---
title: "Terminate TLS connections in a Managed Kubernetes cluster for Envoy Gateway"
sidebar_label: "Terminate TLS connections"
description: "How to configure TLS connection termination"
sidebar_position: 4
---

import Formbricks from '@theme/MDXComponents/Formbricks';
import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
import MoreVerticalIcon from '@selectel/docux/icons/more-vertical';
import { TabItemLabel } from '@selectel/docux/components';

# Terminate TLS connections in a Managed Kubernetes cluster for Envoy Gateway

Terminating a TLS connection for a Managed Kubernetes cluster is the process of decrypting HTTPS traffic and redirecting it to Kubernetes pods as HTTP traffic.

TLS connection termination can be used to:

* protect data transmission between a client and a service in a cluster;
* control access to services in a cluster and protect against unauthorized access;
* improve performance;
* simplify certificate management.

In a Managed Kubernetes cluster, the process of TLS connection termination can be configured on a load balancer. TLS connection termination on a load balancer is available in clusters with Kubernetes version 1.25 and higher. You can [upgrade the cluster version](/managed-kubernetes/clusters/upgrade-version.mdx).

Certificates can be managed via the [Certificate Manager](/certificates-manager/about-certificates-manager.mdx) — [add your custom certificate or issue a Let’s Encrypt® certificate](#add-or-issue-certificate).

1. [Add a custom certificate or issue one](#add-or-issue-certificate) in Secrets Manager.
2. [Create a load balancer](#create-load-balancer).
3. [Change the domain A record](#edit-domain-a-record).

## 1. Add or issue a certificate \{#add-or-issue-certificate}

In Certificate Manager, you can upload a certificate issued by a third-party certificate authority or issue a Let’s Encrypt® certificate.

<Tabs queryString="add-or-issue-certificate">
  <TabItem value="add-certificate" default>
    <TabItemLabel>
      Add a certificate
    </TabItemLabel>

    1. A custom certificate is only valid in the [project](/access-control/projects/about-projects.mdx) it was added to. Make sure you are in the correct project. To do this, open the project menu (the name of the current project) and select the project.

    2. In the [Control panel](https://my.selectel.ru/certificates/), in the top menu, click **Products** and select **Certificate Manager**.

    3. In the **Certificates** section, click **Add certificate**.

    4. Select **Custom certificate**.

    5. Enter the certificate name.

    6. Paste the primary certificate for the domain. It must start with `-----BEGIN CERTIFICATE-----` and end with `-----END CERTIFICATE-----`.

    7. Paste the private key. It must start with `-----BEGIN PRIVATE KEY-----` and end with `-----END PRIVATE KEY-----`.

    8. Optional: to add an intermediate certificate:

       8.1. Select the **Add intermediate certificate** checkbox.

       8.2. In the **Intermediate certificate** field, paste the certificate. It must start with `-----BEGIN CERTIFICATE-----` and end with `-----END CERTIFICATE-----`.

       If you need to add several intermediate certificates, ensure that all certificates (the primary domain certificate, intermediate certificates, and the root certificate) form a complete chain. The `Issuer` value of the primary certificate must match the `Subject` value of the first intermediate certificate, the `Issuer` value of the first intermediate certificate — with the `Subject` value of the second intermediate, and so on.

       You can add intermediate certificates in the **Intermediate Certificate** field in any order. It is important to use the full chain.

    9. Optional: to add a root certificate:

       9.1. Select the **Add root certificate** checkbox.

       9.2. In the **Root certificate** field, paste the certificate. It must start with `-----BEGIN CERTIFICATE-----` and end with `-----END CERTIFICATE-----`.

    10. Click **Add**.

    11. Open the certificate page.

    12. Copy the certificate UUID.
  </TabItem>

  <TabItem value="issue-certificate">
    <TabItemLabel>
      Issue a Let’s Encrypt® certificate
    </TabItemLabel>

    You can issue a Let’s Encrypt® certificate that will be valid:

    * only for the primary domain or for the primary domain and all its subdomains (Wildcard certificate);
    * only for a subdomain. The certificate will not be valid for the primary domain.

    To issue a certificate:

    <Tabs queryString="issue-lets-encrypt-certificate">
      <TabItem value="for-domain-and-subdomain" default>
        <TabItemLabel>
          For a primary domain and subdomains
        </TabItemLabel>

        1. [Create a zone](/dns-hosting/zones/create-zone.mdx) for the domain in DNS hosting.

        2. [Delegate the domain](/dns-hosting/zones/delegate-zone.mdx).

        3. In the [Control panel](https://my.selectel.ru/certificates/), in the top menu, click **Products** and select **Certificate Manager**.

        4. In the **Certificates** section, click **Add certificate**.

        5. Select **Certificates from Let’s Encrypt®**.

        6. Enter a certificate name.

        7. Select the domain that you delegated to DNS hosting in step 2.

        8. Optional: to add a subdomain to the primary domain certificate, click **Add additional domain**.

           Enter the subdomain name. To issue a Wildcard certificate, enter a subdomain like `*.example.com`

        9. Click **Issue certificate**.

        10. Open the certificate page.

        11. Copy the certificate UUID.

        12. In the **Certificate files** block, select the certificate, intermediate certificate chain, root certificate, and private key.

        13. Click **Download**.

        14. Install the files on the side of your service.
      </TabItem>

      <TabItem value="only-for-subdomain">
        <TabItemLabel>
          For a subdomain only
        </TabItemLabel>

        1. [Create a zone](/dns-hosting/zones/create-zone.mdx) for the subdomain in DNS hosting.

        2. [Delegate the subdomain](/dns-hosting/zones/delegate-zone.mdx).

        3. In the [Control panel](https://my.selectel.ru/certificates/), in the top menu, click **Products** and select **Certificate Manager**.

        4. In the **Certificates** section, click **Add certificate**.

        5. Select **Certificates from Let’s Encrypt®**.

        6. Enter a certificate name.

        7. Select the subdomain that you delegated to DNS hosting in step 2.

        8. Click **Issue certificate**.

        9. Open the certificate page.

        10. Copy the certificate UUID.

        11. In the **Certificate files** block, select the certificate, intermediate certificate chain, root certificate, and private key.

        12. Click **Download**.

        13. Install the files on the side of your service.
      </TabItem>
    </Tabs>
  </TabItem>
</Tabs>

## 2. Create a load balancer \{#create-load-balancer}

Use the [Create load balancer](/managed-kubernetes/networks/loadbalancing-with-envoy-gateway/load-balancers-for-envoy-gateway.mdx#create-load-balancer) subsection of the [Create and configure a load balancer in a Managed Kubernetes cluster for Envoy Gateway](/managed-kubernetes/networks/loadbalancing-with-envoy-gateway/load-balancers-for-envoy-gateway.mdx) instruction.

In the Gateway object manifest, add the following annotation to the `annotations` block:

```yaml
loadbalancer.openstack.org/default-tls-container-ref: "<certificate_uuid>"
```

Specify `<certificate_uuid>` — the universal unique identifier (UUID) of the certificate you copied in the [Add or issue a certificate](#add-or-issue-certificate) instruction.

The created load balancer will appear in the [Control panel](https://my.selectel.ru/vpc/default/lbaas/load-balancers/): in the top menu, click **Products** and select **Cloud servers** → section **Load Balancers** → tab **Load Balancers**.

## 3. Change the A record for the domain \{#edit-domain-a-record}

You can accelerate the propagation of resource record changes to caching servers. To do this, a few days before the planned change, reduce the record TTL to the minimum possible value. Then, at the scheduled time, change the resource record, and once the change has propagated to the caching servers, revert the TTL to its previous value.

1. In the [Control panel](https://my.selectel.ru/dns/default/hosting), on the top menu, click **Products** and select **DNS hosting**.
2. In the **Domain zones** section, open the zone page.
3. In the <MoreVerticalIcon /> A record group menu, select **Edit**.
4. Change the IP address to the load balancer IP address. The load balancer IP address can be viewed in the [Control panel](https://my.selectel.ru/vpc/default/lbaas/load-balancers/): in the top menu, click **Products** and select **Cloud Servers** → **Load Balancers** → the **Load Balancers** tab → load balancer card.
5. Click **Save**.
6. Wait for the resource record to update on the DNS servers. The update can take anywhere from the record group TTL to 72 hours. The record group TTL can be viewed in the [Control panel](https://my.selectel.ru/dns/default/hosting): in the top menu, click **Products** → **DNS Hosting** → **Domain Zones** → zone page → record row → field **TTL**.
7. Optional: [check the resource record](/dns-hosting/records/check-records.mdx). If the resource record has not updated after 72 hours, [create a ticket](https://my.selectel.ru/tickets/create).
8. Verify that requests are only reaching the load balancer and that there are no requests from users on the server.

<Formbricks />
