๋กœ์ผ“๐Ÿพ
article thumbnail
[Cert manager] ์„œ๋น„์Šค ๋„๋ฉ”์ธ svc.cluster.local ๊ณผ HTTPS ํ†ต์‹ ํ•˜๊ธฐ
DevOps/Cert Manager 2024. 2. 5. 21:06

์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ๋‚ด๋ถ€๋ผ๋ฆฌ ํ†ต์‹ ์„ ํ•  ๋•Œ ๋ณดํ†ต ์„œ๋น„์Šค์˜ ๋„๋ฉ”์ธ svc.cluster.local ์„ ์ด์šฉํ•˜์—ฌ ํ†ต์‹ ํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. ์™ธ๋ถ€์—์„œ ๋‚ด๋ถ€๋กœ ๋“ค์–ด์˜ค๋Š” ํ†ต์‹ ์— ๋Œ€ํ•ด์„œ๋Š” Ingress ๋ฅผ ์ด์šฉํ•ด https ํ†ต์‹ ์„ ํ•˜๊ฒŒ๋˜์ฃ . ํ•˜์ง€๋งŒ Ingress ๋Š” ๋‚ด๋ถ€ ํ†ต์‹ ์— ๋Œ€ํ•ด์„œ๋Š” https ํ†ต์‹ ์„ ๋ณด์žฅํ•ด์ฃผ์ง„ ์•Š์ฃ . ์ด ๋ถ€๋ถ„์— ๋Œ€ํ•ด์„œ๋Š” Istio ์˜ mTLS ๋ฅผ ์ด์šฉํ•ด์„œ ํŒŒ๋“œ์™€์˜ ํ†ต์‹ ์€ ๋ชจ๋‘ https ํ†ต์‹ ์„ ํ•˜๊ฒŒ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Istio ์˜ mTLS ๊ฐ€ ๊ถ๊ธˆํ•˜๋‹ค๋ฉด? [Istio] ์‰ฟ! ์šฐ๋ฆฌ๋งŒ์˜ ๋น„๋ฐ€์ด์•ผ - mTLS (ํ™•์ธํŽธ) [Istio] ์‰ฟ! ์šฐ๋ฆฌ๋งŒ์˜ ๋น„๋ฐ€์ด์•ผ - mTLS (๊ฒ€์ฆํŽธ) ๊ทธ๋ ‡๋‹ค๋ฉด mTLS ๋ฅผ ์ด์šฉํ•˜์ง€ ์•Š๊ณ  ๋‚ด๋ถ€ ํ†ต์‹ ์€ ์–ด๋–ป๊ฒŒ https ํ†ต์‹ ์„ ํ•  ์ˆ˜ ์žˆ์„๊นŒ์š”? ์ •๋‹ต์€ ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค. ํŒŒ๋“œ ๋งˆ๋‹ค certifica..

article thumbnail
[Cert manager] Let's Encrypt ๋ฅผ ์ด์šฉํ•ด์„œ Istio Gateway ์— TLS ์„ ์ ์šฉํ•ด๋ณด์ž! - Route53
DevOps/Cert Manager 2023. 9. 13. 23:52

์ง€๋‚œ ๊ธ€์—์„œ Cloudflare ์—์„œ ์ƒ์„ฑํ•œ ๋„๋ฉ”์ธ๊ณผ Let's Encrypt ๋ฅผ ์ด์šฉํ•ด์„œ TLS ๋ฅผ httpbin ์— ์ ์šฉํ–ˆ์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ์—๋Š” Cloudflare ๋ณด๋‹ค ๋” ๋Œ€์ค‘์ ์ธ Route53 ์—์„œ ์ƒ์„ฑํ•œ ๋„๋ฉ”์ธ์—๋„ TLS ๋ฅผ ์ ์šฉํ•ด๋ณด๊ณ ์ž ํ•ฉ๋‹ˆ๋‹ค. Route53 ์—์„œ ๊ตฌ๋งคํ•œ ๋„๋ฉ”์ธ์— ๋Œ€ํ•ด์„œ๋Š” AWS ACM ์„ ์ด์šฉํ•ด์„œ ๋ฌด๋ฃŒ๋กœ TLS ๋ฅผ ๋ฐœ๊ธ‰๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๋ฐœ๊ธ‰๋ฐ›์€ TLS ๋ฅผ AWS ALB ์— ๋ฐ”๋กœ ์ ์šฉํ•˜๊ฒŒ ๋˜๋ฉด ์•„์ฃผ ์‰ฝ๊ฒŒ TLS ํ†ต์‹ ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ž˜์„œ ALB ์™€ Istio ๋ฅผ ์ด์šฉํ•˜๊ฒŒ ๋˜๋ฉด ๋Œ€๋žต ์•„๋ž˜ ๊ทธ๋ฆผ๊ณผ ๊ฐ™์ฃ . ํ•˜์ง€๋งŒ ์™ธ๋ถ€๋งŒ TLS ๋ฅผ ํ†ต์‹ ์ด ๊ฐ€๋Šฅํ•˜๋ฏ€๋กœ ๋‚ด๋ถ€์—์„  TLS ํ†ต์‹ ์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ACM ์„ ํ†ตํ•ด ๋„๋ฉ”์ธ์— ๋Œ€ํ•œ Cert ๋ฅผ ๋ฐœ๊ธ‰๋ฐ›์„ ์ˆ˜ ์žˆ๋Š”๋ฐ, ์ด ๊ฐ’์€ ๋‹ค์šด๋ฐ›์•„์„œ ์‚ฌ์šฉ๋ถˆ๊ฐ€๋Šฅ..

article thumbnail
[Cert manager] Let's Encrypt ๋ฅผ ์ด์šฉํ•ด์„œ Istio Gateway ์— TLS ์„ ์ ์šฉํ•ด๋ณด์ž! - Cloudflare
DevOps/Cert Manager 2023. 9. 7. 21:48

์ด ๊ธ€์€ TLS ์— ๋Œ€ํ•œ ๊ธฐ์ดˆ์ ์ธ ๊ฐœ๋…์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์ตœ์†Œํ•œ HTTPS ๊ฐ€ ์–ด๋–ป๊ฒŒ ๋™์ž‘ํ•˜๋ฉฐ, CA, CSR, tls.cert ๋“ฑ๊ณผ ๊ฐ™์€ ๊ฒƒ์ด ๋ฌด์—‡์ธ์ง€ ์•Œ์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋ฏธ๋‹ˆ PC ์—์„œ ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ํด๋Ÿฌ์Šคํ„ฐ๋ฅผ ๊ตฌ์„ฑํ•˜์—ฌ ์ด๊ฒƒ์ €๊ฒƒ ํ•ด๋ณด๊ณ  ์žˆ๋Š”๋ฐ, ๋Š˜ ํ•˜๋‚˜ ๋งˆ์Œ์— ๊ฑธ๋ฆฌ๋Š” ๊ฒƒ์ด ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฐ”๋กœ ๋„๋ฉ”์ธ๊ณผ TLS ์ž…๋‹ˆ๋‹ค! ๋„๋ฉ”์ธ ๊ฐ™์€ ๊ฒฝ์šฐ ๋งฅ /etc/host ์— ์ถ”๊ฐ€ํ•ด์„œ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์—ˆ๊ณ , TLS ๊ฐ€ ์ ์šฉ๋˜์ง€ ์•Š๋‹ค๋ณด๋‹ˆ ๋Š˜ ์ฃผ์˜ ์š”ํ•จ์„ ๋‹ฌ๊ณ  ์žˆ์—ˆ์ฃ . AWS ALB ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด Route53 ๊ณผ ACM ์„ ํ†ตํ•ด์„œ TLS ์ ์šฉํ•˜๊ธฐ ์‰ฝ์ง€๋งŒ, AWS ์—†์ด TLS ๋ฅผ ์ ์šฉํ•˜๋ ค๋ฉด ๊ฒฐ๊ตญ TLS ๋ฅผ ๊ตฌ๋งคํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. TLS ๋Š” ๋ณดํ†ต ์œ ๋ฃŒ์ธ๋ฐ, Let's Ecrypt ๋Š” ๋ฌด๋ฃŒ๋กœ TLS ์„ ์ œ๊ณตํ•ด์ฃผ๊ธฐ ๋•Œ๋ฌธ์— ์ด๋ฒˆ ๊ธ€์—์„œ๋Š” ๋กœ์ปฌ ํ™˜๊ฒฝ์—์„œ ..

profile on loading

Loading...