对于 AI 代理:可在 https://www.mongodb.com/zh-cn/docs/llms.txt 获取文档索引—通过在任何 URL 路径后添加 .md 可获取所有页面的 Markdown 版本。
Docs 菜单

配置 TLS 以迁移到Kubernetes

When you migrate a TLS-enabled replica set from virtual machines into Kubernetes, one replica set is one trust domain. Issue the Kubernetes member certificates from the same certificate authority (CA) that signed the virtual machine certificates. This is the only migration-specific TLS requirement. The general TLS documentation for Kubernetes Operator covers everything else about configuring TLS. A CA mismatch fails the dry run, by design. To learn how the dry run surfaces that failure, see Validate Migration Readiness with a Dry Run.

重要

此页面上的字段仅用于迁移。除非字段说明另有说明,否则请勿在新建的Kubernetes Operator部署上设立它们。

To learn how to issue certificates, structure Secrets and ConfigMaps, and configure the general TLS settings on the MongoDB custom resource, see:

When you follow that documentation for a migration, issue the Kubernetes member certificates from the same CA that signed the virtual machine certificates, not from a new CA. The CA ConfigMap named <resourceName>-ca must contain a ca-pem key populated from that same CA.

您需要满足以下条件:

  • 虚拟机部署的现有 CA 证书和密钥材料。

  • cert-manager 或等效工具,以从同一 CA 颁发Kubernetes成员证书。

  • The generated MongoDB custom resource from Migrate a Replica Set to Kubernetes.

1

按照“设置证书管理器集成”或“生成 X.509 客户端证书”操作,创建名为 <certsSecretPrefix>-<resourceName>-certkubernetes.io/tls Secret,从签署虚拟机证书的同一 CA 颁发证书。

Create the CA ConfigMap named <resourceName>-ca with a ca-pem key populated from that same CA.

如果使用 X.509代理身份验证,还要创建 <certsSecretPrefix>-<resourceName>-agent-certs Secret 并设立spec.security.authentication.agents.clientCertificateSecretRef 以引用它。此要求仅适用于代理身份验证,不适用于内部集群身份验证(spec.security.authentication.internalCluster)。

2

这些字段的存在只是为了使Kubernetes Operator 的文件路径视图与虚拟机部署已布局其证书和密钥文件的方式相匹配。仅设置应用于源部署的设置:

  • spec.security.tls.caFilePath: the absolute path the CA is projected to inside the Pod. Defaults to /mongodb-automation/tls/ca/ca-pem. The path must contain at least two path segments. This field is not supported for the Application Database. If your podTemplate mounts another volume over this path, that mount shadows the projected CA and the Ops Manager Agent cannot read it.

  • spec.security.authentication.agents.autoPEMKeyFilePath: the absolute path of the agent's combined PEM file inside database Pods. This field configures agent authentication only. Setting this field sets the Ops Manager tls.autoPEMKeyFilePath value and mounts the Secret referenced by clientCertificateSecretRef at that path. It defaults to a hash-derived agent certificate mount path, and setting it requires spec.security.authentication.agents.clientCertificateSecretRef to already be set. Set this field only when the virtual machine deployment uses a non-default agent PEM path.

  • spec.downloadBase: the directory where the Ops Manager Agent binary downloads. Defaults to /var/lib/mongodb-mms-automation. Kubernetes Operator derives the keyfile path from this value as <downloadBase>/keyfile.

3

If the virtual machine deployment never configured TLS, set net.tls.mode to disabled in Ops Manager or Cloud Manager on the existing virtual machine deployment before you migrate. Do not set this field on the MongoDB custom resource.

If you leave the source deployment's TLS mode unset, Kubernetes Operator attempts a deployment change that does not match the source automation config, because its default view of TLS differs from a deployment that never configured TLS at all. Setting the field to disabled on the source deployment makes Kubernetes Operator's view match the virtual machine deployment and avoids that spurious change.

4

Apply the resource with the dry-run annotation still present and check the NetworkConnectivityVerified condition. To learn how to read the result and what to do if it fails, see Validate Migration Readiness with a Dry Run.

A sharded cluster needs one certificate per component, following the pattern <resourceName>-config-* for the config server, <resourceName>-<shardIndex>-* for each shard, and <resourceName>-mongos-* for the mongos routers.

注意

Confirm the exact per-component Secret names against the generated resource before you reconcile. To learn how a sharded cluster migration differs from a replica set migration, see Migrate a Sharded Cluster to Kubernetes.