Back
$cat ./production-kubernetes-blueprint-nginx-ingress-ssl.md

Production Kubernetes Blueprint: Nginx Ingress, Cert-Manager SSL & Cloud Native Workflows

S
Surinder Singh•August 14, 2026•2 min read
KubernetesCloudDockerNginxSecurity
Production Kubernetes Blueprint: Nginx Ingress, Cert-Manager SSL & Cloud Native Workflows

Moving from Local Containers to Cloud Kubernetes

Running Docker containers locally with Docker Compose is straightforward. However, deploying multi-tier web applications into production requires Kubernetes (K8s) to manage declarative ingress routing, SSL certificate lifecycle, zero-downtime rolling updates, and container resilience.

Here is a tested production blueprint for setting up Nginx Ingress with automatic Let’s Encrypt SSL via Cert-Manager.


1. Automated SSL with Cert-Manager & Let's Encrypt

Cert-Manager automatically provisions and renews TLS certificates by solving HTTP-01 or DNS-01 ACME challenges without human intervention:

yaml
# cluster-issuer.yaml
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: letsencrypt-production
spec:
  acme:
    server: https://acme-v02.api.letsencrypt.org/directory
    email: ssurindersingh100@gmail.com
    privateKeySecretRef:
      name: letsencrypt-production-key
    solvers:
      - http01:
          ingress:
            class: nginx

2. Production Nginx Ingress with TLS Termination

The Ingress resource routes incoming HTTPS traffic to internal ClusterIP services and mounts the auto-provisioned TLS secret:

yaml
# production-ingress.yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: main-web-ingress
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-production
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
    nginx.ingress.kubernetes.io/proxy-body-size: "25m"
    nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
    nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
spec:
  ingressClassName: nginx
  tls:
    - hosts:
        - surindersingh.dev
        - api.surindersingh.dev
      secretName: portfolio-tls-cert
  rules:
    - host: surindersingh.dev
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: frontend-service
                port:
                  number: 3000
    - host: api.surindersingh.dev
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: backend-api-service
                port:
                  number: 8080

3. Container Resource Limits & Health Probes

To prevent runaway memory consumption (OOM kills) and ensure faulty pods are automatically restarted:

yaml
resources:
  requests:
    cpu: "250m"
    memory: "256Mi"
  limits:
    cpu: "1000m"
    memory: "1024Mi"
livenessProbe:
  httpGet:
    path: /api/health
    port: 3000
  initialDelaySeconds: 15
  periodSeconds: 10
readinessProbe:
  httpGet:
    path: /api/health
    port: 3000
  initialDelaySeconds: 5
  periodSeconds: 5

4. Key Security Best Practices

  1. Non-Root Containers: Always configure securityContext: runAsNonRoot: true in your pod spec.
  2. Network Policies: Restrict pod-to-pod communication so frontend pods cannot directly touch sensitive database ports without passing through the API layer.
  3. Secret Management: Never commit plaintext credentials to Git; use Kubernetes Secrets synced from cloud KMS or HashiCorp Vault.
Explore more articles→

Discussion (0)

Technical insights, critiques, and feedback

Verifying authentication status...

No comments yet. Be the first to start the discussion!