If you want to use a custom domain name for a Knative Service, we recommend that you configure an HTTPS certificate for the custom domain name to improve the security of data transmission. Knative lets you specify an HTTPS certificate by configuring a DomainMapping, which securely maps a Knative Service to the custom domain name.
Prerequisites
Knative is deployed in your ACS cluster. For more information, see Deploy Knative.
Step 1: Create a Knative Service
-
Log on to the Container Compute Service (ACS) console. In the left-side navigation pane, click Clusters.
-
On the Clusters page, click the name of the target cluster. In the left-side navigation pane of the cluster details page, choose Applications > Knative.
-
On the Services tab of the Knative page, set Namespace to default, and then click Create from Template to create a Knative Service (the
helloworld-goService) from the sample template in the console. Complete the creation as instructed. After the Service is created, its status appears as successful on the Services tab, and its default domain name ishelloworld-go.default.example.com. Before you access the Service, you must bind the access domain name to the ingress gateway as a Host.
Step 2: Configure the HTTPS service
The way you configure HTTPS depends on the gateway type:
-
ALB gateway: Certificates are managed centrally by AlbConfig. You enable TLS by using an annotation, without manually handling certificate files.
-
Kourier gateway: You must manually create a certificate Secret, and then bind the Secret to the domain name by using a DomainMapping.
ALB
You can specify a certificate in the AlbConfig and enable TLS access in the Knative Service by using the knative.k8s.alibabacloud/tls: "true" annotation. See the following example.
To enable HTTPS access, add the TLS annotation to the Knative Service and configure a listener on port 443 in the AlbConfig.
-
Add the
knative.k8s.alibabacloud/tls: "true"annotation to the Knative Service YAML.apiVersion: serving.knative.dev/v1 kind: Service metadata: name: helloworld namespace: default annotations: knative.k8s.alibabacloud/tls: "true" spec: template: spec: containers: - image: registry-vpc.cn-shenzhen.aliyuncs.com/knative-sample/helloworld-go:73fbdd56 # Replace the region with the region that you actually use. env: - name: TARGET value: "Knative" -
Add a listener on port 443 in the AlbConfig (for example,
knative-internet) to route HTTPS traffic into the cluster.apiVersion: alibabacloud.com/v1 kind: AlbConfig metadata: name: knative-internet spec: config: ... listeners: - port: 443 # Valid values: HTTP, HTTPS, QUIC protocol: HTTPS ... -
Verify that the Service is accessible over HTTPS.
# Replace alb-ppcate4ox6******.cn-beijing.alb.aliyuncs.com with your ALB gateway address. curl -H "Host: helloworld.knative.top" https://alb-ppcate4ox6******.cn-beijing.alb.aliyuncs.com -kExpected output:
Hello Knative!
Kourier
The Kourier gateway does not provide built-in certificate management. You must first store the TLS certificate in the cluster as a Secret. After the Secret is ready, bind the domain name to the certificate by using a DomainMapping.
1. Create a certificate Secret
The following example uses a self-signed HTTPS certificate generated with OpenSSL. If you already have certificate files in .pem format, you can skip step 1 and start from step 2.
Self-signed certificates are for testing only. In production environments, we recommend that you use certificates issued by a certificate authority (CA).
-
Create a self-signed certificate by using OpenSSL.
openssl genrsa -out knativetop-key.pem 4096 openssl req -subj "/CN=helloworld.knative.top" -sha256 -new -key knativetop-key.pem -out knativetop.csr echo subjectAltName = DNS:helloworld.knative.top > extfile.cnf openssl x509 -req -days 3650 -sha256 -in knativetop.csr -signkey knativetop-key.pem -out knativetop-cert.pem -extfile extfile.cnfExpected output:
Signature ok subject=CN = helloworld.knative.top Getting Private key -
Base64-encode the
knativetop-key.pemandknativetop-cert.pemfiles created in step 1.-
Base64-encode
knativetop-key.pem.cat knativetop-key.pem | base64Expected output:
a25hdGl2ZXRvcC1r****** -
Base64-encode
knativetop-cert.pem.cat knativetop-cert.pem | base64Expected output:
a25hdGl2ZXRvcC1jZ******==
-
-
Create the Secret. The Secret can be used in the TLS configuration of the Knative Service to enable secure access to the domain name
helloworld.knative.top.kubectl create secret tls secret-tls --key knativetop-key.pem --cert knativetop-cert.pemExpected output:
secret/secret-tls created
2. Create a DomainMapping
In Knative, a DomainMapping is a resource object that maps a domain name to one or more Knative Services. After the Secret is ready, use a DomainMapping to bind the custom domain name to the Knative Service, and reference the previously created Secret to enable TLS encryption.
-
Create the
helloworld.knative.top.yamlfile with the following content.apiVersion: serving.knative.dev/v1beta1 kind: DomainMapping metadata: name: helloworld.knative.top namespace: default spec: ref: name: helloworld-go kind: Service apiVersion: serving.knative.dev/v1 # The tls block specifies the secret to be used. tls: secretName: secret-tls -
Apply the DomainMapping to the cluster.
kubectl apply -f helloworld.knative.top.yamlExpected output:
domainmapping.serving.knative.dev/helloworld.knative.top created -
Run the following command to verify that the DomainMapping is ready.
kubectl get domainmapping helloworld.knative.topExpected output:
NAME URL READY REASON helloworld.knative.top https://helloworld.knative.top True -
Verify that the Service is accessible through the custom domain name.
# 8.141.XX.XX is the Kourier gateway address. curl -H "Host: helloworld-go.default.example.com" http://8.141.XX.XX -kExpected output:
Hello Knative!