컨트롤 플레인 TLS 자격증명 수동 순환
컨트롤 플레인 TLS 자격증명 수동 순환 (Manually Rotating Control Plane TLS Credentials)
Linkerd의 신뢰 앵커(trust anchor)와 발급자 인증서·키 쌍을 다운타임 없이 수동으로 순환하는 방법을 단계별로 알려드려요.
본문
Linkerd의 자동 mTLS 기능은 프록시용 TLS 인증서를 생성하기 위해 일련의 TLS 자격증명, 즉 신뢰 앵커와 발급자 인증서·개인 키를 사용합니다. 신뢰 앵커는 제한된 유효 기간을 가집니다. linkerd install이 생성했다면 365일, 수동으로 생성했다면 사용자 지정 값이에요.
따라서 이 수명보다 오래 지속될 것으로 예상되는 클러스터에서는 신뢰 앵커를 수동으로 순환해야 합니다. 이 문서에서는 다운타임 없이 이를 수행하는 방법을 설명해요.
신뢰 앵커와 별개로 발급자 인증서·키 쌍도 만료될 수 있습니다(cert-manager를 사용해 자동 순환을 설정할 수도 있어요). 이 문서는 발급자 인증서·키 쌍을 다운타임 없이 순환하는 방법도 다룹니다.
사전 준비
이 지침은 다음 CLI 도구를 사용합니다.
- step: 인증서와 키를 조작하는 도구
시스템의 현재 상태 이해하기
먼저 다음을 실행하세요:
`linkerd check --proxy
`
구성이 유효하고 자격증명이 곧 만료되지 않는다면 다음과 유사한 출력이 보여야 합니다:
`linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
√ issuer cert is valid for at least 60 days
√ issuer cert is issued by the trust root
linkerd-identity-data-plane
---------------------------
√ data plane proxies certificate match CA
`
하지만 신뢰 앵커("trust root")나 발급자 인증서가 곧 만료될 것이라는 경고 메시지가 보인다면 순환해야 합니다.
이 문서는 신뢰 앵커가 현재 유효할 때만 적용됩니다. 신뢰 앵커가 만료되었다면 대신 만료된 인증서 교체 가이드를 따르세요. (발급자 인증서가 만료되었지만 신뢰 앵커가 여전히 유효하다면 이 문서를 계속 진행하면 됩니다.)
예를 들어 발급자 인증서가 만료되었다면 다음과 유사한 메시지가 보일 거예요:
`linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
× issuer cert is within its validity period
issuer certificate is not valid anymore. Expired on 2019-12-19T09:02:01Z
see https://linkerd.io/2/checks/#l5d-identity-issuer-cert-is-time-valid for hints
`
신뢰 앵커가 만료되었다면 다음과 유사한 메시지가 보일 거예요:
`linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
× trust roots are within their validity period
Invalid roots:
* 79461543992952791393769540277800684467 identity.linkerd.cluster.local not valid anymore. Expired on 2019-12-19T09:11:30Z
see https://linkerd.io/2/checks/#l5d-identity-roots-are-time-valid for hints
`
신뢰 앵커 순환하기
신뢰 앵커를 다운타임 없이 순환하는 것은 여러 단계의 과정입니다. 새 신뢰 앵커를 생성하고, 그것을 이전 것과 번들로 묶고, 발급자 인증서·키 쌍을 순환하고, 마지막으로 번들에서 이전 신뢰 앵커를 제거해야 합니다. 발급자 인증서·키 쌍만 순환하면 된다면 아이덴티티 발급자 인증서 순환하기로 바로 건너뛰고 신뢰 앵커 순환 단계는 무시해도 됩니다.
클러스터에서 현재 신뢰 앵커 인증서 읽기
다운타임을 피하려면 기존 신뢰 앵커 인증서를 새로 생성한 신뢰 앵커 인증서와 함께 인증서 번들로 묶어야 합니다. 번들을 사용하면 어느 신뢰 앵커로든 서명된 워크로드가 메시에서 제대로 동작할 수 있습니다. 인증서는 민감한 정보가 아니므로 클러스터에서 기존 신뢰 앵커 인증서를 그냥 가져올 수 있어요.
다음 명령은 kubectl을 사용해 linkerd-identity-trust-roots ConfigMap에서 Linkerd 구성을 가져와 original-trust.crt에 저장합니다:
`kubectl -n linkerd get cm linkerd-identity-trust-roots -o=jsonpath='{.data.ca-bundle\.crt}' > original-trust.crt
`
새 신뢰 앵커 생성하기
현재 신뢰 앵커 인증서를 저장한 뒤 새 신뢰 앵커 인증서와 개인 키를 생성하세요:
`step certificate create root.linkerd.cluster.local ca-new.crt ca-new.key --profile root-ca --no-password --insecure
`
여기서 --no-password --insecure를 사용해 이 파일들을 패스프레이즈로 암호화하지 않는다는 점을 알아두세요. 개인 키는 나중에 새 발급자 인증서를 생성할 때 사용할 수 있도록 안전한 곳에 보관하세요.
원래 신뢰 앵커를 새 것과 번들로 묶기
다음으로, Linkerd가 현재 사용하는 신뢰 앵커를 새 앵커와 함께 번들로 묶어야 합니다. step으로 두 인증서를 하나의 번들로 결합합니다:
`step certificate bundle ca-new.crt original-trust.crt bundle.crt
`
원하면 rm original-trust.crt도 할 수 있어요.
새 번들을 Linkerd에 배포하기
이 시점에서 linkerd upgrade 명령으로 Linkerd가 새 신뢰 번들로 동작하도록 지시할 수 있습니다:
`linkerd upgrade --identity-trust-anchors-file=./bundle.crt | kubectl apply -f -
`
또는 helm upgrade 명령을 사용할 수도 있습니다:
`helm upgrade linkerd-control-plane --set-file identityTrustAnchorsPEM=./bundle.crt
`
이 작업이 끝나면 meshed 워크로드를 재시작해 새 신뢰 앵커를 사용하도록 해야 합니다. 예를 들어 emojivoto 네임스페이스에 그렇게 하려면:
`kubectl -n emojivoto rollout restart deploy
`
이제 check 명령을 실행해 모든 것이 정상인지 확인할 수 있습니다:
`linkerd check --proxy
`
모든 pod가 재시작되고 올바른 신뢰 앵커로 구성될 때까지 잠시 기다려야 할 수 있습니다. 그동안 경고가 보일 수도 있어요:
`linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
‼ issuer cert is valid for at least 60 days
issuer certificate will expire on 2019-12-19T09:51:19Z
see https://linkerd.io/2/checks/#l5d-identity-issuer-cert-not-expiring-soon for hints
√ issuer cert is issued by the trust root
linkerd-identity-data-plane
---------------------------
‼ data plane proxies certificate match CA
Some pods do not have the current trust bundle and must be restarted:
* emojivoto/emoji-d8d7d9c6b-8qwfx
* emojivoto/vote-bot-588499c9f6-zpwz6
* emojivoto/voting-8599548fdc-6v64k
* emojivoto/web-67c7599f6d-xx98n
* linkerd/linkerd-sp-validator-75f9d96dc-rch4x
* linkerd/linkerd-tap-68d8bbf64-mpzgb
* linkerd/linkerd-web-849f74b7c6-qlhwc
see https://linkerd.io/2/checks/#l5d-identity-data-plane-proxies-certs-match-ca for hints
`
롤아웃이 완료되면 check 명령이 pod를 재시작해야 한다는 경고를 더 이상 내지 않아야 합니다. 하지만 발급자 인증서가 곧 만료된다는 경고는 여전히 낼 수 있어요:
`linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
‼ issuer cert is valid for at least 60 days
issuer certificate will expire on 2019-12-19T09:51:19Z
see https://linkerd.io/2/checks/#l5d-identity-issuer-cert-not-expiring-soon for hints
√ issuer cert is issued by the trust root
linkerd-identity-data-plane
---------------------------
√ data plane proxies certificate match CA
`
이 시점에서 모든 meshed 워크로드는 이전 또는 새 신뢰 앵커로 서명된 연결을 수용할 준비가 되었지만, 여전히 모두 이전 신뢰 앵커로 서명된 인증서를 사용하고 있어요. 그것을 바꾸려면 발급자 인증서를 순환해야 합니다.
아이덴티티 발급자 인증서 순환하기
발급자 인증서·키 쌍을 순환하려면 먼저 새 아이덴티티 발급자 인증서와 키를 생성하세요:
`step certificate create identity.linkerd.cluster.local issuer-new.crt issuer-new.key \
--profile intermediate-ca --not-after 8760h --no-password --insecure \
--ca ca-new.crt --ca-key ca-new.key
`
이 새 발급자 인증서는 새 신뢰 앵커로 서명됩니다. 그래서 새 신뢰 앵커 번들을 설치하는 것이 중요했던 거예요(이전 섹션에서 설명한 대로). 새 번들이 설치되고 linkerd check가 모든 체크가 초록색이고 경고가 없다고 보여주면, upgrade 명령을 다시 사용해 아이덴티티 발급자 인증서·키를 안전하게 순환할 수 있어요:
`linkerd upgrade \
--identity-issuer-certificate-file=./issuer-new.crt \
--identity-issuer-key-file=./issuer-new.key \
| kubectl apply -f -
`
또는
`helm upgrade linkerd-control-plane \
--set-file identity.issuer.tls.crtPEM=./issuer-new.crt \
--set-file identity.issuer.tls.keyPEM=./issuer-new.key
`
이 시점에서 IssuerUpdated Kubernetes 이벤트를 확인해 Linkerd가 새 발급자 인증서를 봤는지 확신할 수 있습니다:
`kubectl get events --field-selector reason=IssuerUpdated -n linkerd
LAST SEEN TYPE REASON OBJECT MESSAGE
9s Normal IssuerUpdated deployment/linkerd-identity Updated identity issuer
`
클러스터의 모든 주입된 워크로드에 대해 프록시를 재시작해 새 발급자가 발급한 인증서를 사용하도록 하세요:
`kubectl -n emojivoto rollout restart deploy
`
check 명령을 실행해 모든 것이 예상대로 진행되는지 확인하세요:
`linkerd check --proxy
`
인증서 만료 경고 없이 출력이 보여야 합니다(만료된 신뢰 앵커를 아직 제거해야 하는 경우는 제외하고요):
`linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
√ issuer cert is valid for at least 60 days
√ issuer cert is issued by the trust root
linkerd-identity-data-plane
---------------------------
√ data plane proxies certificate match CA
`
이전 신뢰 앵커 제거하기
이제 이전 신뢰 앵커가 완전히 사용되지 않으므로, 신뢰 앵커용으로 만든 번들에서 Linkerd를 새 신뢰 앵커 인증서만 사용하도록 전환할 수 있어요:
`linkerd upgrade --identity-trust-anchors-file=./ca-new.crt | kubectl apply -f -
`
또는
`helm upgrade linkerd2 --set-file --set-file identityTrustAnchorsPEM=./ca-new.crt
`
./ca-new.crt 파일은 이 과정의 시작 부분에서 만든 것과 같은 신뢰 앵커라는 점을 알아두세요.
다시 한 번 meshed 워크로드를 명시적으로 재시작하세요:
`kubectl -n emojivoto rollout restart deploy
linkerd check --proxy
`
그리고 다시, check 명령의 출력은 경고나 오류를 만들지 않아야 합니다:
`linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
√ issuer cert is valid for at least 60 days
√ issuer cert is issued by the trust root
linkerd-identity-data-plane
---------------------------
√ data plane proxies certificate match CA
`
축하합니다, 신뢰 앵커를 순환했습니다! 🎉
더 알아보기 (Learn more)
- 만료된 인증서 교체 가이드
- 컨트롤 플레인 TLS 자격증명 자동 순환