bg-tutorials

如何在 Kubernetes 中安装 ACME SSL 证书

在 Kubernetes 中安装 ACME SSL 证书现在是一个标准化且灵活的过程,这要归功于cert-manager等成熟的工具和商业 CA 的广泛支持。无论您是在 NGINX Ingress、Traefik 还是其他网关后面运行生产工作负载,您都可以完全控制安全 HTTPS 的自动化。

在 Kubernetes 上安装 ACME SSL

本指南将向你展示如何使用 cert-manager在 Kubernetes 中安装 ACME SSL 证书。我们将介绍安装、使用外部账户绑定(EAB)设置签发人,以及签发证书以保护入口服务。


所需物品

在潜水之前,请确保

  • 您有一个正常运行的 Kubernetes 集群(建议使用 V1.23 以上版本)
  • kubectl 已配置并运行
  • 您可以访问您的入口控制器(如 NGINX、Traefik)
  • 您的域指向入口控制器的公共 IP
  • 您拥有 ACME 兼容 CA 的 EAB 证书:
    • ACME 目录 URL(如 https://acme.example.com/v2/DV)
    • EAB 关键标识符 (KID)
    • EAB HMAC 密钥

注:https://acme.example.com/v2/DV 在本指南中用作 ACME 目录 URL 的占位符。请使用证书颁发机构提供的真实端点替换它。


第 1 步 – 安装证书管理器

cert-manager 是使用最广泛的 Kubernetes 原生 ACME 客户端。它作为控制器运行,管理证书的发放和更新。

通过 Helm 安装(首选用于生产):

kubectl create namespace cert-manager
helm repo add jetstack https://charts.jetstack.io
helm repo update
helm install cert-manager jetstack/cert-manager \
--namespace cert-manager \
--version v1.14.4 \
--set installCRDs=true

等待几秒钟,确认所有 pod 都已运行:

kubectl get pods -n cert-manager

你会看到三个 pod:cert-manager、cert-manager-webhook 和 cert-manager-cainjector。


第 2 步 – 为 EAB 凭据创建 Kubernetes 密钥

创建 Kubernetes 密钥,安全存储 EAB 密钥:

kubectl create secret generic acme-eab-secret \
--namespace cert-manager \
--from-literal=eab-kid="YOUR_EAB_KID" \
--from-literal=eab-hmac-key="YOUR_EAB_HMAC_KEY"

用您的实际证书代替。避免复制粘贴空白处。


第 3 步 – 定义群集发行人或签发人

现在,创建一个 ClusterIssuer(用于所有命名空间)或 Issuer(单一命名空间)资源,使用 EAB 凭据将 cert-manager 连接到 ACME CA。

下面是一个 ClusterIssuer YAML 示例:

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: acme-issuer
spec:
acme:
server: https://your.acme-server.com/v2/DV
email: [email protected]
privateKeySecretRef:
name: acme-private-key
externalAccountBinding:
keyID: YOUR_EAB_KID
keySecretRef:
name: acme-eab-secret
key: eab-hmac-key
solvers:
- http01:
ingress:
class: nginx

应用它:

kubectl apply -f clusterissuer.yaml

将 ingress.class: nginx 替换为 traefik、nginx-internal 或任何你的 ingress 类。你可以在 ingress 控制器文档中找到。


第 4 步 – 创建证书资源

ClusterIssuer 准备就绪后,创建一个证书资源,告诉 cert-manager 要保护哪个域。 这里有一个例子:

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: my-ssl-cert
namespace: default
spec:
secretName: my-ssl-cert-tls
issuerRef:
name: acme-issuer
kind: ClusterIssuer
commonName: yourdomain.com
dnsNames:
- yourdomain.com
- www.yourdomain.com

应用它:

kubectl apply -f certificate.yaml

cert-manager 将使用签发者,通过入口解决挑战,并将签发的证书存储为 Kubernetes TLS secret。


第 5 步 – 在应用程序中引用证书

更新入口规则以使用生成的证书:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: my-ingress
namespace: default
annotations:
cert-manager.io/cluster-issuer: acme-issuer
spec:
tls:
- hosts:
- yourdomain.com
- www.yourdomain.com
secretName: my-ssl-cert-tls
rules:
- host: yourdomain.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: your-service
port:
number: 80

应用它:

kubectl apply -f ingress.yaml

一旦 cert-manager 检测到注释,它就会开始解决 ACME 挑战并签发证书。


第 6 步 – 验证证书和自动更新

验证一切正常:

kubectl describe certificate my-ssl-cert

查找成功签发的证书。

要检查续订设置,请运行

kubectl get certificaterequests

证书管理器会在到期前 ~30 天自动处理更新。你可以这样模拟一次更新

kubectl cert-manager renew my-ssl-cert


常见问题

在 Kubernetes 中设置 ACME SSL 可能会让人感觉有点抽象,尤其是在处理入口控制器、Secrets 和 DNS 记录时。下面,我们将回答开发人员在 Kubernetes 环境中安装 ACME 证书时面临的一些常见问题,无论你使用的是证书管理器还是其他设置。

可以使用 DNS-01 代替 HTTP-01吗?

是的,cert-manager 支持 Cloudflare、AWS 和 Google Cloud DNS 等提供商的 DNS 验证。如果你不公开 80 端口,请使用它。

证书管理器可以投入生产吗?

当然可以。它为跨企业和公共云的大型 Kubernetes 集群提供 SSL 支持。

能否在 Kubernetes 中使用 ACME 的通配符证书?

是的,但通配符证书需要 DNS-01 验证,这涉及更新 DNS 记录,而不是使用 HTTP 挑战。请确认您的 DNS 提供商是否支持自动化(通过 API),并在证书管理器设置中相应配置 dns01 解算器。

最后的话

您现在知道了如何使用 cert-manager 和 ACME 兼容的证书颁发机构在 Kubernetes 中安装 ACME SSL 证书。该设置完全自动化,可扩展,适用于现代 Kubernetes 环境。您将获得安全的 HTTPS、自动续费以及与 Ingress 的无缝集成,而这一切都无需离开您的集群。

立即订购 SSL 证书, 可节省 10% 的费用!

快速发行, 强大加密, 99.99% 的浏览器信任度, 专业支持和 25 天退款保证. 优惠券代码 SAVE10

龙飞行的详细图像
撰写人

经验丰富的内容撰稿人, 擅长 SSL 证书. 将复杂的网络安全主题转化为清晰, 引人入胜的内容. 通过有影响力的叙述, 为提高数字安全作出贡献.

Avatar of Sergiu Rosca
Technical Review by Sergiu Rosca

Sergiu Rosca is the core web developer behind SSL Dragon. He manages the technical infrastructure, platform performance, and backend integrations that keep the site running smoothly and securely. At SSL Dragon, Sergiu shares practical insights on web development, site optimization, and technical troubleshooting.

All SSL Dragon installation guides are tested on live server environments and undergo a strict peer-review process to ensure your infrastructure remains secure. Read our full Editorial Policy.