【问题标题】:SSL issues with jinja HTTPS load balancer - Google Cloudjinja HTTPS 负载平衡器的 SSL 问题 - Google Cloud
【发布时间】:2019-03-02 13:40:13
【问题描述】:

我已经能够将此负载平衡器部署为 HTTP 负载平衡器,现在正尝试将其部署为 HTTPS 负载平衡器。我在 Google Cloud 上尝试使用 .JUNJA 和 .YAML。

我不断收到错误消息:Invalid value for field 'resource.sslCertificates[0]': 'www.example.com'. The\\ URL is malformed.

resources:
  - name: web-lb-hc #Create a health check for the backend
    type: compute.v1.httpsHealthCheck
    properties:
      port: 443
      requestPath: /

  - name: web-url-map #Required to map url to backend
    type: compute.v1.urlMap
    properties:
      defaultService: $(ref.backend.selfLink)

  - name: backend
    type: compute.v1.backendService #Deployment of backend for VM's 
    properties:
      port: 443
      portName: https
      protocol: HTTPS #Defeined HTTP port for communication with backends
      backends:
      - name: backend
        balancingMode: UTILIZATION
        capacityScaler: 1.0
        group: $(ref.web-ins-group.selfLink)
      maxUtilization: 0.8
      connectionDraining:
        drainingTimeoutSec: 300
      healthChecks: 
      - $(ref.web-lb-hc.selfLink)

  - name: web-http-proxy
    type: compute.v1.targetHttpsProxy
    properties:
      urlMap: $(ref.web-url-map.selfLink)
      sslCertificates: ["www.example.com"]
  - name: web-ipaddress
    type: compute.v1.globalAddress

  - name: web-http-forwardingrule #Creation of forwarding rule 
    type: compute.v1.globalForwardingRule
    properties:
      target: $(ref.web-http-proxy.selfLink)
      IPAddress: $(ref.web-ipaddress.address)
      IPProtocol: TCP #Chosen protocol
      portRange: 443-443

对此的任何帮助将不胜感激!

【问题讨论】:

    标签: google-cloud-platform ssl-certificate jinja2 load-balancing google-deployment-manager


    【解决方案1】:

    sslCertificates 是一个 url 数组。

    要确定 SSL 证书的 URL,请按照以下步骤操作。

    获取 SSL 证书列表:

    gcloud compute ssl-certificates list
    

    获取 SSL 证书的详细信息:

    gcloud compute ssl-certificates describe NAME
    

    在底部附近的返回数据中查找 selfLink。这是您要使用的值。该值将如下所示:

    https://www.googleapis.com/compute/v1/projects/development/global/sslCertificates/production-lb
    

    【讨论】:

    • 感谢您的回复@JohnHanley,命令compute ssl-certificates describe NAME 的结果是-bash: compute: command not found?我将NAME 更改为SSL 名称的名称并仅使用NAME 进行尝试,但都导致相同的错误。
    • @user10190803 我修复了将gcloud 添加到命令示例的命令。
    猜你喜欢
    • 2022-01-10
    • 1970-01-01
    • 2017-05-02
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2018-12-14
    • 1970-01-01
    • 2015-05-22
    相关资源
    最近更新 更多