# How to set gatteway api with HTTPS tls cert

**URL:** <https://discuss.kubernetes.io/t/how-to-set-gatteway-api-with-https-tls-cert/32347>\
**Category:** General Discussions\
**Tags:** development\
**Created:** [May 16, 2025, 11:32am UTC](https://discuss.kubernetes.io/t/how-to-set-gatteway-api-with-https-tls-cert/32347 "2025-05-16T11:32:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Megan\_Liu](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/megan_liu/32/17291_2.png) [@Megan\_Liu](https://discuss.kubernetes.io/u/Megan_Liu)\
**Post date:** [May 16, 2025, 11:32am UTC](https://discuss.kubernetes.io/t/how-to-set-gatteway-api-with-https-tls-cert/32347/1 "2025-05-16T11:32:29Z")

</div>

Asking for help? Comment out what you need so we can get more information to help you!

From kuberent website , it only provide the info for general HTTP based listeners.

> **[Gateway API](https://kubernetes.io/docs/concepts/services-networking/gateway/)**
>
> Gateway API is a family of API kinds that provide dynamic infrastructure provisioning and advanced traffic routing.

```auto
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: example-gateway
spec:
  gatewayClassName: example-class
  listeners:
  - name: http
    protocol: HTTP
    port: 80

```

I need to set the gateway API with HPPS and tls cert for my cluster.  
How should I do it ?  
is this correct way ?

```auto
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: example-gateway
spec:
  gatewayClassName: example-class
  listeners:
  - protocol: HTTPS
    port: 443
   hostname: foo.example.com
   tls:
      certificateRefs:
      - kind: Secret
        group: ""
        name: foo-example-com-cert

```

---

<div class="post-metadata">

**Author:** ![Mario\_Filipe](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/mario_filipe/32/17300_2.png) [@Mario\_Filipe](https://discuss.kubernetes.io/u/Mario_Filipe)\
**Post date:** [May 20, 2025, 11:50pm UTC](https://discuss.kubernetes.io/t/how-to-set-gatteway-api-with-https-tls-cert/32347/2 "2025-05-20T23:50:30Z")

</div>

Hi Megan\_Liu.  
It’s almost correct:

- some identation is not ok
- listener name is missing

So, the manifest correct would be:

```auto
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: example-gateway
spec:
  gatewayClassName: example-class
  listeners:
	- protocol: HTTPS
	  name: https
	  port: 443
	  hostname: foo.example.com
	  tls:
		mode: Terminate
		certificateRefs:
		  - kind: Secret
			group: "" # Can be omitted if it is from the main API group (empty by default)
			name: tls-secret

```

But, a gateway is just a piece.  
If you need to test something like: curl -k [https://foo.example.com:30080](https://foo.example.com:30080), you must have the following components for your gateway it works:

1. install all gateway CRD/controllers (typically are already installed)
2. replace “example-class” by the correct name (give this command and use name under “NAME” column: kubectl get [gatewayclasses.gateway.networking.k8s.io](http://gatewayclasses.gateway.networking.k8s.io))
3. create a TLS secret (please run: ‘kubectl create secret tls --help’, to see more details how to create it)
4. create a deployment or at least a pod (I suggest with nginx image, just to test)
5. create a service to expose the app for the previous step
6. create HTTPRoute object

After create the gateway you referred you should create an http route to test; I suggest something like this:

```auto
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: example-httproute
spec:
  parentRefs:
  - name: example-gateway
  hostnames:
  - "foo.example.com"
  rules:
  - matches:
	- path:
		type: PathPrefix
		value: /
	backendRefs:
	- name: example-svc
	  port: 8080 # assuming that the service created in the step 5, was create with port=8080

```

Be sure that your gateways CRDs included a serviço of type NodePort where you can get the right port to test.  
For that, you can run this command: kubectl get svc -A| grep gateway| grep NodePort

Get the IP of one of your nodes (command: kubectl get nodes -o wide) and add the name [foo.example.com](http://foo.example.com) in your /etc/hosts in the line that corresponds to the node IP.

Finelly you can test the url with: curl -k [https://foo.example.com:30080](https://foo.example.com:30080) (the port may difer)  
and you will nginx default page 🙂

I hope it helps! 🙂
