# Kong Ingress Controller HTTPS AWS ACM

**URL:** <https://discuss.konghq.com/t/kong-ingress-controller-https-aws-acm/8311>\
**Category:** Questions\
**Tags:** kubernetes\
**Created:** [April 28, 2021, 3:18pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-https-aws-acm/8311 "2021-04-28T15:18:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lucao](https://avatars.discourse-cdn.com/v4/letter/l/d2c977/32.png) [@lucao](https://discuss.konghq.com/u/lucao)\
**Post date:** [April 28, 2021, 3:18pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-https-aws-acm/8311/1 "2021-04-28T15:18:07Z")

</div>

Hi guys, I have a problem with HTTPS connections when i pass the annotation of AWS to use my certificate on ACM service.  
When I try to connect in my NLB using http request I received the return from kong running on my eks cluster, but when I try the https request i received erro 400:

> 400 Bad Request The plain HTTP request was sent to HTTPS port

---

<div class="post-metadata">

**Author:** ![lucao](https://avatars.discourse-cdn.com/v4/letter/l/d2c977/32.png) [@lucao](https://discuss.konghq.com/u/lucao)\
**Post date:** [April 28, 2021, 3:21pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-https-aws-acm/8311/2 "2021-04-28T15:21:56Z")

</div>

This is my code, sry, I can’t put it in the post.

This is my code from service kong-proxy:  
apiVersion: v1  
kind: Service  
metadata:  
annotations:  
`service.beta.kubernetes.io/aws-load-balancer-backend-protocol: tcp`  
`service.beta.kubernetes.io/aws-load-balancer-type: nlb`  
`service.beta.kubernetes.io/aws-load-balancer-ssl-cert: [my-certificate]`  
` service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "443"`  
` service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: '*'`  
name: kong-proxy  
namespace: kong  
spec:  
ports:

- name: proxy  
port: 80  
protocol: TCP  
targetPort: 8000
- name: proxy-ssl  
port: 443  
protocol: TCP  
targetPort: 8443  
selector:  
app: ingress-kong  
type: LoadBalancer

Can u can help me with ideas? Thx!

---

<div class="post-metadata">

**Author:** ![shane](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/shane/32/2433_2.png) [@shane](https://discuss.konghq.com/u/shane)\
**Post date:** [June 4, 2021, 1:37pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-https-aws-acm/8311/3 "2021-06-04T13:37:16Z")

</div>

Do you have verbose HTTP response output available? e.g.: curl -vvv $URL

---

<div class="post-metadata">

**Author:** ![jrowinski3d](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jrowinski3d/32/3393_2.png) [@jrowinski3d](https://discuss.konghq.com/u/jrowinski3d)\
**Post date:** [April 14, 2022, 6:13pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-https-aws-acm/8311/4 "2022-04-14T18:13:37Z")

</div>

Hi there, I too am noticing this issue. @shane here is my **verbose** output. I redacted some info from the response.

```auto
* Connected to XXXXXX.com (123.123.123.123) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/cert.pem
* CApath: none
* (304) (OUT), TLS handshake, Client hello (1):
* (304) (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server key exchange (12):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256
* ALPN, server did not agree to a protocol
* Server certificate:
* subject: CN=*.XXXXX.com. < ACM arn certificate loaded properly with appropriate hostname
* start date: Jan 20 00:00:00 2022 GMT
* expire date: Feb 18 23:59:59 2023 GMT
* issuer: C=US; O=Amazon; OU=Server CA 1B; CN=Amazon
* SSL certificate verify ok.
> POST /auth HTTP/1.1
> Host: XXXXX.com
> User-Agent: curl/7.79.1
> accept: application/json
> Content-Type: application/json
> Content-Length: 76
> 
* Mark bundle as not supporting multiuse
< HTTP/1.1 400 Bad Request
< Date: Thu, 14 Apr 2022 18:10:35 GMT
< Content-Type: text/html; charset=UTF-8
< Content-Length: 220
< Connection: close
< X-Kong-Response-Latency: 0
< Server: kong/2.8.0
< 
<html>
<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
<body>
<center><h1>400 Bad Request</h1></center>
<center>The plain HTTP request was sent to HTTPS port</center>
</body>
</html>
* Closing connection 0
* TLSv1.2 (IN), TLS alert, close notify (256):
* TLSv1.2 (OUT), TLS alert, close notify (256):

```

My **Service** is setup the same way as @lucao

Also to note, **HTTP** works correctly but ideally I have to re-route to HTTP(S)

Output from Kong:

```auto
[ingress-kong-558cd9dd85-4rrxv proxy] 2022/04/14 18:16:40 [warn] 1109#0: *10527 using uninitialized "kong_proxy_mode" variable while logging request, client: 10.0.154.134, server: kong, request: "POST /auth HTTP/1.1", host: "XXXXX.com" 
[ingress-kong-558cd9dd85-4rrxv proxy] 2022/04/14 18:16:40 [warn] 1109#0: *10527 [lua] reports.lua:83: log(): [reports] could not determine log suffix (scheme=http, proxy_mode=) while logging request, client: 10.0.154.134, server: kong, request: "POST /auth HTTP/1.1", host: "XXXX.com" 
[ingress-kong-558cd9dd85-4rrxv proxy] 10.0.154.134 - - [14/Apr/2022:18:16:40 +0000] "POST /auth HTTP/1.1" 400 220 "-" "curl/7.79.1"

```

---

<div class="post-metadata">

**Author:** ![jrowinski3d](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jrowinski3d/32/3393_2.png) [@jrowinski3d](https://discuss.konghq.com/u/jrowinski3d)\
**Post date:** [April 14, 2022, 9:23pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-https-aws-acm/8311/5 "2022-04-14T21:23:13Z")

</div>

Just an update from my side, I managed to get **NLB** to work.

```auto
apiVersion: v1
kind: Service
metadata:
  annotations:
    external-dns.alpha.kubernetes.io/hostname: XXX.com
    service.beta.kubernetes.io/aws-load-balancer-backend-protocol: https
    service.beta.kubernetes.io/aws-load-balancer-ssl-cert: XXX
    service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "443"
    service.beta.kubernetes.io/aws-load-balancer-type: nlb
  name: kong-proxy
  namespace: kong
spec:
  ports:
  - name: proxy
    port: 80
    protocol: TCP
    targetPort: 8000
  - name: proxy-ssl
    port: 443
    protocol: TCP
    targetPort: 8000
  selector:
    app: ingress-kong
  type: LoadBalancer

```

If I try to setup my Downstream Service to enforce HTTPS and return a redirect, I get an endless redirect loop. I suspect its due to me switching the targetPort of the ssl config to 8000. Debugging continues.
