cert-manager DNS01 Challenge通配符域名找不到Zone报错如何解决
报错根因
Error presenting challenge: Found no Zones for domain _acme-challenge.my-domain.com. (neither in the sub-domain noir in the SLD) please make sure your domain-entries in the config are correct and the API is correctly setup with Zone.read rights.
该报错核心为cert-manager调用Cloudflare API时,无法匹配到my-domain.com对应的托管Zone资源,多由配置遗漏、权限不足或Zone匹配逻辑异常导致。
需排查修复的配置项
- Cloudflare API Token权限校验
除DNS编辑权限外,必须额外授予API TokenZone:Read权限,且资源范围要指定为你托管my-domain.com的对应Zone,不要选择所有Zone。 - ClusterIssuer补充Zone显式配置
默认cert-manager会递归查找域名对应的Zone,部分场景下自动匹配逻辑失效,需在Cloudflare配置块下显式指定根域名Zone:apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: test-issuer spec: acme: email: <email> server: https://acme-staging-v02.api.letsencrypt.org/directory privateKeySecretRef: name: test-issuer-private-key solvers: - dns01: cloudflare: email: <email> apiTokenSecretRef: name: issuer-access-token key: api-token zone: my-domain.com # 新增该行,填写Cloudflare后台显示的根域名Zone名称 - Secret命名空间校验
ClusterIssuer为集群级资源,默认会从cert-manager安装的命名空间(默认cert-manager)读取API Token Secret,如果你将issuer-access-token创建在了其他命名空间,会导致权限读取失败。 - Certificate资源可选优化
若需要证书同时覆盖根域名my-domain.com,可补充根域名条目:dnsNames: - "my-domain.com" - "*.my-domain.com" - 清理冗余DNS记录
不需要提前手动配置_acme-challenge相关的CNAME或TXT记录,cert-manager会自动创建和清理挑战记录,手动配置的同名记录会导致挑战冲突。
生效验证步骤
- 重新应用修改后的ClusterIssuer和Certificate资源
- 执行
kubectl describe certificaterequests -A查看证书请求状态 - 执行
kubectl describe challenges -A查看挑战执行详细日志,确认是否能正常创建TXT记录
内容的提问来源于stack exchange,提问作者Justas
相关产品推荐
相关产品推荐

