exchange,提问作者AshitAcharya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 18:35:12