【问题标题】:Cert-manager fails to complete dns01 challenge with cloudflareCert-manager 无法使用 cloudflare 完成 dns01 挑战
【发布时间】:2020-08-28 11:06:45
【问题描述】:

使用以下命令在 k3s 版本 v1.18.8+k3s1 和 docker-desktop 版本 v1.16.6-beta.0 上安装 Cert-manager 各种版本(15 和 16):

helm install cert-manager \
--namespace cert-manager jetstack/cert-manager \
--version v0.16.1 \
--set installCRDs=true \
--set 'extraArgs={--dns01-recursive-nameservers=1.1.1.1:53}'

我应用了以下测试 yaml 文件:

apiVersion: v1
kind: Namespace
metadata:
  name: test
---
apiVersion: v1
kind: Secret
metadata:
  name: cloudflare-api-token-secret
  namespace: test
type: Opaque
stringData:
  api-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxx
---
apiVersion: cert-manager.io/v1alpha2
kind: Issuer
metadata:
  name: letsencrypt
  namespace: test
spec:
  acme:
    email: user@example.com
    server: https://acme-staging-v02.api.letsencrypt.org/directory
    privateKeySecretRef:
      name: letsencrypt
    solvers:
    - dns01:
        cloudflare:
          email: user@example.com
          apiTokenSecretRef:
            name: cloudflare-api-token-secret
            key: api-token
---
apiVersion: cert-manager.io/v1alpha2
kind: Certificate
metadata:
  name: example.com
  namespace: test
spec:
  secretName: example.com-tls
  issuerRef:
    name: letsencrypt
  dnsNames:
  - example.com

结果(我等了几个小时):

kubectl -n test get certs,certificaterequests,order,challenges,ingress -o wide
NAME                                      READY   SECRET            ISSUER        STATUS                                         AGE
certificate.cert-manager.io/example.com   False   example.com-tls   letsencrypt   Issuing certificate as Secret does not exist   57s

NAME                                                   READY   ISSUER        STATUS                                                                                   AGE
certificaterequest.cert-manager.io/example.com-rx7jg   False   letsencrypt   Waiting on certificate issuance from order test/example.com-rx7jg-273779930: "pending"   56s

NAME                                                     STATE     ISSUER        REASON   AGE
order.acme.cert-manager.io/example.com-rx7jg-273779930   pending   letsencrypt            55s

NAME                                                                   STATE     DOMAIN        REASON                                                                                AGE
challenge.acme.cert-manager.io/example.com-rx7jg-273779930-625151916   pending   example.com   Cloudflare API error for POST "/zones/xxxxxxxxxxxxxxxxxxxxxxxxxx xxxxx/dns_records"   53s

Cloudflare 设置来自: https://cert-manager.io/docs/configuration/acme/dns01/cloudflare/ 我已经尝试过使用令牌和密钥。

Cert-manager pod 日志:

I0828 08:34:51.370299       1 dns.go:102] cert-manager/controller/challenges/Present "msg"="presenting DNS01 challenge for domain" "dnsName"="example.com" "domain"="example.com" "resource_kind"="Challenge" "resource_name"="example.com-m72dq-3139291111-641020922" "resource_namespace"="test" "type"="dns-01"
E0828 08:34:55.251730       1 controller.go:158] cert-manager/controller/challenges "msg"="re-queuing item  due to error processing" "error"="Cloudflare API error for POST \"/zones/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/dns_records\"" "key"="test/example.com-m72dq-3139291111-641020922"
I0828 08:35:35.251982       1 controller.go:152] cert-manager/controller/challenges "msg"="syncing item" "key"="test/example.com-m72dq-3139291111-641020922"
I0828 08:35:35.252131       1 dns.go:102] cert-manager/controller/challenges/Present "msg"="presenting DNS01 challenge for domain" "dnsName"="example.com" "domain"="example.com" "resource_kind"="Challenge" "resource_name"="example.com-m72dq-3139291111-641020922" "resource_namespace"="test" "type"="dns-01"
E0828 08:35:38.797954       1 controller.go:158] cert-manager/controller/challenges "msg"="re-queuing item  due to error processing" "error"="Cloudflare API error for POST \"/zones/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/dns_records\"" "key"="test/example.com-m72dq-3139291111-641020922"

怎么了?

谢谢!

【问题讨论】:

标签: ssl kubernetes devops lets-encrypt cert-manager


【解决方案1】:

如果它可以解决您的问题,则不是 100%,但我确实遇到了这个线程 - https://github.com/jetstack/cert-manager/issues/1163。他们显示helm 被这样调用并声称它有效。

$ helm install \                                       
  --name cert-manager \
  --namespace cert-manager \
  --version v0.7.0 \
  --set ingressShim.defaultIssuerKind=ClusterIssuer \              
  --set ingressShim.defaultIssuerName=letsencrypt-staging-issuer \
  --set extraArgs='{--dns01-recursive-nameservers-only,--dns01-self-check-nameservers=8.8.8.8:53\,1.1.1.1:53}' \
  jetstack/cert-manager

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2020-09-07
    • 1970-01-01
    • 2021-05-26
    • 2021-01-14
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多