裸金属Kubernetes中Traefik提示Secret不存在但实际存在的问题
Let's break down your problem and walk through the key checks to resolve this "secret does not exist" error, even though the secret is present and your RBAC configuration looks correct.
1. Fix Your Service Account Identity Test First
Your kubectl test command is using the wrong identity format for the service account. In Kubernetes, service accounts are identified by the full string system:serviceaccount:<namespace>:<serviceaccount-name>, not just the service account name alone.
Your current test:
kubectl get secret dex-tls -oyaml --as gem-lb-traefik
This is trying to authenticate as a regular user named gem-lb-traefik, not the service account. Run this corrected command to properly test the service account's permissions:
kubectl get secret traefik-cert -oyaml --as system:serviceaccount:default:gem-lb-traefik
(Note: I switched to traefik-cert since that's the secret your ingress is referencing, not dex-tls—make sure you test the exact secret used in your ingress)
2. Verify Ingress TLS Configuration
Double-check that your ingress resource correctly references the secret name and namespace. Your ingress should look something like this (pay close attention to the secretName field under tls):
apiVersion: extensions/v1beta1 kind: Ingress metadata: name: cheese namespace: default spec: tls: - hosts: - your-domain.example.com secretName: traefik-cert # Must match the exact name of your secret in default namespace rules: - host: your-domain.example.com http: paths: - path: / backend: serviceName: your-service servicePort: 80
Run this command to inspect your actual ingress and confirm the secret name:
kubectl get ingress cheese -n default -oyaml
3. Ensure Traefik Pod Uses the Correct Service Account
Even if your ClusterRole and ClusterRoleBinding are correct, Traefik's pod might not be using the gem-lb-traefik service account. Check your Traefik deployment or DaemonSet to confirm the serviceAccountName field is set:
kubectl describe deployment gem-lb-traefik -n default | grep -i "serviceaccount"
If it's not set, update your Traefik manifest to include:
spec: template: spec: serviceAccountName: gem-lb-traefik
Then verify the pod has the service account token mounted:
kubectl describe pod <traefik-pod-name> -n default | grep -A5 -B5 "VolumeMounts"
You should see a volume mount for the service account token (typically named gem-lb-traefik-token-xxxx).
4. Check for RBAC Edge Cases (Kubernetes v1.10 Specific)
Kubernetes v1.10 is quite old (released in 2018), and there were some RBAC edge cases in older versions. A few things to check:
- Ensure your ClusterRole doesn't have any typos in the resource name (
secretsis plural, which you have correct) - Confirm no namespace-scoped RoleBindings are overriding the ClusterRoleBinding (run
kubectl get rolebindings -n defaultto check if any bindings might restrict permissions) - Restart the Traefik pods to ensure they pick up any RBAC changes:
kubectl rollout restart deployment gem-lb-traefik -n default
5. Validate the Secret Exists and is Properly Formatted
Even if you know the secret exists, confirm it's a valid TLS secret with the correct keys (tls.crt and tls.key):
kubectl get secret traefik-cert -n default -oyaml
The data section should contain both tls.crt and tls.key entries. If either is missing, recreate the secret using:
kubectl create secret tls traefik-cert --cert=path/to/tls.crt --key=path/to/tls.key -n default
内容的提问来源于stack exchange,提问作者everCurious

