{"id":6558,"date":"2023-06-28T17:38:34","date_gmt":"2023-06-28T09:38:34","guid":{"rendered":"https:\/\/nj.transwarp.cn:8180\/?p=6558"},"modified":"2023-06-28T17:38:31","modified_gmt":"2023-06-28T09:38:31","slug":"registry%e7%9a%845000%e7%ab%af%e5%8f%a3%e5%ae%b9%e5%99%a8%e5%90%af%e5%8a%a8%e5%a4%b1%e8%b4%a5%e6%8a%a5%e9%94%99httptls-handshake-error-from-ipport-remote-errorbad-certificate","status":"publish","type":"post","link":"https:\/\/kbwp.transwarp.cn\/?p=6558","title":{"rendered":"\u5bb9\u5668\u542f\u52a8\u62a5\u9519 http:TLS handshake error from ip:port: remote error:bad certificate \u7684\u89e3\u51b3\u65b9\u6cd5"},"content":{"rendered":"<h3>\u6982\u8981\u63cf\u8ff0<\/h3>\n<p>\u672c\u6587\u63cf\u8ff0\u4e86registry pod\u65e5\u5fd7\u62a5\u9519\u201chttp:TLS handshake error from ip:port: remote error:bad certificate\u201d\u89e3\u51b3\u65b9\u6cd5<\/p>\n<h3>\u8be6\u7ec6\u63cf\u8ff0<\/h3>\n<h4>1 \u95ee\u9898\u63cf\u8ff0<\/h4>\n<p>\u670d\u52a1\u65e0\u6cd5\u62c9\u53d6\u955c\u50cf\uff0cTOS\u9875\u9762\u663e\u793a\u6b63\u5e38\uff0c\u663e\u793apod\u90fd\u6b63\u5e38<\/p>\n<pre><code class=\"language-shell\">kubectl get pods -n kube-system<\/code><\/pre>\n<p>\u663e\u793a5000\u7aef\u53e3\u6ca1\u6709\u88ab\u5360\u7528<\/p>\n<pre><code class=\"language-shell\">netstat -antulp | grep 5000<\/code><\/pre>\n<p>\u627e\u5230\u5bf9\u5e94\u7684container-id<\/p>\n<pre><code class=\"language-shell\">docker ps |grep registry\ndocker logs [container-id]<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/nj.transwarp.cn:8180\/wp-content\/uploads\/2021\/08\/image-1630290362649.png\" alt=\"file\" \/><\/p>\n<p>\u4ee5\u4e0b\u662fcontainer\u7684\u62a5\u9519\u65e5\u5fd7 <strong><code>http:TLS handshake error from ip: port: remote error:bad certificate<\/code><\/strong><\/p>\n<pre><code class=\"language-java\">I0619 11:15:54.941451       1 endpoint.go:66] ccResolverWrapper: sending new addresses to cc: [{https:\/\/gddc-bd1:4001 0  <nil>} {https:\/\/gddc-bd2:4001 0  <nil>} {https:\/\/gddc-bd3:4001 0  <nil>}]\nW0619 11:15:54.948032       1 clientconn.go:1120] grpc: addrConn.createTransport failed to connect to {https:\/\/gddc-bd3:4001 0  <nil>}. Err :connection error: desc = \"transport: authentication handshake failed: remote error: tls: bad certificate\". Reconnecting...\n<\/code><\/pre>\n<h4>2 root cause<\/h4>\n<p>\u67e5\u770b registry pod \u4fe1\u606f\uff0c\u786e\u8ba4\u4f7f\u7528\u7684 key \u548c certificate \u6587\u4ef6\uff1b<\/p>\n<pre><code class=\"language-shell\">describe pod tos-registry-tos-hostname1 -n kube-system<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/nj.transwarp.cn:8180\/wp-content\/uploads\/2021\/08\/image-1630294347280.png\" alt=\"file\" \/><\/p>\n<p>\u7136\u540e\u68c0\u67e5 \/srv\/kubernetes \u76ee\u5f55\uff0c\u662f\u5426\u7f3a\u5c11\u54cd\u5e94\u7684 key \u6587\u4ef6\uff0c\/srv\/kubernetes \u76ee\u5f55\u4e0b\u7f3a\u5931\u76f8\u5173\u7684 key \u6587\u4ef6<\/p>\n<p>\u6b63\u5e38\u7684\u5e94\u8be5\u662f\u6709\u4ee5\u4e0b key \u6587\u4ef6\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/nj.transwarp.cn:8180\/wp-content\/uploads\/2021\/08\/image-1687944790728.png\" alt=\"file\" \/><\/p>\n<h4>3 \u89e3\u51b3\u65b9\u6848<\/h4>\n<p>\u5907\u4efd\u539f\u59cb\/srv\/kubernetes \u6587\u4ef6\u5939<\/p>\n<pre><code class=\"language-shell\">cp -r \/srv\/kubernetes \/tmp\/kubernetes_bak<\/code><\/pre>\n<p>\u624b\u52a8\u751f\u6210\u65b0\u7684\u5bc6\u94a5<\/p>\n<pre><code class=\"language-shell\">docker run --volume \/srv\/kubernetes\/:\/srv\/kubernetes\/ --net=host transwarp\/gencerts:transwarp-xxx \/usr\/bin\/entry.sh\uff08transwarp-xxx \u6362\u6210\u5b9e\u9645\u7684\u7248\u672c\uff0c\u5982 transwarp-5.2.0-final\uff09<\/code><\/pre>\n<p>\u751f\u6210\u4e86\u65b0\u7684\u5bc6\u94a5\u6587\u4ef6\u4e4b\u540e\uff0c\u53bb \/srv\/kubernetes\/ \u76ee\u5f55\u4e0b\u67e5\u770b\u5bc6\u94a5\u6587\u4ef6\u7684\u521b\u5efa\u65f6\u95f4\uff1b<\/p>\n<pre><code class=\"language-shell\">systemctl restart haproxy && docker rm -vf $(docker ps -qa) && systemctl restart kubelet<\/code><\/pre>\n<p>\u7136\u540e\u91cd\u542f registry<\/p>\n<pre><code class=\"language-shell\">mv \/opt\/kubernetes\/manifests-multi\/tos-registry.manifest \/tmp\/\nmv \/tmp\/tos-registry.manifest \/opt\/kubernetes\/manifests-multi\/<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981\u63cf\u8ff0 \u672c\u6587\u63cf\u8ff0\u4e86registry pod\u65e5\u5fd7\u62a5\u9519\u201chttp:TLS handshake error fro ..<\/p>\n<div class=\"clear-fix\"><\/div>\n<p><a href=\"https:\/\/kbwp.transwarp.cn\/?p=6558\" title=\"read more...\">Read more<\/a><\/p>\n","protected":false},"author":15,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-6558","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"_links":{"self":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/6558","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6558"}],"version-history":[{"count":3,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/6558\/revisions"}],"predecessor-version":[{"id":10442,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/6558\/revisions\/10442"}],"wp:attachment":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6558"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}