You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Kubernetes ConfigMap挂载到cert-manager Helm Chart的/etc/ssl/certs

挂载自定义ConfigMap到cert-manager容器

具体配置方法

在cert-manager的values.yaml中,针对需要挂载的组件(比如controller、webhook)添加volumes和volumeMounts配置,以controller组件为例:

# values.yaml 片段
controller:
  # 定义要挂载的ConfigMap卷
  volumes:
    - name: custom-ssl-certs
      configMap:
        name: <你的ConfigMap名称>  # 替换为Terraform创建的ConfigMap实际名称
        optional: false  # 若ConfigMap必须存在则设为false,可选则设为true

  # 配置容器内的挂载路径
  volumeMounts:
    - name: custom-ssl-certs
      mountPath: /etc/ssl/certs
      readOnly: true

关键细节

  • 卷名称custom-ssl-certs可以自定义,但必须和volumeMounts中的name保持一致。
  • 如果需要给cert-manager的其他组件(如webhook、cainjector)挂载同一份ConfigMap,只需在对应组件的节点下(比如webhook.volumes和webhook.volumeMounts)复制上述配置即可。
  • 设置readOnly: true是最佳实践,因为ConfigMap内容无需修改,避免意外篡改。

验证挂载结果

部署完成后,通过以下命令进入pod检查挂载是否成功:

kubectl exec -n <你的命名空间> <cert-manager-controller-pod-name> -- ls /etc/ssl/certs

执行后应该能看到ConfigMap中存储的证书文件。

内容的提问来源于stack exchange,提问作者leonms.dev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 09:39:27