# Ssl-policy annotations with AWS NLB in Kong Ingress Controller

**URL:** <https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088>\
**Category:** Questions\
**Tags:** kubernetes\
**Created:** [March 23, 2021, 6:37pm UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088 "2021-03-23T18:37:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pulpo](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/pulpo/32/2654_2.png) [@pulpo](https://discuss.konghq.com/u/pulpo)\
**Post date:** [March 23, 2021, 6:37pm UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088/1 "2021-03-23T18:37:58Z")

</div>

I was not able to find a way to pass a annotation for kong ingress to change the default ssl policy for the listener, by default is using the `ELBSecurityPolicy-2016-08` value, described as default at AWS’s documentation [Create an HTTPS listener for your Application Load Balancer - Elastic Load Balancing](https://docs.aws.amazon.com/elasticloadbalancing/latest/application/create-https-listener.html#describe-ssl-policies)

I’ve found that kubernetes-sig has some implementation for that using the annotation ssl-policy [https://kubernetes-sigs.github.io/aws-load-balancer-controller/guide/ingress/annotations/#ssl-policy](https://kubernetes-sigs.github.io/aws-load-balancer-controller/guide/ingress/annotations/#ssl-policy)

Has kong some kind of annotation to tell AWS to change the ssl-policy?

---

<div class="post-metadata">

**Author:** ![traines](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/traines/32/158_2.png) [@traines](https://discuss.konghq.com/u/traines)\
**Post date:** [March 29, 2021, 11:14pm UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088/2 "2021-03-29T23:14:35Z")

</div>

Were you actually able to create an ALB? As best I know, the AWS cloud provider only creates ALBs if you’re using their ingress controller. Services that request a LoadBalancer directly (such as the Kong proxy Service) are limited to L4 NLBs, and those annotations won’t apply.

For Kong, that type of configuration is set via [various TLS configuration settings in kong.conf](https://github.com/Kong/kong/blob/2.3.3/kong.conf.default#L490-L547) or equivalent environment variables, not per-Ingress.

---

<div class="post-metadata">

**Author:** ![pulpo](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/pulpo/32/2654_2.png) [@pulpo](https://discuss.konghq.com/u/pulpo)\
**Post date:** [March 30, 2021, 1:19pm UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088/3 "2021-03-30T13:19:29Z")

</div>

Sorry if my text was confusing, as it stands in the tittle what was created was a NLB (Network Load Balancer), my point was that the listener that AWS creates when I apply the manifest, use the default TLS configuration, and since I configuared the certificate in use by the listeners using an annotation ([service.beta.kubernetes.io/aws-load-balancer-ssl-cert](http://service.beta.kubernetes.io/aws-load-balancer-ssl-cert)) I thought that the place to configure the protocol of the listeners was the same place.

I made a test changing the listeners **ssl-policy** from AWS [according to their documentation](https://docs.aws.amazon.com/elasticloadbalancing/latest/application/listener-update-certificates.html) and no weak cypher was used in the communication, but I had to do it manually, and was not able to found a place to do it from the manifest itself.

As much as I understand, changing values in kong.conf will not affect the NLB’s listeners configurations, because the problem I found is the use of a weak algorithm into the listener itself.

---

<div class="post-metadata">

**Author:** ![traines](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/traines/32/158_2.png) [@traines](https://discuss.konghq.com/u/traines)\
**Post date:** [March 31, 2021, 11:40pm UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088/4 "2021-03-31T23:40:37Z")

</div>

The title and body were referencing different things and I looked more at the latter. [Annotations - AWS LoadBalancer Controller](https://kubernetes-sigs.github.io/aws-load-balancer-controller/guide/ingress/annotations/#ssl-policy) is listing annotations that can be applied to an Ingress resource when using AWS’s controller, which spawns ALBs and configures them per-Ingress.

When you use our controller, any AWS LB configuration is instead set at the Service level, on the Service that requests a LoadBalancer for our proxy. If you’re using an NLB that handles TLS termination (the manual change to AWS configuration making a difference implies you are), the `service.beta.kubernetes.io/aws-load-balancer-ssl-negotiation-policy` from [Annotations - AWS LoadBalancer Controller](https://kubernetes-sigs.github.io/aws-load-balancer-controller/guide/service/annotations/) should be the equivalent Service-level annotation.

If you’re using an NLB that _doesn’t_ terminate TLS, Kong is the first TLS-capable hop the client would hit, and that’s when the kong.conf settings would apply.

---

<div class="post-metadata">

**Author:** ![pulpo](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/pulpo/32/2654_2.png) [@pulpo](https://discuss.konghq.com/u/pulpo)\
**Post date:** [April 11, 2021, 2:03pm UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088/5 "2021-04-11T14:03:52Z")

</div>

Right,I’ve the problem when I use the NLB that handles TLS termination, the annotation doesn’t have effect.

---

<div class="post-metadata">

**Author:** ![erikhh](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/erikhh/32/2641_2.png) [@erikhh](https://discuss.konghq.com/u/erikhh)\
**Post date:** [April 14, 2021, 9:17am UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088/6 "2021-04-14T09:17:45Z")

</div>

I used to have similar problems with our setup. In the end I found it a lot easier to take the NLB out of the equation and let Kong do the TLS termination. It has the added benefit that you can do all certificate management within Kubernetes as well which is fully automated with Let’s Encrypt without any DNS records hassle and such. It’s really quite wonderful 🙂

I found the setup of cert-manager is really surprisingly straightforward. And the Kong part is documented here in great detail: [Using cert-manager for automated TLS certificate - v1.2.x | Kong - Open-Source API Management and Microservice Management](https://docs.konghq.com/kubernetes-ingress-controller/1.2.x/guides/cert-manager/) from there you can also find links to the cert-manager setup instructions.

---

<div class="post-metadata">

**Author:** ![traines](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/traines/32/158_2.png) [@traines](https://discuss.konghq.com/u/traines)\
**Post date:** [April 16, 2021, 11:11pm UTC](https://discuss.konghq.com/t/ssl-policy-annotations-with-aws-nlb-in-kong-ingress-controller/8088/7 "2021-04-16T23:11:22Z")

</div>

> [@pulpo](#):
>
> when I use the NLB that handles TLS termination, the annotation doesn’t have effect.

If the Service annotation isn’t working, check with AWS support. We don’t have any view into the code EKS uses to provision an LB according to the annotations on a Service, so while we can suggest the annotation that looks correct, we can’t diagnose issues where the provisioned LB doesn’t actually honor that request.
