4 ms·
I don't know about terminating on the load balancer level, but it works fine on the ingress-level (http router) with cert-manager, nginx-ingress-controller and
by DelightOne 7y ago
I don't know about terminating on the load balancer level, but it works fine on the ingress-level (http router) with cert-manager, nginx-ingress-controller and the Ingress-definition.
- status_quo69 7y agoLoad balancer certs via annotations are supported, but they're a bit iffy when pairing with controllers like ambassador, since ambassador expects to own TLS termination (although the ambassador docs do say this is configurable). https://www.digitalocean.com/docs/kubernetes/how-to/configure-load-balancers/#ssl-certificates https://www.digitalocean.com/docs/kubernetes/how-to/configur...
- DelightOne 7y agoAh good to know, thank you!
- bndw 7y agoaside: ambassador definitely supports external TLS termination (tested with AWS ELB).
- mjfisher 7y agoThat's exactly how I manage it too. It means there only needs to be one load balancer per cluster, and adding a new SSL cert is just a matter of adding a couple of lines to the ingress config.