证书管理员无法通过Cloudflare完成dns01挑战

问题描述

使用以下命令在k3s版本v1.18.8 + k3s1和docker-desktop版本v1.16.6-beta.0上安装证书管理器的各种版本(15和16):

helm install cert-manager \
--namespace cert-manager jetstack/cert-manager \
--version v0.16.1 \
--set installCRDs=true \
--set 'extraArgs={--dns01-recursive-nameservers=1.1.1.1:53}'

我应用了以下测试yaml文件:

apiVersion: v1
kind: Namespace
metadata:
  name: test
---
apiVersion: v1
kind: Secret
metadata:
  name: cloudflare-api-token-secret
  namespace: test
type: Opaque
stringData:
  api-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxx
---
apiVersion: cert-manager.io/v1alpha2
kind: Issuer
metadata:
  name: letsencrypt
  namespace: test
spec:
  acme:
    email: user@example.com
    server: https://acme-staging-v02.api.letsencrypt.org/directory
    privateKeySecretRef:
      name: letsencrypt
    solvers:
    - dns01:
        cloudflare:
          email: user@example.com
          apiTokenSecretRef:
            name: cloudflare-api-token-secret
            key: api-token
---
apiVersion: cert-manager.io/v1alpha2
kind: Certificate
metadata:
  name: example.com
  namespace: test
spec:
  secretName: example.com-tls
  issuerRef:
    name: letsencrypt
  dnsNames:
  - example.com

结果(我已经等了几个小时):

kubectl -n test get certs,certificaterequests,order,challenges,ingress -o wide
NAME                                      READY   SECRET            ISSUER        STATUS                                         AGE
certificate.cert-manager.io/example.com   False   example.com-tls   letsencrypt   Issuing certificate as Secret does not exist   57s

NAME                                                   READY   ISSUER        STATUS                                                                                   AGE
certificaterequest.cert-manager.io/example.com-rx7jg   False   letsencrypt   Waiting on certificate issuance from order test/example.com-rx7jg-273779930: "pending"   56s

NAME                                                     STATE     ISSUER        REASON   AGE
order.acme.cert-manager.io/example.com-rx7jg-273779930   pending   letsencrypt            55s

NAME                                                                   STATE     DOMAIN        REASON                                                                                AGE
challenge.acme.cert-manager.io/example.com-rx7jg-273779930-625151916   pending   example.com   Cloudflare API error for POST "/zones/xxxxxxxxxxxxxxxxxxxxxxxxxx xxxxx/dns_records"   53s

Cloudflare设置来自: https://cert-manager.io/docs/configuration/acme/dns01/cloudflare/,我已经尝试过令牌和密钥。

证书管理者pod日志:

I0828 08:34:51.370299       1 dns.go:102] cert-manager/controller/challenges/Present "msg"="presenting DNS01 challenge for domain" "dnsName"="example.com" "domain"="example.com" "resource_kind"="Challenge" "resource_name"="example.com-m72dq-3139291111-641020922" "resource_namespace"="test" "type"="dns-01"
E0828 08:34:55.251730       1 controller.go:158] cert-manager/controller/challenges "msg"="re-queuing item  due to error processing" "error"="Cloudflare API error for POST \"/zones/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/dns_records\"" "key"="test/example.com-m72dq-3139291111-641020922"
I0828 08:35:35.251982       1 controller.go:152] cert-manager/controller/challenges "msg"="syncing item" "key"="test/example.com-m72dq-3139291111-641020922"
I0828 08:35:35.252131       1 dns.go:102] cert-manager/controller/challenges/Present "msg"="presenting DNS01 challenge for domain" "dnsName"="example.com" "domain"="example.com" "resource_kind"="Challenge" "resource_name"="example.com-m72dq-3139291111-641020922" "resource_namespace"="test" "type"="dns-01"
E0828 08:35:38.797954       1 controller.go:158] cert-manager/controller/challenges "msg"="re-queuing item  due to error processing" "error"="Cloudflare API error for POST \"/zones/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/dns_records\"" "key"="test/example.com-m72dq-3139291111-641020922"

怎么了?

谢谢!

解决方法

如果它可以解决您的问题,则不是 100%,但我确实遇到过此主题 - https://github.com/jetstack/cert-manager/issues/1163。它们显示 helm 被这样调用并声称它有效。

$ helm install \                                       
  --name cert-manager \
  --namespace cert-manager \
  --version v0.7.0 \
  --set ingressShim.defaultIssuerKind=ClusterIssuer \              
  --set ingressShim.defaultIssuerName=letsencrypt-staging-issuer \
  --set extraArgs='{--dns01-recursive-nameservers-only,--dns01-self-check-nameservers=8.8.8.8:53\,1.1.1.1:53}' \
  jetstack/cert-manager

相关问答

依赖报错 idea导入项目后依赖报错,解决方案:https://blog....
错误1:代码生成器依赖和mybatis依赖冲突 启动项目时报错如下...
错误1:gradle项目控制台输出为乱码 # 解决方案:https://bl...
错误还原:在查询的过程中,传入的workType为0时,该条件不起...
报错如下,gcc版本太低 ^ server.c:5346:31: 错误:‘struct...