You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes本地Registry配置:证书分发问题咨询

Got it, let's work through getting your local Kubernetes-hosted Docker Registry properly secured with trusted certificates. Since you're running Docker for Mac (Edge) with a local cluster, we need to cover two critical pieces: making your local Docker client trust the registry (so you can push images) and ensuring Kubernetes nodes trust it too (so pods can pull those images without certificate errors). Here's a step-by-step guide tailored to your setup:

Step 1: Generate Self-Signed Certificates

First, we'll create a custom CA and a certificate for your registry using openssl (included with Docker for Mac by default).

  • Create a directory to store your certificates:

    mkdir -p ~/registry-certs && cd ~/registry-certs
    
  • Generate a CA key and root certificate (valid for 1 year):

    openssl req -newkey rsa:4096 -nodes -sha256 -keyout ca.key -x509 -days 365 -out ca.crt -subj "/CN=local-registry-ca"
    
  • Generate a key and certificate signing request (CSR) for your registry. We'll use registry.local as the public domain (you can pick any local domain, just stick with it):

    openssl req -newkey rsa:4096 -nodes -sha256 -keyout registry.key -out registry.csr -subj "/CN=registry.local"
    
  • Create an extensions file to add Subject Alternative Names (SANs)—this is crucial because Kubernetes might access the registry via its internal service name, so the certificate needs to validate that too:

    cat > extfile.cnf <<EOF
    authorityKeyIdentifier=keyid,issuer
    basicConstraints=CA:FALSE
    keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment
    subjectAltName = @alt_names
    
    [alt_names]
    DNS.1 = registry.local
    DNS.2 = guiding-hedgehog-docker-registry.default.svc.cluster.local
    DNS.3 = guiding-hedgehog-docker-registry.default.svc
    EOF
    

    Note: Replace guiding-hedgehog with your actual Helm release name (get it with helm list)

  • Sign the CSR with your CA to get the final registry certificate:

    openssl x509 -req -in registry.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out registry.crt -days 365 -sha256 -extfile extfile.cnf
    
Step 2: Update Your Helm Registry Deployment to Use TLS

Now we'll configure the Registry to use our new certificates via a Kubernetes Secret and Helm overrides.

  • Create a TLS Secret in your cluster:

    kubectl create secret tls registry-tls --cert=registry.crt --key=registry.key
    
  • Create a values-override.yaml file to enable TLS in the Registry Helm chart:

    tls:
      enabled: true
      secretName: registry-tls
    service:
      type: ClusterIP
    
  • Upgrade your Helm release with these TLS settings:

    helm upgrade guiding-hedgehog stable/docker-registry -f values-override.yaml
    
Step 3: Make Docker for Mac Trust the CA Certificate

To push images to the registry without Docker throwing untrusted certificate errors, we need to add our CA to the system trust store.

  • Add the ca.crt to your Mac's System Keychain:

    1. Open Keychain Access
    2. Drag ca.crt into the "System" keychain
    3. Double-click the certificate, expand the "Trust" section
    4. Set "When using this certificate" to Always Trust
    5. Enter your Mac password to save changes
  • Restart Docker for Mac to apply the new trust settings.

  • Map the registry.local domain to your local machine by adding an entry to /etc/hosts:

    echo "127.0.0.1 registry.local" | sudo tee -a /etc/hosts
    
  • Update your port forwarding to use the standard HTTPS port (443) instead of 8080:

    export POD_NAME=$(kubectl get pods --namespace default -l "app=docker-registry,release=guiding-hedgehog" -o jsonpath="{.items[0].metadata.name}")
    kubectl port-forward $POD_NAME 443:5000
    

    Now you can access the registry securely at https://registry.local

Step 4: Make Kubernetes Trust the CA Certificate

Kubernetes needs to trust our CA so pods can pull images from the registry without validation failures.

  • Patch the cluster-wide kube-root-ca.crt ConfigMap (mounted by default in most pods) to include our CA:
    First, encode the CA cert to base64:

    CA_CRT_BASE64=$(base64 -i ca.crt | tr -d '\n')
    

    Create a patch file:

    cat > ca-patch.yaml <<EOF
    data:
      registry.local.crt: ${CA_CRT_BASE64}
    EOF
    

    Apply the patch:

    kubectl patch configmap kube-root-ca.crt -n kube-system --patch-file ca-patch.yaml
    
  • For Docker for Mac's Kubernetes VM, you can also add the CA directly to the node's trusted store to cover edge cases:

    NODE_NAME=$(kubectl get nodes -o jsonpath="{.items[0].metadata.name}")
    docker cp ca.crt ${NODE_NAME}:/usr/local/share/ca-certificates/registry.local.crt
    docker exec ${NODE_NAME} update-ca-certificates
    
Step 5: Test Push and Pull

Let's verify everything works end-to-end:

  • Tag a test image for your registry:

    docker pull nginx:alpine
    docker tag nginx:alpine registry.local/nginx:alpine
    
  • Push the image to the registry:

    docker push registry.local/nginx:alpine
    
  • Create a test deployment using the image:

    cat > test-deployment.yaml <<EOF
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: test-registry
    spec:
      replicas: 1
      selector:
        matchLabels:
          app: test-registry
      template:
        metadata:
          labels:
            app: test-registry
        spec:
          containers:
          - name: nginx
            image: registry.local/nginx:alpine
            ports:
            - containerPort: 80
    EOF
    
  • Apply the deployment and check if the pod runs successfully:

    kubectl apply -f test-deployment.yaml
    kubectl get pods
    

    If the pod shows Running, your certificate setup is working!


内容的提问来源于stack exchange,提问作者Chris G.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:55:14