Skip to content

Kubernetes Deployment with HTTPS on Kubernetes

This guide walks through deploying NGINX with automatic HTTPS certificates using cert-manager and Traefik ingress.

Prerequisites

  • Kubernetes cluster with Traefik ingress controller
  • cert-manager installed and configured
  • DNS domain pointed to your cluster nodes. please refer to How To Add DNS guide.
  • kubectl installed and configured. refer to How To Install kubectl guide.

Note

IP address of the kubernetes that you give in the DNS is: 172.236.204.215

Step 1: Create NGINX Deployment

You first need to create a kubernetes manifest for your deployment. This manifest defines the deployment and the service. This will vary app to app. It is similar to the docker-compose.yml file we create for our projects now.

Create nginx-deployment.yaml:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: nginx-web
  namespace: default
spec:
  replicas: 1
  selector:
    matchLabels:
      app: nginx-web
  template:
    metadata:
      labels:
        app: nginx-web
    spec:
      containers:
        - name: nginx
          image: nginx:latest
          ports:
            - containerPort: 80
              name: http
---
apiVersion: v1
kind: Service
metadata:
  name: nginx-web
  namespace: default
spec:
  selector:
    app: nginx-web
  ports:
    - port: 80
      targetPort: 80
      name: http
  type: ClusterIP

Apply the deployment:

kubectl apply -f nginx-deployment.yaml

Step 3: Create Certificate Resource

You need to create a kubernetes manifest for your certificate.

Note

Here I am using nginx.rit.services as the domain name. Please change it to your subdomain name.

Create nginx-certificate.yaml:

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: nginx-web-cert
  namespace: default
spec:
  secretName: nginx-web-tls
  dnsNames:
    - nginx.rit.services
  issuerRef:
    name: letsencrypt-prod
    kind: ClusterIssuer
    group: cert-manager.io
  privateKey:
    rotationPolicy: Always

Apply the certificate:

kubectl apply -f nginx-certificate.yaml

Step 4: Create Ingress with TLS

Create nginx-ingressroute.yaml:

apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
  name: nginx-web-ingressroute
  namespace: default
spec:
  entryPoints:
    - web
    - websecure
  routes:
    - match: Host(`nginx.rit.services`)
      kind: Rule
      services:
        - name: nginx-web
          port: 80
  tls:
    secretName: nginx-web-tls

Apply the ingress:

```bash
kubectl apply -f nginx-ingressroute.yaml

Step 5: Verify Deployment

Check all resources are running:

# Check deployment
kubectl get deployment nginx-web
kubectl get pods -l app=nginx-web

# Check service
kubectl get svc nginx-web

# Check certificate status
kubectl get certificate nginx-web-cert
kubectl describe certificate nginx-web-cert

# Check ingress
kubectl get ingress nginx-web-ingress

Step 6: Test HTTPS Access

Once the certificate is issued (Status: Ready):

# Test HTTPS access
curl https://nginx.rit.services

# Check certificate details
openssl s_client -connect nginx.rit.services:443 -servername nginx.rit.services

Troubleshooting

Certificate not issuing

# Check certificate status
kubectl describe certificate nginx-web-cert

# Check cert-manager logs
kubectl logs -n cert-manager deployment/cert-manager

# Check challenge status
kubectl get challenges
kubectl describe challenge <challenge-name>

Ingress not working

# Check Traefik logs
kubectl logs -n kube-system deployment/traefik

# Test service directly
kubectl port-forward svc/nginx-web 8080:80
# Then browse to http://localhost:8080

DNS Issues

Ensure your domain DNS points to one of your cluster node IPs:

kubectl get nodes -o wide
nslookup nginx.rit.services