Skip to content

[BUG] - Traefik cannot validate external TLS certificate. #612

Description

@truongduchuy910

Describe the bug

Mailu frontend pod uses a cert-manager-issued external TLS certificate (DNS name only: mail.example.com) without IP Subject Alternative Names (SANs). When Traefik ingress controller connects to the Mailu backend pod via internal pod IP (10.42.4.31), the x509 certificate validation fails because the certificate lacks the required IP SANs for pod-to-pod HTTPS validation.

To Reproduce

Steps to reproduce the behavior:

  1. Set up cert-manager with a Let's Encrypt issuer
  2. Deploy Mailu with ingress class traefik and cert-manager issuer annotations
  3. Access Mailu via domain (mail.example.com)
  4. Check Traefik logs:
    kubectl logs -n kube-system -l app.kubernetes.io/name=traefik -f
  5. Observe error: cannot validate certificate for 10.42.4.31 because it doesn't contain any IP SANs

Expected behavior

Traefik should successfully validate the Mailu backend certificate when connecting internally via pod IP, or certificate validation should be properly configured to handle DNS-only certificates in pod-to-pod HTTPS connections.

Environment

  • Helm Chart Version: Mailu 2025.1+
  • Helm Version: v3.13.0+
  • Kubernetes Version: k3s 1.26+
  • Kubernetes Platform: k3s (3-node cluster)
  • Mailu Version: 2025.1
  • Traefik Version: 2.10+

Values.yaml Configuration

hostnames:
  - mail.example.com
 
ingress:
  enabled: true
  ingressClassName: "traefik"
  tls: true
  selfSigned: false
  annotations:
    cert-manager.io/cluster-issuer: "lets-encrypt"

Root Cause:

  • Mailu frontend certificate issued by cert-manager + Let's Encrypt contains DNS SANs only (mail.example.com)
  • Traefik strict TLS validation expects IP SANs when connecting to backend via pod IP address (10.42.4.31)
  • Mismatch causes x509 validation failure

Evidence

front deployment required this certificate

      volumes:
        - name: certs
          secret:
            items:
              - key: tls.crt
                path: cert.pem
              - key: tls.key
                path: key.pem
            secretName: {{ include "mailu.certificatesSecretName" . }}

that same with that front ingress

  {{- if .Values.ingress.tls }}
  tls:
    {{- if or (include "mailu.ingress.certManagerRequest" ( dict "annotations" .Values.ingress.annotations )) .Values.ingress.secrets .Values.ingress.selfSigned .Values.ingress.existingSecret }}
    - secretName: {{ include "mailu.certificatesSecretName" . }}
      hosts:
        {{- range .Values.hostnames }}
        - {{ . | quote }}
        {{- end }}
    {{- end }}

Error Log:

level=error msg="tls: failed to verify certificate: x509: cannot validate certificate for 10.42.4.31 because it doesn't contain any IP SANs"

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugIssues that are confirmed to be bugs

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions