You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS中国区Kubernetes集群安装GoDaddy SSL证书及替代方案?

Got it, let's tackle your problem step by step since AWS China doesn't support ACM, but you have a GoDaddy SSL cert to work with. Here's how you can make this happen:

1. Install GoDaddy SSL Cert on AWS Load Balancer (for K8s LoadBalancer Service)

Since ACM isn't available in AWS China, we'll use AWS IAM to store the certificate and attach it to the ELB provisioned by your K8s LoadBalancer service.

  • Prepare your certificate files:GoDaddy provides three core files: your domain certificate (e.g., domain.crt), the intermediate certificate bundle (e.g., gd_bundle-g2-g1.crt), and your private key (e.g., domain.key). Ensure all are in PEM format—this is required for AWS IAM.

  • Upload the cert to AWS IAM:Use the AWS CLI (configured for your AWS China region, e.g., Beijing cn-north-1) to upload the certificate:

    aws iam upload-server-certificate \
      --server-certificate-name my-godaddy-domain-cert \
      --certificate-body file://domain.crt \
      --private-key file://domain.key \
      --certificate-chain file://gd_bundle-g2-g1.crt \
      --endpoint-url https://iam.cn-north-1.amazonaws.com
    

    Save the ARN returned by this command—you'll need it for your K8s service.

  • Update your K8s LoadBalancer Service:Modify your Service YAML to reference the IAM certificate via annotations. Here's an example snippet:

    apiVersion: v1
    kind: Service
    metadata:
      name: your-app-service
      annotations:
        # Reference the IAM cert ARN from the previous step
        service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws-cn:iam::YOUR_ACCOUNT_ID:server-certificate/my-godaddy-domain-cert"
        # Enable SSL on port 443
        service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "443"
        # Optional: Redirect HTTP (80) to HTTPS (443)
        service.beta.kubernetes.io/aws-load-balancer-redirect-http-to-https: "true"
    spec:
      type: LoadBalancer
      ports:
      - name: http
        port: 80
        targetPort: 8080
      - name: https
        port: 443
        targetPort: 8080
      selector:
        app: your-app
    

    Apply the updated service with kubectl apply -f your-service.yaml, and AWS will provision an ELB with your GoDaddy cert attached.

2. Alternative Solutions

If you don't want to handle SSL at the load balancer level, here are two viable alternatives:

Option A: Embed SSL Cert in Tomcat Container (Build Custom Image)

You can package the GoDaddy certificate directly into your Tomcat image to handle SSL termination at the container level.

  • Convert certs to Tomcat-compatible JKS format:Tomcat uses JKS keystores by default. First, bundle your cert and key into a PKCS12 file, then convert it to JKS:

    # Create PKCS12 file
    openssl pkcs12 -export \
      -in domain.crt \
      -inkey domain.key \
      -out keystore.p12 \
      -name tomcat \
      -CAfile gd_bundle-g2-g1.crt \
      -caname root \
      -password pass:YOUR_STRONG_PASSWORD
    
    # Convert to JKS
    keytool -importkeystore \
      -deststorepass YOUR_STRONG_PASSWORD \
      -destkeypass YOUR_STRONG_PASSWORD \
      -destkeystore tomcat.jks \
      -srckeystore keystore.p12 \
      -srcstoretype PKCS12 \
      -srcstorepass YOUR_STRONG_PASSWORD \
      -alias tomcat
    
  • Modify Tomcat's server.xml:Update the SSL connector in server.xml to use your JKS keystore:

    <Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
               maxThreads="150" SSLEnabled="true">
        <SSLHostConfig>
            <Certificate certificateKeystoreFile="/usr/local/tomcat/conf/tomcat.jks"
                         type="RSA"
                         certificateKeystorePassword="YOUR_STRONG_PASSWORD"/>
        </SSLHostConfig>
    </Connector>
    
  • Build the custom Tomcat image:Create a Dockerfile like this:

    FROM tomcat:9-jdk11
    # Copy the JKS keystore to Tomcat's config directory
    COPY tomcat.jks /usr/local/tomcat/conf/
    # Replace the default server.xml with your modified one
    COPY server.xml /usr/local/tomcat/conf/server.xml
    

    Build and push the image to your registry:

    docker build -t your-registry/my-tomcat-ssl:v1 .
    docker push your-registry/my-tomcat-ssl:v1
    

    Update your K8s Deployment to use this new image, and expose port 8443 in your Service.

Option B: Use NGINX Ingress Controller (Manage Certs via K8s Secrets)

This approach uses an Ingress controller to handle SSL termination, keeping your certificates managed within the K8s cluster.

  • Create a TLS Secret in K8s:First, merge your domain cert and intermediate bundle (append the bundle content to the end of domain.crt), then create a Secret:

    kubectl create secret tls godaddy-tls-secret \
      --cert=merged-domain.crt \
      --key=domain.key
    
  • Deploy NGINX Ingress Controller:Deploy the official NGINX Ingress Controller to your cluster (adjust image paths if needed to use AWS China-compatible mirrors).

  • Create an Ingress Resource:Reference the TLS Secret in your Ingress to enable SSL:

    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: your-app-ingress
      annotations:
        nginx.ingress.kubernetes.io/ssl-redirect: "true"
    spec:
      tls:
      - hosts:
        - your-domain.com
        secretName: godaddy-tls-secret
      rules:
      - host: your-domain.com
        http:
          paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: your-app-service
                port:
                  number: 8080
    

    Apply the Ingress with kubectl apply -f your-ingress.yaml, and the NGINX controller will handle SSL termination using your GoDaddy cert.

内容的提问来源于stack exchange,提问作者Arun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 09:03:07