如何在AWS中国区Kubernetes集群安装GoDaddy SSL证书及替代方案?
Got it, let's tackle your problem step by step since AWS China doesn't support ACM, but you have a GoDaddy SSL cert to work with. Here's how you can make this happen:
Since ACM isn't available in AWS China, we'll use AWS IAM to store the certificate and attach it to the ELB provisioned by your K8s LoadBalancer service.
Prepare your certificate files:GoDaddy provides three core files: your domain certificate (e.g.,
domain.crt), the intermediate certificate bundle (e.g.,gd_bundle-g2-g1.crt), and your private key (e.g.,domain.key). Ensure all are in PEM format—this is required for AWS IAM.Upload the cert to AWS IAM:Use the AWS CLI (configured for your AWS China region, e.g., Beijing
cn-north-1) to upload the certificate:aws iam upload-server-certificate \ --server-certificate-name my-godaddy-domain-cert \ --certificate-body file://domain.crt \ --private-key file://domain.key \ --certificate-chain file://gd_bundle-g2-g1.crt \ --endpoint-url https://iam.cn-north-1.amazonaws.comSave the ARN returned by this command—you'll need it for your K8s service.
Update your K8s LoadBalancer Service:Modify your Service YAML to reference the IAM certificate via annotations. Here's an example snippet:
apiVersion: v1 kind: Service metadata: name: your-app-service annotations: # Reference the IAM cert ARN from the previous step service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws-cn:iam::YOUR_ACCOUNT_ID:server-certificate/my-godaddy-domain-cert" # Enable SSL on port 443 service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "443" # Optional: Redirect HTTP (80) to HTTPS (443) service.beta.kubernetes.io/aws-load-balancer-redirect-http-to-https: "true" spec: type: LoadBalancer ports: - name: http port: 80 targetPort: 8080 - name: https port: 443 targetPort: 8080 selector: app: your-appApply the updated service with
kubectl apply -f your-service.yaml, and AWS will provision an ELB with your GoDaddy cert attached.
If you don't want to handle SSL at the load balancer level, here are two viable alternatives:
Option A: Embed SSL Cert in Tomcat Container (Build Custom Image)
You can package the GoDaddy certificate directly into your Tomcat image to handle SSL termination at the container level.
Convert certs to Tomcat-compatible JKS format:Tomcat uses JKS keystores by default. First, bundle your cert and key into a PKCS12 file, then convert it to JKS:
# Create PKCS12 file openssl pkcs12 -export \ -in domain.crt \ -inkey domain.key \ -out keystore.p12 \ -name tomcat \ -CAfile gd_bundle-g2-g1.crt \ -caname root \ -password pass:YOUR_STRONG_PASSWORD # Convert to JKS keytool -importkeystore \ -deststorepass YOUR_STRONG_PASSWORD \ -destkeypass YOUR_STRONG_PASSWORD \ -destkeystore tomcat.jks \ -srckeystore keystore.p12 \ -srcstoretype PKCS12 \ -srcstorepass YOUR_STRONG_PASSWORD \ -alias tomcatModify Tomcat's server.xml:Update the SSL connector in
server.xmlto use your JKS keystore:<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true"> <SSLHostConfig> <Certificate certificateKeystoreFile="/usr/local/tomcat/conf/tomcat.jks" type="RSA" certificateKeystorePassword="YOUR_STRONG_PASSWORD"/> </SSLHostConfig> </Connector>Build the custom Tomcat image:Create a
Dockerfilelike this:FROM tomcat:9-jdk11 # Copy the JKS keystore to Tomcat's config directory COPY tomcat.jks /usr/local/tomcat/conf/ # Replace the default server.xml with your modified one COPY server.xml /usr/local/tomcat/conf/server.xmlBuild and push the image to your registry:
docker build -t your-registry/my-tomcat-ssl:v1 . docker push your-registry/my-tomcat-ssl:v1Update your K8s Deployment to use this new image, and expose port 8443 in your Service.
Option B: Use NGINX Ingress Controller (Manage Certs via K8s Secrets)
This approach uses an Ingress controller to handle SSL termination, keeping your certificates managed within the K8s cluster.
Create a TLS Secret in K8s:First, merge your domain cert and intermediate bundle (append the bundle content to the end of
domain.crt), then create a Secret:kubectl create secret tls godaddy-tls-secret \ --cert=merged-domain.crt \ --key=domain.keyDeploy NGINX Ingress Controller:Deploy the official NGINX Ingress Controller to your cluster (adjust image paths if needed to use AWS China-compatible mirrors).
Create an Ingress Resource:Reference the TLS Secret in your Ingress to enable SSL:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-app-ingress annotations: nginx.ingress.kubernetes.io/ssl-redirect: "true" spec: tls: - hosts: - your-domain.com secretName: godaddy-tls-secret rules: - host: your-domain.com http: paths: - path: / pathType: Prefix backend: service: name: your-app-service port: number: 8080Apply the Ingress with
kubectl apply -f your-ingress.yaml, and the NGINX controller will handle SSL termination using your GoDaddy cert.
内容的提问来源于stack exchange,提问作者Arun

