CentOS7裸金属K8s环境下,如何让Ingress终止SSL并代理服务?
Alright, since you've already adjusted Weave to allow hostNetwork and started deploying the Nginx Ingress Controller as a DaemonSet, let's wrap up the setup to get SSL termination working exactly as you want. Here's a practical, step-by-step breakdown:
1. Create a TLS Secret for Your SSL Certificate
First, you need to store your SSL certificate and private key as a Kubernetes Secret. If you don't have a trusted cert yet, generate a self-signed one for testing:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.crt -subj "/CN=your-domain.com/O=your-org"
Then create the Secret in the same namespace as your Ingress Controller (we'll use ingress-nginx here):
kubectl create secret tls my-tls-secret --key tls.key --cert tls.crt -n ingress-nginx
2. Finalize Your Nginx Ingress Controller DaemonSet Configuration
Make sure your DaemonSet includes these critical settings to support SSL termination. Here's a refined version of your config with key additions:
apiVersion: extensions/v1beta1 kind: DaemonSet metadata: name: nginx-ingress-controller namespace: ingress-nginx labels: k8s-app: nginx-ingress-controller spec: template: metadata: labels: k8s-app: nginx-ingress-controller spec: hostNetwork: true # You already set this—great for direct port access serviceAccountName: nginx-ingress-serviceaccount containers: - name: nginx-ingress-controller image: quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.30.0 args: - /nginx-ingress-controller - --configmap=$(POD_NAMESPACE)/nginx-configuration - --default-ssl-certificate=$(POD_NAMESPACE)/my-tls-secret # Tie to your TLS secret - --publish-service=$(POD_NAMESPACE)/ingress-nginx ports: - name: http containerPort: 80 - name: https containerPort: 443 env: - name: POD_NAME valueFrom: fieldRef: fieldPath: metadata.name - name: POD_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace
Note: Swap the image tag for one compatible with your Kubernetes version, and ensure the
serviceAccountNameexists with permissions to manage Ingress resources.
3. Deploy the Ingress Resource to Route Traffic
Create an Ingress manifest that enforces SSL termination and routes traffic to your backend HTTP service. Example:
apiVersion: extensions/v1beta1 kind: Ingress metadata: name: my-app-ingress annotations: nginx.ingress.kubernetes.io/ssl-redirect: "true" # Auto-redirect HTTP to HTTPS nginx.ingress.kubernetes.io/force-ssl-redirect: "true" spec: tls: - hosts: - your-domain.com secretName: my-tls-secret # Match the TLS secret we created earlier rules: - host: your-domain.com http: paths: - path: / backend: serviceName: my-backend-service servicePort: 80 # Your backend's plain HTTP port
4. Verify the Setup
- Check if Ingress Controller pods are running without errors:
kubectl get pods -n ingress-nginx - Inspect controller logs to confirm it loaded the TLS secret correctly:
kubectl logs -n ingress-nginx -l k8s-app=nginx-ingress-controller - Test SSL termination with a curl request:
curl -v https://your-domain.com - To confirm the backend receives plain HTTP, check your backend service logs—you should see requests coming over port 80 with no SSL encryption.
Quick Troubleshooting Tips
- Open ports 80 and 443 on CentOS7's firewalld:
firewall-cmd --add-port=80/tcp --permanent firewall-cmd --add-port=443/tcp --permanent firewall-cmd --reload - If SELinux blocks traffic, allow the controller to connect to network resources:
setsebool -P httpd_can_network_connect 1 - Double-check your backend service is reachable via plain HTTP from the Ingress Controller pods.
内容的提问来源于stack exchange,提问作者yee379

