---
title: "From On-Prem to the Cloud: A Step-by-Step Guide to Google Kubernetes Engine Ingress from Certificate Upload to Domain Binding"
description: "A guide on how to create an Ingress in GKE, upload a Cloudflare SSL certificate, and bind a domain to a Kubernetes cluster to implement L7 traffic management."
canonical_url: "https://blog.markkulab.net/en/post/create-ingress-and-binding-domain-in-gke"
author: "Mark Ku"
author_url: "https://blog.markkulab.net/en/author/mark-ku"
site: "Mark Ku's Tech Notes"
date_published: "2024-11-23T01:01:35+08:00"
category: "Cloud"
tags: ["gke", "kubernetes", "ingress", "cloudflare", "ssl", "domain", "load balancer", "cloud"]
language: "en"
license: "CC BY 4.0"
license_url: "https://creativecommons.org/licenses/by/4.0/"
attribution: "when reusing or quoting, credit the author and link back to the original"
---

# From On-Prem to the Cloud: A Step-by-Step Guide to Google Kubernetes Engine Ingress from Certificate Upload to Domain Binding

## What is Ingress?
Ingress is a key component in a Kubernetes cluster, primarily responsible for simplifying and managing access for external traffic to internal services. In principle, a Kubernetes cluster exists in a **private network space**, and external sources cannot directly access services or Pods within the cluster. Therefore, you need to use a **Service (LTM)** or **Ingress** to route traffic to services inside the cluster.

## Service (LTM) vs. Ingress

In GKE, a **Service** provides **Layer 4 load balancing** and cannot process HTTP protocol content. Although you can point a DNS or CNAME record to the load balancer's external IP and set Cloudflare's SSL to "Flexible" to bind a domain, a Service cannot redirect or set rules based on the HTTP protocol, request content, or path.

However, **Ingress** provides **Layer 7 load balancing**, understands the HTTP protocol, and can use Ingress rules to determine how to forward requests to specific Services based on the **path or domain name**.

For example:
```
www.letgo.com.tw => Service A => Cluster => Pods => Container
```

Ingress is similar to [Nginx's domain resolution](https://blog.markkulab.net/nginx-https-forwarding/) and traffic forwarding capabilities, but its functionality is more focused on traffic management (Nginx also provides website features like caching). Through Ingress's domain resolution and path forwarding, we can easily implement traffic splitting.

Example:
```
/blog  => Service A  
/store => Service B
```

## Creating an Ingress
There are three ways to create an Ingress: through the web interface, using commands, or by writing a YAML configuration file. Before you start, you must first create a Deployment and a Service. It's crucial to note that this Service's type must be set to `ClusterIP`, not `LoadBalancer`. This example will demonstrate how to create an Ingress through the web interface.

1. Go to GCP's Google Kubernetes Engine > Gateways, Services & Ingress > click the SERVICES tab > select your Service.
![create ingress by service](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/create-ingress-by-service.png)

2. Enter the Ingress name
![image](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/create-ingress-by-service-2.png)

P.S. Selecting the External type will automatically generate a unique IP address.

3. Enter the domain name and bind it to the previously created Service
![enter domain name and select service](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/enter-domain-name-and-select-service.png)
P.S. The previously created Service's Type must be ClusterIP.

#### 2. Configure the Cloudflare Certificate
![set up certificate](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/set-up-certificate.png)

#### 3. Obtain the certificate. Using Cloudflare as an example, if you want to point your domain to the Ingress IP, you can follow these steps to obtain a Cloudflare certificate:
Log in to the Cloudflare dashboard, go to SSL/TLS > Overview > Configure > SSL/TLS encryption > set it to Full
![ssl encryption](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/ssl-encryption.png)
SSL/TLS > Origin Server > Create Certificate > Create > Create
![get certificate](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/get-certificate.png)

Additional Notes
* A client certificate focuses on authentication and encryption from the client to the server.
* An origin server certificate provides encryption between Cloudflare and your backend server.

Once the Ingress is created, it will generate a unique IP. You can then point your domain to the Ingress's external IP via DNS.
![get ingress-real ip](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/get-ingress-real-ip.png)

#### Next, add an A record in your DNS and point it to the real IP of the previously created Ingress.
![create a record in dns](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/create-a-record-in-dns.png)

At this point, your website domain, HTTPS certificate, and Google Kubernetes Engine Ingress are now integrated.
![result](https://blog.markkulab.net/content/markku/posts/create-ingress-and-binding-domain-in-gke/images/result.png)


## Additional Notes - Uploading a Certificate via Command and Creating an Ingress via Config File (YAML)

Use the `kubectl` command to upload (get the certificate from Cloudflare as shown before):

```
kubectl create secret tls letgo.com.tw --cert letgo.cert.pem --key  letgo.cert.key
```
Create `ingress.yaml`
```
---
apiVersion: "networking.k8s.io/v1"
kind: "Ingress"
metadata:
  name: "k8s-next-ec-service-ingress"
  namespace: "default"
spec:
  tls:
  - secretName: "letgo.com.tw"
  rules:
  - http:
      paths:
      - path: ""
        backend:
          service:
            name: "k8s-next-ec-service"
            port:
              number: 80
        pathType: "ImplementationSpecific"
    host: "gke-1.letgo.com.tw"
status:
  loadBalancer: {}
```
kubectl apply -f ./ingress.yaml

## References
* Special thanks to Mickey and David for their guidance
* [Is the Gateway API, which uses an Ingress mechanism, more convenient?](https://www.youtube.com/watch?v=nO_aD-2sOMk)
* [Deploying to GKE with Azure DevOps (2) — Load Balancer vs. Ingress](https://medium.com/chouhsiang/azure-devops-%E9%83%A8%E7%BD%B2%E5%88%B0-gke-2-gke-service-ingress-99bfc79884ad)
* [The Things About Kubernetes — Ingress Chapter (Part 1)](https://medium.com/andy-blog/kubernetes-%E9%82%A3%E4%BA%9B%E4%BA%8B-ingress-%E7%AF%87-%E4%B8%80-92944d4bf97d)
* [Deploying to GKE with Azure DevOps (8) — Cloudflare Integration](https://medium.com/chouhsiang/azure-devops-%E9%83%A8%E7%BD%B2%E5%88%B0-gke-7-%E6%95%B4%E5%90%88cloudflare-7864906a5b2a)

---

## About this article and its author

Originally published on [Mark Ku's Tech Notes](https://blog.markkulab.net/en/post/create-ingress-and-binding-domain-in-gke)

License: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — when reusing or quoting, credit the author and link back to the original

### About the author

**[Mark Ku](https://blog.markkulab.net/en/author/mark-ku)** — Software Solution Provider

- 10+ years senior software engineer, now an AI Builder
- Focused on large-platform architecture — North-American e-commerce, AI SaaS subscription billing
- Combining AI Agents and automation to build evolvable product foundations

### Free tools built by the author

All of these are free to use:

- [Free PDF Sign Tool](https://blog.markkulab.net/en/tools/pdf-sign): Online PDF sign tool — draw, type, or upload a signature, then drag, resize, and download. Everything runs in your browser; nothing is uploaded.
- [VS Code Refactory](https://blog.markkulab.net/en/tools/refactory): Refactory is a VS Code refactoring extension: 34 actions plus a 37-rule code-smell inspection layer with a Code Health dashboard, across 18 languages, backed by 534 tests. It learns your repo's conventions: where interfaces live, where DI is registered, whether 'use client' belongs. It ranks files by git churn × complexity so you know what to fix first, and hands any smell to the Claude Code already on your machine. Free to use, and your source never leaves your computer.
- [DB-Kit Database Manager](https://blog.markkulab.net/en/tools/db-kit): DB-Kit is a lightweight, cross-platform database manager built with Tauri + Rust + React. Manage MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, MongoDB, Redis, Kafka, Elasticsearch and RabbitMQ from one consistent interface: passwords encrypted in the OS keychain, SSH tunnels, full CRUD, a visual query builder, stacked multi-statement result sets, cross-connection data transfer and compare/sync, Excel / CSV import & export, visualized execution plans, ER diagrams, scheduled backups, SQL stress testing with p50–p99 latency percentiles, a 15-rule SQL review engine, Kafka message browsing with monitoring & alerts, a bilingual UI (Traditional Chinese / English), a built-in AI assistant (natural-language SQL, AI review and tuning advice) and the dbk CLI. Free and open source (MIT), with installers for Windows, macOS and Linux.
- [VS Code Super Mermaid](https://blog.markkulab.net/en/tools/super-mermaid): Super Mermaid is a VS Code extension for beautiful Mermaid diagrams out of the box: auto-colored live preview, mouse pan & zoom, high-res PNG / SVG export, 21 templates and multiple themes. Free and open source (MIT).
- [React Super Mermaid](https://blog.markkulab.net/en/tools/react-super-mermaid): react-super-mermaid is an open-source React component library: render beautiful Mermaid diagrams with a single <MermaidViewer>, with built-in colorful / sketch themes, pan & zoom, in-diagram search, and high-res SVG / PNG export. Lightweight, SSR-safe, fully typed. Free and open source (MIT).
- [Jira / Confluence Super Mermaid](https://blog.markkulab.net/en/tools/jira-super-mermaid): An Atlassian Forge app: write Mermaid syntax directly inside a Jira issue or a Confluence page and get flowcharts, sequence diagrams, state machines and Gantt charts. 11 diagram types, SVG / PNG export, light and dark themes, full CJK support. Runs on Atlassian: your diagrams live in your own site and the app calls no third-party service. Free, coming soon to the Atlassian Marketplace.
- [Mermaid Live Preview](https://blog.markkulab.net/en/tools/mermaid-preview): Write Mermaid in your browser, see it render instantly, and share the whole diagram as a single link. No sign-up, nothing uploaded to a server, and mermaid.live share links work as-is.
- [React Intl Phone Number](https://blog.markkulab.net/en/tools/react-intl-phone-number): react-intl-phone-number is an open-source React component: framework-agnostic and antd-free, with E.164 in/out, a searchable flag / country-code dropdown, configurable validation levels (strict / mobile-strict / loose), themeable CSS, and i18n — phone logic powered by google-libphonenumber. Lightweight and fully typed. Free and open source (MIT).
- [Uptime Kuma Cluster](https://blog.markkulab.net/en/tools/uptime-kuma-cluster): Turn single-node Uptime Kuma into a highly available cluster: OpenResty + Lua smart load balancing, shared MariaDB state, health checks and automatic failover, plus cluster-management REST APIs. One Docker Compose command to start. Free and open source (MIT).
- [Special Education](https://blog.markkulab.net/en/education): Learning materials crafted for special education students

### Daily podcasts

- [Mark's Tech Insights — Daily AI News](https://blog.markkulab.net/en/category/tech-news): Daily curated AI and tech trends. Catch the latest developments via audio summaries — covering AI applications, software architecture, DevOps, and engineering practice. — RSS: https://blog.markkulab.net/feed.xml
- [AI股市蝦聊](https://blog.markkulab.net/en/category/ai-stock-chat): Every trading day, an AI-analyzed take on the Taiwan stock market, delivered as a two-host conversation covering the session and the next-day outlook. — RSS: https://blog.markkulab.net/ai-stock-chat/feed.xml
- [開源好物週報](https://blog.markkulab.net/en/category/open-source-weekly): A weekly two-host pick of free open-source tools surfaced from real Hacker News, GitHub, and Reddit buzz — what pain they solve and the fastest way to get started. — RSS: https://blog.markkulab.net/open-source-weekly/feed.xml

### Newsletter

[Subscribe to the newsletter](https://blog.markkulab.net/en/subscribe) — Be the first to know about new posts. No spam, unsubscribe anytime.
