Back to Practice
Lab

TLS-Terminating Ingress

Serve traffic over HTTPS: package a certificate and key into a kubernetes.io/tls Secret, then wire an Ingress to terminate TLS for a host using it. A CKS cluster-setup essential.

Your mission

Serving an app over HTTPS through an Ingress is two objects: a kubernetes.io/tls Secret holding the certificate and private key, and an Ingress whose tls stanza points a hostname at that Secret. The ingress controller then terminates TLS at the edge, so pods behind it can speak plain HTTP.

You'll do both in the web namespace (already created) for the host secure.example.com. (No ingress controller runs here — the Ingress object is what's graded, exactly as on the exam.)

kubectl config set-context --current --namespace=web

Skills you'll put into practice

securityingresstlscks

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation