AWS Kubernetes集群配置HTTPS(SSL)实现应用HTTPS访问求助
How to Configure SSL/HTTPS for Your Kubernetes App on AWS
Nice work getting your app fully set up with HTTP access! Let's get that SSL configured so users can reach it via https://www.example.com using your existing certificate files. Here's a step-by-step breakdown:
1. Store Your SSL Certificate in a Kubernetes Secret
Kubernetes uses TLS Secrets to securely store SSL certificates and private keys. Run this command to create one using your existing files:
kubectl create secret tls example-tls-secret \ --key=/path/to/your/private-key-file.key \ --cert=/path/to/your/certificate-chain-file.crt
- Replace
example-tls-secretwith a name that makes sense for your app (you'll reference this later). - Ensure your files are in PEM format (most SSL providers issue certificates in this format by default).
- If your app runs in a specific namespace, add the
-n your-namespaceflag to the command.
2. Update or Create an Ingress Resource
Since you already have HTTP access working, you likely have an Ingress resource configured. We'll modify it to enable HTTPS:
Example Ingress YAML (with TLS enabled)
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: example-app-ingress annotations: # For NGINX Ingress Controller, add this to auto-redirect HTTP to HTTPS: # nginx.ingress.kubernetes.io/ssl-redirect: "true" # For AWS ALB Ingress Controller, use annotations like: # alb.ingress.kubernetes.io/scheme: internet-facing # alb.ingress.kubernetes.io/target-type: ip spec: tls: - hosts: - www.example.com secretName: example-tls-secret # Match the Secret name you created earlier rules: - host: www.example.com http: paths: - path: / pathType: Prefix backend: service: name: your-app-service # Replace with your app's Service name port: number: 80
- Key addition: The
tlssection links your Secret directly to thewww.example.comdomain. - The
ssl-redirectannotation (for NGINX) will automatically send all HTTP traffic to HTTPS—remove it if you want to keep both protocols enabled. - Apply this updated Ingress with:
kubectl apply -f your-ingress-file.yaml
3. Verify the Configuration
- Check that your Ingress is properly configured:
You should see thekubectl get ingress example-app-ingressADDRESSfield populated (your load balancer endpoint) and the TLS section listed. - Test access by visiting
https://www.example.comin a browser—you should see your app with a valid, trusted SSL certificate. - If you run into issues, inspect the Ingress Controller logs (e.g., for NGINX:
kubectl logs -n kube-system deployment/nginx-ingress-controller) to debug certificate or routing problems.
Quick Notes
- Double-check that your SSL certificate is valid for
www.example.com(wildcard certificates work too if you need subdomain support). - Ensure your Secret and Ingress are in the same namespace—cross-namespace references require additional configuration depending on your Ingress Controller.
- For AWS ALB, the Ingress Controller will automatically provision an HTTPS listener using your certificate from the Secret.
内容的提问来源于stack exchange,提问作者Ketan Modi
相关产品推荐
相关产品推荐

