Azure Kubernetes Service (AKS) : How to enable HTTPS between Nginx Kubernetes Ingress Controller & Asp.Net Core 6.0 WebAPI PODs?

Viewed 115

I'm attempting to configure AKS, and I have the below setup

enter image description here

I want to enable HTTPS between Nginx Kubernetes Ingress Controller & Asp.Net Core 6.0 WebAPI PODs, like

enter image description here

How do I setup this? Where do I store the WebAPI SSL certificate?

1 Answers

Reference documentation for annotation to set the ingress backend to HTTPS:

nginx.ingress.kubernetes.io/backend-protocol: HTTPS

Follow the guidance here to setup SSL certs for your WebAPI pods.

The certs can be stored in kubernetes generic secret and can be mounted onto the pods as volumes. In production, the AKS secret storage could be backed by Azure KeyVault, so the cert would be really stored in the KeyVault.

For your test environment, here is how you create secret:

kubectl create secret generic webapi-cert-secret 
  --from-file=cert=yourcert.pfx
  --from-literal=pass='yourcertpasswd'

Then mount into your pod/deployment definition (truncated for brevity):

      env:
      - name: Kestrel__Certificates__Default__Path
        value: /certs/aspnet-cert.pfx
      - name: Kestrel__Certificates__Default__Password
        valueFrom:
          secretKeyRef:
            name: webapi-cert-secret
            key: pass
      volumeMounts:
      - name: certsvolume
        mountPath: /certs/aspnet-cert.pfx
        subPath: aspnet-cert.pfx
        readOnly: true
  volumes:
  - name: certsvolume
    secret:
      secretName: webapi-cert-secret
      items:
      - key: cert
        path: aspnet-cert.pfx
Related