当前位置:网站首页>[azure microservice service fabric] the service fabric cluster hangs up because the certificate expires (the upgrade cannot be completed, and the node is unavailable)
[azure microservice service fabric] the service fabric cluster hangs up because the certificate expires (the upgrade cannot be completed, and the node is unavailable)
2022-07-07 22:06:00 【51CTO】
Problem description
establish Service Fabric when , Certificates are a very important part of the whole cluster , With user authentication , Communication between nodes ,SF Upgrade the identity and authorization authentication and other functions . If the certificate is expired, the nodes will be affected and the cluster will not work properly .
When the certificate expires or is revoked , The usual problems are :
- Service Fabric The cluster cannot use the upgrade service
- Service Fabric Explorer Unable to connect
- Disable all nodes , Unable to view any node information
When the above situation occurs , The quickest way is to build a brand new Service Fabric colony , This is also the most efficient way . To prevent certificate expiration, send , Here are two suggestions :
One : stay Key Vault When creating a certificate in , Choose to automatically renew the new version certificate .

Two : And if you don't automatically renew the new version certificate , Then you need to specify a maintenance plan , Update the certificate before it expires . and Service Fabric The process of replacing the security certificate , First of all, you need to put Upload the new certificate to key vault in , And then through powershell Or add auxiliary certificates for the cluster in the form of templates , And then in Portal Operation switching certificate .
Please refer to :( At present Service Fabric Export templates from the resource group of , Yes certificateSecondary The nodes are modified )
When the auxiliary certificate is added , You can see two certificates in the portal , Click... In the red box ... In exchange for the main / Supporting certificate .

Use Powershell Command to load secondary certificates (Secondary Certificate):
Execute command reference :

perform Add-AzServiceFabricClusterCertificate The progress of the prompt after the command is as follows :

Reference link :
####
Add-AzServiceFabricClusterCertificate: Add a secondary cluster certificate to the cluster, https://docs.microsoft.com/en-us/powershell/module/az.servicefabric/add-azservicefabricclustercertificate?view=azps-5.2.0
####
az sf cluster certificate add: Add a secondary cluster certificate to the cluster. https://docs.microsoft.com/en-us/cli/azure/sf/cluster/certificate?view=azure-cli-latest#az_sf_cluster_certificate_add
####
management SF The documentation of the cluster certificate can be referred to : https://docs.azure.cn/zh-cn/service-fabric/service-fabric-cluster-security-update-certs-azure
When facing problems in a complex environment , The way to check things needs : The turbid and quiet Xu Qing , An Yidong's Xu Sheng . In the clouds , Just so !
边栏推荐
- 三元表达式、各生成式、匿名函数
- An overview of the latest research progress of "efficient deep segmentation of labels" at Shanghai Jiaotong University, which comprehensively expounds the deep segmentation methods of unsupervised, ro
- Oracle advanced (VI) Oracle expdp/impdp details
- Restapi version control strategy [eolink translation]
- Ad domain group policy management
- SQL injection error report injection function graphic explanation
- 【Azure微服务 Service Fabric 】因证书过期导致Service Fabric集群挂掉(升级无法完成,节点不可用)
- The latest Android interview collection, Android video extraction audio
- L'enregistreur de disque dur NVR est connecté à easycvr par le Protocole GB 28181. Quelle est la raison pour laquelle l'information sur le canal de l'appareil n'est pas affichée?
- Talk about relational database and serverless
猜你喜欢

Automatic classification of defective photovoltaic module cells in electronic images
![Jerry's about TWS pairing mode configuration [chapter]](/img/fd/dd1e252617d30dd7147dbab25de5b4.png)
Jerry's about TWS pairing mode configuration [chapter]

使用 BlocConsumer 同时构建响应式组件和监听状态

Where is the big data open source project, one-stop fully automated full life cycle operation and maintenance steward Chengying (background)?

三元表达式、各生成式、匿名函数

Have you ever been confused? Once a test / development programmer, ignorant gadget C bird upgrade

100million single men and women "online dating", supporting 13billion IPOs
![[C language] advanced pointer --- do you really understand pointer?](/img/ee/79c0646d4f1bfda9543345b9da0f25.png)
[C language] advanced pointer --- do you really understand pointer?

It's worth seeing. Interview sites and interview skills

Two kinds of updates lost and Solutions
随机推荐
Virtual machine network configuration in VMWare
Demon daddy C
谈谈制造企业如何制定敏捷的数字化转型策略
强化学习-学习笔记9 | Multi-Step-TD-Target
Navicat connect 2002 - can't connect to local MySQL server through socket '/var/lib/mysql/mysql Sock 'solve
[开源] .Net ORM 访问 Firebird 数据库
Arlo's troubles
Devil daddy B1 hearing the last barrier, break through with all his strength
用语雀写文章了,功能真心强大!
L'enregistreur de disque dur NVR est connecté à easycvr par le Protocole GB 28181. Quelle est la raison pour laquelle l'information sur le canal de l'appareil n'est pas affichée?
Jerry's power on automatic pairing [chapter]
DBSync新增对MongoDB、ES的支持
2022 how to evaluate and select low code development platforms?
The new version of onespin 360 DV has been released, refreshing the experience of FPGA formal verification function
MIT6.S081-Lab9 FS [2021Fall]
QT compile IOT management platform 39 alarm linkage
An in-depth understanding of fp/fn/precision/recall
Wechat official account oauth2.0 authorizes login and displays user information
Matplotlib drawing interface settings
JNI primary contact