Usually when I deploy a Simple HTTPS server in VM I do
Create Certificate with ip
$ openssl req -new -x509 -keyout private_key.pem -out public_cert.pem -days 365 -nodes
Generating a RSA private key
..+++++
.................................+++++
writing new private key to 'private_key.pem'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]:IN
State or Province Name (full name) [Some-State]:Tamil Nadu
Locality Name (eg, city) []:Chennai
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Company ,Inc
Organizational Unit Name (eg, section) []: company division
Common Name (e.g. server FQDN or YOUR name) []:35.222.65.55 <----------------------- this ip should be server ip very important
Email Address []:
Start Simple HTTPS Python Server
# libraries needed:
from http.server import HTTPServer, SimpleHTTPRequestHandler
import ssl , socket
# address set
server_ip = '0.0.0.0'
server_port = 3389
# configuring HTTP -> HTTPS
httpd = HTTPServer((server_ip, server_port), SimpleHTTPRequestHandler)
httpd.socket = ssl.wrap_socket(httpd.socket, certfile='./public_cert.pem',keyfile='./private_key.pem', server_side=True)
httpd.serve_forever()
now this works fine for
Curl from local
curl --cacert /Users/padmanabanpr/Downloads/public_cert.pem --cert-type PEM https://35.222.65.55:3389
now how to deploy the same to kubernetes cluster and access via load-balancer?
Assuming i have
- public docker nginx container with write access , python3 , and this python https server file
- deployment yaml with nginx
apiVersion: apps/v1
kind: Deployment
metadata:
name: external-nginx-server
labels:
app: external-nginx-server
spec:
replicas: 1
selector:
matchLabels:
app: external-nginx-server
template:
metadata:
labels:
app: external-nginx-server
spec:
containers:
- name: external-nginx-server
image: <docker nginx public image>
ports:
- containerPort: 3389
---
kind: Service
apiVersion: v1
metadata:
name: external-nginx-service
spec:
selector:
app: external-nginx-server
ports:
- protocol: TCP
port: 443
name: https
targetPort: 3389
type: LoadBalancer