You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

cert-manager DNS01 Challenge通配符域名找不到Zone报错如何解决

报错根因

Error presenting challenge: Found no Zones for domain _acme-challenge.my-domain.com. (neither in the sub-domain noir in the SLD) please make sure your domain-entries in the config are correct and the API is correctly setup with Zone.read rights.

该报错核心为cert-manager调用Cloudflare API时,无法匹配到my-domain.com对应的托管Zone资源,多由配置遗漏、权限不足或Zone匹配逻辑异常导致。

需排查修复的配置项

  • Cloudflare API Token权限校验
    除DNS编辑权限外,必须额外授予API TokenZone:Read权限,且资源范围要指定为你托管my-domain.com的对应Zone,不要选择所有Zone。
  • ClusterIssuer补充Zone显式配置
    默认cert-manager会递归查找域名对应的Zone,部分场景下自动匹配逻辑失效,需在Cloudflare配置块下显式指定根域名Zone:
    apiVersion: cert-manager.io/v1
    kind: ClusterIssuer
    metadata:
      name: test-issuer
    spec:
      acme:
        email: <email>
        server: https://acme-staging-v02.api.letsencrypt.org/directory
        privateKeySecretRef:
          name: test-issuer-private-key
        solvers:
        - dns01:
            cloudflare:
              email: <email>
              apiTokenSecretRef:
                name: issuer-access-token
                key: api-token
              zone: my-domain.com # 新增该行,填写Cloudflare后台显示的根域名Zone名称
    
  • Secret命名空间校验
    ClusterIssuer为集群级资源,默认会从cert-manager安装的命名空间(默认cert-manager)读取API Token Secret,如果你将issuer-access-token创建在了其他命名空间,会导致权限读取失败。
  • Certificate资源可选优化
    若需要证书同时覆盖根域名my-domain.com,可补充根域名条目:
    dnsNames:
    - "my-domain.com"
    - "*.my-domain.com"
    
  • 清理冗余DNS记录
    不需要提前手动配置_acme-challenge相关的CNAME或TXT记录,cert-manager会自动创建和清理挑战记录,手动配置的同名记录会导致挑战冲突。

生效验证步骤

  1. 重新应用修改后的ClusterIssuer和Certificate资源
  2. 执行kubectl describe certificaterequests -A查看证书请求状态
  3. 执行kubectl describe challenges -A查看挑战执行详细日志,确认是否能正常创建TXT记录

内容的提问来源于stack exchange,提问作者Justas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 15:15:05