You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Letsencrypt+Docker+AWS部署证书:Mac本地生成证书遇授权失败

Fixing Let's Encrypt Authorization Error for Local Cert Generation (Mac → Docker → AWS K8s)

Let's break down why you're hitting that urn:acme:error:unauthorized error and walk through solutions tailored to your end-to-end workflow.

Why the Error Happens

The http-01 challenge that Certbot's standalone mode uses requires Let's Encrypt's servers to reach your domain's port 80 and fetch a unique verification file. Since you're running Certbot on your local MacBook, your machine doesn't have a public IP tied to my.domain—Let's Encrypt can't reach your local 80 port at all, hence the authorization failure.

Local cert generation is messy long-term (you'll have to manually renew and redeploy certificates), so these options prioritize automation and compatibility with AWS Kubernetes:

1. Use AWS Certificate Manager (ACM) (Simplest Option)

ACM issues free, auto-renewing certificates that integrate natively with AWS services like ALB (Application Load Balancer), which you'll likely use with your K8s ingress:

  • Head to the AWS Console → ACM → "Request a certificate"
  • Enter my.domain, choose DNS validation (more reliable than HTTP, no port 80 required)
  • Follow the prompts to add a CNAME record to your domain's DNS provider (e.g., Route53 if you use AWS DNS)
  • Once verified, configure your K8s Ingress resource to reference the ACM certificate ARN. Your ALB will automatically use the certificate—no need to package it into your Docker image.

2. Use cert-manager in Your AWS K8s Cluster (Best for K8s Native Automation)

cert-manager is the de facto tool for managing TLS certificates in Kubernetes, handling generation and auto-renewal automatically:

  • Install cert-manager to your cluster (match the setup to your K8s version)
  • Create a ClusterIssuer resource pointing to Let's Encrypt's staging/production endpoint
  • Update your Ingress manifest to include a tls section referencing your domain. cert-manager will automatically generate a certificate, mount it to your pods, and renew it before expiration.

If You Must Generate Certificates Locally

If you need a local cert for testing or specific requirements, fix the authorization issue with one of these methods:

Option A: Expose Local Port 80 to the Public

Use a tool like ngrok to temporarily forward your local 80 port to a public URL:

  1. Run ngrok http 80 in your terminal—you'll get a public URL like abc123.ngrok.io
  2. Update your my.domain DNS records to point to ngrok's public IP (or add a CNAME to the ngrok URL)
  3. Re-run your Certbot command: sudo certbot certonly -a standalone -d my.domain
  4. Once the certificate is generated, revert your DNS records back to their original state

Option B: Use DNS-01 Validation (No Port Forwarding Needed)

This method uses DNS TXT records instead of HTTP, so you don't need to expose your local machine. If your domain uses AWS Route53, use the certbot-dns-route53 plugin:

  1. Install the plugin via Homebrew: brew install certbot-dns-route53
  2. Configure AWS credentials on your Mac (create an IAM user with Route53 record modification permissions, then run aws configure)
  3. Generate the certificate with: sudo certbot certonly -a dns-route53 -d my.domain
    Certbot will automatically add the required TXT record to Route53, wait for verification, then clean up the record once done.

内容的提问来源于stack exchange,提问作者wild_nothing

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:57:18