직접 만드는 mTLS 루트 인증서
직접 만드는 mTLS 루트 인증서 (Generating your own mTLS root certificates)
메시가 적용된 pod 사이의 mTLS 연결을 지원하려면 Linkerd에 트러스트 앵커 인증서와 그에 대응하는 키가 있는 발급자(issuer) 인증서가 필요해요. 직접 생성하는 방법을 알아봐요.
본문
메시가 적용된 pod 사이의 mTLS 연결을 지원하려면 Linkerd는 트러스트 앵커(trust anchor) 인증서와, 그에 대응하는 키가 있는 발급자(issuer) 인증서가 필요해요.
linkerd install로 설치할 때는 이 인증서들이 자동으로 생성돼요. 또는 --identity-* 플래그를 사용해 직접 지정할 수도 있어요 (자세한 내용은 linkerd install 참조 문서를 확인하세요).
반면 Helm으로 Linkerd를 설치할 때는 인증서를 자동 생성할 수 없으므로 직접 제공해야 해요.
openssl이나 step 같은 도구로 이 인증서들을 생성할 수 있어요. 모든 인증서는 step의 기본값인 ECDSA P-256 알고리즘을 사용해야 해요. openssl로 ECDSA P-256 인증서를 생성하려면 openssl ecparam -name prime256v1 명령어를 사용하면 돼요. 이 튜토리얼에서는 step CLI로 생성하는 방법을 안내해요.
Linkerd 프로덕션 팁
이 페이지는 오픈소스 커뮤니티의 최선(best-effort) 노력으로 작성된 내용이에요. 미션 크리티컬 애플리케이션을 운영하는 프로덕션 사용자는 Linkerd 프로덕션 리소스를 숙지하고, 상용 Linkerd 제공업체와 연결하는 것을 권장해요.
step으로 인증서 생성하기
트러스트 앵커 인증서 (Trust anchor certificate)
먼저 개인 키와 함께 루트 인증서를 생성해요 (step 0.10.1 버전 사용):
step certificate create root.linkerd.cluster.local ca.crt ca.key \
--profile root-ca --no-password --insecure
이 명령은 ca.crt와 ca.key 파일을 생성해요. ca.crt 파일은 CLI로 Linkerd를 설치할 때 --identity-trust-anchors-file 옵션에 전달하고, Helm으로 linkerd-control-plane 차트를 설치할 때는 identityTrustAnchorsPEM 값에 전달해야 해요.
--no-password --insecure를 사용하는 이유는 이 파일들을 passphrase로 암호화하지 않기 위해서예요.
더 오래 유효한 트러스트 앵커 인증서가 필요하다면 step 명령에 --not-after 인자를 원하는 값과 함께 전달하세요 (예: --not-after=87600h).
발급자 인증서와 키 (Issuer certificate and key)
다음으로 Linkerd 프록시의 CSR을 서명하는 데 사용할 중간(intermediate) 인증서와 키 쌍을 생성해요.
step certificate create identity.linkerd.cluster.local issuer.crt issuer.key \
--profile intermediate-ca --not-after 8760h --no-password --insecure \
--ca ca.crt --ca-key ca.key
이 명령은 issuer.crt와 issuer.key 파일을 생성해요.
인증서를 Linkerd에 전달하기
마지막으로 CLI로 Linkerd를 설치할 때 이 파일들을 제공하면 돼요.
# first, install the Linkerd CRDs
linkerd install --crds | kubectl apply -f -
# install the Linkerd control plane, with the certificates we just generated.
linkerd install \
--identity-trust-anchors-file ca.crt \
--identity-issuer-certificate-file issuer.crt \
--identity-issuer-key-file issuer.key \
| kubectl apply -f -
또는 Helm으로 설치할 때는 먼저 linkerd-crds 차트를 설치해요.
helm install linkerd-crds linkerd/linkerd-crds -n linkerd --create-namespace
그런 다음 linkerd-control-plane 차트를 설치해요.
helm install linkerd-control-plane -n linkerd \
--set-file identityTrustAnchorsPEM=ca.crt \
--set-file identity.issuer.tls.crtPEM=issuer.crt \
--set-file identity.issuer.tls.keyPEM=issuer.key \
linkerd/linkerd-control-plane