The requirement is that traffic remain encrypted all the way from the external client to the backend Service . Therefore, TLS must not terminate at the Cilium Gateway/Envoy proxy .
With TLS Passthrough , Cilium forwards the encrypted TLS stream to the backend without decrypting the application traffic. Envoy can inspect the TLS ClientHello/SNI sufficiently to select the appropriate backend, but the TLS session itself continues to the Service. Cilium specifically supports TLS passthrough with the Gateway API TLSRoute resource .
By contrast, TLS Terminate + HTTPRoute decrypts the connection at the Gateway. Although a separate encrypted connection to the backend can be configured in some architectures, that is not the same as preserving the original end-to-end TLS session requested here. Cilium's HTTPS Gateway examples use TLS termination when the Gateway itself handles the certificate.
Study Guide topic: Service Mesh.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit