|
|
|
|
|
by zaroth
3203 days ago
|
|
Thank you. So there is a DNAT to get to the Ingress Controller but from there at least it's direct routing to the service endpoint(s)? Does that mean the Virtual IP given to the Service is basically bypassed when using Ingress Controller? TLS termination at the Ingress Controller and by default unencrypted from there to the service endpoint? I found this useful: http://blog.wercker.com/troubleshooting-ingress-kubernetes Interesting discussion here: https://github.com/kubernetes/ingress/issues/257 It seems like a lot of overhead before even starting to process a request! |
|
We are doing TLS termination at the ELB (we're running on AWS).
> Interesting discussion here: https://github.com/kubernetes/ingress/issues/257
Great, thanks!
Regarding ways of updating of the NGINX upstreams without requiring a reload, I was just made aware of modules like ngx_dynamic_upstream[1]. I'm sure there are other ways to address this in a less disruptive way than reloading everything, so this is probably something that could be improved in the future.
[1] https://github.com/cubicdaiya/ngx_dynamic_upstream