Production Kubernetes Blueprint: Nginx Ingress, Cert-Manager SSL & Cloud Native Workflows
Moving from Local Containers to Cloud Kubernetes
Running Docker containers locally with Docker Compose is straightforward. However, deploying multi-tier web applications into production requires Kubernetes (K8s) to manage declarative ingress routing, SSL certificate lifecycle, zero-downtime rolling updates, and container resilience.
Here is a tested production blueprint for setting up Nginx Ingress with automatic Let’s Encrypt SSL via Cert-Manager.
1. Automated SSL with Cert-Manager & Let's Encrypt
Cert-Manager automatically provisions and renews TLS certificates by solving HTTP-01 or DNS-01 ACME challenges without human intervention:
# cluster-issuer.yaml
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-production
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: ssurindersingh100@gmail.com
privateKeySecretRef:
name: letsencrypt-production-key
solvers:
- http01:
ingress:
class: nginx2. Production Nginx Ingress with TLS Termination
The Ingress resource routes incoming HTTPS traffic to internal ClusterIP services and mounts the auto-provisioned TLS secret:
# production-ingress.yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: main-web-ingress
annotations:
cert-manager.io/cluster-issuer: letsencrypt-production
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-body-size: "25m"
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
spec:
ingressClassName: nginx
tls:
- hosts:
- surindersingh.dev
- api.surindersingh.dev
secretName: portfolio-tls-cert
rules:
- host: surindersingh.dev
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: frontend-service
port:
number: 3000
- host: api.surindersingh.dev
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: backend-api-service
port:
number: 80803. Container Resource Limits & Health Probes
To prevent runaway memory consumption (OOM kills) and ensure faulty pods are automatically restarted:
resources:
requests:
cpu: "250m"
memory: "256Mi"
limits:
cpu: "1000m"
memory: "1024Mi"
livenessProbe:
httpGet:
path: /api/health
port: 3000
initialDelaySeconds: 15
periodSeconds: 10
readinessProbe:
httpGet:
path: /api/health
port: 3000
initialDelaySeconds: 5
periodSeconds: 54. Key Security Best Practices
- Non-Root Containers: Always configure
securityContext: runAsNonRoot: truein your pod spec. - Network Policies: Restrict pod-to-pod communication so frontend pods cannot directly touch sensitive database ports without passing through the API layer.
- Secret Management: Never commit plaintext credentials to Git; use Kubernetes Secrets synced from cloud KMS or HashiCorp Vault.
Discussion (0)
Technical insights, critiques, and feedback
No comments yet. Be the first to start the discussion!