TLS and Path Routing

TLS Termination and Path-Based Routing

With mode: Terminate the Gateway decrypts HTTPS with the certificate in a kubernetes.io/tls Secret and forwards plain HTTP; Passthrough hands the encrypted stream to a TLSRoute backend that holds its own key. A self-signed certificate serves the local cluster:

A self-signed certificate for books.example.com, stored as a TLS SecretShell
openssl req -x509 -newkey rsa:2048 -nodes -days 90 -subj /CN=books.example.com \
  -addext subjectAltName=DNS:books.example.com -keyout ~/books.key -out ~/books.crt 2>/dev/null
kubectl create secret tls books-tls --cert=$HOME/books.crt --key=$HOME/books.key
Output
secret/books-tls created

In production, cert-manager 90,581 (github.com/cert-manager/cert-manager (https://github.com/cert-manager/cert-manager 14,093 ), Apache-2.0, v1.21.2) fills that Secret from Let's Encrypt 1,144 when you annotate the Gateway with an issuer, and renews it. A RequestRedirect filter (scheme: https) on the port-80 listener's route sends visitors to HTTPS.

Path matches are Exact, PathPrefix (element-wise) or RegularExpression (syntax defined by each implementation). When several rules match, the most specific wins: exact before prefix, longer prefix before shorter, then method, header and query matches. So BookNest's catch-all rule never swallows /api/books.