GKE中使用Cert-Manager与NGINX Ingress无法分配证书求助
Hey there, let's work through why your cert-manager certificate is stuck in the "InProgress" state. I've spotted a couple of obvious issues in your config first, plus some additional checks to run:
1. Fix the Issuer Type Mismatch in Your Ingress
You created a ClusterIssuer named letsencrypt-staging, but your Ingress is using the annotation for a namespace-scoped Issuer. That's a common mix-up!
Update your Ingress annotation from:
cert-manager.io/issuer: "letsencrypt-staging"
To:
cert-manager.io/cluster-issuer: "letsencrypt-staging"
This tells cert-manager to look for the cluster-wide issuer instead of one limited to your app's namespace.
2. Fix the Domain Typo in Your Ingress
I noticed in your Ingress tls section you listed domain.con, but in the rules section it's domain.com. That mismatch will break validation—make sure both sections use the exact same domain name!
3. Dig Into the CertificateRequest Details
Your certificate is waiting on a CertificateRequest to complete. Let's check that request for specific errors:
kubectl describe certificaterequest create-new-secret-2447513806 -n <your-namespace>
This output will show you exactly where the process is failing—whether it's an ACME validation error, missing resources, or permission issues.
4. Verify HTTP01 Challenge Accessibility (Critical for Internal Ingress)
Since you're using an Internal Nginx Ingress, keep in mind that HTTP01 validation requires Let's Encrypt's servers to reach your service at http://domain.com/.well-known/acme-challenge/. If your internal ingress isn't exposed to the public internet, Let's Encrypt can't send the validation request, which will stall the certificate process.
If that's the case, you have two options:
- Switch to DNS01 validation (this only requires you to control your domain's DNS records, no public ingress access needed)
- Adjust your network setup to allow public access to the ACME challenge path only, or use a separate public ingress for validation
5. Check Cert-manager Logs for Clues
If the above steps don't uncover the issue, look at the cert-manager pod logs for detailed error messages:
kubectl logs -n cert-manager -l app=cert-manager
Logs will often reveal things like failed challenge attempts, misconfigured solvers, or API permission issues.
6. Consider Version Compatibility
You're using cert-manager 0.15.1 with Kubernetes 1.14.x—while they're technically compatible, older cert-manager versions have known bugs that might cause this kind of stall. If all else fails, try upgrading to a more recent stable version (like v0.16.x, just double-check compatibility with K8s 1.14 first).
内容的提问来源于stack exchange,提问作者Ram

