You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

裸金属Kubernetes中Traefik提示Secret不存在但实际存在的问题

Troubleshooting Traefik Ingress TLS Secret Access Issue

Let's break down your problem and walk through the key checks to resolve this "secret does not exist" error, even though the secret is present and your RBAC configuration looks correct.

1. Fix Your Service Account Identity Test First

Your kubectl test command is using the wrong identity format for the service account. In Kubernetes, service accounts are identified by the full string system:serviceaccount:<namespace>:<serviceaccount-name>, not just the service account name alone.

Your current test:

kubectl get secret dex-tls -oyaml --as gem-lb-traefik

This is trying to authenticate as a regular user named gem-lb-traefik, not the service account. Run this corrected command to properly test the service account's permissions:

kubectl get secret traefik-cert -oyaml --as system:serviceaccount:default:gem-lb-traefik

(Note: I switched to traefik-cert since that's the secret your ingress is referencing, not dex-tls—make sure you test the exact secret used in your ingress)

2. Verify Ingress TLS Configuration

Double-check that your ingress resource correctly references the secret name and namespace. Your ingress should look something like this (pay close attention to the secretName field under tls):

apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: cheese
  namespace: default
spec:
  tls:
  - hosts:
      - your-domain.example.com
    secretName: traefik-cert  # Must match the exact name of your secret in default namespace
  rules:
  - host: your-domain.example.com
    http:
      paths:
      - path: /
        backend:
          serviceName: your-service
          servicePort: 80

Run this command to inspect your actual ingress and confirm the secret name:

kubectl get ingress cheese -n default -oyaml

3. Ensure Traefik Pod Uses the Correct Service Account

Even if your ClusterRole and ClusterRoleBinding are correct, Traefik's pod might not be using the gem-lb-traefik service account. Check your Traefik deployment or DaemonSet to confirm the serviceAccountName field is set:

kubectl describe deployment gem-lb-traefik -n default | grep -i "serviceaccount"

If it's not set, update your Traefik manifest to include:

spec:
  template:
    spec:
      serviceAccountName: gem-lb-traefik

Then verify the pod has the service account token mounted:

kubectl describe pod <traefik-pod-name> -n default | grep -A5 -B5 "VolumeMounts"

You should see a volume mount for the service account token (typically named gem-lb-traefik-token-xxxx).

4. Check for RBAC Edge Cases (Kubernetes v1.10 Specific)

Kubernetes v1.10 is quite old (released in 2018), and there were some RBAC edge cases in older versions. A few things to check:

  • Ensure your ClusterRole doesn't have any typos in the resource name (secrets is plural, which you have correct)
  • Confirm no namespace-scoped RoleBindings are overriding the ClusterRoleBinding (run kubectl get rolebindings -n default to check if any bindings might restrict permissions)
  • Restart the Traefik pods to ensure they pick up any RBAC changes:
    kubectl rollout restart deployment gem-lb-traefik -n default
    

5. Validate the Secret Exists and is Properly Formatted

Even if you know the secret exists, confirm it's a valid TLS secret with the correct keys (tls.crt and tls.key):

kubectl get secret traefik-cert -n default -oyaml

The data section should contain both tls.crt and tls.key entries. If either is missing, recreate the secret using:

kubectl create secret tls traefik-cert --cert=path/to/tls.crt --key=path/to/tls.key -n default

内容的提问来源于stack exchange,提问作者everCurious

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:37:10