- 概述
- 要求
- 部署模板
- 手动:准备安装
- 手动:准备安装
- 步骤 2:为离线安装配置符合 OCI 的注册表
- 步骤 3:配置外部对象存储
- 步骤 4:配置 High Availability Add-on
- 步骤 5:配置 SQL 数据库
- 步骤 7:配置 DNS
- 步骤 8:配置磁盘
- 步骤 9:配置内核和操作系统级别设置
- 步骤 10:配置节点端口
- 步骤 11:应用其他设置
- 步骤 12:验证并安装所需的 RPM 包
- 步骤 13:生成 cluster_config.json
- Cluster_config.json 示例
- 常规配置
- 配置文件配置
- 证书配置
- 数据库配置
- 外部对象存储配置
- 预签名 URL 配置
- ArgoCD 配置
- Kerberos 身份验证配置
- 符合 OCI 的外部注册表配置
- Disaster Recovery:主动/被动和主动/主动配置
- High Availability Add-on 配置
- 特定于 Orchestrator 的配置
- Insights 特定配置
- Process Mining 特定配置
- Document Understanding 特定配置
- Automation Suite Robot 特定配置
- 监控配置
- 可选:配置代理服务器
- 可选:在多节点 HA 就绪生产集群中启用区域故障恢复
- 可选:传递自定义 resolv.conf
- 可选:提高容错能力
- 添加具有 GPU 支持的专用代理节点
- 为 Automation Suite Robot 添加专用代理节点
- 步骤 15:为离线安装配置临时 Docker 注册表
- 步骤 16:验证安装的先决条件
- 正在运行 uipathctl
- 手动:执行安装
- 安装后
- 集群管理
- 监控和警示
- 迁移和升级
- 特定于产品的配置
- 最佳实践和维护
- 故障排除
- 如何在安装过程中对服务进行故障排除
- 如何减少 NFS 备份目录的权限
- 如何卸载集群
- 如何清理离线工件以改善磁盘空间
- 如何清除 Redis 数据
- 如何启用 Istio 日志记录
- 如何手动清理日志
- 将 Ceph 退出只读模式
- 如何清理存储在 sf-logs 存储桶中的旧日志
- 如何禁用 AI Center 的流日志
- 如何对失败的 Automation Suite 安装进行调试
- 如何在升级后从旧安装程序中删除映像
- 如何禁用 TX 校验和卸载
- 如何手动将 ArgoCD 日志级别设置为 Info
- 如何扩展 AI Center 存储
- 如何为外部注册表生成已编码的 pull_secret_value
- 如何解决 TLS 1.2 中的弱密码问题
- 如何查看 TLS 版本
- 如何使用证书
- 如何计划 Ceph 备份和还原数据
- 如何使用集群内对象存储 (Ceph) 收集 DU 使用情况数据
- 如何在离线环境中安装 RKE2 SELinux
- 如何清理 NFS 服务器上的旧差异备份
- 如何在已启用 FIPS 的集群中部署 Insights
- 如何迁移到 cgroup v2
- 如何在虚拟机重新启动后恢复 Kerberos 身份验证
- 如何将本地 Docker 映像推送到集群内注册表
- 如何从备份中排除存储桶
- 无法获取沙盒映像
- Pod 未显示在 ArgoCD 用户界面中
- Redis 探测器失败
- RKE2 服务器无法启动
- ArgoCD 在首次安装后进入“进行中”状态
- 处于 CrashLoopBackOff 状态的 ArgoCD 存储库服务器 Pod
- 手动 ArgoCD 网络策略缓解措施 (MHSA-47m3-95c7-g2g8)
- 监控仪表板中缺少 Ceph-rook 指标
- 诊断性运行状况检查期间报告的错误不匹配
- 为 uipathctl 创建的工作负载配置资源请求和限制
- 无正常的上游问题
- 杀毒软件阻止了 Redis 启动
- 无法在启用 TLS 证书验证的情况下启动 AI Center 和 Document Understanding Pod
- Fluentd 不会在 IPv6 环境中导出日志
- Studio 桌面版无法加载 Integration Service 连接器和活动
- 使用 Process Mining 运行高可用性
- 使用 Kerberos 登录时 Process Mining 挖掘失败
- 无法使用 pyodbc 格式连接字符串连接到 AutomationSuite_ProcessMining_Warehouse 数据库
- Airflow 安装失败,并显示 sqlalchemy.exc.ArgumentError:无法从字符串“”中解析 rfc1738 URL
- 如何添加 IP 表格规则以使用 SQL Server 端口 1433
- 运行 CData Sync 的服务器不信任 Automation Suite 证书
- Process Mining fails to load after disabling and re-enabling it
- 运行诊断工具
- 使用 Automation Suite 支持捆绑包
- 探索日志
将自签名证书替换为 CA 签名证书,并在 Automation Suite 中管理证书生命周期。
安装流程会代表您生成自签名证书。这些证书符合 FIPS 标准,并将在 90 天后过期。安装完成后,您必须将这些证书替换为由受信任的证书颁发机构 (CA) 签名的证书。如果不更新证书,安装将在 90 天后停止工作。
如果您在启用 FIPS 的主机上安装了 Automation Suite,并想要更新证书,请确保它们与 FIPS 兼容。
安装捆绑包提供了一个集群管理工具,使您能够在安装后更新证书。 要访问该工具,请导航到安装程序捆绑包的位置:
cd /opt/UiPathAutomationSuite/
cd /opt/UiPathAutomationSuite/
生成证书签名请求 (CSR) 和私钥
要生成 CSR 和私钥,请运行以下命令:
# copy the machine openssl configuration locally
cp /etc/pki/tls/openssl.cnf ./openssl.tmp.cnf
# Replace the [AUTOMATION_SUITE_FQDN] value. For example, "automationsuite.corp.com"
AS_FQDN=[AUTOMATION_SUITE_FQDN]
cat >> ./openssl.tmp.cnf <<EOF
[SAN]
subjectAltName=DNS:$AS_FQDN,DNS:alm.$AS_FQDN,DNS:monitoring.$AS_FQDN,DNS:registry.$AS_FQDN,DNS:objectstore.$AS_FQDN,DNS:insights.$AS_FQDN,DNS:apps.$AS_FQDN
EOF
# create the certificate request
openssl req -new -sha256 -newkey rsa:2048 -nodes -keyout server.key -subj "/C=xx/ST=xx/O=xx/OU=xx/CN=$AS_FQDN" -reqexts SAN -config openssl.tmp.cnf -out ${AS_FQDN}.csr
# copy the machine openssl configuration locally
cp /etc/pki/tls/openssl.cnf ./openssl.tmp.cnf
# Replace the [AUTOMATION_SUITE_FQDN] value. For example, "automationsuite.corp.com"
AS_FQDN=[AUTOMATION_SUITE_FQDN]
cat >> ./openssl.tmp.cnf <<EOF
[SAN]
subjectAltName=DNS:$AS_FQDN,DNS:alm.$AS_FQDN,DNS:monitoring.$AS_FQDN,DNS:registry.$AS_FQDN,DNS:objectstore.$AS_FQDN,DNS:insights.$AS_FQDN,DNS:apps.$AS_FQDN
EOF
# create the certificate request
openssl req -new -sha256 -newkey rsa:2048 -nodes -keyout server.key -subj "/C=xx/ST=xx/O=xx/OU=xx/CN=$AS_FQDN" -reqexts SAN -config openssl.tmp.cnf -out ${AS_FQDN}.csr
您的 IT 团队使用获取的值生成签名证书。 生成的私钥保留在本地。
管理服务器证书
要查看有关服务器证书的更多信息,请运行以下命令:
./bin/uipathctl config tls-certificates --help
./bin/uipathctl config tls-certificates --help
输出:
************************************************************************************
Manage tls certificates
Usage:
uipathctl config tls-certificates [flags]
uipathctl config tls-certificates [command]
Available Commands:
get Get the current tls certificates
update Update tls certificates
Flags:
-h, --help help for tls-certificates
Global Flags:
--context string name of the kubeconfig context to use
-f, --force override all user prompts to true
--kubeconfig string kubectl configuration file (default: ~/.kube/config)
--log-format string log format. one of [text,json] (default "text")
--log-level string set log level. one of [trace,debug,info,error] (default "info")
-q, --quiet disable progress indicators (emoji/formatted status messages)
--timeout duration timeout of the command (default: 90 minutes) (default 1h30m0s)
--versions string optional path to versions file
Use "uipathctl config tls-certificates [command] --help" for more information about a command.
************************************************************************************
************************************************************************************
Manage tls certificates
Usage:
uipathctl config tls-certificates [flags]
uipathctl config tls-certificates [command]
Available Commands:
get Get the current tls certificates
update Update tls certificates
Flags:
-h, --help help for tls-certificates
Global Flags:
--context string name of the kubeconfig context to use
-f, --force override all user prompts to true
--kubeconfig string kubectl configuration file (default: ~/.kube/config)
--log-format string log format. one of [text,json] (default "text")
--log-level string set log level. one of [trace,debug,info,error] (default "info")
-q, --quiet disable progress indicators (emoji/formatted status messages)
--timeout duration timeout of the command (default: 90 minutes) (default 1h30m0s)
--versions string optional path to versions file
Use "uipathctl config tls-certificates [command] --help" for more information about a command.
************************************************************************************
以下部分描述了可以使用 uipathctl config tls-certificates 命令执行的操作。
更新服务器证书
在线安装:如何查找服务器证书
证书在 Istio 级别存储为机密。 您可以在istio-system命名空间的istio-ingressgateway-certs名称下找到证书。
请参阅以下列表中的证书文件:
- 服务器 TLS 证书存储为
tls.crt - 作为
tls.key的服务器 TLS 私钥 - CA 捆绑包存储为
ca.crt
您可以使用以下命令验证密码:
kubectl -n istio-system get secrets istio-ingressgateway-certs -o yaml
kubectl -n istio-system get secrets istio-ingressgateway-certs -o yaml
证书也存储在 UiPath 命名空间中。这适用于需要证书信息以信任传入调用的所有 UiPath™ 产品。有关详细信息,请参阅了解与证书相关的容器架构。
离线安装:如何查找服务器证书
除了在线部署所需的证书之外,离线部署还有两个附加位置,这两个位置使用相同的rootCA.crt和tls.crt :ArgoCD 和 Docker 注册表。然后,证书将存储在 Docker 和 ArgoCD 命名空间中。
您可以使用以下命令验证密码:
# For docker registry
kubectl -n docker-registry get secrets docker-registry-tls -o yaml
# For Argocd
argocd login alm.cluster_fqnd --username argocd_username --password argocd_password
argocd cert list --cert-type https
# For docker registry
kubectl -n docker-registry get secrets docker-registry-tls -o yaml
# For Argocd
argocd login alm.cluster_fqnd --username argocd_username --password argocd_password
argocd cert list --cert-type https
如何更新服务器证书
在更新服务器证书之前,您必须解密证书密钥。 跳过解密步骤将导致错误。
要解密证书密钥,请运行以下命令:
# replace /path/to/encrypted/cert/key to absolute file path of key
# replace /path/to/decrypt/cert/key to store decrypt key
# Once prompted, please entry the passphrase or password to decrypt the key
openssl rsa -in /path/to/encrypted/cert/key -out /path/to/decrypt/cert/key
# replace /path/to/encrypted/cert/key to absolute file path of key
# replace /path/to/decrypt/cert/key to store decrypt key
# Once prompted, please entry the passphrase or password to decrypt the key
openssl rsa -in /path/to/encrypted/cert/key -out /path/to/decrypt/cert/key
证书链的组合方式
运行uipathctl config tls-certificates update命令时, uipathctl会从两个单独的输入文件组合完整证书链:
server.crt- PEM 格式的完整公共服务器证书链:叶服务器证书、后跟的中间 CA 证书和根 CA 构成该叶证书的签名路径。仅包含属于叶证书实际签名链的证书,不包含同级 CA 证书、不相关证书、重复证书或备用 CA 证书。ca.crt- 完整的 CA 链,包括所有中间证书和根 CA。该文件必须仅包含用于对 TLS 服务器证书进行签名的证书。包括其他任何内容都会导致失败。
uipathctl在运行时合并这些文件。
要更新证书,请提供三个证书文件中每一个的路径。所有证书文件必须为PEM格式。
- 证书颁发机构捆绑包- 用于对 TLS 服务器证书进行签名的完整 CA 链。包括所有中间证书和根 CA。不要包含分支证书或未用于对 TLS 服务器证书进行签名的任何其他证书,因为包含其他任何证书都会导致失败。链式证书上限为最多九个证书。
- 服务器证书- PEM 格式的完整公共服务器证书链,从分支服务器证书开始,然后是中间 CA 证书和根 CA。仅包括形成叶证书实际签名链的证书。
- 私钥- 服务器证书的私钥。
./bin/uipathctl config tls-certificates update --cert server.crt --cacert ca.crt --key server.key
./bin/uipathctl config tls-certificates update --cert server.crt --cacert ca.crt --key server.key
有关 TLS 证书验证错误的故障排除,请参阅TLS 证书验证错误。
以下文件存储在/directory/path/to/store/certificate位置。
访问 TLS 证书
要打印证书文件,请运行以下命令,并指定存储证书的目录。
./bin/uipathctl config tls-certificates get --show-details
./bin/uipathctl config tls-certificates get --show-details
将 CA 证书添加到主机信任存储
您负责确保生成的证书受信任。
当您的环境使用并不全局受信任的私有 CA 或自签名证书时,必须执行此步骤。如果 Linux 主机信任存储中尚不存在私有 CA,则源自主机节点的调用将失败,并显示 SSL 错误。如果您的 CA 已受主机信任,则可以跳过此步骤。
要将证书添加到主机虚拟机信任存储区,请在集群中的所有节点上运行以下命令:
# 1. Copy the certificate file to the /usr/share/pki/ca-trust-source/anchors/ or the /etc/pki/ca-trust/source/anchors/ directory
cp /path/to/the/ca-cert /usr/share/pki/ca-trust-source/anchors/
# 2. Update the trust store configuration
update-ca-trust
# 1. Copy the certificate file to the /usr/share/pki/ca-trust-source/anchors/ or the /etc/pki/ca-trust/source/anchors/ directory
cp /path/to/the/ca-cert /usr/share/pki/ca-trust-source/anchors/
# 2. Update the trust store configuration
update-ca-trust
管理其他 CA 证书
要查看有关其他 CA 证书的更多信息,请运行以下命令:
./bin/uipathctl config additional-ca-certificates --help
./bin/uipathctl config additional-ca-certificates --help
输出:
***************************************************************************************
Manage additional ca certificates
Usage:
uipathctl config additional-ca-certificates [flags]
uipathctl config additional-ca-certificates [command]
Available Commands:
get Get the current additional ca certificates
update Update additional ca certificates
Flags:
-h, --help help for additional-ca-certificates
Global Flags:
--context string name of the kubeconfig context to use
-f, --force override all user prompts to true
--kubeconfig string kubectl configuration file (default: ~/.kube/config)
--log-format string log format. one of [text,json] (default "text")
--log-level string set log level. one of [trace,debug,info,error] (default "info")
-q, --quiet suppress all output except for errors and warnings
--timeout duration timeout of the command (default: 90 minutes) (default 1h30m0s)
--versions string optional path to versions file
Use "uipathctl config additional-ca-certificates [command] --help" for more information about a command.
***************************************************************************************
***************************************************************************************
Manage additional ca certificates
Usage:
uipathctl config additional-ca-certificates [flags]
uipathctl config additional-ca-certificates [command]
Available Commands:
get Get the current additional ca certificates
update Update additional ca certificates
Flags:
-h, --help help for additional-ca-certificates
Global Flags:
--context string name of the kubeconfig context to use
-f, --force override all user prompts to true
--kubeconfig string kubectl configuration file (default: ~/.kube/config)
--log-format string log format. one of [text,json] (default "text")
--log-level string set log level. one of [trace,debug,info,error] (default "info")
-q, --quiet suppress all output except for errors and warnings
--timeout duration timeout of the command (default: 90 minutes) (default 1h30m0s)
--versions string optional path to versions file
Use "uipathctl config additional-ca-certificates [command] --help" for more information about a command.
***************************************************************************************
以下部分描述了可以使用 uipathctl config additional-ca-certificates 命令执行的操作。
更新 CA 证书
当您的环境依赖私有 CA 或自签名证书时,请使用此命令。添加 CA 证书可让 Automation Suite 服务与使用该 CA 签名证书的外部组件(例如 SQL Server、对象存储或 SMTP 服务器)安全地通信。
要更新 CA 证书,请执行以下步骤:
-
更新
cluster_config.json文件,使其指向具有additional_ca_certs文件。有关详细信息,请参阅证书配置。 -
应用清单:
./bin/uipathctl manifest apply cluster_config.json --versions versions.json./bin/uipathctl manifest apply cluster_config.json --versions versions.json此命令可能会失败,并显示如下错误:
Error: [failed to wait for application argocd/<app-name1>: timed out waiting for the condition, failed to wait for application argocd/<app-name2>: timed out waiting for the condition]]Error: [failed to wait for application argocd/<app-name1>: timed out waiting for the condition, failed to wait for application argocd/<app-name2>: timed out waiting for the condition]]无论失败原因如何,请继续执行步骤 3 以重新启动部署并稳定环境。
-
手动重新启动
uipath命名空间中的所有部署和状态集:kubectl rollout restart deployment -n <uipath> kubectl rollout restart sts -n <uipath>kubectl rollout restart deployment -n <uipath> kubectl rollout restart sts -n <uipath>
要附加旧证书,您必须使用访问 CA 证书部分中的get命令,并将其附加到 CA 证书.pem文件中,您必须在additional_ca_certs字段中提供该文件。CA 证书捆绑包文件应为有效的.pem格式,并且可以包含多个证书。
访问 CA 证书
要下载已配置的 CA 证书,请运行以下命令:
./bin/uipathctl config additional-ca-certificates get
./bin/uipathctl config additional-ca-certificates get
将 CA 证书添加到主机信任存储
您负责确保生成的证书受信任。
当您的环境使用并不全局受信任的私有 CA 或自签名证书时,必须执行此步骤。如果 Linux 主机信任存储中尚不存在私有 CA,则源自主机节点的调用将失败,并显示 SSL 错误。如果您的 CA 已受主机信任,则可以跳过此步骤。
要将证书添加到主机虚拟机信任存储区,请在集群中的所有节点上运行以下命令:
# 1. Copy the certificate file to the /usr/share/pki/ca-trust-source/anchors/ or the /etc/pki/ca-trust/source/anchors/ directory
cp /path/to/the/ca-cert /usr/share/pki/ca-trust-source/anchors/
# 2. Update the trust store configuration
update-ca-trust
# 1. Copy the certificate file to the /usr/share/pki/ca-trust-source/anchors/ or the /etc/pki/ca-trust/source/anchors/ directory
cp /path/to/the/ca-cert /usr/share/pki/ca-trust-source/anchors/
# 2. Update the trust store configuration
update-ca-trust
对于 Windows 环境,请参阅本指南以安装受信任的根证书。
管理身份令牌签名证书
Automation Suite 提供了两种方法来管理身份令牌签名证书的轮换:自动和手动。
要查看有关身份令牌签名证书的更多信息,请运行以下命令:
./bin/uipathctl config token-signing-certificates --help
./bin/uipathctl config token-signing-certificates --help
输出:
************************************************************************************
Manage token signing certificates
Usage:
uipathctl config token-signing-certificates [flags]
uipathctl config token-signing-certificates [command]
Available Commands:
automatic-key-management Manage key management
get Get the current token signing certificate
rotate Rotate token signing certificates
update Update future token signing certificate
Flags:
-h, --help help for token-signing-certificates
Global Flags:
--context string name of the kubeconfig context to use
-f, --force override all user prompts to true
--kubeconfig string kubectl configuration file (default: ~/.kube/config)
--log-format string log format. one of [text,json] (default "text")
--log-level string set log level. one of [trace,debug,info,error] (default "info")
-q, --quiet suppress all output except for errors and warnings
--timeout duration timeout of the command (default: 90 minutes) (default 1h30m0s)
--versions string optional path to versions file
Use "uipathctl config token-signing-certificates [command] --help" for more information about a command.
************************************************************************************
************************************************************************************
Manage token signing certificates
Usage:
uipathctl config token-signing-certificates [flags]
uipathctl config token-signing-certificates [command]
Available Commands:
automatic-key-management Manage key management
get Get the current token signing certificate
rotate Rotate token signing certificates
update Update future token signing certificate
Flags:
-h, --help help for token-signing-certificates
Global Flags:
--context string name of the kubeconfig context to use
-f, --force override all user prompts to true
--kubeconfig string kubectl configuration file (default: ~/.kube/config)
--log-format string log format. one of [text,json] (default "text")
--log-level string set log level. one of [trace,debug,info,error] (default "info")
-q, --quiet suppress all output except for errors and warnings
--timeout duration timeout of the command (default: 90 minutes) (default 1h30m0s)
--versions string optional path to versions file
Use "uipathctl config token-signing-certificates [command] --help" for more information about a command.
************************************************************************************
您可以使用最大密钥长度 4096 位对证书进行签名。 作为最佳实践,我们强烈建议您使用至少 512 位(64 字节)长度的密钥。
下一节将详细介绍可以使用uipathctl config token-signing-certificates命令执行的操作。
自动证书轮换
自动证书轮换意味着 Automation Suite 管理签名密钥的生命周期。 这包括每 90 天轮换一次密钥,在轮换前 14 天宣布新密钥,轮换后将旧密钥保留 14 天,然后在 14 天的期限结束时将其删除。
如果要从旧版本升级到 2.2510,默认情况下会禁用自动证书轮换。要启用自动密钥管理,请运行以下命令:
./bin/uipathctl config token-signing-certificates automatic-key-management enable
./bin/uipathctl config token-signing-certificates automatic-key-management enable
启用自动证书轮换可能会导致长达一小时的停机。
默认情况下,为全新 Automation Suite 安装启用证书自动轮换。要禁用自动密钥管理,请运行以下命令:
./bin/uipathctl config token-signing-certificates automatic-key-management disable
./bin/uipathctl config token-signing-certificates automatic-key-management disable
如果禁用了自动管理功能,则需要手动更新和轮换签名证书。有关手动密钥管理的详细信息,请参阅有关手动更新和轮换证书的文档。
手动更新证书
以下命令不会替换现有令牌签名证书。
确保您提供的证书为.pem格式。server.crt文件必须包含整个链,如以下示例所示:
-----server cert-----
-----root ca chain-----
-----server cert-----
-----root ca chain-----
要上传新证书以对令牌进行签名,请运行以下命令:
./bin/uipathctl config token-signing-certificates update --cert server.crt --key server.key
./bin/uipathctl config token-signing-certificates update --cert server.crt --key server.key
手动轮换证书
要轮换旧证书或将其替换为新证书,请运行以下命令:
./bin/uipathctl config token-signing-certificates rotate
./bin/uipathctl config token-signing-certificates rotate
证书更新和轮换之间应有大约 24 到 48 小时的前置时间。
我们需要这个提前期来继续支持由旧证书签名的缓存令牌的身份验证。
如果在缓存令牌过期之前过早轮换证书可能会导致停机。您可能需要重新启动所有机器人。
紧急证书轮换
以下过程仅适用于紧急情况。 您应该在证书到期日期之前轮换证书
要执行紧急证书更新,请执行以下步骤:
-
获取新证书或创建自签名证书,并将其复制到用于执行后续轮换步骤的集群服务器节点。 要创建新的自签名证书,请运行以下命令:
openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout identityserver.key -out identityserver.crt openssl pkcs12 -export -out identityserver.pfx -inkey identityserver.key -in identityserver.crtopenssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout identityserver.key -out identityserver.crt openssl pkcs12 -export -out identityserver.pfx -inkey identityserver.key -in identityserver.crt -
如果
IdentityServer1.pfx已过期,请轮换并更新证书。有关说明,请参阅轮换证书。 -
如果
IdentityServer2.pfx已过期,请更新证书。 -
如果两个证书均已过期,请再次更新、轮换和更新。
-
重新启动所有部署。有关说明,请参阅故障排除。
-
清除所有浏览器缓存。 如果您在隐身模式或隐私模式下运行,则可以跳过此步骤。
-
对于 Firefox,请按CTRL + SHIFT + DEL ,选择“缓存” ,然后选择“确定” 。
-
对于 Chrome,请按CTRL+SHIFT+DEL ,选择“缓存的图像和文件” ,然后选择“清除数据” 。
访问证书
运行以下命令以下载当前的令牌签名证书:
./bin/uipathctl config token-signing-certificates get --show-details
./bin/uipathctl config token-signing-certificates get --show-details
管理 RKE2 证书
默认情况下,RKE2 证书将在 12 个月后过期。在到期日期前的 90 天内,当您重新启动 RKE2 时,证书将轮换。
有关详细信息,请参阅RKE2 - 高级选项 - 证书轮换。
检查 RKE2 证书到期日期
要检查 RKE2 证书的到期日期,请在任意节点上运行以下命令:
if [[ -d "/var/lib/rancher/rke2/server/tls" ]]; then
dir="/var/lib/rancher/rke2/server/tls"
elif [[ -d "/var/lib/rancher/rke2/agent/tls" ]]; then
dir="/var/lib/rancher/rke2/agent/tls"
else
dir="/var/lib/rancher/rke2/agent/"
fi
# Loop through each .crt file in the directory
for file in "$dir"/*.crt; do
# Extract the expiry date from the certificate
expiry=$(openssl x509 -enddate -noout -in "$file" | cut -d= -f 2-)
# Get the file name without the path
filename=$(basename "$file")
# Print the filename and expiry date in a pretty format
printf "%-30s %s\n" "$filename:" "$expiry"
done
if [[ -d "/var/lib/rancher/rke2/server/tls" ]]; then
dir="/var/lib/rancher/rke2/server/tls"
elif [[ -d "/var/lib/rancher/rke2/agent/tls" ]]; then
dir="/var/lib/rancher/rke2/agent/tls"
else
dir="/var/lib/rancher/rke2/agent/"
fi
# Loop through each .crt file in the directory
for file in "$dir"/*.crt; do
# Extract the expiry date from the certificate
expiry=$(openssl x509 -enddate -noout -in "$file" | cut -d= -f 2-)
# Get the file name without the path
filename=$(basename "$file")
# Print the filename and expiry date in a pretty format
printf "%-30s %s\n" "$filename:" "$expiry"
done
获取的输出应类似于下图所示内容:
轮换 RKE2 证书
默认情况下,RKE2 证书将在 12 个月后过期。在到期日期前的 90 天内,当您重新启动 RKE2 时,证书将轮换。但是,如果证书的有效期超过 90 天,则必须按照RKE2 - 高级选项 - 证书轮换中提到的步骤手动轮换证书。
如果要自定义 RKE2 证书的过期期限以满足特定要求,可以在为服务器节点和代理节点重新启动 RKE2 服务之前执行此操作。
要轮换 RKE2 证书,您必须首先在服务器节点上执行一系列操作,然后在代理节点上继续执行一些步骤。
在服务器节点上执行以下步骤:
-
停止 RKE2 服务器:
systemctl stop rke2-server.servicesystemctl stop rke2-server.service -
清除所有剩余的 RKE2 流程:
rke2-killall.shrke2-killall.sh -
删除位于
/var/lib/rancher/rke2/server/tls/的dynamic-cert.json文件。 -
要自定义 RKE2 证书的过期期限,请使用以下命令。 请注意,此示例将有效期设置为 1000 天,但您可以根据要求更改此值。
SERVICE_NAME="rke2-server.service" conf_file_path="/etc/systemd/system/${SERVICE_NAME}.d/cert.conf" mkdir -p /etc/systemd/system/"${SERVICE_NAME}".d/ cat > "$conf_file_path" <<EOF [Service] Environment="CATTLE_NEW_SIGNED_CERT_EXPIRATION_DAYS=1000" EOF systemctl daemon-reloadSERVICE_NAME="rke2-server.service" conf_file_path="/etc/systemd/system/${SERVICE_NAME}.d/cert.conf" mkdir -p /etc/systemd/system/"${SERVICE_NAME}".d/ cat > "$conf_file_path" <<EOF [Service] Environment="CATTLE_NEW_SIGNED_CERT_EXPIRATION_DAYS=1000" EOF systemctl daemon-reload -
重新启动 RKE2 服务器:
systemctl start rke2-server.servicesystemctl start rke2-server.service备注:如果集群具有多个服务器节点,则可能无法完全执行步骤 1-4,因为 etcd 可能无法完成领导者选择。如果发生这种情况,请在其他服务器节点上重复步骤 1-4。
-
从
kube-system命名空间中删除rke2-serving密码:kubectl delete secret -n kube-system rke2-servingkubectl delete secret -n kube-system rke2-serving备注:在多节点部署中,在必要数量的服务器节点上完成前四个操作之前,您可能无法运行
kubectl命令。这是为了满足 etcd 法定人数要求。您可以在 RKE2 服务器启动后立即删除rke2-serving密码。
当 etcd 达到法定人数,RKE2 服务器就可以启动其余的控制平面 Pod。然后,您应该会看到已成功执行 kubectl get nodes 命令。服务器节点准备就绪后,您可以前往代理节点重新生成证书。
在代理节点上执行以下步骤:
-
停止 RKE2 服务器:
systemctl stop rke2-agent.servicesystemctl stop rke2-agent.service -
清除所有剩余的 RKE2 流程:
rke2-killall.shrke2-killall.sh -
要自定义 RKE2 证书的过期期限,请使用以下命令。 请注意,此示例将有效期设置为 1000 天,但您可以根据要求更改此值。
SERVICE_NAME="rke2-agent.service" conf_file_path="/etc/systemd/system/${SERVICE_NAME}.d/cert.conf" mkdir -p /etc/systemd/system/"${SERVICE_NAME}".d/ cat > "$conf_file_path" <<EOF [Service] Environment="CATTLE_NEW_SIGNED_CERT_EXPIRATION_DAYS=1000" EOF systemctl daemon-reloadSERVICE_NAME="rke2-agent.service" conf_file_path="/etc/systemd/system/${SERVICE_NAME}.d/cert.conf" mkdir -p /etc/systemd/system/"${SERVICE_NAME}".d/ cat > "$conf_file_path" <<EOF [Service] Environment="CATTLE_NEW_SIGNED_CERT_EXPIRATION_DAYS=1000" EOF systemctl daemon-reload -
重新启动 RKE2 服务器:
systemctl start rke2-agent.servicesystemctl start rke2-agent.service
管理符合 OCI 的外部注册表证书
要在安装后更新符合 OCI 的外部注册表的证书,请执行以下步骤:
-
更新
cluster_config.json文件中的registry_ca_cert标志。有关详细信息,请参阅符合外部 OCI 的注册表配置。 -
通过在所有节点上运行以下命令,更新外部符合 OCI 的注册表使用的根 CA:
./bin/uipathctl rke2 generate-registries cluster_config.json --current-config-path /etc/rancher/rke2/registries.yaml > /etc/rancher/rke2/registries.yaml.tmp mv -f /etc/rancher/rke2/registries.yaml.tmp /etc/rancher/rke2/registries.yaml systemctl restart rke2-server || systemctl restart rke2-agent./bin/uipathctl rke2 generate-registries cluster_config.json --current-config-path /etc/rancher/rke2/registries.yaml > /etc/rancher/rke2/registries.yaml.tmp mv -f /etc/rancher/rke2/registries.yaml.tmp /etc/rancher/rke2/registries.yaml systemctl restart rke2-server || systemctl restart rke2-agent -
更新外部符合 OCI 的注册表的 ArgoCD 受信任 CA 证书:
./bin/uipathctl config argocd ca-certificates update --cacert [PATH]./bin/uipathctl config argocd ca-certificates update --cacert [PATH]