当前位置:网站首页>[azure microservice service fabric] the service fabric cluster hangs up because the certificate expires (the upgrade cannot be completed, and the node is unavailable)
[azure microservice service fabric] the service fabric cluster hangs up because the certificate expires (the upgrade cannot be completed, and the node is unavailable)
2022-07-07 22:06:00 【51CTO】
Problem description
establish Service Fabric when , Certificates are a very important part of the whole cluster , With user authentication , Communication between nodes ,SF Upgrade the identity and authorization authentication and other functions . If the certificate is expired, the nodes will be affected and the cluster will not work properly .
When the certificate expires or is revoked , The usual problems are :
- Service Fabric The cluster cannot use the upgrade service
- Service Fabric Explorer Unable to connect
- Disable all nodes , Unable to view any node information
When the above situation occurs , The quickest way is to build a brand new Service Fabric colony , This is also the most efficient way . To prevent certificate expiration, send , Here are two suggestions :
One : stay Key Vault When creating a certificate in , Choose to automatically renew the new version certificate .
Two : And if you don't automatically renew the new version certificate , Then you need to specify a maintenance plan , Update the certificate before it expires . and Service Fabric The process of replacing the security certificate , First of all, you need to put Upload the new certificate to key vault in , And then through powershell Or add auxiliary certificates for the cluster in the form of templates , And then in Portal Operation switching certificate .
Please refer to :( At present Service Fabric Export templates from the resource group of , Yes certificateSecondary The nodes are modified )
When the auxiliary certificate is added , You can see two certificates in the portal , Click... In the red box ... In exchange for the main / Supporting certificate .
Use Powershell Command to load secondary certificates (Secondary Certificate):
Execute command reference :
perform Add-AzServiceFabricClusterCertificate The progress of the prompt after the command is as follows :
Reference link :
####
Add-AzServiceFabricClusterCertificate: Add a secondary cluster certificate to the cluster, https://docs.microsoft.com/en-us/powershell/module/az.servicefabric/add-azservicefabricclustercertificate?view=azps-5.2.0
####
az sf cluster certificate add: Add a secondary cluster certificate to the cluster. https://docs.microsoft.com/en-us/cli/azure/sf/cluster/certificate?view=azure-cli-latest#az_sf_cluster_certificate_add
####
management SF The documentation of the cluster certificate can be referred to : https://docs.azure.cn/zh-cn/service-fabric/service-fabric-cluster-security-update-certs-azure
When facing problems in a complex environment , The way to check things needs : The turbid and quiet Xu Qing , An Yidong's Xu Sheng . In the clouds , Just so !
边栏推荐
- Use camunda to do workflow design and reject operations
- ISO 26262 - considerations other than requirements based testing
- [开源] .Net ORM 访问 Firebird 数据库
- Demon daddy guide post - simple version
- [advanced MySQL] index details (I): index data page structure
- NVR硬盘录像机通过国标GB28181协议接入EasyCVR,设备通道信息不显示是什么原因?
- The latest Android interview collection, Android video extraction audio
- 2022 how to evaluate and select low code development platforms?
- Win11时间怎么显示星期几?Win11怎么显示今天周几?
- An in-depth understanding of fp/fn/precision/recall
猜你喜欢
Goal: do not exclude yaml syntax. Try to get started quickly
Ten thousand word summary data storage, three knowledge points
The function is really powerful!
Talk about relational database and serverless
大数据开源项目,一站式全自动化全生命周期运维管家ChengYing(承影)走向何方?
The latest Android interview collection, Android video extraction audio
NVR硬盘录像机通过国标GB28181协议接入EasyCVR,设备通道信息不显示是什么原因?
Automatic classification of defective photovoltaic module cells in electronic images
Jenkins user rights management
NVR hard disk video recorder is connected to easycvr through the national standard gb28181 protocol. What is the reason why the device channel information is not displayed?
随机推荐
Dry goods sharing | devaxpress v22.1 original help document download collection
【JDBC Part 1】概述、获取连接、CRUD
Win11游戏模式怎么开启?Win11开启游戏模式的方法
Tcp/ip protocol stack
The whole network "chases" Zhong Xuegao
Redis - basic use (key, string, list, set, Zset, hash, geo, bitmap, hyperloglog, transaction)
Jerry's about TWS pairing mode configuration [chapter]
Jerry's key to initiate pairing [chapter]
Why can't win11 display seconds? How to solve the problem that win11 time does not display seconds?
Oracle advanced (VI) Oracle expdp/impdp details
Nine degree 1201 - traversal of binary sort number - binary sort tree "suggestions collection"
[开源] .Net ORM 访问 Firebird 数据库
Can I open a stock account directly online now? Is it safe?
PKPM 2020软件安装包下载及安装教程
SAR image quality evaluation
operator
Virtual machine network configuration in VMWare
Actual combat: sqlserver 2008 Extended event XML is converted to standard table format [easy to understand]
How much does it cost to develop a small program mall?
反爬通杀神器