当前位置:网站首页>[azure microservice service fabric] the service fabric cluster hangs up because the certificate expires (the upgrade cannot be completed, and the node is unavailable)
[azure microservice service fabric] the service fabric cluster hangs up because the certificate expires (the upgrade cannot be completed, and the node is unavailable)
2022-07-07 22:06:00 【51CTO】
Problem description
establish Service Fabric when , Certificates are a very important part of the whole cluster , With user authentication , Communication between nodes ,SF Upgrade the identity and authorization authentication and other functions . If the certificate is expired, the nodes will be affected and the cluster will not work properly .
When the certificate expires or is revoked , The usual problems are :
- Service Fabric The cluster cannot use the upgrade service
- Service Fabric Explorer Unable to connect
- Disable all nodes , Unable to view any node information
When the above situation occurs , The quickest way is to build a brand new Service Fabric colony , This is also the most efficient way . To prevent certificate expiration, send , Here are two suggestions :
One : stay Key Vault When creating a certificate in , Choose to automatically renew the new version certificate .

Two : And if you don't automatically renew the new version certificate , Then you need to specify a maintenance plan , Update the certificate before it expires . and Service Fabric The process of replacing the security certificate , First of all, you need to put Upload the new certificate to key vault in , And then through powershell Or add auxiliary certificates for the cluster in the form of templates , And then in Portal Operation switching certificate .
Please refer to :( At present Service Fabric Export templates from the resource group of , Yes certificateSecondary The nodes are modified )
When the auxiliary certificate is added , You can see two certificates in the portal , Click... In the red box ... In exchange for the main / Supporting certificate .

Use Powershell Command to load secondary certificates (Secondary Certificate):
Execute command reference :

perform Add-AzServiceFabricClusterCertificate The progress of the prompt after the command is as follows :

Reference link :
####
Add-AzServiceFabricClusterCertificate: Add a secondary cluster certificate to the cluster, https://docs.microsoft.com/en-us/powershell/module/az.servicefabric/add-azservicefabricclustercertificate?view=azps-5.2.0
####
az sf cluster certificate add: Add a secondary cluster certificate to the cluster. https://docs.microsoft.com/en-us/cli/azure/sf/cluster/certificate?view=azure-cli-latest#az_sf_cluster_certificate_add
####
management SF The documentation of the cluster certificate can be referred to : https://docs.azure.cn/zh-cn/service-fabric/service-fabric-cluster-security-update-certs-azure
When facing problems in a complex environment , The way to check things needs : The turbid and quiet Xu Qing , An Yidong's Xu Sheng . In the clouds , Just so !
边栏推荐
- DBSync新增对MongoDB、ES的支持
- Use blocconsumer to build responsive components and monitor status at the same time
- The cyberspace office announced the measures for data exit security assessment, which will come into force on September 1
- Use camunda to do workflow design and reject operations
- Win11时间怎么显示星期几?Win11怎么显示今天周几?
- Where is the big data open source project, one-stop fully automated full life cycle operation and maintenance steward Chengying (background)?
- Time standard library
- Latest Android advanced interview questions summary, Android interview questions and answers
- Actual combat: sqlserver 2008 Extended event XML is converted to standard table format [easy to understand]
- Oracle advanced (VI) Oracle expdp/impdp details
猜你喜欢

Kirin Xin'an operating system derivative solution | storage multipath management system, effectively improving the reliability of data transmission

The strongest installation of the twin tower model, Google is playing "antique" again?

Win11如何解禁键盘?Win11解禁键盘的方法
Preparing for the interview and sharing experience

Google SEO external chain backlinks research tool recommendation

How to turn on win11 game mode? How to turn on game mode in win11

Use camunda to do workflow design and reject operations

Jenkins user rights management

解决uni-app中uni.request发送POST请求没有反应。

大数据开源项目,一站式全自动化全生命周期运维管家ChengYing(承影)走向何方?
随机推荐
What if the win11u disk does not display? Solution to failure of win11 plug-in USB flash disk
为什么Win11不能显示秒数?Win11时间不显示秒怎么解决?
Display optimization when the resolution of easycvr configuration center video recording plan page is adjusted
使用 CustomPaint 绘制基本图形
Relationship between URL and URI
Use br to recover backup data on azure blob storage
[开源] .Net ORM 访问 Firebird 数据库
It's worth seeing. Interview sites and interview skills
Demon daddy C
Reinforcement learning - learning notes 9 | multi step TD target
Demon daddy B3 read extensively in a small amount, and completed 20000 vocabulary+
大数据开源项目,一站式全自动化全生命周期运维管家ChengYing(承影)走向何方?
Google SEO external chain backlinks research tool recommendation
Usage of MySQL subquery keywords (exists)
Win11如何解禁键盘?Win11解禁键盘的方法
三元表达式、各生成式、匿名函数
SAR image quality evaluation
Ten thousand word summary data storage, three knowledge points
Use br to back up tidb cluster data to azure blob storage
The function is really powerful!