k8s ingress 自签名通配符证书 Kubernetes Ingress Controller Fake Certificate

namespace=kube-system

ingress-nginx-controller错误日志

W0805 02:43:15.093543       6 controller.go:1133] Unexpected error validating SSL certificate "harbor/hknaruto.com" for server "core.harbor.hknaruto.com": x509: certificate is valid for *.hknaruto.com, *.abc.com, not core.harbor.hknaruto.com
W0805 02:43:15.093548       6 controller.go:1134] Validating certificate against DNS names. This will be deprecated in a future version.
W0805 02:43:15.093553       6 controller.go:1139] SSL certificate "harbor/hknaruto.com" does not contain a Common Name or Subject Alternative Name for server "core.harbor.hknaruto.com": x509: certificate is valid for *.hknaruto.com, *.abc.com, not core.harbor.hknaruto.com
W0805 02:43:15.093558       6 controller.go:1141] Using default certificate

经测试,nginx ingress采用嗯通佩服证书不支持三级域名, 如:core.harbor.hknaruto.com,但是支持harbor.hknaruto.com这种二级域名。

猜你喜欢

转载自blog.csdn.net/hknaruto/article/details/107809815