Kubernetes本地Registry配置:证书分发问题咨询
Got it, let's work through getting your local Kubernetes-hosted Docker Registry properly secured with trusted certificates. Since you're running Docker for Mac (Edge) with a local cluster, we need to cover two critical pieces: making your local Docker client trust the registry (so you can push images) and ensuring Kubernetes nodes trust it too (so pods can pull those images without certificate errors). Here's a step-by-step guide tailored to your setup:
First, we'll create a custom CA and a certificate for your registry using openssl (included with Docker for Mac by default).
Create a directory to store your certificates:
mkdir -p ~/registry-certs && cd ~/registry-certsGenerate a CA key and root certificate (valid for 1 year):
openssl req -newkey rsa:4096 -nodes -sha256 -keyout ca.key -x509 -days 365 -out ca.crt -subj "/CN=local-registry-ca"Generate a key and certificate signing request (CSR) for your registry. We'll use
registry.localas the public domain (you can pick any local domain, just stick with it):openssl req -newkey rsa:4096 -nodes -sha256 -keyout registry.key -out registry.csr -subj "/CN=registry.local"Create an extensions file to add Subject Alternative Names (SANs)—this is crucial because Kubernetes might access the registry via its internal service name, so the certificate needs to validate that too:
cat > extfile.cnf <<EOF authorityKeyIdentifier=keyid,issuer basicConstraints=CA:FALSE keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment subjectAltName = @alt_names [alt_names] DNS.1 = registry.local DNS.2 = guiding-hedgehog-docker-registry.default.svc.cluster.local DNS.3 = guiding-hedgehog-docker-registry.default.svc EOFNote: Replace
guiding-hedgehogwith your actual Helm release name (get it withhelm list)Sign the CSR with your CA to get the final registry certificate:
openssl x509 -req -in registry.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out registry.crt -days 365 -sha256 -extfile extfile.cnf
Now we'll configure the Registry to use our new certificates via a Kubernetes Secret and Helm overrides.
Create a TLS Secret in your cluster:
kubectl create secret tls registry-tls --cert=registry.crt --key=registry.keyCreate a
values-override.yamlfile to enable TLS in the Registry Helm chart:tls: enabled: true secretName: registry-tls service: type: ClusterIPUpgrade your Helm release with these TLS settings:
helm upgrade guiding-hedgehog stable/docker-registry -f values-override.yaml
To push images to the registry without Docker throwing untrusted certificate errors, we need to add our CA to the system trust store.
Add the
ca.crtto your Mac's System Keychain:- Open Keychain Access
- Drag
ca.crtinto the "System" keychain - Double-click the certificate, expand the "Trust" section
- Set "When using this certificate" to Always Trust
- Enter your Mac password to save changes
Restart Docker for Mac to apply the new trust settings.
Map the
registry.localdomain to your local machine by adding an entry to/etc/hosts:echo "127.0.0.1 registry.local" | sudo tee -a /etc/hostsUpdate your port forwarding to use the standard HTTPS port (443) instead of 8080:
export POD_NAME=$(kubectl get pods --namespace default -l "app=docker-registry,release=guiding-hedgehog" -o jsonpath="{.items[0].metadata.name}") kubectl port-forward $POD_NAME 443:5000Now you can access the registry securely at
https://registry.local
Kubernetes needs to trust our CA so pods can pull images from the registry without validation failures.
Patch the cluster-wide
kube-root-ca.crtConfigMap (mounted by default in most pods) to include our CA:
First, encode the CA cert to base64:CA_CRT_BASE64=$(base64 -i ca.crt | tr -d '\n')Create a patch file:
cat > ca-patch.yaml <<EOF data: registry.local.crt: ${CA_CRT_BASE64} EOFApply the patch:
kubectl patch configmap kube-root-ca.crt -n kube-system --patch-file ca-patch.yamlFor Docker for Mac's Kubernetes VM, you can also add the CA directly to the node's trusted store to cover edge cases:
NODE_NAME=$(kubectl get nodes -o jsonpath="{.items[0].metadata.name}") docker cp ca.crt ${NODE_NAME}:/usr/local/share/ca-certificates/registry.local.crt docker exec ${NODE_NAME} update-ca-certificates
Let's verify everything works end-to-end:
Tag a test image for your registry:
docker pull nginx:alpine docker tag nginx:alpine registry.local/nginx:alpinePush the image to the registry:
docker push registry.local/nginx:alpineCreate a test deployment using the image:
cat > test-deployment.yaml <<EOF apiVersion: apps/v1 kind: Deployment metadata: name: test-registry spec: replicas: 1 selector: matchLabels: app: test-registry template: metadata: labels: app: test-registry spec: containers: - name: nginx image: registry.local/nginx:alpine ports: - containerPort: 80 EOFApply the deployment and check if the pod runs successfully:
kubectl apply -f test-deployment.yaml kubectl get podsIf the pod shows
Running, your certificate setup is working!
内容的提问来源于stack exchange,提问作者Chris G.

