You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS7裸金属K8s环境下,如何让Ingress终止SSL并代理服务?

Configuring SSL Termination at Ingress Layer with Plain HTTP to Backends on CentOS7 Kubernetes Cluster

Alright, since you've already adjusted Weave to allow hostNetwork and started deploying the Nginx Ingress Controller as a DaemonSet, let's wrap up the setup to get SSL termination working exactly as you want. Here's a practical, step-by-step breakdown:

1. Create a TLS Secret for Your SSL Certificate

First, you need to store your SSL certificate and private key as a Kubernetes Secret. If you don't have a trusted cert yet, generate a self-signed one for testing:

openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.crt -subj "/CN=your-domain.com/O=your-org"

Then create the Secret in the same namespace as your Ingress Controller (we'll use ingress-nginx here):

kubectl create secret tls my-tls-secret --key tls.key --cert tls.crt -n ingress-nginx

2. Finalize Your Nginx Ingress Controller DaemonSet Configuration

Make sure your DaemonSet includes these critical settings to support SSL termination. Here's a refined version of your config with key additions:

apiVersion: extensions/v1beta1
kind: DaemonSet
metadata:
  name: nginx-ingress-controller
  namespace: ingress-nginx
  labels:
    k8s-app: nginx-ingress-controller
spec:
  template:
    metadata:
      labels:
        k8s-app: nginx-ingress-controller
    spec:
      hostNetwork: true  # You already set this—great for direct port access
      serviceAccountName: nginx-ingress-serviceaccount
      containers:
        - name: nginx-ingress-controller
          image: quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.30.0
          args:
            - /nginx-ingress-controller
            - --configmap=$(POD_NAMESPACE)/nginx-configuration
            - --default-ssl-certificate=$(POD_NAMESPACE)/my-tls-secret  # Tie to your TLS secret
            - --publish-service=$(POD_NAMESPACE)/ingress-nginx
          ports:
            - name: http
              containerPort: 80
            - name: https
              containerPort: 443
          env:
            - name: POD_NAME
              valueFrom:
                fieldRef:
                  fieldPath: metadata.name
            - name: POD_NAMESPACE
              valueFrom:
                fieldRef:
                  fieldPath: metadata.namespace

Note: Swap the image tag for one compatible with your Kubernetes version, and ensure the serviceAccountName exists with permissions to manage Ingress resources.

3. Deploy the Ingress Resource to Route Traffic

Create an Ingress manifest that enforces SSL termination and routes traffic to your backend HTTP service. Example:

apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: my-app-ingress
  annotations:
    nginx.ingress.kubernetes.io/ssl-redirect: "true"  # Auto-redirect HTTP to HTTPS
    nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
spec:
  tls:
    - hosts:
        - your-domain.com
      secretName: my-tls-secret  # Match the TLS secret we created earlier
  rules:
    - host: your-domain.com
      http:
        paths:
          - path: /
            backend:
              serviceName: my-backend-service
              servicePort: 80  # Your backend's plain HTTP port

4. Verify the Setup

  • Check if Ingress Controller pods are running without errors:
    kubectl get pods -n ingress-nginx
    
  • Inspect controller logs to confirm it loaded the TLS secret correctly:
    kubectl logs -n ingress-nginx -l k8s-app=nginx-ingress-controller
    
  • Test SSL termination with a curl request:
    curl -v https://your-domain.com
    
  • To confirm the backend receives plain HTTP, check your backend service logs—you should see requests coming over port 80 with no SSL encryption.

Quick Troubleshooting Tips

  • Open ports 80 and 443 on CentOS7's firewalld:
    firewall-cmd --add-port=80/tcp --permanent
    firewall-cmd --add-port=443/tcp --permanent
    firewall-cmd --reload
    
  • If SELinux blocks traffic, allow the controller to connect to network resources:
    setsebool -P httpd_can_network_connect 1
    
  • Double-check your backend service is reachable via plain HTTP from the Ingress Controller pods.

内容的提问来源于stack exchange,提问作者yee379

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:45:29