You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Kubernetes集群配置HTTPS(SSL)实现应用HTTPS访问求助

How to Configure SSL/HTTPS for Your Kubernetes App on AWS

Nice work getting your app fully set up with HTTP access! Let's get that SSL configured so users can reach it via https://www.example.com using your existing certificate files. Here's a step-by-step breakdown:

1. Store Your SSL Certificate in a Kubernetes Secret

Kubernetes uses TLS Secrets to securely store SSL certificates and private keys. Run this command to create one using your existing files:

kubectl create secret tls example-tls-secret \
  --key=/path/to/your/private-key-file.key \
  --cert=/path/to/your/certificate-chain-file.crt
  • Replace example-tls-secret with a name that makes sense for your app (you'll reference this later).
  • Ensure your files are in PEM format (most SSL providers issue certificates in this format by default).
  • If your app runs in a specific namespace, add the -n your-namespace flag to the command.

2. Update or Create an Ingress Resource

Since you already have HTTP access working, you likely have an Ingress resource configured. We'll modify it to enable HTTPS:

Example Ingress YAML (with TLS enabled)

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: example-app-ingress
  annotations:
    # For NGINX Ingress Controller, add this to auto-redirect HTTP to HTTPS:
    # nginx.ingress.kubernetes.io/ssl-redirect: "true"
    # For AWS ALB Ingress Controller, use annotations like:
    # alb.ingress.kubernetes.io/scheme: internet-facing
    # alb.ingress.kubernetes.io/target-type: ip
spec:
  tls:
  - hosts:
    - www.example.com
    secretName: example-tls-secret  # Match the Secret name you created earlier
  rules:
  - host: www.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: your-app-service  # Replace with your app's Service name
            port:
              number: 80
  • Key addition: The tls section links your Secret directly to the www.example.com domain.
  • The ssl-redirect annotation (for NGINX) will automatically send all HTTP traffic to HTTPS—remove it if you want to keep both protocols enabled.
  • Apply this updated Ingress with:
    kubectl apply -f your-ingress-file.yaml
    

3. Verify the Configuration

  • Check that your Ingress is properly configured:
    kubectl get ingress example-app-ingress
    
    You should see the ADDRESS field populated (your load balancer endpoint) and the TLS section listed.
  • Test access by visiting https://www.example.com in a browser—you should see your app with a valid, trusted SSL certificate.
  • If you run into issues, inspect the Ingress Controller logs (e.g., for NGINX: kubectl logs -n kube-system deployment/nginx-ingress-controller) to debug certificate or routing problems.

Quick Notes

  • Double-check that your SSL certificate is valid for www.example.com (wildcard certificates work too if you need subdomain support).
  • Ensure your Secret and Ingress are in the same namespace—cross-namespace references require additional configuration depending on your Ingress Controller.
  • For AWS ALB, the Ingress Controller will automatically provision an HTTPS listener using your certificate from the Secret.

内容的提问来源于stack exchange,提问作者Ketan Modi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:30:56