NGINX Ingress SSL Passthrough Ignored
You encounter a nginx configuration issue that prevents your workflow from completing. This guide walks through the fix step by step.
Wrong ❌
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
annotations:
nginx.ingress.kubernetes.io/ssl-passthrough: "true"
# Not enabled in controller flags
Wrong Output
SSL passthrough not working. TLS terminated at ingress. Backend gets plaintext.
Right ✅
# Enable in controller args: --enable-ssl-passthrough
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
annotations:
nginx.ingress.kubernetes.io/ssl-passthrough: "true"
kubernetes.io/ingress.class: nginx
spec:
tls:
- hosts: [secure.example.com]
secretName: backend-tls
rules:
- host: secure.example.com
http:
paths:
- path: /
pathType: Prefix
backend: { service: { name: backend-service, port: { number: 443 } } }
Right Output
SSL passthrough active. TLS connection passed directly to backend.
Prevention
- Enable --enable-ssl-passthrough in controller args.
- Once enabled, works per-ingress via annotation.
- When on, TLS terminates at backend.
- Use for services managing their own TLS.
- Not compatible with some other annotations.
DodaTech applies similar defensive patterns across Doda Browser, DodaZIP, and Durga Antivirus Pro infrastructure for production reliability.
Common Mistakes with ingress ssl passthrough
- Mixing let bindings with <- bindings in do notation, producing type errors
- Overlapping type class instances that cause GHC to reject the program with ambiguous dispatch errors
- Non-exhaustive pattern matches that compile with warnings then crash at runtime
These mistakes appear frequently in real-world NGINX code. DodaTech's contributors have identified these patterns through analysis of open-source projects and production systems.
Practice Exercise
Write a pure function that safely divides two integers using Maybe, then test it with edge cases like division by zero and negative numbers.
This exercise reinforces the concepts covered in this guide. Try implementing it before checking online solutions.
FAQ
This quick fix is part of the DodaTech infrastructure engineering series. Learn more at DodaTech tutorials.
Built by the developers of DodaTech
Doda Browser, DodaZIP & Durga Antivirus Pro