# Enable https with nginx-ingress, cert-manager and letsencrypt

**URL:** <https://discourse.jupyter.org/t/enable-https-with-nginx-ingress-cert-manager-and-letsencrypt/4157>\
**Category:** Zero to JupyterHub on Kubernetes\
**Created:** [April 26, 2020, 3:35pm UTC](https://discourse.jupyter.org/t/enable-https-with-nginx-ingress-cert-manager-and-letsencrypt/4157 "2020-04-26T15:35:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![edoladin98](https://avatars.discourse-cdn.com/v4/letter/e/9dc877/32.png) [@edoladin98](https://discourse.jupyter.org/u/edoladin98)\
**Post date:** [April 26, 2020, 3:35pm UTC](https://discourse.jupyter.org/t/enable-https-with-nginx-ingress-cert-manager-and-letsencrypt/4157/1 "2020-04-26T15:35:01Z")

</div>

Hello,  
I have followed the documentation to enable a nginx-ingress and it is working : [https://zero-to-jupyterhub.readthedocs.io/en/latest/administrator/advanced.html#ingress](https://zero-to-jupyterhub.readthedocs.io/en/latest/administrator/advanced.html#ingress)

Then i wanted to enable https but the documentation refers to kube-lego which is deprecated :  
[https://zero-to-jupyterhub.readthedocs.io/en/latest/administrator/advanced.html#ingress-and-automatic-https-with-kube-lego-let-s-encrypt](https://zero-to-jupyterhub.readthedocs.io/en/latest/administrator/advanced.html#ingress-and-automatic-https-with-kube-lego-let-s-encrypt)

I tried to use cert-manager instead, installed with helm, but without success. Did anyone manage to do that?

---

<div class="post-metadata">

**Author:** ![jorgecarleitao](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/jorgecarleitao/32/2544_2.png) [@jorgecarleitao](https://discourse.jupyter.org/u/jorgecarleitao)\
**Post date:** [August 9, 2020, 4:57am UTC](https://discourse.jupyter.org/t/enable-https-with-nginx-ingress-cert-manager-and-letsencrypt/4157/2 "2020-08-09T04:57:55Z")

</div>

Yes.

This assumes that you have correctly installed cert-manager with a cluster-issuer named `letsencrypt-prod`, using nginx ingress.

The following configuration is sufficient:

```auto
ingress:
  enabled: true
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/ssl-redirect: "false"
    cert-manager.io/cluster-issuer: letsencrypt-prod
  hosts:
    - notebook.example.com
  tls:
    - hosts:
      - notebook.example.com
      secretName: a_secret_name

proxy:
  service:
    type: ClusterIP
  https:
    enabled: false
  secretToken: 'something entropic'

```

---

<div class="post-metadata">

**Author:** ![salvis2](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/salvis2/32/2235_2.png) [@salvis2](https://discourse.jupyter.org/u/salvis2)\
**Post date:** [August 21, 2020, 11:00pm UTC](https://discourse.jupyter.org/t/enable-https-with-nginx-ingress-cert-manager-and-letsencrypt/4157/3 "2020-08-21T23:00:02Z")

</div>

Sounds similar to the Zero-to-BinderHub HTTPS setup: [https://binderhub.readthedocs.io/en/latest/https.html](https://binderhub.readthedocs.io/en/latest/https.html)
