You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于cert-manager部署中Ingress-Nginx证书匹配异常的技术问询

Troubleshooting cert-manager Secret Not Found by Ingress-Nginx

Hey there, let's break down why you're seeing the namespace/monitoring-xxx-com lookup failure in your Ingress-Nginx logs, and how to fix it:

Why the namespace/secret-name format shows up

Ingress-Nginx uses this fully qualified format to reference Secrets internally—this is its standard way to ensure it's targeting the exact resource, even if there are Secrets with the same name across different namespaces. The fact that it's failing to find the resource usually points to one of two core issues:

  • The Secret monitoring-xxx-com wasn't actually created by cert-manager
  • The Secret exists, but it's in a different namespace than your Ingress resource

Step-by-step troubleshooting

  • Verify the Secret exists
    Run this command to check if cert-manager generated the target Secret in your expected namespace:

    kubectl get secrets -n <your-ingress-namespace>
    

    If monitoring-xxx-com isn't listed, the problem lies with cert-manager's certificate issuance workflow, not Ingress-Nginx itself.

  • Check cert-manager logs for issuance errors
    Dig into cert-manager's logs to see why the Secret wasn't created:

    kubectl logs -n cert-manager -l app=cert-manager
    

    Look for entries related to your certificate—common issues include failed ACME challenges (HTTP-01 or DNS-01), misconfigured issuer details (like incorrect Let's Encrypt server URL), or mismatched DNS names between your Certificate resource and Ingress hosts.

  • Validate your Ingress and Certificate configurations

    • Ensure your Ingress's tls.secretName exactly matches the spec.secretName in your cert-manager Certificate resource.
    • Confirm both the Ingress and the target Secret are in the same namespace (unless you're using cross-namespace references, which require extra RBAC permissions).

Common fixes to resolve the issue

  1. Fix cert-manager certificate issuance
    If the Secret is missing, correct any errors in your Certificate or Issuer/ClusterIssuer resources. For example:

    • Make sure spec.dnsNames in the Certificate includes all hostnames defined in your Ingress.
    • Double-check your ACME issuer has a valid email address and points to the correct Let's Encrypt endpoint (use production or staging URLs as needed).
  2. Ensure namespace alignment
    If the Secret exists but in a different namespace, either move the Ingress to that namespace, or update your Certificate to generate the Secret in the Ingress's namespace.

  3. Refresh Ingress-Nginx cache
    Sometimes the controller caches resource state—restart the Ingress-Nginx deployment to force it to recheck for the Secret:

    kubectl rollout restart deployment ingress-nginx-controller -n ingress-nginx
    

内容的提问来源于stack exchange,提问作者Christopher Thomas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:09:49