Describe the bug
Mailu frontend pod uses a cert-manager-issued external TLS certificate (DNS name only: mail.example.com) without IP Subject Alternative Names (SANs). When Traefik ingress controller connects to the Mailu backend pod via internal pod IP (10.42.4.31), the x509 certificate validation fails because the certificate lacks the required IP SANs for pod-to-pod HTTPS validation.
To Reproduce
Steps to reproduce the behavior:
- Set up cert-manager with a Let's Encrypt issuer
- Deploy Mailu with ingress class
traefik and cert-manager issuer annotations
- Access Mailu via domain (
mail.example.com)
- Check Traefik logs:
kubectl logs -n kube-system -l app.kubernetes.io/name=traefik -f
- Observe error: cannot validate certificate for 10.42.4.31 because it doesn't contain any IP SANs
Expected behavior
Traefik should successfully validate the Mailu backend certificate when connecting internally via pod IP, or certificate validation should be properly configured to handle DNS-only certificates in pod-to-pod HTTPS connections.
Environment
- Helm Chart Version: Mailu 2025.1+
- Helm Version: v3.13.0+
- Kubernetes Version: k3s 1.26+
- Kubernetes Platform: k3s (3-node cluster)
- Mailu Version: 2025.1
- Traefik Version: 2.10+
Values.yaml Configuration
hostnames:
- mail.example.com
ingress:
enabled: true
ingressClassName: "traefik"
tls: true
selfSigned: false
annotations:
cert-manager.io/cluster-issuer: "lets-encrypt"
Root Cause:
- Mailu frontend certificate issued by cert-manager + Let's Encrypt contains DNS SANs only (mail.example.com)
- Traefik strict TLS validation expects IP SANs when connecting to backend via pod IP address (10.42.4.31)
- Mismatch causes x509 validation failure
Evidence
front deployment required this certificate
volumes:
- name: certs
secret:
items:
- key: tls.crt
path: cert.pem
- key: tls.key
path: key.pem
secretName: {{ include "mailu.certificatesSecretName" . }}
that same with that front ingress
{{- if .Values.ingress.tls }}
tls:
{{- if or (include "mailu.ingress.certManagerRequest" ( dict "annotations" .Values.ingress.annotations )) .Values.ingress.secrets .Values.ingress.selfSigned .Values.ingress.existingSecret }}
- secretName: {{ include "mailu.certificatesSecretName" . }}
hosts:
{{- range .Values.hostnames }}
- {{ . | quote }}
{{- end }}
{{- end }}
Error Log:
level=error msg="tls: failed to verify certificate: x509: cannot validate certificate for 10.42.4.31 because it doesn't contain any IP SANs"
Describe the bug
Mailu frontend pod uses a cert-manager-issued external TLS certificate (DNS name only:
mail.example.com) without IP Subject Alternative Names (SANs). When Traefik ingress controller connects to the Mailu backend pod via internal pod IP (10.42.4.31), the x509 certificate validation fails because the certificate lacks the required IP SANs for pod-to-pod HTTPS validation.To Reproduce
Steps to reproduce the behavior:
traefikand cert-manager issuer annotationsmail.example.com)Expected behavior
Traefik should successfully validate the Mailu backend certificate when connecting internally via pod IP, or certificate validation should be properly configured to handle DNS-only certificates in pod-to-pod HTTPS connections.
Environment
Values.yaml Configuration
Root Cause:
Evidence
front deployment required this certificate
that same with that front ingress
Error Log: