Kubernetes Deployment with HTTPS on Kubernetes
This guide walks through deploying NGINX with automatic HTTPS certificates using cert-manager and Traefik ingress.
Prerequisites
- Kubernetes cluster with Traefik ingress controller
- cert-manager installed and configured
- DNS domain pointed to your cluster nodes. please refer to How To Add DNS guide.
- kubectl installed and configured. refer to How To Install kubectl guide.
Note
IP address of the kubernetes that you give in the DNS is: 172.236.204.215
Step 1: Create NGINX Deployment
You first need to create a kubernetes manifest for your deployment. This manifest defines the deployment and the service. This will vary app to app. It is similar to the docker-compose.yml file we create for our projects now.
Create nginx-deployment.yaml:
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-web
namespace: default
spec:
replicas: 1
selector:
matchLabels:
app: nginx-web
template:
metadata:
labels:
app: nginx-web
spec:
containers:
- name: nginx
image: nginx:latest
ports:
- containerPort: 80
name: http
---
apiVersion: v1
kind: Service
metadata:
name: nginx-web
namespace: default
spec:
selector:
app: nginx-web
ports:
- port: 80
targetPort: 80
name: http
type: ClusterIP
Apply the deployment:
kubectl apply -f nginx-deployment.yaml
Step 3: Create Certificate Resource
You need to create a kubernetes manifest for your certificate.
Note
Here I am using nginx.rit.services as the domain name. Please change it to your subdomain name.
Create nginx-certificate.yaml:
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: nginx-web-cert
namespace: default
spec:
secretName: nginx-web-tls
dnsNames:
- nginx.rit.services
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
group: cert-manager.io
privateKey:
rotationPolicy: Always
Apply the certificate:
kubectl apply -f nginx-certificate.yaml
Step 4: Create Ingress with TLS
Create nginx-ingressroute.yaml:
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: nginx-web-ingressroute
namespace: default
spec:
entryPoints:
- web
- websecure
routes:
- match: Host(`nginx.rit.services`)
kind: Rule
services:
- name: nginx-web
port: 80
tls:
secretName: nginx-web-tls
Apply the ingress:
```bash
kubectl apply -f nginx-ingressroute.yaml
Step 5: Verify Deployment
Check all resources are running:
# Check deployment
kubectl get deployment nginx-web
kubectl get pods -l app=nginx-web
# Check service
kubectl get svc nginx-web
# Check certificate status
kubectl get certificate nginx-web-cert
kubectl describe certificate nginx-web-cert
# Check ingress
kubectl get ingress nginx-web-ingress
Step 6: Test HTTPS Access
Once the certificate is issued (Status: Ready):
# Test HTTPS access
curl https://nginx.rit.services
# Check certificate details
openssl s_client -connect nginx.rit.services:443 -servername nginx.rit.services
Troubleshooting
Certificate not issuing
# Check certificate status
kubectl describe certificate nginx-web-cert
# Check cert-manager logs
kubectl logs -n cert-manager deployment/cert-manager
# Check challenge status
kubectl get challenges
kubectl describe challenge <challenge-name>
Ingress not working
# Check Traefik logs
kubectl logs -n kube-system deployment/traefik
# Test service directly
kubectl port-forward svc/nginx-web 8080:80
# Then browse to http://localhost:8080
DNS Issues
Ensure your domain DNS points to one of your cluster node IPs:
kubectl get nodes -o wide
nslookup nginx.rit.services