Estoy configurando un secreto que contiene el certificado para el controlador de ingreso, pero obtengo el siguiente error cuando reviso los registros de ingreso
Registros de ingreso:
W0304 05:47:32.020497 7 controller.go:1153] Error getting SSL certificate "default/auth-tls": local SSL certificate default/auth-tls was not found. Using default certificate W0304 05:47:32.020516 7 controller.go:1407] Error getting SSL certificate "default/auth-tls": local SSL certificate default/auth-tls was not found I0304 05:47:32.114777 7 main.go:117] "successfully validated configuration, accepting" ingress="hello-kubernetes-ingress" namespace="default"Secreto:
$ kubectl create secret tls auth-tls --cert key.pem --key out.key $ kubectl describe secret auth-tls Name: auth-tls Namespace: default Labels: <none> Annotations: <none> Type: kubernetes.io/tls Data ==== tls.crt: 3231 bytes tls.key: 1732 bytesA continuación se muestra mi archivo yaml para el ingreso
apiVersion: networking.k8s.io/v1beta1 kind: Ingress metadata: name: hello-kubernetes-ingress annotations: kubernetes.io/ingress.class: nginx nginx.ingress.kubernetes.io/auth-url: https://externalauthentication/authorize spec: rules: - host: hw1.yourdomain http: paths: - backend: serviceName: hello-kubernetes-first servicePort: 80 - host: hw2.yourdomain http: paths: - backend: serviceName: hello-kubernetes-second servicePort: 80 tls: - hosts: - externalauthentication - hw1.yourdomain secretName: auth-tlsTanto Ingress como Secret son recursos con espacio de nombres. Puedes comprobarlo tú mismo con:
$ kubectl api-resources --namespaced=true NAME SHORTNAMES APIGROUP NAMESPACED KIND ... secrets true Secret ... ingresses ing extensions true Ingress ingresses ing networking.k8s.io true Ingress Sólo pueden trabajar dentro de su espacio de nombres . Entonces, en su caso de uso, debe colocar ambos ( Ingress y Secret ) en el mismo espacio de nombres.