2 ms·
> TLS termination at the Ingress Controller and by default unencrypted from there to the service endpoint? We are doing TLS termination at the ELB (we're runni
by danielmartins 9y ago
> TLS termination at the Ingress Controller and by default unencrypted from there to the service endpoint?
We are doing TLS termination at the ELB (we're running on AWS).
> Interesting discussion here: https://github.com/kubernetes/ingress/issues/257 https://github.com/kubernetes/ingress/issues/257
Great, thanks!
Regarding ways of updating of the NGINX upstreams without requiring a reload, I was just made aware of modules like ngx_dynamic_upstream[1]. I'm sure there are other ways to address this in a less disruptive way than reloading everything, so this is probably something that could be improved in the future.
[1] https://github.com/cubicdaiya/ngx_dynamic_upstream https://github.com/cubicdaiya/ngx_dynamic_upstream
- gtirloni 9y agoMay I ask how you are automating the ELB/TLS configuration and how that ties into the Ingress controller? Do you somehow specify which ELB it should use? We're in a similar situation.
- danielmartins 9y agoYou can annotate any Service of type LoadBalancer in order to configure various aspects[1] of the associated ELB, including which ACM-managed certificate you want to attach to each listener port. [1] https://github.com/kubernetes/kubernetes/blob/master/pkg/cloudprovider/providers/aws/aws.go https://github.com/kubernetes/kubernetes/blob/master/pkg/clo...
- gtirloni 9y agoThanks a lot, this will save us quite some time.