This message was deleted.
# k3s
This message was deleted.
that should work as far as I can tell, but both Traefik v1 and Kubernetes 1.20 are end of support so there probably aren’t too many folks poking at that any more.
🎯 1
The last version of the v1 chart we shipped was v1.81, so the values might be different than what you’re using?
hmm no, looks like it’s still ssl.cipherSuites
Thanks for the 👀 Brad. We’re working on the move to k8s 1.21 and traefik v2 soon, so hopefully setting a custom set of ciphers goes more smoothly with that version.
in the mean time I would probably just go look at what the chart is doing - see what the resulting config looks like in the cluster
The resulting config looks good as far as I can tell:
Copy code
kubectl -n kube-system get cm traefik -o yaml
apiVersion: v1
  traefik.toml: |
    # traefik.toml
    logLevel = "info"
    defaultEntryPoints = ["http","https"]
      address = ":80"
      compress = true
      address = ":443"
      compress = true
          minVersion = "VersionTLS12"
          cipherSuites = [
          CertFile = "/ssl/tls.crt"
          KeyFile = "/ssl/tls.key"
can you hit the pod directly and get a TLS response?
Looks like yes:
Copy code
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server key exchange (12):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256
might be something with the service then? Is it passing health checks? Do you see the pod IP in the endpoints list for the service?
Checks passing, traefik pod IP is present in the traefik load balancer service endpoints list 👍
hmm. You just can’t hit it on the node port?