Objective
In this post, I’ll explain how to encrypt the traffic between Cloudflare and your Kubernetes cluster using TLS certificates. This ensures end-to-end encryption from the user’s browser to your application pods.
The Setup
The architecture involves:
- Cloudflare as the CDN and DNS provider (handles browser-to-Cloudflare TLS)
- Traefik as the Kubernetes ingress controller
- TLS certificates for Cloudflare-to-cluster encryption
Steps
Step 1: In your Cloudflare dashboard, go to SSL/TLS and set the encryption mode to Full (Strict).
Step 2: Generate an Origin Certificate in Cloudflare. Go to SSL/TLS > Origin Server > Create Certificate. Download both the certificate and private key.
Step 3: Create a Kubernetes TLS secret with the Cloudflare origin certificate:
kubectl create secret tls cloudflare-origin-cert \
--cert=origin-cert.pem \
--key=origin-key.pem \
-n default
Step 4: Configure Traefik IngressRoute to use the TLS certificate:
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
name: site-a-ingress
namespace: default
spec:
entryPoints:
- websecure
routes:
- match: Host(`your-domain.com`)
kind: Rule
services:
- name: site-a-service
port: 80
tls:
secretName: cloudflare-origin-cert
Extending to Multiple Domains
To add another domain, repeat the process:
- Generate a new origin certificate for the additional domain in Cloudflare
- Create a new TLS secret in Kubernetes
- Add a new IngressRoute pointing to the appropriate service
With this setup, all traffic between Cloudflare and your Kubernetes cluster is encrypted, ensuring end-to-end security for your applications.




Top comments (0)